For AI agents: a documentation index is available at /llms.txt. A markdown version of this page is available at /guide/mcp/introduction.md.
MCP / AI Connect
Connect Claude, ChatGPT, Cursor or Copilot to Orangescrum over OAuth: 74 tools across projects, tasks, sprints, test management and checklists.
Orangescrum ships a Model Context Protocol server. Point any MCP-compatible client at it, sign in through your browser, and your assistant gains a working set of Orangescrum tools. It can plan a sprint, file a defect, tick off a checklist, log time or search your uploaded documents on your behalf.
#Endpoint
POST https://v4-api.orangescrum.com/mcp/partner
The server speaks JSON-RPC 2.0 over HTTP and authenticates with OAuth 2.1
an Authorization: Bearer token your client obtains for itself. Most clients
need nothing but the URL: they discover the authorization server, register
themselves, and open a browser for you to sign in and pick a workspace.
OAuth, not an API key
This is a change from earlier releases. /mcp/partner no longer accepts the
X-API-KEY header, partner keys still work for the
REST API, but MCP has its own OAuth flow with
per-scope consent. See Authentication for the
full picture, including the legacy key path that remains for in-flight
integrations.
#What your assistant gets
Projects, tasks, backlog hierarchy, sprints, timelogs, users, test management, checklists, context and document search.
💬2 promptsdaily_standup and overdue_report, surfaced as slash commands.
Read-only catalogs the client can attach as context.
#Coverage at a glance
| Domain | Tools | Scopes |
|---|---|---|
| Test management, cases, scenarios, steps, defects | 21 | mcp:tests.read · mcp:tests.write |
| Checklists, catalog, templates, per-item rails | 20 | mcp:checklists.read · mcp:checklists.write |
| Tasks, including statuses and types | 8 | mcp:tasks.read · mcp:tasks.write |
| Sprints | 7 | mcp:sprints.read · mcp:sprints.write |
| Projects | 5 | mcp:projects.read · mcp:projects.write |
| Backlog hierarchy, epic, feature, story, subtask | 4 | mcp:epics.write |
| Timelogs | 3 | mcp:timelogs.read · mcp:timelogs.write |
| Users | 3 | mcp:users.read |
| Project context ("memory") | 2 | mcp:context.read · mcp:context.write |
| Document search (RAG) | 1 | mcp:documents.read |
Full names and descriptions are on the Tools page.
#Supported clients
| Client | How it connects | Config |
|---|---|---|
| Claude.ai / Claude Desktop | Custom connector, paste the URL | No file to edit |
| Claude Code | claude mcp add --transport http | CLI |
| ChatGPT | Custom connector, paste the URL | No file to edit |
| Cursor | Remote HTTP with OAuth | ~/.cursor/mcp.json |
| VS Code + GitHub Copilot | Remote HTTP with OAuth | .vscode/mcp.json |
| OpenAI Codex CLI | Remote HTTP with OAuth | ~/.codex/config.toml |
Full snippets for each are on the Client setup page.
Browser-based connectors now work
Because authentication is OAuth, custom connectors on claude.ai and ChatGPT connect directly. They were not able to before. There is no key to paste into a config file and no shared secret sitting on disk.
#Is this safe to point at production?
Worth deciding deliberately before you connect it:
- The tools include writes. An assistant can create and change real projects, tasks, sprints, defects and timelogs, not just read them.
- Scopes are the boundary. You approve a specific set on the consent screen, and your workspace administrator caps what can ever be asked for. A read-only grant gives you a research assistant that cannot change anything.
- Consent is per workspace. The token is bound to the single workspace you picked when you authorized, so an assistant cannot wander into another one.
- Access can be cut instantly. Revoking the workspace entitlement fails in-flight tokens on their very next request, no waiting for expiry.
- Every call lands in the audit trail with its status code and response time, so you can see exactly what the assistant did.
Tip
Start with read-only scopes against a non-critical workspace, watch the audit log for a few days, then re-authorize with write scopes once you trust the workflows.