Build with the API
Connect an AI agent (MCP)
Let Claude Code, Claude Desktop or Cursor list files, read reports and upload data with an API key.
Gridline speaks the Model Context Protocol (MCP), so an AI agent such as Claude Code, Claude Desktop or Cursor can work with your company's data: list files, read quality reports, compare versions and upload new data. It uses the same services as the dashboard and the REST API, so access, quotas and the audit log work exactly as they do there.
Connect an agent
- Create an API key (Developers → API keys) with the
mcpscope, plus the scopes for what the agent may do. - Give the key to your agent's MCP client.
With Claude Code:
claude mcp add --transport http gridline https://gridline-data-analysis-app.duckdns.org/api/mcp \
--header "Authorization: Bearer gl_live_…"Any client that supports Streamable HTTP and a bearer header works the same way. Behind the proxy the address is /api/mcp; reached directly it is /mcp.
What the agent can see
The agent is offered only the tools its key may use. A key acts as the person who created it, as they are right now: demote or disable them and the agent changes with them on its next call. A key is never more powerful than its owner or its scopes.
| Scope | Tools it adds |
|---|---|
mcp | Lets the key use the endpoint at all. |
files:read | list_files, get_file, list_file_versions, get_quality_report, preview_file, compare_versions, list_comments, get_plan_and_quota, list_quality_rules |
files:write | upload_file, upload_file_version, rebuild_quality_report |
rules:write (admins) | create_quality_rule, update_quality_rule, delete_quality_rule |
billing:read (admins) | get_current_bill, list_invoices, get_invoice |
audit:read (admins) | list_audit_log, get_audit_entry |
notifications:read | list_notifications, get_unread_count, mark_notifications_read |
Uploading through an agent
An agent sends a file as plain text (for a CSV) or as base64 (for any spreadsheet), up to 8 MB. Larger files go through POST /files. What the file is gets decided from its content, never its name, exactly as for any upload. It counts against your plan's file quota, and a refusal says why.
If a call times out, the agent repeats it with the same idempotencyKey (any UUID): it cannot upload twice. See Idempotent requests.
The record
Everything an agent changes is written to the audit log with via: "mcp" and the key that acted, so you can see what an agent did and when. The read-only demo company offers agents no write tools at all.
What an agent cannot do
Comments, people, plans and payment, API keys, webhooks, deleting files and changing who can see one stay with a signed-in person. Revoke the key and the agent is cut off immediately.