AI Assistants (MCP)
EOS Hub has an MCP server, so AI assistants such as Claude, ChatGPT or Claude Code can work with your EOS data. You can ask "What are my open to-dos and how did our Scorecard do this week?", or "Add an issue about the delayed release to the Leadership Team", and the assistant answers from EOS Hub or makes the change for you.
MCP (Model Context Protocol) is the open standard AI assistants use to connect to other applications.
INFO
An assistant works with your rights, never more. It sees and changes exactly what you can see and change in the web app, and only in organizations that allow AI assistants. A Read only connection cannot change anything.
Before You Start: the Organization Must Allow It
AI assistants are off in every organization until an Owner or Admin allows them:
- Open Organization settings > General.
- Turn on Allow AI assistants (MCP) and confirm.
While it is off, assistants don't see the organization at all; your other organizations are not affected. Switching it off takes effect immediately and keeps everyone's connections, so switching it back on restores access.
The platform operator can also switch MCP off for the whole platform (Platform > MCP), for example during an incident.
Connecting an Assistant
Open Settings > AI assistants (MCP) and copy the Server URL. It is your EOS Hub address followed by /mcp, for example https://eoshub.pixon.eu/mcp.
Claude (claude.ai and Claude Desktop)
- In Claude open Settings > Connectors and choose Add custom connector.
- Enter a name (for example EOS Hub) and paste the server URL.
- Click Connect. A window with EOS Hub opens.
- Sign in to EOS Hub, with Google or your password, unless you are signed in already.
- Review the request and click Allow (see The Consent Screen).
The window closes and Claude can use EOS Hub. On a Team or Enterprise plan, an owner of the Claude organization may have to add the connector first.
ChatGPT
- In ChatGPT open Settings > Apps & Connectors > Advanced settings and turn on Developer mode.
- Create a connector with the server URL and OAuth authentication.
- Sign in to EOS Hub and click Allow.
Claude Code
Run:
claude mcp add --transport http eos-hub https://eoshub.pixon.eu/mcpThen type /mcp in Claude Code, choose eos-hub and sign in to EOS Hub in the browser window that opens.
Other Tools and Scripts (API Key)
Tools that can't sign in through a browser can use an API key instead. They send it in the Authorization: Bearer ak_… header to the server URL. The key's access (read only or read & write) applies, as on the REST API.
The Consent Screen
When an assistant connects, EOS Hub shows what it is asking for:
- The app's name and where you will return, for example claude.ai. The app chooses its own name, so check the address: if you didn't start the connection yourself, click Deny.
- Access:
- Read only: the assistant can read to-dos, issues, Rocks, Scorecards, meetings and the V/TO.
- Read and change: it can also create and update to-dos, issues, Rocks, Scorecard values and meeting notes.
- Platform administration (platform operators only, unticked by default): read the platform's organizations and users.
- Your organizations, each marked as available or switched off for AI assistants.
What an Assistant Can Do
| Area | Read | Change (Read and change) |
|---|---|---|
| Orientation | who you are, your organizations and teams with your roles, today, the current Scorecard week and quarter; a team overview | — |
| To-dos | your to-dos across teams, a team's to-dos, overdue ones | create, edit, complete, reopen, delete |
| Issues | a team's issues by status or priority | create, edit, change status (Open, Solving, Solved), delete |
| Rocks | team and company Rocks with milestones | create, edit, report status (on/off track, done), add and complete milestones, delete |
| Scorecard | metrics with goals and the last 1–26 weeks | enter or clear a week's value (met or missed follows from the goal) |
| Meetings | meetings with ratings, segues, headlines and cascading messages | add a headline or cascading message, rate a meeting |
| Reference | V/TO, Accountability Chart, People Analyzer, documents | — |
| Platform (operators) | organizations, users | — |
Some things stay in the web app and the REST API: running an L10 meeting step by step, defining Scorecard metrics, editing the V/TO and the Accountability Chart, People Analyzer entries, documents, and organization and platform settings.
There is also a ready-made prompt, Prepare a Level 10 meeting. In Claude, pick it from the connector's prompts and enter the team. The assistant gathers the Scorecard, Rocks, overdue to-dos and open issues and drafts the agenda.
Deleting asks for confirmation in most assistants; EOS Hub marks those actions as destructive.
Managing Connections
Settings > AI assistants (MCP) > Connected apps lists every assistant you connected, with its access, when it was connected and when it was last used. Click Disconnect (the plug icon) to end a connection: the assistant loses access immediately.
Connecting the same app again replaces its earlier connection.
The platform operator sees each user's connection count in Platform > Users and can disconnect a connection there, for example if a device was lost.
Security
- EOS Hub uses OAuth 2.1 with PKCE. Your password or Google account is never shared with the assistant, which only gets tokens issued by EOS Hub.
- Access tokens are valid for one hour. The assistant renews them with a refresh token that is valid for 30 days and replaced on every renewal. If an old refresh token is ever used again, EOS Hub assumes it was copied and ends the connection.
- Tokens work only for the MCP server, never for the REST API, and EOS Hub stores only fingerprints (hashes) of them.
- Your access follows your current roles. If you are removed from a team or an organization, the assistant loses that access at once. A suspended organization is read only.
Troubleshooting
| Problem | What to do |
|---|---|
| The assistant sees no organization | An Owner or Admin must allow AI assistants in Organization settings > General. The settings page lists your organizations where it is still off. |
| "This connection can't be set up" | The app asked to return to an address it didn't register. Start the connection again from the app. |
| "AI assistants are switched off" | The platform operator switched MCP off. Try again later. |
| An action fails with forbidden | Your role doesn't allow it (for example, a Viewer can't add to-dos), or the connection is Read only. |
| An action fails with orgSuspended | The organization is suspended and read only. |
| The assistant stops working after a while | The connection was disconnected or expired after 30 days without use. Connect again. |