Automate with the API & MCP server
Trigger checks, read results, and act on recommendations from your own tools — everything the dashboard shows is also reachable from a script, an integration, or an AI assistant.
What you get
- Workspace-scoped API tokens with fine-grained scopes, so a reporting script and a run-triggering integration can carry different permissions.
- A REST API covering the core workflow: trigger a run, list recommendations and alerts, read run results.
- An MCP server so AI assistants that speak the Model Context Protocol can drive your workspace directly, on Max and Enterprise.
Mint a workspace API token
- Open Settings → API keys.
- Create a token and choose only the scopes it needs — read-only for a reporting script, run-trigger for an automation that kicks off checks.
- Copy the token once; it's shown only at creation.
Use the REST API
The public REST API is documented at API docs, with authentication and every endpoint's request and response shape. It uses the same workspace tokens you mint above, so an integration never has more access than the scopes you granted it.
Connect an AI assistant with MCP
On Max and Enterprise, the built-in MCP server lets an AI assistant call your workspace's tools directly — see the MCP server guide for setup. Assistants connect with a workspace token or, for clients that support it, an OAuth sign-in where a workspace member approves access at a consent screen before anything can be read or changed.
Tips
- Scope tokens narrowly and rotate them like any other credential — a leaked read-only token can't trigger a run.
- Name each token for what uses it, so a stale integration is easy to spot on the list.
Go further
- Send alerts to Slack — route the same events into a channel instead of polling the API.
- Manage & switch workspaces — API tokens are scoped per workspace.
- Billing & credits basics — which tiers include the MCP server.

