Build with the API

Connect an AI agent (MCP)

Let Claude Code, Claude Desktop or Cursor list files, read reports and upload data with an API key.

Gridline speaks the Model Context Protocol (MCP), so an AI agent such as Claude Code, Claude Desktop or Cursor can work with your company's data: list files, read quality reports, compare versions and upload new data. It uses the same services as the dashboard and the REST API, so access, quotas and the audit log work exactly as they do there.

Connect an agent

  1. Create an API key (Developers → API keys) with the mcp scope, plus the scopes for what the agent may do.
  2. Give the key to your agent's MCP client.

With Claude Code:

shell
claude mcp add --transport http gridline https://gridline-data-analysis-app.duckdns.org/api/mcp \
  --header "Authorization: Bearer gl_live_…"

Any client that supports Streamable HTTP and a bearer header works the same way. Behind the proxy the address is /api/mcp; reached directly it is /mcp.

What the agent can see

The agent is offered only the tools its key may use. A key acts as the person who created it, as they are right now: demote or disable them and the agent changes with them on its next call. A key is never more powerful than its owner or its scopes.

ScopeTools it adds
mcpLets the key use the endpoint at all.
files:readlist_files, get_file, list_file_versions, get_quality_report, preview_file, compare_versions, list_comments, get_plan_and_quota, list_quality_rules
files:writeupload_file, upload_file_version, rebuild_quality_report
rules:write (admins)create_quality_rule, update_quality_rule, delete_quality_rule
billing:read (admins)get_current_bill, list_invoices, get_invoice
audit:read (admins)list_audit_log, get_audit_entry
notifications:readlist_notifications, get_unread_count, mark_notifications_read

Uploading through an agent

An agent sends a file as plain text (for a CSV) or as base64 (for any spreadsheet), up to 8 MB. Larger files go through POST /files. What the file is gets decided from its content, never its name, exactly as for any upload. It counts against your plan's file quota, and a refusal says why.

If a call times out, the agent repeats it with the same idempotencyKey (any UUID): it cannot upload twice. See Idempotent requests.

The record

Everything an agent changes is written to the audit log with via: "mcp" and the key that acted, so you can see what an agent did and when. The read-only demo company offers agents no write tools at all.

What an agent cannot do

Comments, people, plans and payment, API keys, webhooks, deleting files and changing who can see one stay with a signed-in person. Revoke the key and the agent is cut off immediately.