Set up MCP
Fieldbook's optional MCP endpoint lets authorized people connect an AI client to content and reporting tools. Operators configure Supabase authorization and client registration; each person signs in and approves the capabilities their account may use.
MCP is optional. It connects external AI clients to Fieldbook content and reporting tools. Ordinary reading, Search and administration work without it; Ask AI is a separate feature.
Configure authorization
First complete installation and Google sign-in. Fresh database setup already includes the MCP tables, functions and token hook.
In the installation's Supabase project:
- Confirm that Site URL matches
FIELDBOOK_URL, and retain the application's/auth/callbackin the redirect list. - Enable Authentication → OAuth Server and set Authorization Path to
/oauth/consent. - Use an asymmetric JWT signing key, such as ES256 or RS256.
- Enable the Custom Access Token hook with the existing SQL function
public.fb_access_token_hook.
See Supabase's OAuth Server setup (opens in a new tab) and signing-key guidance (opens in a new tab).
The hook binds approved client tokens to this installation. Fieldbook records the resource during consent; no manual resource-table entry is needed.
Register and connect a client
Use the registration method your AI client supports:
- Manual: add an OAuth app in Supabase with the client's exact callback, public or confidential type, and token authentication method. Supply its client ID and, for a confidential client only, its secret to the AI client.
- Dynamic: enable dynamic registration only if your client needs to register itself. Registration does not approve Fieldbook tools.
Connect the client to:
https://YOUR-FIELDBOOK-HOST/api/mcpUse the canonical HTTPS origin. Do not supply a Supabase server secret, database password or cleanup credential as an MCP token.
The client callback is separate from Google's Supabase callback and Fieldbook's /auth/callback. Follow Supabase's MCP authentication guidance (opens in a new tab) for registration details.
Approve access
Sign in with an active Administrator, Contributor or scoped Manager account, start the client connection and approve the capabilities you want it to use.
| Account | Available scope |
|---|---|
| Learner | No MCP tools |
| Manager | Reports for explicitly managed teams |
| Contributor | Content, media and feedback; assigned-team reports |
| Administrator | Those tools, assignments and all-team reports |
Access always depends on both the current account and approved connection. The identity scope offline_access allows token refresh; it does not grant Fieldbook tools.
Ask the connected client what it can do, or have it call get_capabilities. Try a relevant read or draft operation to confirm the connection. Publication is a separate action.
Manage or revoke connections at /connections. A promotion to Administrator requires renewed consent.
Routing and changes
A deployment-protection screen can block client discovery. An unauthenticated /api/mcp request normally returns HTTP 401 with authorization metadata.
Clients sending an Origin header must use the canonical site, https://chatgpt.com (opens in a new tab) or https://claude.ai. (opens in a new tab) Other browser-client origins require a software change in the current implementation.
For an address change, update FIELDBOOK_URL, Supabase's Site URL and application callback, then redeploy and reconnect clients at the new endpoint. Update the cleanup destination too. Google's callback changes if the Supabase Auth address changes.
See AI clients and MCP for everyday use. The generated contract (opens in a new tab) describes tool inputs and supported operations.