MCP server
Sealcord’s MCP server lets an AI assistant work with your organization. It can look up a customer’s licences and machines, issue, revoke, expire and reinstate licences, free seats, see your payment integrations and manage their Polar mappings, see your organization and manage its team, and see your webhook endpoints and their deliveries. The tools page lists each one.
The server is a client of the Admin API, so every rule, scope and limit stays the API’s. It reaches only your own organization.
The server is at https://mcp.sealcord.com/mcp. It speaks Streamable HTTP, so any client that
supports remote MCP servers can connect.
Connect with your sign-in
Section titled “Connect with your sign-in”The assistant signs in through the Console, where you choose what it may do.
Claude Code
claude mcp add --transport http sealcord https://mcp.sealcord.com/mcpThen run /mcp in Claude Code, pick sealcord and choose Authenticate. A browser opens on the
Console. Sign in as a developer with your passkey or an emailed link (a code sign-in cannot grant
access), check what the assistant asks for, untick what it should not have, and choose Allow.
Claude Code keeps the tokens and refreshes them, so there is nothing to copy.
Claude Desktop and claude.ai
Open Settings, then Connectors, then Add custom connector. Enter the URL
https://mcp.sealcord.com/mcp, leave the client id empty, connect, and sign in the same way.
Any other client
A client that implements the MCP authorization specification only needs the URL. It finds the
sign-in server from the server’s 401 answer, and runs the authorization code flow with PKCE.
What you can grant
Section titled “What you can grant”What you may grant depends on your role. Owners and admins can grant every scope except
products:write and licences:anonymise; support and read-only members can grant read scopes. The grant is for the
organization your session acts in: the assistant sees and changes that organization’s products,
licences and team, and nothing else.
An assistant you connected before a scope existed keeps what you granted then. To grant a new
scope, connect it again. In Claude Code, run /mcp, pick sealcord and authenticate again.
Actions an assistant takes with your sign-in are recorded in the licence’s audit log as you, made through the MCP server.
Connect with an admin API key
Section titled “Connect with an admin API key”For scripts, or a client you configure by hand, send an admin API key. Give it the fewest
scopes the job needs. The key’s scopes decide what the assistant can
do: a read-only key gives a read-only assistant. A key without licences:write makes every
licence and machine write tool fail with insufficient_scope.
Name the key after the assistant, so its actions are easy to find in the audit log and it can be revoked alone.
Claude Code
claude mcp add --transport http sealcord https://mcp.sealcord.com/mcp \ --header "Authorization: Bearer $SEALCORD_TOKEN"Or in .mcp.json, keeping the key in your environment:
{ "mcpServers": { "sealcord": { "type": "http", "url": "https://mcp.sealcord.com/mcp", "headers": { "Authorization": "Bearer ${SEALCORD_TOKEN}" } } }}Claude Desktop with a key
Its custom connectors cannot send a fixed header, so bridge with
mcp-remote in claude_desktop_config.json. Keep the
spaces out of args:
{ "mcpServers": { "sealcord": { "command": "npx", "args": [ "-y", "mcp-remote", "https://mcp.sealcord.com/mcp", "--transport", "http-only", "--header", "Authorization:${SEALCORD_AUTH}" ], "env": { "SEALCORD_AUTH": "Bearer sc_…" } } }}The key sits in that file in plain text. Use a read-only or short-lived key there, or connect with your sign-in instead.
What it cannot do
Section titled “What it cannot do”- Connect, check or disconnect a payment integration, or see a provider token or a webhook secret. Those stay in the Console.
- Add, change or remove a webhook endpoint, or replace its secret. An assistant can read endpoints and deliveries and retry a delivery.
- Create or change products, or rotate a signing key. A wrong rotation breaks apps you already shipped, so use the Admin API or the Console.
- Anonymise a licence. It cannot be undone, so it needs the
licences:anonymisescope, which no assistant is granted. - Rename, delete or transfer the organization.
- Change the team without a person.
members:writeis granted only to an assistant you sign in, never to an API key, and each change runs as you, with your role at that moment.
Limits
Section titled “Limits”The server accepts 120 requests a minute per client address. A key the API refused is answered
401 for 5 minutes without being checked again.
Licence keys are secrets that belong to your customers. Only sealcord_get_licence_key and
sealcord_issue_licence return one. Anything a tool returns enters the assistant’s context, so
prefer the read tools that do not return keys.
Questions
Section titled “Questions”Is it safe to connect an assistant?
Section titled “Is it safe to connect an assistant?”The assistant can do exactly what you grant, or what its key’s scopes allow, and nothing more. Grant read scopes for support questions, and ask the assistant to confirm before any tool that revokes, expires, frees a seat or changes your team.
Can an assistant see my customers’ licence keys?
Section titled “Can an assistant see my customers’ licence keys?”Only if it holds licences:read and calls sealcord_get_licence_key, or issues a licence. The
other tools leave keys out.
Does an assistant act as me?
Section titled “Does an assistant act as me?”When you sign in, yes: its actions are recorded as you, through the MCP server, and held to your role. With an API key, they are recorded as that key.
Which clients work?
Section titled “Which clients work?”Any MCP client that supports Streamable HTTP servers. Claude Code, Claude Desktop and claude.ai are covered above.