diff --git a/go/generated/guides/asana/meta.yaml b/go/generated/guides/asana/meta.yaml index 491d5b9..d0ae280 100644 --- a/go/generated/guides/asana/meta.yaml +++ b/go/generated/guides/asana/meta.yaml @@ -41,7 +41,7 @@ remotes: locator: https://developers.asana.com/docs/integrating-with-asanas-mcp-server name: Integrating with Asana's MCP Server classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://developers.asana.com/docs/using-asanas-mcp-server name: Using Asana's MCP Server @@ -50,11 +50,11 @@ remotes: - source: endpoint-observation locator: https://mcp.asana.com/v2/mcp classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://mcp.asana.com/.well-known/oauth-protected-resource/v2 classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" provenance: - source: pulsemcp locator: com.pulsemcp.mirror/asana-mcp @@ -66,7 +66,7 @@ provenance: locator: https://developers.asana.com/docs/integrating-with-asanas-mcp-server name: Integrating with Asana's MCP Server classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://developers.asana.com/docs/using-asanas-mcp-server name: Using Asana's MCP Server @@ -115,17 +115,17 @@ provenance: - source: endpoint-observation locator: https://mcp.asana.com/v2/mcp classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://mcp.asana.com/.well-known/oauth-protected-resource/v2 classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://app.asana.com/.well-known/oauth-authorization-server classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-06T23:24:28Z" + observed_at: "2026-09-30T21:30:00Z" diff --git a/go/generated/guides/asana/speakeasy.md b/go/generated/guides/asana/speakeasy.md index b0974b2..a384fc3 100644 --- a/go/generated/guides/asana/speakeasy.md +++ b/go/generated/guides/asana/speakeasy.md @@ -3,62 +3,38 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Select **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **From the catalog**. 4. On the **MCP Catalog** page, find **Asana** using **Search MCP servers...**. -5. Open the **Asana** entry. -6. Select **Add**. -7. In **Add to Project**, select **Add to Project**. +5. Open the **Asana** entry and click **Add**. +6. In the **Add to Project** dialog, under **Identity**, select **User Identity**. The dialog may preselect **No Identity**. +7. Click **Add to Project**. If the dialog offers a **Guardrails** step, finish it or click **Skip for now**. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +Asana needs a client registered by hand, so the result says to finish setup in **Settings > Identity**, and the server stays **Disabled** for now. This is expected. Click **Finish setup** on the server's result to open its **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. +In the server's **Settings**, find the **Identity** section. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm the provider is `https://app.asana.com`. It may be badged **Will be created**. If no provider or a different one is selected, open the picker, search for `app.asana.com` in **Search identity providers…**, and choose it. +3. Under the provider, choose **Manual**. +4. Paste the **Client ID** from [Create the MCP app](external.md#create-mcp-app) into **Client ID**. +5. Paste the **Client secret** from [Create the MCP app](external.md#create-mcp-app) into **Client secret**. Asana requires it, even though the field shows "Optional". +6. Open **Advanced** and enter `default` in **Scope**. Do not add other scopes; Asana rejects them with "Invalid scope(s) requested". +7. Click **Save**. -#### Select the identity provider +This section does not show the redirect URI. Asana accepts the connection only if [Configure the OAuth redirect](external.md#configure-oauth-redirect) registered `{{ gram.oauth.callback_url }}`. -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). +Then turn the server on: -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. +1. In **Settings**, open **Danger Zone**. +2. Under **Server Availability**, turn on **Enable MCP server** so it shows **Enabled**. -For a new provider, enter **Issuer URL** `https://app.asana.com` and keep the auto-derived **Slug**. If discovery does not populate **Endpoints**, enter: +Each user sees Asana's authorization prompt the first time they use the server. -Authorization endpoint: - -```text -https://app.asana.com/-/oauth_authorize -``` - -Token endpoint: - -```text -https://app.asana.com/-/oauth_token -``` - - - -#### Select the session client - -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: - -Do not enter a scope during this setup. - -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Paste the **Client ID** saved in [Create the MCP app](external.md#create-mcp-app) into **Client ID**. -1. Paste the **Client secret** saved in [Create the MCP app](external.md#create-mcp-app) into **Client Secret (optional)**. - -#### Verify the callback and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. - -For the provider-side callback setting, see [Configure the OAuth redirect](external.md#configure-oauth-redirect). - - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Asana's MCP documentation](https://developers.asana.com/docs/using-asanas-mcp-server). diff --git a/go/generated/guides/atlassian/external.md b/go/generated/guides/atlassian/external.md index 2c86c43..5973c4a 100644 --- a/go/generated/guides/atlassian/external.md +++ b/go/generated/guides/atlassian/external.md @@ -17,14 +17,14 @@ You need no Atlassian-side configuration unless your organization restricts OAut 5. Check whether the allowed domains cover this hosted OAuth callback: ``` - https://app.getgram.ai/mcp/remote_login_callback + {{ gram.oauth.callback_url }} ``` 6. If it is not covered, select **Add domain**. 7. Enter this exact custom domain pattern: ``` - https://app.getgram.ai/mcp/remote_login_callback + {{ gram.oauth.callback_url }} ``` 8. Use the submission control shown in the console. diff --git a/go/generated/guides/atlassian/meta.yaml b/go/generated/guides/atlassian/meta.yaml index a364ee3..0730405 100644 --- a/go/generated/guides/atlassian/meta.yaml +++ b/go/generated/guides/atlassian/meta.yaml @@ -22,24 +22,24 @@ documentation: speakeasy: speakeasy.md remotes: - id: rovo - url: https://mcp.atlassian.com/v1/mcp/authv2 + url: https://mcp.atlassian.com/v2/mcp transport: streamable-http authentication: - oauth-dcr provenance: - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/ - name: Getting started with the Atlassian Rovo MCP Server + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/get-started-with-the-atlassian-remote-mcp-server/ + name: Get started with the Atlassian MCP server classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation - locator: https://mcp.atlassian.com/v1/mcp/authv2 + locator: https://mcp.atlassian.com/v2/mcp classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation - locator: https://mcp.atlassian.com/.well-known/oauth-protected-resource/v1/mcp/authv2 + locator: https://mcp.atlassian.com/.well-known/oauth-protected-resource/v2/mcp classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" provenance: - source: pulsemcp locator: query:atlassian @@ -54,82 +54,82 @@ provenance: status: hosted callback confirmed; hosted outbound IP ranges unknown observed_at: "2026-08-07T21:49:51Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/ - name: Getting started with the Atlassian Rovo MCP Server + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/get-started-with-the-atlassian-remote-mcp-server/ + name: Get started with the Atlassian MCP server classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/setting-up-clients/ - name: Setting up clients + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/set-up-clients/ + name: Set up clients classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/authentication-and-authorization/ + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/authentication-and-authorization/ name: Authentication and authorization classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/configuring-oauth-2-1/ - name: Configuring OAuth 2.1 + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/configure-oauth-2-1/ + name: Configure OAuth 2.1 classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/configuring-authentication-via-api-token/ - name: Configuring authentication via API token + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/configure-authentication-via-api-token/ + name: Configure authentication via API token classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/using-with-other-supported-mcp-clients/ - name: Using with other supported MCP clients + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/use-atlassian-rovo-mcp-server/ + name: Use Atlassian Rovo MCP Server classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/security-and-access-policies/docs/control-atlassian-rovo-mcp-server-settings/ + locator: https://support.atlassian.com/security-and-access-policies/docs/control-atlassian-mcp-server-settings/ name: Control Atlassian Rovo MCP server settings classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/ name: Specify IP addresses for product access classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/security-and-access-policies/docs/available-atlassian-rovo-mcp-server-domains/ + locator: https://support.atlassian.com/security-and-access-policies/docs/available-atlassian-mcp-server-domains/ name: Available Atlassian Rovo MCP server domains classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://support.atlassian.com/atlassian-rovo-mcp-server/docs/troubleshooting-and-verifying-your-setup/ - name: Troubleshooting and verifying your setup + locator: https://support.atlassian.com/atlassian-ai-gateway/docs/troubleshoot-and-verify-your-setup/ + name: Troubleshoot and verify your setup classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-marketing locator: https://www.atlassian.com/platform/remote-mcp-server name: Atlassian Rovo MCP server classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation - locator: https://mcp.atlassian.com/v1/mcp/authv2 + locator: https://mcp.atlassian.com/v2/mcp classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation - locator: https://mcp.atlassian.com/.well-known/oauth-protected-resource/v1/mcp/authv2 + locator: https://mcp.atlassian.com/.well-known/oauth-protected-resource/v2/mcp classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation - locator: protected-resource-discovered authorization-server metadata - name: Atlassian authorization-server metadata with DCR registration endpoint + locator: https://auth.atlassian.com/.well-known/oauth-authorization-server/VCeDsk8ZHncYF1g234fKtc4lNipbBhu3 + name: Atlassian path-issuer authorization-server metadata (https://auth.atlassian.com/VCeDsk8ZHncYF1g234fKtc4lNipbBhu3) classification: official - status: authorization, token, and registration endpoints verified from metadata; empty DCR POST returned HTTP 400 - observed_at: "2026-08-07T21:49:51Z" + status: CIMD supported and registration endpoint advertised; anonymous DCR registration returned HTTP 201 + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation locator: https://auth.atlassian.com/.well-known/oauth-authorization-server name: Atlassian base authorization-server metadata classification: official - status: stable base issuer plus authorization and token endpoints verified; no registration endpoint advertised here - observed_at: "2026-08-07T21:49:51Z" + status: base issuer advertises CIMD but no registration endpoint; not the issuer the PRM names + observed_at: "2026-09-30T00:00:00Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-07T21:49:51Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/atlassian/speakeasy.md b/go/generated/guides/atlassian/speakeasy.md index df01446..112e1e2 100644 --- a/go/generated/guides/atlassian/speakeasy.md +++ b/go/generated/guides/atlassian/speakeasy.md @@ -2,68 +2,53 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, find **MCP Gateway** and select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. -If an **Atlassian Rovo** result in the catalog clearly identifies the current remote URL shown below: +If an **Atlassian Rovo** result in the catalog clearly identifies the remote URL shown below: 1. Choose **From the catalog**. 2. On the **MCP Catalog** page, enter `Atlassian` in **Search MCP servers...**. 3. Open that result. 4. Click **Add**. -5. In **Add to Project**, click **Add to Project**. +5. In **Add to Project**, under **Identity**, select **User Identity**. +6. Click **Add to Project**. If the dialog offers a **Guardrails** step, click **Skip for now**. +7. After **Server added successfully**, click **Configure MCP settings**. -If no clearly current **Atlassian Rovo** result appears in the catalog, use the custom remote path: +If no such result appears, use the custom remote path: 1. Choose **Hosted remotely**. 2. On **New remote MCP server**, paste this value into **MCP server URL**: ``` - https://mcp.atlassian.com/v1/mcp/authv2 + https://mcp.atlassian.com/v2/mcp ``` -3. Click **Verify connectivity**, then **Save**. +3. Click **Verify connectivity**. +4. Under **Identity**, keep **User Identity** selected. +5. Click **Save**. -After catalog installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. Saving a custom remote server opens **Overview**; open **Settings** from there. +On save, Speakeasy discovers Atlassian's identity provider and registers a client automatically. When that works, the server is ready. When it cannot, the server is kept **Disabled** and the result says to finish setup in **Settings > Identity**. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server’s **Settings**. +Open the server's **Settings** and find the **Identity** section. If creation already configured the identity, **User Identity** is selected with the Atlassian provider and **Auto-Configure**; skip to step 6. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. - -#### Select the identity provider - -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). - -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. - -1. In **Attach Remote Identity Provider**, confirm that the issuer/base auth URL is: +1. Select **User Identity**. +2. Under **Choose an identity provider**, confirm the preselected provider uses this issuer. A provider that does not exist yet shows **Will be created**. ``` - https://auth.atlassian.com + https://auth.atlassian.com/VCeDsk8ZHncYF1g234fKtc4lNipbBhu3 ``` -1. Keep the automatically derived **Slug**. -1. Keep the automatically derived **Display name (optional)**. -1. Under **Endpoints**, wait for automatic discovery of the seeded issuer. After typing or changing **Issuer URL**, click **Discover** only if offered, then confirm the authorization, token, and registration endpoints. - -#### Select the session client - -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Attach the provider** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: - -1. Under **Session Client**, keep **Client Type** set to **Dynamic Client Registration (DCR)**. -1. Keep the discovered **Token Endpoint Auth Method**. -1. Leave **Scope (override)** and **Audience (optional)** empty. - -#### Attach the provider - -Click **Attach Identity Provider**. DCR handles client registration; you do not need to register a callback URL manually. -You do not need to paste a **Client ID** or **Client Secret**. +3. If the picker preselects a different provider on `auth.atlassian.com`, open the picker with **Search identity providers…** and choose the one for the issuer above. +4. Keep **Auto-Configure** selected. There is no **Client ID** or secret to paste. +5. Click **Save**. +6. If the server shows **Disabled**, open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -When Atlassian prompts you for access: +When a person first uses the server, Atlassian prompts them in the browser: 1. Sign in with the intended Atlassian account. 2. Authorize the intended Atlassian Cloud site. @@ -71,6 +56,6 @@ When Atlassian prompts you for access: If organization policy rejects the flow, complete [Allow the Speakeasy OAuth domain](external.md#allow-speakeasy-domain), then retry the connection. - + -This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Atlassian's MCP documentation](https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/). +This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Atlassian's MCP documentation](https://support.atlassian.com/atlassian-ai-gateway/docs/get-started-with-the-atlassian-remote-mcp-server/). diff --git a/go/generated/guides/box/external.md b/go/generated/guides/box/external.md index 74bd6a1..43b2b88 100644 --- a/go/generated/guides/box/external.md +++ b/go/generated/guides/box/external.md @@ -32,9 +32,12 @@ integration. 1. Select **Integrations**. 2. Apply the **MCP Category** filter, or type `Custom Box MCP Server` in the search bar at the top of the page. -3. Find the **Custom Box MCP Server** tile. +3. Find the **Custom Box MCP Server** tile. Some Box pages call this tile + **Box MCP server**; if `Custom Box MCP Server` finds nothing, search for + `Box MCP server` instead. -Do not select the **Box MCP Server** tab or a named partner tile. +Do not use the **Box MCP Server** tab, which controls tool access, or a named +partner tile. @@ -49,7 +52,7 @@ If the **Custom Box MCP Server** tile shows **Configuration**: Otherwise: -1. Hover over **Custom Box MCP Server**. +1. Hover over the **Custom Box MCP Server** (or **Box MCP server**) tile. 2. Click **Configure**. 3. Open **Additional Configuration**. 4. Click **+ Add Integration Credentials**. diff --git a/go/generated/guides/box/meta.yaml b/go/generated/guides/box/meta.yaml index cc544ca..c5dd138 100644 --- a/go/generated/guides/box/meta.yaml +++ b/go/generated/guides/box/meta.yaml @@ -51,17 +51,17 @@ remotes: locator: https://developer.box.com/guides/box-mcp/setup name: Set up the MCP server classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-metadata locator: https://mcp.box.com/.well-known/oauth-protected-resource name: Box Model Context Protocol Server classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation - locator: https://www.speakeasy.com/docs/ai-control-plane/distribute/mcp-servers/remote-servers + locator: https://www.speakeasy.com/docs/ai-control-plane/mcp-gateway/remote-servers name: Remote MCP servers classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" provenance: - source: pulsemcp locator: com.pulsemcp.mirror/box @@ -84,7 +84,7 @@ provenance: locator: https://docs.box.com/en/box-mcp/configuring-box-mcp-server/claude-code name: Claude Code classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://docs.box.com/en/box-mcp/configuring-box-mcp-server/anthropic-messages-api name: Anthropic Messages API @@ -139,7 +139,7 @@ provenance: locator: https://developer.box.com/guides/box-mcp/setup name: Set up the MCP server classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://support.box.com/hc/en-us/articles/43847256139923 name: Managing Box MCP Servers @@ -154,14 +154,24 @@ provenance: locator: https://mcp.box.com/.well-known/oauth-protected-resource name: Box Model Context Protocol Server classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation - locator: https://www.speakeasy.com/docs/ai-control-plane/distribute/mcp-servers/remote-servers + locator: https://www.speakeasy.com/docs/ai-control-plane/mcp-gateway/remote-servers name: Remote MCP servers classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" + - source: endpoint-metadata + locator: https://api.box.com/.well-known/oauth-authorization-server + name: Box authorization server metadata + classification: official + observed_at: "2026-09-30T21:30:00Z" + - source: provider-documentation + locator: https://developer.box.com/reference/get-authorize/ + name: Authorize user + classification: official + observed_at: "2026-09-30T21:30:00Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Canonical Speakeasy setup classification: official - observed_at: "2026-08-28T23:25:24Z" + observed_at: "2026-09-30T21:30:00Z" diff --git a/go/generated/guides/box/speakeasy.md b/go/generated/guides/box/speakeasy.md index 7aa16f8..e6e118e 100644 --- a/go/generated/guides/box/speakeasy.md +++ b/go/generated/guides/box/speakeasy.md @@ -3,49 +3,65 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **From the catalog**. 4. On the **MCP Catalog** page, use **Search MCP servers...** to find **Box**. -5. Open the **Box** entry. -6. Click **Add**. -7. In the **Add to Project** dialog, click **Add to Project**. +5. Open the **Box** entry and click **Add**. +6. In the **Add to Project** dialog, under **Identity**, select **User Identity**. The dialog may preselect **No Identity**. +7. Click **Add to Project**. If the dialog offers a **Guardrails** step, finish it or click **Skip for now**. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +Box needs a client registered by hand, so the result says to finish setup in **Settings > Identity**, and the server stays **Disabled** for now. This is expected. Click **Finish setup** on the server's result to open its **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. +Box's server names its sign-in provider as `https://api.box.com/`, with a trailing slash, while Box's provider metadata says `https://api.box.com`. The provider picker cannot create a provider from that mismatch, so create the Box provider by hand first. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +In the server's **Settings**, find the **Identity** section and select **User Identity**. Then create the provider: -#### Select the identity provider +1. Open **Choose an identity provider** and click **Create a custom identity provider**. This opens **Remote Identity Providers**. +2. Click **New Remote Identity Provider**. +3. In **Issuer URL**, enter `https://api.box.com`, with no trailing slash. +4. Click **Discover**. +5. Under **Endpoints**, confirm **Authorization Endpoint** and **Token Endpoint** show these values. If they are empty, enter them: -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + ```text + https://account.box.com/api/oauth2/authorize + ``` -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + ```text + https://api.box.com/oauth2/token + ``` -For **Identity Provider > Add new**, use **Issuer URL** `https://api.box.com/`, authorization endpoint `https://account.box.com/api/oauth2/authorize`, and token endpoint `https://api.box.com/oauth2/token`. Keep the auto-derived **Slug**. +6. Keep the derived **Slug** and click **Create**. -#### Select the session client +Add the Box client to that provider: -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: +1. On the new provider, click **Add Client**. +2. Set **Client Type** to **Manual**. +3. Paste the [Box Client ID](external.md#copy-client-credentials) into **Client ID**. +4. Paste the [Box Client Secret](external.md#copy-client-credentials) into **Client Secret (optional)**. Box requires it. +5. Leave **Scope (override)** empty. Box then grants the **Access scopes** selected in [Check the Access scopes](external.md#check-access-scopes). +6. Confirm the displayed **Redirect URI** matches the value you entered in [Set the Redirect URI](external.md#set-redirect-uri). +7. Click **Create**. -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Paste the [Box Client ID](external.md#copy-client-credentials) into - **Client ID**. -1. Paste the [Box Client Secret](external.md#copy-client-credentials) into - **Client Secret (optional)**. +Connect the server to that client: -#### Verify the callback and attach +1. Return to the server's **Settings > Identity** and select **User Identity**. +2. In **Choose an identity provider**, open the picker and choose the `api.box.com` provider you created. +3. Choose **Existing client**. +4. Under **Client**, pick the client you created. +5. Click **Save**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +Then turn the server on: -For the provider-side callback setting, see [Redirect URIs](external.md#set-redirect-uri). +1. In **Settings**, open **Danger Zone**. +2. Under **Server Availability**, turn on **Enable MCP server** so it shows **Enabled**. + +Each user sees Box's authorization prompt the first time they use the server. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Box's MCP documentation](https://docs.box.com/en/box-mcp/about-box-mcp-server). diff --git a/go/generated/guides/github/external.md b/go/generated/guides/github/external.md index 9a59819..e56c9b3 100644 --- a/go/generated/guides/github/external.md +++ b/go/generated/guides/github/external.md @@ -6,7 +6,7 @@ setup_version: 1 Before you begin, obtain: -- Administrative access to the GitHub Enterprise Cloud organization that will own the OAuth app. +- Administrative access to the GitHub organization that will own the OAuth app. - Standard GitHub.com hosting for the target organization. This Setup Guide does not cover GitHub Enterprise Cloud with data residency or GitHub Enterprise Server. - The organization-approved public URL for this connection from the application or cloud security owner. - If the target organization restricts OAuth apps, access to an organization owner who can grant access — see [Connect your credentials](speakeasy.md#connect-speakeasy-credentials). @@ -42,7 +42,7 @@ If the page shows **New OAuth App**, click it. If the page instead shows **Regis 5. Leave **Enable Device Flow** off. 6. Click **Register application**. This opens the app's settings page. -If the target organization restricts OAuth apps, complete the organization approval flow after attaching credentials in [Connect your credentials](speakeasy.md#connect-speakeasy-credentials). +If the target organization restricts OAuth apps, complete the organization approval flow after saving credentials in [Connect your credentials](speakeasy.md#connect-speakeasy-credentials). diff --git a/go/generated/guides/github/meta.yaml b/go/generated/guides/github/meta.yaml index 10c24e9..a0f3e16 100644 --- a/go/generated/guides/github/meta.yaml +++ b/go/generated/guides/github/meta.yaml @@ -54,15 +54,15 @@ remotes: locator: https://github.com/github/github-mcp-server/blob/main/docs/host-integration.md name: GitHub Remote MCP Integration Guide for MCP Host Authors classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://api.githubcopilot.com/mcp/ classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://api.githubcopilot.com/.well-known/oauth-protected-resource/mcp/ classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" provenance: - source: pulsemcp name: io.github.github/github-mcp-server @@ -84,12 +84,12 @@ provenance: locator: https://github.com/github/github-mcp-server/blob/main/docs/host-integration.md name: GitHub Remote MCP Integration Guide for MCP Host Authors classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://github.com/github/github-mcp-server/blob/main/docs/scope-filtering.md name: Scope Filtering classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://github.com/github/github-mcp-server/blob/main/docs/policies-and-governance.md name: Policies & Governance for the GitHub MCP Server @@ -138,17 +138,17 @@ provenance: - source: endpoint-observation locator: https://api.githubcopilot.com/mcp/ classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation locator: https://api.githubcopilot.com/.well-known/oauth-protected-resource/mcp/ classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: endpoint-observation - locator: https://github.com/login/oauth/.well-known/oauth-authorization-server + locator: https://github.com/.well-known/oauth-authorization-server/login/oauth classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-06T23:22:50Z" + observed_at: "2026-09-30T21:30:00Z" diff --git a/go/generated/guides/github/speakeasy.md b/go/generated/guides/github/speakeasy.md index 5f45e08..cfec2f4 100644 --- a/go/generated/guides/github/speakeasy.md +++ b/go/generated/guides/github/speakeasy.md @@ -3,45 +3,42 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **From the catalog**. 4. On the **MCP Catalog** page, find GitHub using **Search MCP servers...**. -5. Open its entry. -6. Click **Add**. -7. In the **Add to Project** dialog, click **Add to Project**. +5. Open its entry and click **Add**. +6. In the **Add to Project** dialog, under **Identity**, select **User Identity**. The dialog may preselect **No Identity**. +7. Click **Add to Project**. If the dialog offers a **Guardrails** step, finish it or click **Skip for now**. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +GitHub needs a client registered by hand, so the result says to finish setup in **Settings > Identity**, and the server stays **Disabled** for now. This is expected. Click **Finish setup** on the server's result to open its **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. +In the server's **Settings**, find the **Identity** section. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm the provider is `https://github.com/login/oauth`. It may be badged **Will be created**. If no provider or a different one is selected, open the picker, search for `github.com` in **Search identity providers…**, and choose the `github.com/login/oauth` provider. +3. Under the provider, choose **Manual**. +4. Paste the **Client ID** from [Generate the OAuth credentials](external.md#generate-oauth-credentials) into **Client ID**. +5. Paste the client secret from [Generate the OAuth credentials](external.md#generate-oauth-credentials) into **Client secret**. GitHub requires it, even though the field shows "Optional". +6. Open **Advanced** and enter the scopes users may grant in **Scope**, on one line. Start from the full list GitHub's server advertises and delete any your organization does not allow: -#### Select the identity provider + ```text + repo read:org read:user user:email read:packages write:packages read:project project gist notifications + ``` -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + A blank **Scope** requests every scope in this list, including `repo`, `write:packages`, and `gist`. -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. +7. Click **Save**. -For a new provider, use the authorization-server issuer `https://github.com/login/oauth` identified by GitHub’s protected-resource metadata. If discovery does not supply the endpoints, ask your administrator for the documented authorization and token endpoints before continuing; do not infer them from the MCP URL. +This section does not show the redirect URI. GitHub accepts the connection only if [Register the OAuth app](external.md#register-oauth-app) set **Authorization callback URL** to `{{ gram.oauth.callback_url }}`. -#### Select the session client +Then turn the server on: -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: - -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Paste the **Client ID** saved in [Generate the OAuth credentials](external.md#generate-oauth-credentials) into **Client ID**. -1. Paste the saved client secret into **Client Secret (optional)** — although the field is labeled optional, this OAuth connection requires it. - -#### Verify the callback and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. - -For the provider-side callback setting, see [Register the OAuth app](external.md#register-oauth-app). +1. In **Settings**, open **Danger Zone**. +2. Under **Server Availability**, turn on **Enable MCP server** so it shows **Enabled**. If the target organization restricts OAuth apps, have a user authorize the connection, then complete the following: @@ -65,6 +62,6 @@ Then have an organization owner approve the pending request: If the user's first authorization attempt was blocked before approval, have the user retry it after access is granted. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [GitHub's MCP documentation](https://github.com/github/github-mcp-server/blob/main/docs/remote-server.md). diff --git a/go/generated/guides/gmail/meta.yaml b/go/generated/guides/gmail/meta.yaml index 1cb74e4..bcd6dcf 100644 --- a/go/generated/guides/gmail/meta.yaml +++ b/go/generated/guides/gmail/meta.yaml @@ -34,7 +34,7 @@ remotes: - source: google-developers locator: https://developers.google.com/workspace/gmail/api/guides/configure-mcp-server classification: official - observed_at: "2026-08-20T19:49:41Z" + observed_at: "2026-09-30T21:25:46Z" - source: google-developers locator: https://developers.google.com/workspace/gmail/api/reference/mcp classification: official @@ -46,7 +46,7 @@ provenance: - source: google-developers locator: https://developers.google.com/workspace/gmail/api/guides/configure-mcp-server classification: official - observed_at: "2026-08-20T19:49:41Z" + observed_at: "2026-09-30T21:25:46Z" - source: google-developers locator: https://developers.google.com/workspace/gmail/api/reference/mcp classification: official @@ -54,7 +54,7 @@ provenance: - source: google-developers locator: https://developers.google.com/workspace/preview classification: official - observed_at: "2026-08-20T19:49:41Z" + observed_at: "2026-09-30T21:25:46Z" - source: google-cloud-console locator: https://console.cloud.google.com/ classification: official @@ -71,7 +71,17 @@ provenance: locator: https://support.google.com/cloud/answer/15549257?hl=en classification: official observed_at: "2026-08-20T19:49:41Z" + - source: provider-metadata + locator: https://gmailmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 + name: Gmail MCP protected-resource metadata + classification: official + observed_at: "2026-09-30T21:25:46Z" + - source: provider-metadata + locator: https://accounts.google.com/.well-known/oauth-authorization-server + name: Google OAuth authorization-server metadata + classification: official + observed_at: "2026-09-30T21:25:46Z" - source: speakeasy-doctrine locator: doctrine/speakeasy-setup.md classification: official - observed_at: "2026-08-20T19:49:41Z" + observed_at: "2026-09-30T21:25:46Z" diff --git a/go/generated/guides/gmail/speakeasy.md b/go/generated/guides/gmail/speakeasy.md index 8fa9e4c..dcca5c7 100644 --- a/go/generated/guides/gmail/speakeasy.md +++ b/go/generated/guides/gmail/speakeasy.md @@ -5,77 +5,43 @@ 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. 2. Click **Add new** to open **Add MCP server**. 3. Choose **Hosted remotely**. -4. On the **New remote MCP server** page, paste this value into **MCP server URL**: - -```text -https://gmailmcp.googleapis.com/mcp/v1 -``` - -5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - - - -### Connect your credentials {#connect-speakeasy-credentials} - -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` - - Token endpoint: +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ```text - https://oauth2.googleapis.com/token + https://gmailmcp.googleapis.com/mcp/v1 ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -#### New session client only +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Gmail; the next section finishes it. -1. Paste the **Client ID** from [Create the OAuth client](external.md#create-oauth-client) into **Client ID**. -1. Paste the **Client Secret** from [Create the OAuth client](external.md#create-oauth-client) into **Client Secret (optional)**. The Gmail setup requires this value despite the generic optional label. + -#### Check client requirements +### Connect your credentials {#connect-speakeasy-credentials} -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. +Open the server's **Settings** and find the **Identity** section. -For a new client, enter these comma-separated scopes in **Scope (override)**. For a reused client, inspect its read-only **Scope** value; if it does not include both scopes, choose **Add new** instead. The scopes must also match the Google app's **Data Access** configuration: +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm that the preselected provider is Google's issuer, `https://accounts.google.com/`. It is badged **Will be created** when the project has no Google provider yet. If another provider is selected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Under the provider, choose **Manual**. If **Existing client** is preselected, switch to **Manual**. +4. Paste the **Client ID** from [Create the OAuth client](external.md#create-oauth-client) into **Client ID**. +5. Paste the **Client Secret** from [Create the OAuth client](external.md#create-oauth-client) into **Client secret**. Gmail requires the secret even though the field shows "Optional". +6. Open **Advanced**. In **Scope**, enter this value on one line. Do not leave **Scope** blank: a blank value requests every scope the Gmail server advertises, including `https://mail.google.com/`, which your Google app does not grant. -```text -https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.compose -``` + ```text + https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.compose + ``` -#### Verify and attach +7. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +8. Open **Settings > Danger Zone > Server Availability**. +9. Turn on **Enable MCP server** so the switch shows **Enabled**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +When a person first uses the server, Google's browser authorization prompt appears. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Gmail's MCP documentation](https://developers.google.com/workspace/gmail/api/guides/configure-mcp-server). diff --git a/go/generated/guides/google-big-query/meta.yaml b/go/generated/guides/google-big-query/meta.yaml index 1fcfb21..3ff555f 100644 --- a/go/generated/guides/google-big-query/meta.yaml +++ b/go/generated/guides/google-big-query/meta.yaml @@ -3,6 +3,7 @@ schema_version: 1 slug: google-big-query title: Google BigQuery summary: Query and manage BigQuery data through Google's hosted BigQuery MCP server. +speakeasy_add_server: catalog aliases: - com.pulsemcp.mirror/google-bigquery credential_setup: @@ -39,7 +40,7 @@ remotes: locator: https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp name: Use the BigQuery MCP server classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: provider-documentation locator: https://docs.cloud.google.com/bigquery/docs/reference/mcp name: BigQuery MCP reference @@ -54,18 +55,18 @@ remotes: locator: https://bigquery.googleapis.com/mcp name: BigQuery MCP endpoint classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: endpoint-observation locator: https://bigquery.googleapis.com/.well-known/oauth-protected-resource/mcp name: BigQuery MCP protected-resource metadata classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" provenance: - source: provider-documentation locator: https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp name: Use the BigQuery MCP server classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: provider-documentation locator: https://docs.cloud.google.com/bigquery/docs/reference/mcp name: BigQuery MCP reference @@ -183,34 +184,34 @@ provenance: observed_at: "2026-08-06T23:23:41Z" - source: endpoint-observation locator: https://bigquery.googleapis.com/mcp - name: BigQuery MCP endpoint (tools/list 200 unauthenticated; tools/call 401) + name: BigQuery MCP endpoint (initialize and tools/list 200 unauthenticated; tools/call 401) classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: endpoint-observation locator: https://bigquery.googleapis.com/.well-known/oauth-protected-resource/mcp name: BigQuery MCP protected-resource metadata classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: product-source - locator: speakeasy-api/gram@96f7f73:client/dashboard/src/pages/mcp/x/tabs/settings/sections/authentication/IssuerFormFields.tsx - name: Speakeasy identity-provider form fields + locator: speakeasy-api/gram@68b3f78:client/dashboard/src/pages/mcp/x/tabs/settings/sections/authentication/RemoteMcpIdentitySection.tsx + name: Speakeasy remote MCP Identity section classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: product-source - locator: speakeasy-api/gram@96f7f73:client/dashboard/src/pages/mcp/x/tabs/settings/sections/authentication/AttachRemoteIdentityProviderSheet.tsx - name: Speakeasy identity-provider attachment sheet + locator: speakeasy-api/gram@68b3f78:client/dashboard/src/pages/catalog/AddServerDialog.tsx + name: Speakeasy catalog Add to Project dialog classification: official - observed_at: "2026-08-06T23:23:41Z" + observed_at: "2026-09-30T21:25:43Z" - source: provider-documentation locator: https://docs.cloud.google.com/contact-center/ccai-platform/docs/oauth-email-google name: Configure an email channel for OAuth with Gmail diff --git a/go/generated/guides/google-big-query/speakeasy.md b/go/generated/guides/google-big-query/speakeasy.md index e9f9928..ddc3bd5 100644 --- a/go/generated/guides/google-big-query/speakeasy.md +++ b/go/generated/guides/google-big-query/speakeasy.md @@ -4,86 +4,43 @@ In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open **Add MCP server**. -1. Choose **Hosted remotely**. -2. On the **New remote MCP server** page, paste this URL into **MCP server URL**: +1. Choose **From the catalog**. +2. On the **MCP Catalog** page, search for `BigQuery` in **Search MCP servers...**. +3. Open the **BigQuery** catalog entry. +4. Click **Add**. This opens the **Add to Project** dialog. +5. Under **Identity**, select **User Identity**. The dialog preselects **No Identity** for this entry, so change it. +6. Click **Add to Project**. +7. If the dialog offers a **Guardrails** step, finish it or click **Skip for now**. +8. When the dialog finishes, the result reads "Added, but disabled until identity is set up." Click **Finish setup** to open the server's **Settings**. - ``` - https://bigquery.googleapis.com/mcp - ``` - -3. Click **Verify connectivity**, then **Save**. - -This creates the hosted MCP server and opens its **Overview** page. +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for BigQuery; continue with the next section. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. +Open the server's **Settings** and find the **Identity** section. -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token - ``` - -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -Google's web client requires its generated secret even though the field is labeled **Client Secret (optional)**. - -1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. -1. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client Secret (optional)**. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter this value: +1. Confirm **User Identity** is selected. +2. Under **Choose an identity provider**, confirm the preselected Google provider (`https://accounts.google.com`). A new provider shows **Will be created**. If a different provider is preselected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Choose **Manual**. If **Existing client** is preselected, switch to **Manual** unless that client is the one created in [Create the OAuth client](external.md#create-oauth-client) with the BigQuery scope. +4. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. +5. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client secret**. Google requires this secret even though the field shows "Optional". +6. Under **Advanced > Scope**, enter this value. Do not leave **Scope** blank. ``` https://www.googleapis.com/auth/bigquery ``` -#### Verify and attach +7. Click **Save**. If asked to confirm, click **Save changes**. + +Turn the server on: -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +1. Open **Settings > Danger Zone > Server Availability**. +2. Turn on the switch (**Enable MCP server**) so it shows **Enabled**. -For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). +At first connection, complete Google's browser authorization with an account granted the roles in [Grant the BigQuery MCP roles](external.md#grant-bigquery-mcp-roles). An **External** app in **Testing** also requires that account under **Test users**. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's BigQuery MCP documentation](https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp). diff --git a/go/generated/guides/google-calendar/meta.yaml b/go/generated/guides/google-calendar/meta.yaml index c35b2a4..7bdefe4 100644 --- a/go/generated/guides/google-calendar/meta.yaml +++ b/go/generated/guides/google-calendar/meta.yaml @@ -46,23 +46,23 @@ remotes: locator: https://developers.google.com/workspace/calendar/api/guides/configure-mcp-server name: Configure the Calendar MCP server classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: provider-metadata locator: https://calendarmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Calendar MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" provenance: - source: provider-documentation locator: https://developers.google.com/workspace/calendar/api/guides/configure-mcp-server name: Configure the Calendar MCP server classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: provider-documentation locator: https://developers.google.com/workspace/preview name: Google Workspace Developer Preview Program classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: provider-documentation locator: https://docs.cloud.google.com/mcp/authenticate-mcp name: Authenticate to Google and Google Cloud MCP servers @@ -107,16 +107,16 @@ provenance: locator: https://calendarmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Calendar MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: provider-metadata locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google OAuth authorization-server metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical file - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: pulsemcp locator: credential-free Pulse snapshot for Google Calendar name: Google Calendar catalog lookup diff --git a/go/generated/guides/google-calendar/speakeasy.md b/go/generated/guides/google-calendar/speakeasy.md index 57c92d4..f764c69 100644 --- a/go/generated/guides/google-calendar/speakeasy.md +++ b/go/generated/guides/google-calendar/speakeasy.md @@ -7,83 +7,43 @@ 3. Choose **Hosted remotely**. 4. On **New remote MCP server**, paste this URL into **MCP server URL**: - ``` + ```text https://calendarmcp.googleapis.com/mcp/v1 ``` -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -This creates the hosted MCP server and opens its Overview page. +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Google Calendar; the next section finishes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. +Open the server's **Settings** and find the **Identity** section. -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm that the preselected provider is Google's issuer, `https://accounts.google.com/`. It is badged **Will be created** when the project has no Google provider yet. If another provider is selected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Under the provider, choose **Manual**. If **Existing client** is preselected, switch to **Manual**. +4. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client ID**. +5. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client secret**. Google requires the secret even though the field shows "Optional". +6. Open **Advanced**. In **Scope**, enter this value on one line. Do not leave **Scope** blank: a blank value requests every scope the Calendar server advertises, including full `https://www.googleapis.com/auth/calendar`, which your Google app does not grant. ```text - https://accounts.google.com/ + https://www.googleapis.com/auth/calendar.calendarlist.readonly https://www.googleapis.com/auth/calendar.events.freebusy https://www.googleapis.com/auth/calendar.events.readonly ``` -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token - ``` - -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -1. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google requires this value despite the optional Speakeasy label. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter all three scopes as a comma-separated value in **Scope (override)**: - -```text -https://www.googleapis.com/auth/calendar.calendarlist.readonly, https://www.googleapis.com/auth/calendar.events.freebusy, https://www.googleapis.com/auth/calendar.events.readonly -``` - -#### Verify and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +7. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +8. Open **Settings > Danger Zone > Server Availability**. +9. Turn on **Enable MCP server** so the switch shows **Enabled**. -For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). +The callback Speakeasy uses is the `{{ gram.oauth.callback_url }}` value you registered in [Create the OAuth client](external.md#create-oauth-client). At first connection, authorize the requested access with an intended Google account that is eligible under the Developer Preview terms, has `mcp.tools.call` on the project, access to the required calendars, applicable **Test user** status, and Workspace API-control approval when required. **MCP Tool User** is the normal predefined grant for `mcp.tools.call`, but another role containing the permission can suffice. Use the visible controls on Google's authorization screen. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's MCP documentation](https://developers.google.com/workspace/calendar/api/guides/configure-mcp-server). diff --git a/go/generated/guides/google-compute-engine/meta.yaml b/go/generated/guides/google-compute-engine/meta.yaml index 6d33314..75e5db8 100644 --- a/go/generated/guides/google-compute-engine/meta.yaml +++ b/go/generated/guides/google-compute-engine/meta.yaml @@ -49,7 +49,7 @@ remotes: locator: https://docs.cloud.google.com/compute/docs/use-compute-engine-mcp name: Use the Compute Engine MCP server classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" - source: provider-documentation locator: https://docs.cloud.google.com/compute/docs/reference/mcp name: Compute Engine MCP reference @@ -64,7 +64,7 @@ remotes: locator: https://compute.googleapis.com/.well-known/oauth-protected-resource/mcp name: Compute Engine MCP protected-resource metadata classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" provenance: - source: pulsemcp locator: com.googleapis.compute/mcp @@ -76,7 +76,7 @@ provenance: locator: https://docs.cloud.google.com/compute/docs/use-compute-engine-mcp name: Use the Compute Engine MCP server classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" - source: provider-documentation locator: https://docs.cloud.google.com/compute/docs/reference/mcp name: Compute Engine MCP reference @@ -149,16 +149,21 @@ provenance: observed_at: "2026-07-31T19:17:08Z" - source: endpoint-observation locator: https://compute.googleapis.com/mcp - name: Compute Engine MCP endpoint (tools/list 200 unauthenticated, tools/call 401) + name: Compute Engine MCP endpoint (initialize and tools/list 200 unauthenticated, tools/call 401) classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" - source: endpoint-observation locator: https://compute.googleapis.com/.well-known/oauth-protected-resource/mcp name: Compute Engine MCP protected-resource metadata classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-07-31T19:17:08Z" + observed_at: "2026-09-30T21:25:43Z" + - source: repository-doctrine + locator: doctrine/speakeasy-setup.md + name: Speakeasy setup canonical section + classification: official + observed_at: "2026-09-30T21:25:43Z" diff --git a/go/generated/guides/google-compute-engine/speakeasy.md b/go/generated/guides/google-compute-engine/speakeasy.md index e99d22b..f4c2b33 100644 --- a/go/generated/guides/google-compute-engine/speakeasy.md +++ b/go/generated/guides/google-compute-engine/speakeasy.md @@ -4,86 +4,43 @@ In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open **Add MCP server**. -Choose **From the catalog**. On the **MCP Catalog** page, search for `Google Compute Engine` in **Search MCP servers...**, open the matched entry, and click **Add**. In the **Add to Project** dialog, click **Add to Project**. +1. Choose **From the catalog**. +2. On the **MCP Catalog** page, search for `Google Compute Engine` in **Search MCP servers...**. +3. Open the **Google Compute Engine** catalog entry. +4. Click **Add**. This opens the **Add to Project** dialog. +5. Under **Identity**, select **User Identity**. The dialog preselects **No Identity** for this entry, so change it. +6. Click **Add to Project**. +7. If the dialog offers a **Guardrails** step, finish it or click **Skip for now**. +8. When the dialog finishes, the result reads "Added, but disabled until identity is set up." Click **Finish setup** to open the server's **Settings**. -After the server is added, click **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Compute Engine; continue with the next section. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). +Open the server's **Settings** and find the **Identity** section. -#### Choose an authentication provider +1. Confirm **User Identity** is selected. +2. Under **Choose an identity provider**, confirm the preselected Google provider (`https://accounts.google.com`). A new provider shows **Will be created**. If a different provider is preselected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Choose **Manual**. If **Existing client** is preselected, switch to **Manual** unless that client is the one created in [Create the OAuth client](external.md#create-oauth-client) with the Compute Engine scope. +4. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. +5. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client secret**. Google requires this secret even though the field shows "Optional". +6. Under **Advanced > Scope**, enter this value. Do not leave **Scope** blank; without it, the token can lack Compute Engine access. -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token + https://www.googleapis.com/auth/compute ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. Paste the client ID from - [Copy the client credentials](external.md#copy-client-credentials) into - **Client ID**. -1. Paste the client secret into **Client Secret (optional)** — despite - the label, Google requires the secret, so treat the field as - required. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Verify the new or reused Google client has these required scopes, matching the Google app's **Data Access** configuration: - -```text -https://www.googleapis.com/auth/compute -``` - -#### Verify and attach +7. Click **Save**. If asked to confirm, click **Save changes**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +Turn the server on: -For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). +1. Open **Settings > Danger Zone > Server Availability**. +2. Turn on the switch (**Enable MCP server**) so it shows **Enabled**. - +Each user who then connects signs in with their own Google account. They need the roles from [Grant IAM roles](external.md#grant-iam-roles) and, while an **External** app's publishing status is **Testing**, a listing under **Test users** in [Configure the consent screen](external.md#consent-screen). -Each user who then connects signs in with their own Google account. -For their sign-in to succeed, they need the roles from -[Grant IAM roles](external.md#grant-iam-roles), and — while an External app's -publishing status is **Testing** — a listing under **Test users** in -[Configure the consent screen](external.md#consent-screen). + -This guide covers setup only. For anything beyond it — billing, tool -behavior, limits — see [Google's Compute Engine MCP documentation](https://docs.cloud.google.com/compute/docs/use-compute-engine-mcp). +This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's Compute Engine MCP documentation](https://docs.cloud.google.com/compute/docs/use-compute-engine-mcp). diff --git a/go/generated/guides/google-docs/external.md b/go/generated/guides/google-docs/external.md index 35901aa..d3088f5 100644 --- a/go/generated/guides/google-docs/external.md +++ b/go/generated/guides/google-docs/external.md @@ -4,12 +4,26 @@ setup_version: 1 # Set up Google Docs -Sign in to [console.cloud.google.com](https://console.cloud.google.com) with an account that can select a Google Cloud project, enable APIs, configure the **Google Auth platform**, and create OAuth credentials. Google does not document a Google Docs MCP-specific paid plan or license requirement. Enabling APIs requires `serviceusage.services.enable`; **Service Usage Admin** provides this permission. Each account that will connect needs **MCP Tool User** (`roles/mcp.toolUser`) on the project and access to the Google Docs it will use. Obtain the approved support and contact addresses before you begin. If your organization restricts high-risk Drive and Docs scopes or unconfigured apps, you also need a Google Workspace administrator with the **Service Settings administrator** privilege. +Sign in to [console.cloud.google.com](https://console.cloud.google.com) with an account that can select a Google Cloud project, enable APIs, configure the **Google Auth platform**, and create OAuth credentials. Google does not document a Google Docs MCP-specific paid plan or license requirement, but the Docs MCP server is available only through the Google Workspace Developer Preview Program, so the project must be registered in it. Enabling APIs requires `serviceusage.services.enable`; **Service Usage Admin** provides this permission. Granting **MCP Tool User** (`roles/mcp.toolUser`) requires IAM administration access on the project. Each account that will connect needs that role and access to the Google Docs it will use. Obtain the approved support and contact addresses before you begin. If your organization restricts high-risk Drive and Docs scopes or unconfigured apps, you also need a Google Workspace administrator with the **Service Settings administrator** privilege. + +### Join the Google Workspace Developer Preview Program {#join-developer-preview} + +1. Open [developers.google.com/workspace/preview](https://developers.google.com/workspace/preview). +2. Review the **Developer Preview Program Terms** with the application or security owner. +3. Click **Apply to join the Developer Preview Program**. +4. In the application form, enter the requested Google Workspace account and Google Cloud project information. +5. Agree to the terms only with organizational approval. +6. Submit the form with the visible or equivalent submission control. +7. Wait for Google's project-registration confirmation at the submitted email address. Google says this should complete within a couple of days. + +Use the registered project for every Google Cloud step that follows. + + ### Enable the Docs MCP APIs {#enable-docs-mcp-apis} 1. In the toolbar, open the resource selector. -2. Select the Google Cloud project that will own the credentials. +2. Select the Google Cloud project registered in the Developer Preview Program. 3. Open **APIs & Services** > **Library**. 4. Open **Google Docs API**. 5. Click **Enable**. @@ -19,9 +33,23 @@ Sign in to [console.cloud.google.com](https://console.cloud.google.com) with an If **Enable** is unavailable, ask the project administrator for `serviceusage.services.enable`. + + +### Grant the MCP Tool User role {#grant-mcp-tool-user} + +1. Open [console.cloud.google.com/iam-admin/iam](https://console.cloud.google.com/iam-admin/iam). +2. Select the same project. +3. Click **Grant access**. +4. In **New principals**, enter the Google Account email of a user who will connect from the Speakeasy AI Control Plane. +5. Click **Select a role**. +6. Search for `MCP Tool User`. +7. Select **MCP Tool User**. +8. Click **Save**. +9. Repeat these steps for every connecting user. + Open **Google Auth platform** > **Branding**. - + ### Configure the OAuth consent screen {#configure-oauth-consent} diff --git a/go/generated/guides/google-docs/meta.yaml b/go/generated/guides/google-docs/meta.yaml index d1a765b..8244c55 100644 --- a/go/generated/guides/google-docs/meta.yaml +++ b/go/generated/guides/google-docs/meta.yaml @@ -22,6 +22,8 @@ credential_setup: - external.md#create-oauth-client - external.md#copy-client-credentials requirements: + - id: developer-preview + description: Google has registered the Google Cloud project in the Google Workspace Developer Preview Program, which the Docs MCP server requires - id: google-cloud-project description: A Google Cloud project that will own the Google Docs API, Google Docs MCP API, and OAuth client - id: google-cloud-administrator @@ -45,23 +47,33 @@ remotes: locator: https://developers.google.com/workspace/docs/api/guides/configure-mcp-server name: Configure the Docs MCP server classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://docsmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Docs MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" provenance: + - source: provider-documentation + locator: https://developers.google.com/workspace/preview + name: Google Workspace Developer Preview Program + classification: official + observed_at: "2026-09-30T21:25:45Z" + - source: provider-documentation + locator: https://docs.cloud.google.com/iam/docs/grant-role-console + name: Grant an IAM role by using the Google Cloud console + classification: official + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/docs/api/guides/configure-mcp-server name: Configure the Docs MCP server classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/guides/configure-mcp-servers name: Configure the Google Workspace MCP servers classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/guides/configure-oauth-consent name: Configure the OAuth consent screen and choose scopes @@ -91,7 +103,7 @@ provenance: locator: https://docs.cloud.google.com/mcp/set-up-authentication-mcp-servers name: Set up authentication to Google and Google Cloud MCP servers classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://docs.cloud.google.com/service-usage/docs/enable-disable name: Enable and disable services @@ -111,17 +123,17 @@ provenance: locator: https://docsmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Docs MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-29T15:13:21Z" + observed_at: "2026-09-30T21:25:45Z" - source: pulsemcp locator: credential-free Pulse snapshot name: Google Docs catalog lookup diff --git a/go/generated/guides/google-docs/speakeasy.md b/go/generated/guides/google-docs/speakeasy.md index 2d9ecd0..a5dcccb 100644 --- a/go/generated/guides/google-docs/speakeasy.md +++ b/go/generated/guides/google-docs/speakeasy.md @@ -11,79 +11,37 @@ https://docsmcp.googleapis.com/mcp/v1 ``` -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. The **Transport** field is read-only. +Speakeasy saves the server as **Disabled** and says to finish setup in **Settings > Identity**. This is expected; the next section completes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). +1. Open the server's **Settings** and find the **Identity** section. +2. Confirm that **User Identity** is selected. +3. In **Choose an identity provider**, confirm that the preselected provider is Google (`https://accounts.google.com/`). If another provider is shown, open the picker, search in **Search identity providers…**, and choose the Google provider. A provider badged **Will be created** is created when you save. +4. Choose **Manual**. +5. In **Client ID**, paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). +6. In **Client secret**, paste the **Client secret** from the same section. Google requires it even though the field says "Optional". +7. Open **Advanced**. In **Scope**, enter this value on one line: -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token + https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/documents.readonly https://www.googleapis.com/auth/documents ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. In **Client ID**, paste the value you [copied from Google](external.md#copy-client-credentials). -1. In **Client Secret (optional)**, paste the secret you [copied from Google](external.md#copy-client-credentials). Google requires this value. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter this value: - - ``` - https://www.googleapis.com/auth/drive.readonly, https://www.googleapis.com/auth/drive.file, https://www.googleapis.com/auth/documents.readonly, https://www.googleapis.com/auth/documents - ``` - -#### Verify and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. + Do not leave **Scope** blank. A blank value requests every scope the server advertises, including full Drive access, which the consent screen does not grant. -For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). +8. Click **Save**. +9. Open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -Complete Google's browser authorization with the intended account. If the app is **External** and in **Testing**, that account must be listed under **Test users**. +When a person first uses the server, Google's browser authorization prompt appears. They must sign in with an account granted [MCP Tool User](external.md#grant-mcp-tool-user). If the app's audience is **External** and in **Testing**, the account must also be listed under **Test users**. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's Docs MCP documentation](https://developers.google.com/workspace/docs/api/guides/configure-mcp-server). diff --git a/go/generated/guides/google-drive/external.md b/go/generated/guides/google-drive/external.md index 51412bd..96cdc89 100644 --- a/go/generated/guides/google-drive/external.md +++ b/go/generated/guides/google-drive/external.md @@ -4,9 +4,23 @@ setup_version: 1 # Set up Google Drive -Use a Google Cloud project where you can enable services, configure the Google Auth platform, create credentials, and grant project roles. You need **Service Usage Admin** or **Owner** to enable the APIs and appropriate IAM administration access to grant **MCP Tool User**. Every connecting user needs a Google Account with access to the intended Drive files. +The Drive MCP server is available only through the Google Workspace Developer Preview Program, so the Google Cloud project must be registered in it. Use a Google Cloud project where you can enable services, configure the Google Auth platform, create credentials, and grant project roles. You need **Service Usage Admin** or **Owner** to enable the APIs and appropriate IAM administration access to grant **MCP Tool User**. Every connecting user needs a Google Account with access to the intended Drive files. -Sign in at [console.cloud.google.com](https://console.cloud.google.com) and select the project that will own the APIs and credentials. If your organization restricts high-risk Drive scopes, arrange access to a **Service Settings administrator** and obtain an approved app-access setting from the application or cloud security owner. +Sign in at [console.cloud.google.com](https://console.cloud.google.com) and select the project registered in the Developer Preview Program. It owns the APIs and credentials. If your organization restricts high-risk Drive scopes, arrange access to a **Service Settings administrator** and obtain an approved app-access setting from the application or cloud security owner. + +### Join the Google Workspace Developer Preview Program {#join-developer-preview} + +1. Open [developers.google.com/workspace/preview](https://developers.google.com/workspace/preview). +2. Review the **Developer Preview Program Terms** with the application or security owner. +3. Click **Apply to join the Developer Preview Program**. +4. In the application form, enter the requested Google Workspace account and Google Cloud project information. +5. Agree to the terms only with organizational approval. +6. Submit the form with the visible or equivalent submission control. +7. Wait for Google's project-registration confirmation at the submitted email address. Google says this should complete within a couple of days. + +Use the registered project for every Google Cloud step that follows. + + ### Enable the Google Drive API {#enable-drive-api} @@ -109,7 +123,7 @@ Do not add **Authorized JavaScript origins**. Before the next action, prepare an 1. In **OAuth 2.0 client created**, copy the **Client ID** to your approved secret store. 2. Under **Client secrets**, copy the **Client secret** to the same location. -3. Keep both values ready for [Speakeasy setup](speakeasy.md#connect-speakeasy-credentials). +3. Keep both values ready for [Speakeasy setup](speakeasy.md#add-server-in-speakeasy). If you lose the client secret before connecting, delete it and create a new one. diff --git a/go/generated/guides/google-drive/meta.yaml b/go/generated/guides/google-drive/meta.yaml index 7a163ce..dafc029 100644 --- a/go/generated/guides/google-drive/meta.yaml +++ b/go/generated/guides/google-drive/meta.yaml @@ -21,6 +21,8 @@ credential_setup: - external.md#create-oauth-client - external.md#copy-client-credentials requirements: + - id: developer-preview + description: Google has registered the Google Cloud project in the Google Workspace Developer Preview Program, which the Drive MCP server requires - id: google-cloud-project description: A Google Cloud project whose administrator can enable the Google Drive API and Google Drive MCP API, configure the Google Auth platform, create OAuth credentials, and grant connecting users the MCP Tool User role - id: workspace-policy-access @@ -39,7 +41,7 @@ remotes: locator: https://developers.google.com/workspace/drive/api/guides/configure-mcp-server name: Configure the Drive MCP server classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/drive/api/reference/mcp name: Google Drive MCP reference @@ -54,18 +56,23 @@ remotes: locator: https://drivemcp.googleapis.com/mcp/v1 name: Google Drive MCP endpoint classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://drivemcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Drive MCP protected-resource metadata classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" provenance: + - source: provider-documentation + locator: https://developers.google.com/workspace/preview + name: Google Workspace Developer Preview Program + classification: official + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/drive/api/guides/configure-mcp-server name: Configure the Drive MCP server classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/drive/api/reference/mcp name: Google Drive MCP reference @@ -105,7 +112,7 @@ provenance: locator: https://docs.cloud.google.com/mcp/set-up-authentication-mcp-servers name: Set up authentication to Google and Google Cloud MCP servers classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://docs.cloud.google.com/mcp/manage-mcp-servers name: Manage MCP servers @@ -140,19 +147,19 @@ provenance: locator: https://drivemcp.googleapis.com/mcp/v1 name: Google Drive MCP endpoint classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://drivemcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Drive MCP protected-resource metadata classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-29T20:37:22Z" + observed_at: "2026-09-30T21:25:45Z" diff --git a/go/generated/guides/google-drive/speakeasy.md b/go/generated/guides/google-drive/speakeasy.md index 1a3318f..76ca8e3 100644 --- a/go/generated/guides/google-drive/speakeasy.md +++ b/go/generated/guides/google-drive/speakeasy.md @@ -11,78 +11,37 @@ https://drivemcp.googleapis.com/mcp/v1 ``` -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. +Speakeasy saves the server as **Disabled** and says to finish setup in **Settings > Identity**. This is expected; the next section completes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token - ``` - -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). -1. Paste the **Client Secret (optional)** from the same section. Google's Web application flow requires the generated secret despite the optional field label. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -Configure these two scopes as required: +1. Open the server's **Settings** and find the **Identity** section. +2. Confirm that **User Identity** is selected. +3. In **Choose an identity provider**, confirm that the preselected provider is Google (`https://accounts.google.com/`). If another provider is shown, open the picker, search in **Search identity providers…**, and choose the Google provider. A provider badged **Will be created** is created when you save. +4. Choose **Manual**. +5. In **Client ID**, paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). +6. In **Client secret**, paste the **Client secret** from the same section. Google requires it even though the field says "Optional". +7. Open **Advanced**. In **Scope**, enter this value on one line: ``` - https://www.googleapis.com/auth/drive.readonly - https://www.googleapis.com/auth/drive.file + https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file ``` -#### Verify and attach + Do not leave **Scope** blank. A blank value requests every scope the server advertises, including full Drive access, which the consent screen does not grant. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +8. Click **Save**. +9. Open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). +When a person first uses the server, Google's browser authorization prompt appears. They must sign in with an account granted [MCP Tool User](external.md#grant-mcp-tool-user). If the app's audience is **External** and in **Testing**, the account must also be listed under **Test users**. - + -For more information, see [Google's Drive MCP documentation](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server). +This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's Drive MCP documentation](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server). diff --git a/go/generated/guides/google-people/external.md b/go/generated/guides/google-people/external.md index 7eeda39..ed3b73b 100644 --- a/go/generated/guides/google-people/external.md +++ b/go/generated/guides/google-people/external.md @@ -4,12 +4,24 @@ setup_version: 1 # Set up Google People -You need a Google Cloud project and access to the [Google Cloud console](https://console.cloud.google.com). To enable the People API, you need `serviceusage.services.enable`, normally through **Service Usage Admin** or **Owner**. To grant project roles, you need **Project IAM Admin**. Each connecting user must already have access to the intended Google profile, contacts, and directory data. Google documents that application developers are responsible for screening prompts and responses for malicious content or prompt injection; Model Armor is one documented option. +The People API MCP server is in the Google Workspace Developer Preview Program. You need a Google Workspace account that can be added to Google Groups and a Google Cloud project that your organization can register in the program. To enable the People API, you need `serviceusage.services.enable`, normally through **Service Usage Admin** or **Owner**. To grant project roles, you need **Project IAM Admin**. Each connecting user must already have access to the intended Google profile, contacts, and directory data. Google documents that application developers are responsible for screening prompts and responses for malicious content or prompt injection; Model Armor is one documented option. + +### Join the Google Workspace Developer Preview Program {#join-developer-preview} + +1. Open [developers.google.com/workspace/preview](https://developers.google.com/workspace/preview). +2. Review the **Developer Preview Program Terms** with the application or security owner. +3. Click **Apply to join the Developer Preview Program**. +4. In the current application form, enter the requested Google Workspace account and Google Cloud project information. +5. Agree to the terms only with organizational approval. +6. Submit the form with the visible or equivalent submission control. Google verifies the Workspace account, adds it to the program group, and then registers the Cloud project. +7. Wait for the final project-registration confirmation at the submitted email address. Google says this should complete within a couple of days. + + ### Enable the People API {#enable-people-api} 1. Sign in to the [Google Cloud console](https://console.cloud.google.com). -2. In the console toolbar, use the resource selector to select the project that will own this configuration. +2. In the console toolbar, use the resource selector to select the project registered in the Developer Preview Program. 3. Open **APIs & Services** > **API Library**. 4. In **Search for APIs & Services**, search for `People API`. 5. Open **People API**. diff --git a/go/generated/guides/google-people/meta.yaml b/go/generated/guides/google-people/meta.yaml index 43a1bd3..73b45ba 100644 --- a/go/generated/guides/google-people/meta.yaml +++ b/go/generated/guides/google-people/meta.yaml @@ -21,6 +21,8 @@ credential_setup: - external.md#create-oauth-client - external.md#copy-oauth-credentials requirements: + - id: developer-preview + description: Google has confirmed the intended Google Workspace account and registered the Google Cloud project in the Google Workspace Developer Preview Program - id: google-cloud-project description: A Google Cloud project where an administrator can enable the People API, grant project IAM roles, configure Google Auth platform, and create OAuth credentials - id: connecting-user-access @@ -40,18 +42,23 @@ remotes: locator: https://developers.google.com/people/v1/configure-mcp-server name: Configure the People API MCP server classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: endpoint-observation locator: https://people.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google People API MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" provenance: - source: provider-documentation locator: https://developers.google.com/people/v1/configure-mcp-server name: Configure the People API MCP server classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" + - source: provider-documentation + locator: https://developers.google.com/workspace/preview + name: Google Workspace Developer Preview Program + classification: official + observed_at: "2026-09-30T21:25:46Z" - source: provider-documentation locator: https://developers.google.com/people/api/mcp name: People API MCP reference @@ -116,14 +123,14 @@ provenance: locator: https://people.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google People API MCP protected-resource metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-29T15:13:24Z" + observed_at: "2026-09-30T21:25:46Z" diff --git a/go/generated/guides/google-people/speakeasy.md b/go/generated/guides/google-people/speakeasy.md index d4df93e..eac631c 100644 --- a/go/generated/guides/google-people/speakeasy.md +++ b/go/generated/guides/google-people/speakeasy.md @@ -10,90 +10,50 @@ 2. On the **MCP Catalog** page, find Google People in **Search MCP servers...**. 3. Open the matching entry. 4. Click **Add**. - 5. In **Add to Project**, click **Add to Project**. + 5. In **Add to Project**, under **Identity**, select **User Identity**. + 6. Click **Add to Project**. If a **Guardrails** step appears, click **Skip for now**. + 7. When the dialog finishes, the result reads "Added, but disabled until identity is set up." Click **Finish setup** to open the server's **Settings**. - If no matching catalog entry is available: 1. Choose **Hosted remotely**. 2. On **New remote MCP server**, paste this URL into **MCP server URL**: - ``` + ```text https://people.googleapis.com/mcp/v1 ``` - 3. Click **Verify connectivity**, then **Save**. + 3. Leave **User session issuer** at its default. + 4. Click **Verify connectivity**. + 5. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. + 6. If **Guardrails** appears, leave it off. + 7. Click **Save**. -For the catalog path, click **Configure MCP settings** on the completion screen to open the server, then open **Settings**. The **Hosted remotely** path opens **Overview** after **Save**; open **Settings** there. +Either way, Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Google People; the next section finishes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth - ``` +Open the server's **Settings** and find the **Identity** section. - Token endpoint: +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm that the preselected provider is Google's issuer, `https://accounts.google.com/`. It is badged **Will be created** when the project has no Google provider yet. If another provider is selected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Under the provider, choose **Manual**. If **Existing client** is preselected, switch to **Manual**. +4. Paste the **Client ID** from the [OAuth credentials](external.md#copy-oauth-credentials) into **Client ID**. +5. Paste the **Client Secret** from the [OAuth credentials](external.md#copy-oauth-credentials) into **Client secret**. Google requires the secret even though the field shows "Optional". +6. Open **Advanced**. In **Scope**, enter this value on one line: ```text - https://oauth2.googleapis.com/token + https://www.googleapis.com/auth/directory.readonly https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/contacts.readonly ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. Paste the **Client ID** from the [OAuth credentials](external.md#copy-oauth-credentials). -1. Paste the **Client Secret (optional)** from the [OAuth credentials](external.md#copy-oauth-credentials). Google requires this secret even though the field is labeled optional. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter these three identifiers using the field's visible or equivalent multi-scope format: - - ``` - https://www.googleapis.com/auth/directory.readonly - https://www.googleapis.com/auth/userinfo.profile - https://www.googleapis.com/auth/contacts.readonly - ``` - -#### Verify and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +7. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +8. Open **Settings > Danger Zone > Server Availability**. +9. Turn on **Enable MCP server** so the switch shows **Enabled**. -For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). +The callback Speakeasy uses is the `{{ gram.oauth.callback_url }}` value you registered in [Create the OAuth client](external.md#create-oauth-client). At first connection, follow Google's visible or equivalent browser authorization controls with an account that has [MCP Tool User access](external.md#grant-mcp-tool-user). - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's People API MCP documentation](https://developers.google.com/people/v1/configure-mcp-server). diff --git a/go/generated/guides/google-sheets/external.md b/go/generated/guides/google-sheets/external.md index 94569c2..d9cc4c5 100644 --- a/go/generated/guides/google-sheets/external.md +++ b/go/generated/guides/google-sheets/external.md @@ -4,9 +4,23 @@ setup_version: 1 # Set up Google Sheets -Use a Google Cloud project where you can enable services, grant project IAM roles, configure the **Google Auth platform**, and create OAuth credentials. You normally need **Service Usage Admin** or **Owner** to enable the APIs and **Project IAM Admin** to grant access. Each person who will connect needs access to the intended spreadsheets. Before setup, have the application or security owner configure prompt and response screening for malicious content or prompt injection. +The Sheets MCP server is available only through the Google Workspace Developer Preview Program, so the Google Cloud project must be registered in it. Use a Google Cloud project where you can enable services, grant project IAM roles, configure the **Google Auth platform**, and create OAuth credentials. You normally need **Service Usage Admin** or **Owner** to enable the APIs and **Project IAM Admin** to grant access. Each person who will connect needs access to the intended spreadsheets. Before setup, have the application or security owner configure prompt and response screening for malicious content or prompt injection. -Sign in to the [Google Cloud console](https://console.cloud.google.com). In the console toolbar, use the resource selector to choose the project that will own this configuration. Keep the same project selected throughout setup. +Sign in to the [Google Cloud console](https://console.cloud.google.com). In the console toolbar, use the resource selector to choose the project registered in the Developer Preview Program. Keep the same project selected throughout setup. + +### Join the Google Workspace Developer Preview Program {#join-developer-preview} + +1. Open [developers.google.com/workspace/preview](https://developers.google.com/workspace/preview). +2. Review the **Developer Preview Program Terms** with the application or security owner. +3. Click **Apply to join the Developer Preview Program**. +4. In the application form, enter the requested Google Workspace account and Google Cloud project information. +5. Agree to the terms only with organizational approval. +6. Submit the form with the visible or equivalent submission control. +7. Wait for Google's project-registration confirmation at the submitted email address. Google says this should complete within a couple of days. + +Use the registered project for every Google Cloud step that follows. + + ### Enable the Google Sheets APIs {#enable-google-sheets-apis} @@ -106,6 +120,6 @@ This opens **OAuth 2.0 client created**. If you miss the one-time **Client secret**, delete it and create a new one before continuing. -Keep both values available, then [connect your credentials in the Speakeasy AI Control Plane](speakeasy.md#connect-speakeasy-credentials). +Keep both values available, then [add the server in the Speakeasy AI Control Plane](speakeasy.md#add-server-in-speakeasy). diff --git a/go/generated/guides/google-sheets/meta.yaml b/go/generated/guides/google-sheets/meta.yaml index 07c5992..eb10f96 100644 --- a/go/generated/guides/google-sheets/meta.yaml +++ b/go/generated/guides/google-sheets/meta.yaml @@ -21,6 +21,8 @@ credential_setup: - external.md#create-oauth-client - external.md#copy-oauth-credentials requirements: + - id: developer-preview + description: Google has registered the Google Cloud project in the Google Workspace Developer Preview Program, which the Sheets MCP server requires - id: google-cloud-project description: A Google Cloud project where an administrator can enable the Google Sheets API and Google Sheets MCP API, grant project IAM roles, configure Google Auth platform, and create OAuth credentials - id: connecting-user-access @@ -41,28 +43,33 @@ remotes: locator: https://developers.google.com/workspace/sheets/api/guides/configure-mcp-server name: Configure the Sheets MCP server classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://sheetsmcp.googleapis.com/mcp/v1 name: Google Sheets MCP endpoint classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://sheetsmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Sheets MCP protected-resource metadata classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" provenance: + - source: provider-documentation + locator: https://developers.google.com/workspace/preview + name: Google Workspace Developer Preview Program + classification: official + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/sheets/api/guides/configure-mcp-server name: Configure the Sheets MCP server classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/guides/configure-mcp-servers name: Configure the Google Workspace MCP servers classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://developers.google.com/workspace/guides/configure-oauth-consent name: Configure the OAuth consent screen and choose scopes @@ -82,7 +89,7 @@ provenance: locator: https://docs.cloud.google.com/mcp/set-up-authentication-mcp-servers name: Set up authentication to Google and Google Cloud MCP servers classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: provider-documentation locator: https://cloud.google.com/service-usage/docs/enable-disable name: Enable and disable services @@ -118,20 +125,20 @@ provenance: name: Google Sheets MCP endpoint classification: official status: MCP initialize returned HTTP 200 - version: "2025-03-26" - observed_at: "2026-07-29T20:37:05Z" + version: "2025-06-18" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://sheetsmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Sheets MCP protected-resource metadata classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-29T20:37:05Z" + observed_at: "2026-09-30T21:25:45Z" diff --git a/go/generated/guides/google-sheets/speakeasy.md b/go/generated/guides/google-sheets/speakeasy.md index 29883e7..8ca9838 100644 --- a/go/generated/guides/google-sheets/speakeasy.md +++ b/go/generated/guides/google-sheets/speakeasy.md @@ -11,79 +11,37 @@ https://sheetsmcp.googleapis.com/mcp/v1 ``` -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. +Speakeasy saves the server as **Disabled** and says to finish setup in **Settings > Identity**. This is expected; the next section completes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). +1. Open the server's **Settings** and find the **Identity** section. +2. Confirm that **User Identity** is selected. +3. In **Choose an identity provider**, confirm that the preselected provider is Google (`https://accounts.google.com/`). If another provider is shown, open the picker, search in **Search identity providers…**, and choose the Google provider. A provider badged **Will be created** is created when you save. +4. Choose **Manual**. +5. In **Client ID**, paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). +6. In **Client secret**, paste the **Client secret** from the same section. Google requires it even though the field says "Optional". +7. Open **Advanced**. In **Scope**, enter this value on one line: -#### Choose an authentication provider - -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token + https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/spreadsheets.readonly https://www.googleapis.com/auth/spreadsheets ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. In **Client ID**, paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -1. In **Client Secret (optional)**, paste the **Client secret** from the same step. Google requires this generated secret. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter this value: - - ``` - https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/drive.file,https://www.googleapis.com/auth/spreadsheets.readonly,https://www.googleapis.com/auth/spreadsheets - ``` - -#### Verify and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. + Do not leave **Scope** blank. A blank value requests every scope the server advertises, including full Drive access, which the consent screen does not grant. -For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). +8. Click **Save**. +9. Open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -At first connection, complete Google's browser authorization with an account granted [MCP Tool User](external.md#grant-mcp-tool-user) and access to the intended spreadsheets. +When a person first uses the server, Google's browser authorization prompt appears. They must sign in with an account granted [MCP Tool User](external.md#grant-mcp-tool-user). If the app's audience is **External** and in **Testing**, the account must also be listed under **Test users**. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's Sheets MCP documentation](https://developers.google.com/workspace/sheets/api/guides/configure-mcp-server). diff --git a/go/generated/guides/google-slides/external.md b/go/generated/guides/google-slides/external.md index 9866979..5cf7d17 100644 --- a/go/generated/guides/google-slides/external.md +++ b/go/generated/guides/google-slides/external.md @@ -4,11 +4,27 @@ setup_version: 1 # Set up Google Slides -The Google Slides MCP Server is in Developer Preview. Google does not document a Google Slides MCP-specific paid plan or license requirement. +The Google Slides MCP Server is in Developer Preview. Google requires membership in the Google Workspace Developer Preview Program, with the Google Cloud project registered in the program. Google does not document a Google Slides MCP-specific paid plan or license requirement. Use a Google Cloud project where you can enable services, grant project roles, configure **Google Auth platform**, and create OAuth credentials. Each connecting user needs access to the intended presentations. An application or security owner must also configure prompt and response screening for malicious content or prompt injection. -Sign in to the [Google Cloud console](https://console.cloud.google.com). In the console toolbar, select the project that will own this configuration, and keep it selected throughout the Google Cloud steps. +### Join the Google Workspace Developer Preview Program {#join-developer-preview} + +Skip this step if Google has already registered the project in the program. + +1. Open [developers.google.com/workspace/preview](https://developers.google.com/workspace/preview). +2. Review the **Developer Preview Program Terms** with the application or security owner. +3. Click **Apply to join the Developer Preview Program**. +4. In the current application form, enter the requested Google Workspace account and Google Cloud project information. The submitted email must accept being added to Google Groups. +5. Agree to the terms only with organizational approval. +6. Submit the form with the visible or equivalent submission control. +7. Wait for the final project-registration confirmation at the submitted email address. Google says this should complete within a couple of days. +8. After confirmation, sign in to the [Google Cloud console](https://console.cloud.google.com). +9. In the console toolbar, select the registered project. + +Keep that project selected throughout the Google Cloud steps. + + ### Enable the Google Slides APIs {#enable-google-slides-apis} diff --git a/go/generated/guides/google-slides/meta.yaml b/go/generated/guides/google-slides/meta.yaml index 80c6e9b..6d95589 100644 --- a/go/generated/guides/google-slides/meta.yaml +++ b/go/generated/guides/google-slides/meta.yaml @@ -22,6 +22,8 @@ credential_setup: - external.md#create-oauth-client - external.md#copy-oauth-credentials requirements: + - id: developer-preview + description: Google has registered the Google Cloud project in the Google Workspace Developer Preview Program, and the applicant's email accepts being added to the program's Google Group - id: google-cloud-project description: A Google Cloud project where an administrator can enable the Google Slides API and Google Slides MCP API, grant project IAM roles, configure Google Auth platform, and create OAuth credentials - id: connecting-user-access @@ -44,25 +46,30 @@ remotes: locator: https://developers.google.com/workspace/slides/api/guides/configure-mcp-server name: Configure the Slides MCP server classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" - source: endpoint-observation locator: https://slidesmcp.googleapis.com/mcp/v1 name: Google Slides MCP endpoint classification: official status: MCP initialize returned HTTP 200 - version: "2025-03-26" - observed_at: "2026-07-29T21:55:52Z" + version: "2025-06-18" + observed_at: "2026-09-30T21:25:42Z" - source: endpoint-observation locator: https://slidesmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Slides MCP protected-resource metadata classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" provenance: - source: provider-documentation locator: https://developers.google.com/workspace/slides/api/guides/configure-mcp-server name: Configure the Slides MCP server classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" + - source: provider-documentation + locator: https://developers.google.com/workspace/preview + name: Google Workspace Developer Preview Program + classification: official + observed_at: "2026-09-30T21:25:42Z" - source: provider-documentation locator: https://developers.google.com/workspace/guides/configure-mcp-servers name: Configure the Google Workspace MCP servers @@ -123,20 +130,20 @@ provenance: name: Google Slides MCP endpoint classification: official status: MCP initialize returned HTTP 200 - version: "2025-03-26" - observed_at: "2026-07-29T21:55:52Z" + version: "2025-06-18" + observed_at: "2026-09-30T21:25:42Z" - source: endpoint-observation locator: https://slidesmcp.googleapis.com/.well-known/oauth-protected-resource/mcp/v1 name: Google Slides MCP protected-resource metadata classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" - source: endpoint-observation locator: https://accounts.google.com/.well-known/oauth-authorization-server name: Google authorization-server metadata classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-29T21:55:52Z" + observed_at: "2026-09-30T21:25:42Z" diff --git a/go/generated/guides/google-slides/speakeasy.md b/go/generated/guides/google-slides/speakeasy.md index 48cdcf0..b5e5795 100644 --- a/go/generated/guides/google-slides/speakeasy.md +++ b/go/generated/guides/google-slides/speakeasy.md @@ -11,79 +11,41 @@ https://slidesmcp.googleapis.com/mcp/v1 ``` -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. After verification succeeds, select **User Identity** under **Identity**. The page preselects **No Identity** for this server, so change it. +8. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. **Transport** is read-only. +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Google Slides; continue with the next section. - + ### Connect your credentials {#connect-speakeasy-credentials} -Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). +Open the server's **Settings** and find the **Identity** section. -#### Choose an authentication provider +1. Confirm **User Identity** is selected. +2. Under **Choose an identity provider**, confirm the preselected Google provider (`https://accounts.google.com`). A new provider shows **Will be created**. If a different provider is preselected, open the picker, search in **Search identity providers…**, and choose the Google provider. +3. Choose **Manual**. If **Existing client** is preselected, switch to **Manual** unless that client is the one created in [Create the OAuth client](external.md#create-oauth-client) with the four scopes below. +4. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client ID**. +5. Paste the **Client secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client secret**. Google requires this secret even though the field shows "Optional". +6. Under **Advanced > Scope**, enter this value on one line: -- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. -- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. -- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. - -In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. - -#### New provider only - -1. Choose **Add new** and enter **Issuer URL**: - - ```text - https://accounts.google.com/ - ``` - -2. Confirm the auto-derived **Slug** is unique in the project. -3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. -4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. - - Authorization endpoint: - - ```text - https://accounts.google.com/o/oauth2/v2/auth ``` - - Token endpoint: - - ```text - https://oauth2.googleapis.com/token + https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/presentations.readonly https://www.googleapis.com/auth/presentations ``` -#### Choose a session client - -- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. -- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. - -#### New session client only - -1. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -1. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google's web client requires this generated secret. - -#### Check client requirements - -For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. - -Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. - -For a new client, enter this value: - - ``` - https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/drive.file,https://www.googleapis.com/auth/presentations.readonly,https://www.googleapis.com/auth/presentations - ``` + Do not leave **Scope** blank. A blank value also requests full Google Drive access (`https://www.googleapis.com/auth/drive`), which the consent screen does not grant. -#### Verify and attach +7. Click **Save**. If asked to confirm, click **Save changes**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +Turn the server on: -For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). +1. Open **Settings > Danger Zone > Server Availability**. +2. Turn on the switch (**Enable MCP server**) so it shows **Enabled**. At first connection, complete Google's browser authorization with an account granted **MCP Tool User** in [Grant MCP Tool User access](external.md#grant-mcp-tool-user) and access to the intended presentations. An **External** app in **Testing** also requires that account under **Test users**. - + -For anything beyond setup — billing, tool behavior, or limits — see [Google's Slides MCP documentation](https://developers.google.com/workspace/slides/api/guides/configure-mcp-server). +This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Google's Slides MCP documentation](https://developers.google.com/workspace/slides/api/guides/configure-mcp-server). diff --git a/go/generated/guides/hubspot/external.md b/go/generated/guides/hubspot/external.md index 2b63c9b..281943c 100644 --- a/go/generated/guides/hubspot/external.md +++ b/go/generated/guides/hubspot/external.md @@ -8,23 +8,23 @@ You need a HubSpot account and a user who can open the **Development** workspace from the main navigation bar. The remote MCP server is available to all HubSpot accounts. Sign in at [app.hubspot.com](https://app.hubspot.com). -### Open MCP Auth Apps in the Development workspace {#open-mcp-auth-apps} +### Open MCP Connectors in the Development workspace {#open-mcp-auth-apps} 1. Sign in at [app.hubspot.com](https://app.hubspot.com). 2. In the main navigation bar, select **Development**. -3. In the left sidebar menu, select **MCP Auth Apps**. +3. In the left sidebar menu, select **MCP Connectors**. If **Development** is unavailable, use the direct -[MCP Auth Apps page](https://app.hubspot.com/l/mcp-auth-apps/). If you still +[MCP Connectors page](https://app.hubspot.com/l/mcp-auth-apps/). If you still cannot open it, ask your HubSpot administrator to confirm your access to this developer feature. - + -### Create the MCP auth app {#create-mcp-auth-app} +### Create the MCP connector {#create-mcp-auth-app} -1. In the upper right, click **Create MCP auth app**. -2. In **App name**, enter a recognizable name, such as +1. In the upper right, click **Create MCP connector**. +2. In **Name**, enter a recognizable name, such as `Speakeasy AI Control Plane`. 3. Optionally, enter a **Description**. 4. In **Redirect URL**, paste this value: @@ -40,11 +40,11 @@ If you configure multiple redirect URLs, keep `{{ gram.oauth.callback_url }}` first because HubSpot uses the first URL as the default. - + ### Copy the client credentials {#copy-client-credentials} -HubSpot opens the app's details page. +HubSpot opens the connector's details page. 1. Copy the **Client ID**. 2. Copy the **Client secret**. diff --git a/go/generated/guides/hubspot/meta.yaml b/go/generated/guides/hubspot/meta.yaml index 5264490..c1eb9da 100644 --- a/go/generated/guides/hubspot/meta.yaml +++ b/go/generated/guides/hubspot/meta.yaml @@ -2,7 +2,7 @@ schema_version: 1 slug: hubspot title: HubSpot -summary: Connect HubSpot's hosted MCP server using an MCP auth app and OAuth. +summary: Connect HubSpot's hosted MCP server using an MCP connector and OAuth. aliases: - com.pulsemcp.mirror/hubspot speakeasy_add_server: catalog @@ -23,7 +23,7 @@ credential_setup: - external.md#copy-client-credentials requirements: - id: hubspot-account - description: HubSpot account whose user can open the Development workspace from the main navigation bar to create and manage MCP auth apps + description: HubSpot account whose user can open the Development workspace from the main navigation bar to create and manage MCP connectors documentation: external: external.md speakeasy: speakeasy.md @@ -38,11 +38,11 @@ remotes: locator: https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server name: Integrate AI tools with the HubSpot MCP server classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation locator: https://mcp.hubspot.com/.well-known/oauth-protected-resource classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" provenance: - source: pulsemcp name: com.pulsemcp.mirror/hubspot @@ -54,7 +54,7 @@ provenance: locator: https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server name: Integrate AI tools with the HubSpot MCP server classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://developers.hubspot.com/docs/llms.txt name: HubSpot developer documentation index @@ -93,13 +93,13 @@ provenance: - source: endpoint-observation locator: https://mcp.hubspot.com/.well-known/oauth-protected-resource classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation locator: https://mcp.hubspot.com/.well-known/oauth-authorization-server classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-28T18:22:41Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/hubspot/speakeasy.md b/go/generated/guides/hubspot/speakeasy.md index c6521de..b275a76 100644 --- a/go/generated/guides/hubspot/speakeasy.md +++ b/go/generated/guides/hubspot/speakeasy.md @@ -9,43 +9,32 @@ **HubSpot**. 5. Open the **HubSpot** entry. 6. Click **Add**. -7. In the **Add to Project** dialog, click **Add to Project**. +7. In the **Add to Project** dialog, under **Identity**, select **User Identity**. The dialog preselects **No Identity** for HubSpot. +8. Click **Add to Project**. If the dialog offers a **Guardrails** step, click **Skip for now**. +9. When the dialog finishes, the result reads "Added, but disabled until identity is set up." Click **Finish setup** to open the server's **Settings**. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +HubSpot needs a client registered by hand, so the server is kept **Disabled** and the result says to finish setup in **Settings > Identity**. This is expected. - + ### Connect your credentials {#connect-speakeasy-credentials} -Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. +Open the server's **Settings** and find the **Identity** section. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. - -#### Select the identity provider - -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). - -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. - -For **Identity Provider > Add new**, use **Issuer URL** `https://mcp.hubspot.com`, authorization endpoint `https://mcp.hubspot.com/oauth/authorize/user`, and token endpoint `https://mcp.hubspot.com/oauth/v3/token`. Keep the auto-derived **Slug**. - -#### Select the session client - -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: - -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Paste the **Client ID** copied in +1. Select **User Identity**. +2. Under **Choose an identity provider**, confirm the preselected provider is `https://mcp.hubspot.com`. A provider that does not exist yet shows **Will be created**. +3. Select **Manual**. It is the default for HubSpot unless the provider already has a client. +4. In **Client ID**, paste the **Client ID** copied in [Copy the client credentials](external.md#copy-client-credentials). -1. Paste the **Client Secret (optional)** copied in - [Copy the client credentials](external.md#copy-client-credentials). -1. Leave any scope override empty. - -#### Verify the callback and attach +5. In **Client secret**, paste the **Client secret** copied in + [Copy the client credentials](external.md#copy-client-credentials). HubSpot requires it, even though the field shows "Optional". +6. Leave **Advanced > Scope** blank. HubSpot determines scopes automatically and advertises none, so a blank field requests nothing extra. +7. Click **Save**. +8. Open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +This screen does not show the redirect URI. If authorization later fails with a redirect error, check that the connector's **Redirect URL** in HubSpot is `{{ gram.oauth.callback_url }}`, as set in [Create the MCP connector](external.md#create-mcp-auth-app). - + For the HubSpot account's first connection, use an account admin. HubSpot does not document which admin role qualifies. diff --git a/go/generated/guides/intercom/meta.yaml b/go/generated/guides/intercom/meta.yaml index 901c5ea..cb30c00 100644 --- a/go/generated/guides/intercom/meta.yaml +++ b/go/generated/guides/intercom/meta.yaml @@ -40,7 +40,7 @@ remotes: locator: https://developers.intercom.com/docs/guides/mcp name: Model Context Protocol (MCP) classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: operator-validation locator: draft-guide operator notes for intercom status: manual OAuth validated @@ -56,7 +56,7 @@ remotes: locator: https://developers.intercom.com/docs/guides/mcp name: Model Context Protocol (MCP) classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: operator-validation locator: draft-guide operator notes for intercom status: manual OAuth validated @@ -66,7 +66,7 @@ provenance: locator: https://developers.intercom.com/docs/guides/mcp name: Model Context Protocol (MCP) classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://developers.intercom.com/docs/build-an-integration/getting-started name: Set up a Workspace @@ -76,7 +76,7 @@ provenance: locator: https://developers.intercom.com/docs/build-an-integration/learn-more/authentication/setting-up-oauth name: Setting up OAuth classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://developers.intercom.com/docs/build-an-integration/learn-more/authentication/oauth-scopes name: OAuth Scopes @@ -105,7 +105,11 @@ provenance: - source: endpoint-observation locator: https://mcp.intercom.com/.well-known/oauth-authorization-server classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" + - source: endpoint-observation + locator: https://mcp.eu.intercom.com/.well-known/oauth-authorization-server + classification: official + observed_at: "2026-09-30T00:00:00Z" - source: operator-validation locator: draft-guide operator notes for intercom status: manual OAuth recommended; DCR requires callback allowlisting @@ -114,4 +118,4 @@ provenance: locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-29T15:06:51Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/intercom/speakeasy.md b/go/generated/guides/intercom/speakeasy.md index ce91917..0c0ace5 100644 --- a/go/generated/guides/intercom/speakeasy.md +++ b/go/generated/guides/intercom/speakeasy.md @@ -3,54 +3,67 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **Hosted remotely**. 4. On **New remote MCP server**, paste the remote URL from [Identify the workspace region](external.md#identify-workspace-region) into **MCP server URL**. -5. Click **Verify connectivity**, then **Save**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for this server, so change it. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Intercom; the next section finishes it. - + ### Connect your credentials {#connect-speakeasy-credentials} -From the server's **Overview**, open **Settings**. +Intercom's server does not publish metadata the provider picker can use, so create the Intercom provider and its client first. Use the values for the region you recorded in [Identify the workspace region](external.md#identify-workspace-region). -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Open the server's **Settings** and find the **Identity** section. +2. Select **User Identity**. +3. Open **Choose an identity provider** and click **Create a custom identity provider**. This opens **Remote Identity Providers**. +4. Click **New Remote Identity Provider**. +5. In **Issuer URL**, enter `https://mcp.intercom.com` for a US workspace or `https://mcp.eu.intercom.com` for an EU workspace. -#### Select the identity provider +6. Under **Endpoints**, in **Authorization Endpoint**, enter the value for your region. -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). - -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. - -1. Enter `https://mcp.intercom.com` as **Issuer URL**. -1. Under **Endpoints**, set the authorization endpoint to `https://app.intercom.com/oauth`. -1. Set the token endpoint to this URL: + US workspace: + ```text + https://app.intercom.com/oauth ``` - https://api.intercom.io/auth/eagle/token - ``` - -#### Select the session client -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + EU workspace: -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). -1. Paste the **Client Secret (optional)** from [Copy the client credentials](external.md#copy-client-credentials). -1. Leave **Scope (override)** empty. -1. Leave **Audience (optional)** empty. - -#### Verify the callback and attach + ```text + https://app.eu.intercom.com/oauth + ``` -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. + Do not click **Discover**: it fills in Intercom's MCP `/authorize` and `/token` endpoints, which do not work with the app you created. -For the provider-side callback setting, see [Configure OAuth](external.md#configure-oauth). +7. In **Token Endpoint**, enter this value for either region: - + ```text + https://api.intercom.io/auth/eagle/token + ``` -When a client initiates Intercom access, complete the on-screen browser prompts with the intended workspace account. +8. Keep the derived **Slug** and click **Create**. +9. On the new provider, click **Add Client**. +10. Set **Client Type** to **Manual**. +11. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. +12. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client Secret (optional)**. Intercom requires the secret. +13. Leave **Scope (override)** empty. The permissions you selected in [Configure OAuth](external.md#configure-oauth) apply. +14. Confirm that the displayed **Redirect URI** matches the callback you registered in [Configure OAuth](external.md#configure-oauth), then click **Create**. +15. Return to the server's **Settings > Identity** and select **User Identity**. +16. In **Choose an identity provider**, select the Intercom provider you created. +17. Choose **Existing client** and pick the new client under **Client**. +18. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +19. Open **Settings > Danger Zone > Server Availability**. +20. Turn on **Enable MCP server** so the switch shows **Enabled**. + +When a person first uses the server, Intercom's browser authorization prompt appears. Complete it with an account in the intended workspace. + + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Intercom's MCP documentation](https://developers.intercom.com/docs/guides/mcp). diff --git a/go/generated/guides/netsuite/external.md b/go/generated/guides/netsuite/external.md index 357414a..818edce 100644 --- a/go/generated/guides/netsuite/external.md +++ b/go/generated/guides/netsuite/external.md @@ -58,7 +58,7 @@ Sign in to the NetSuite application as an Administrator or delegated administrat ``` For a sandbox or Release Preview account, replace underscores with hyphens and uppercase letters with lowercase letters. For example, `123456_SB1` becomes `123456-sb1`. -4. Keep the completed endpoint for **Remote MCP server URL** in the Speakeasy AI Control Plane. +4. Keep the completed endpoint for **MCP server URL** in the Speakeasy AI Control Plane. diff --git a/go/generated/guides/netsuite/meta.yaml b/go/generated/guides/netsuite/meta.yaml index d4bf84e..a26549e 100644 --- a/go/generated/guides/netsuite/meta.yaml +++ b/go/generated/guides/netsuite/meta.yaml @@ -39,7 +39,7 @@ remotes: locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_0714082142.html name: Connect to the NetSuite AI Connector Service classification: official - observed_at: "2026-08-07T22:23:30Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/article_0902023450.html name: Installing the MCP Standard Tools SuiteApp @@ -50,7 +50,7 @@ provenance: locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/article_4160616848.html name: NetSuite AI Connector Service FAQ classification: official - observed_at: "2026-08-07T22:23:30Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/article_3200541651.html name: Get Started with the NetSuite AI Connector Service @@ -75,7 +75,7 @@ provenance: locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_0714082142.html name: Connect to the NetSuite AI Connector Service classification: official - observed_at: "2026-08-07T22:23:30Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_157771733782.html name: Create Integration Records for Applications to Use OAuth 2.0 @@ -91,11 +91,26 @@ provenance: name: URLs for Account-Specific Domains classification: official observed_at: "2026-08-07T22:23:30Z" + - source: provider-documentation + locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_158081944642.html + name: Step One GET Request to the Authorization Endpoint + classification: official + observed_at: "2026-09-30T00:00:00Z" + - source: provider-documentation + locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_158081952044.html + name: Step Two POST Request to the Token Endpoint + classification: official + observed_at: "2026-09-30T00:00:00Z" + - source: provider-documentation + locator: https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_160855299656.html + name: Configure NetSuite as OIDC Provider + classification: official + observed_at: "2026-09-30T00:00:00Z" - source: speakeasy-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical file classification: official - observed_at: "2026-08-07T22:23:30Z" + observed_at: "2026-09-30T00:00:00Z" - source: operator-validation locator: draft-guide operator notes for netsuite status: Bundle ID 522506; public-client PKCE path; scoped non-admin role; Attach Remote Identity Provider shows Redirect URI with a copy button before credential entry; Speakeasy MCP Catalog result overridden-tenanted for query netsuite; tenanted remote requires Custom remote path diff --git a/go/generated/guides/netsuite/speakeasy.md b/go/generated/guides/netsuite/speakeasy.md index a94825d..e063804 100644 --- a/go/generated/guides/netsuite/speakeasy.md +++ b/go/generated/guides/netsuite/speakeasy.md @@ -3,43 +3,61 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **Hosted remotely**. -4. On **New remote MCP server**, paste the account-specific endpoint you formed in [Record the account-specific MCP URL](external.md#record-account-mcp-url) into **MCP server URL**. **Transport** is read-only. -5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. +4. On **New remote MCP server**, paste the account-specific endpoint you formed in [Record the account-specific MCP URL](external.md#record-account-mcp-url) into **MCP server URL**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity** if it is not already selected. +8. If **Guardrails** appears, leave it off. +9. Click **Save**. - +If Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**, that is expected; the next section finishes it. -### Connect your credentials {#connect-speakeasy-credentials} - -From the server's **Overview**, open **Settings**. + -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. - -#### Select the identity provider +### Connect your credentials {#connect-speakeasy-credentials} -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). +Create a NetSuite provider for your account, add the integration's client to it, then select it on the server. In each value below, replace `` with the same domain-form account ID you used in [Record the account-specific MCP URL](external.md#record-account-mcp-url). -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. +1. Open the server's **Settings** and find the **Identity** section. +2. Select **User Identity**. +3. Open **Choose an identity provider** and click **Create a custom identity provider**. This opens **Remote Identity Providers**. +4. Click **New Remote Identity Provider**. +5. In **Issuer URL**, enter: -If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. + ```text + https://.suitetalk.api.netsuite.com + ``` -#### Select the session client +6. Under **Endpoints**, in **Authorization Endpoint**, enter: -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + ```text + https://.app.netsuite.com/app/login/oauth2/authorize.nl + ``` -1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -1. Use the displayed **Redirect URI** and its copy button to confirm that the value matches the callback registered in [Create the OAuth integration](external.md#create-oauth-integration). -1. Paste the **Client ID** copied in that step. -1. Leave **Client Secret (optional)** empty. +7. In **Token Endpoint**, enter: -#### Verify the callback and attach + ```text + https://.suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token + ``` -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +8. Keep the derived **Slug** and click **Create**. +9. On the new provider, click **Add Client**. +10. Set **Client Type** to **Manual**. +11. Paste the **Client ID** from [Create the OAuth integration](external.md#create-oauth-integration) into **Client ID**. +12. Leave **Client Secret (optional)** empty. The integration is a public client. +13. In **Scope (override)**, enter `mcp`. NetSuite accepts `mcp` only on its own, so add no other scope. +14. Confirm that the displayed **Redirect URI** matches the callback you registered in [Create the OAuth integration](external.md#create-oauth-integration), then click **Create**. +15. Return to the server's **Settings > Identity** and select **User Identity**. +16. In **Choose an identity provider**, select the NetSuite provider you created. +17. Choose **Existing client** and pick the new client under **Client**. +18. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +19. Open **Settings > Danger Zone > Server Availability**. +20. Turn on **Enable MCP server** so the switch shows **Enabled**. -When a client first requests access, sign in to NetSuite with the scoped non-Administrator role assigned in [Configure a scoped non-admin role](external.md#configure-scoped-role). Review the allow/deny prompt, then allow access only after reviewing your organization's data-sharing controls. +When a person first uses the server, NetSuite's browser sign-in appears. Sign in with the scoped non-Administrator role assigned in [Configure a scoped non-admin role](external.md#configure-scoped-role), review the allow/deny prompt, and allow access only after reviewing your organization's data-sharing controls. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [NetSuite's MCP documentation](https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/article_4160616848.html). diff --git a/go/generated/guides/salesforce/external.md b/go/generated/guides/salesforce/external.md index 031efb6..7521d6c 100644 --- a/go/generated/guides/salesforce/external.md +++ b/go/generated/guides/salesforce/external.md @@ -4,7 +4,7 @@ setup_version: 1 # Connect Salesforce to the Speakeasy AI Control Plane -Use Salesforce System Administrator credentials for an API-enabled production org where Hosted MCP Servers are available. Salesforce documents availability for Enterprise Edition and above. You need authority to install the Speakeasy application or create an **External Client App**, and enable Hosted MCP Servers. +Use Salesforce System Administrator credentials for an API-enabled production or sandbox org where Hosted MCP Servers are available. Salesforce documents availability for Enterprise Edition and above. You need authority to install the Speakeasy application or create an **External Client App**, and enable Hosted MCP Servers. Sign in to the Salesforce org you want to connect. Install or create the app in that same org. This guide does not cover scratch orgs. For a lower-edition org, confirm Hosted MCP availability in [Salesforce Setup](#open-salesforce-setup) before starting either path. @@ -41,7 +41,7 @@ After installation, **contact Speakeasy support to finish OAuth setup**. Install -## Create your own Salesforce app +## Create your own Salesforce app {#create-your-own-salesforce-app} Before creating the app, choose a server in the [endpoint reference](#endpoint-reference) and confirm its prerequisites. Then create an **External Client App** in the org you want to connect and enable that server. @@ -85,7 +85,7 @@ This path uses the app's **Consumer Key** without a client secret. Salesforce do Select **Create**. -The app can take up to 30 minutes to become operational. If attachment fails immediately, allow that window before retrying. +The app can take up to 30 minutes to become operational. If sign-in fails immediately, allow that window before retrying. @@ -116,64 +116,120 @@ Choose the least-privileged server that meets your team's needs using the endpoi If you created your own app, continue to [Speakeasy setup](speakeasy.md#add-server-in-speakeasy) with your selected URL and **Consumer Key**. If you installed Speakeasy's app, continue with Speakeasy support. -## Endpoint reference +## Endpoint reference {#endpoint-reference} -The following endpoints are for production orgs. Copy the URL for your selected server. +Copy the production or sandbox URL for your selected server. It must match the org where you created the app and enabled the server. **SObject Reads (sobject-reads)** Discovery, query, search, and relationship traversal; no record changes. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-reads +``` + **SObject Mutations (sobject-mutations)** Read, create, and update records; no deletes. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/platform/sobject-mutations ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-mutations +``` + **SObject Deletes (sobject-deletes)** Identify and delete records; no creates or updates. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/platform/sobject-deletes ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-deletes +``` + **SObject All (sobject-all)** Create, read, update, delete, query, and search records. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/platform/sobject-all ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-all +``` + **Data 360 (data360)** Query data and change customer-data configuration. Requires a Data 360 license, API v66.0+, and **Manage Data 360** for configuration or **View Data 360** for read-only operations. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/data/data360 ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/data/sandbox/data360 +``` + **Headless 360 (Beta) (platform/headless-360)** Broad Setup and platform operations, not read-only record access. Available starting July 2026 under Beta Services Terms. Requires API v67.0+, an External Client App with `mcp_api`, and an OAuth client. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/platform/headless-360 ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/platform/headless-360 +``` + **Tableau Next (analytics/tableau-next)** Semantic-model and analytics access. Confirm the org has the required Tableau Next capabilities. +Production: + ``` https://api.salesforce.com/platform/mcp/v1/analytics/tableau-next ``` +Sandbox: + +``` +https://api.salesforce.com/platform/mcp/v1/sandbox/analytics/tableau-next +``` + Calls remain subject to the signed-in user's field-level security, object permissions, and sharing rules. If the connection fails with valid credentials, confirm that the selected server is enabled, the URL matches the selected server, and the org has API access. diff --git a/go/generated/guides/salesforce/meta.yaml b/go/generated/guides/salesforce/meta.yaml index 83a78ae..b1d4243 100644 --- a/go/generated/guides/salesforce/meta.yaml +++ b/go/generated/guides/salesforce/meta.yaml @@ -212,17 +212,17 @@ provenance: locator: https://api.salesforce.com/.well-known/oauth-protected-resource/platform/mcp/v1/platform/sobject-reads name: Salesforce SObject Reads protected-resource metadata classification: official - observed_at: "2026-08-06T23:23:14Z" + observed_at: "2026-09-30T21:25:35Z" - source: endpoint-observation locator: https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads name: Salesforce SObject Reads production endpoint classification: official - observed_at: "2026-08-06T23:23:14Z" + observed_at: "2026-09-30T21:25:35Z" - source: repository-doctrine locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-06T23:23:14Z" + observed_at: "2026-09-30T21:25:35Z" - source: provider-documentation locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/setup-overview.html name: Set Up Your Org @@ -277,3 +277,18 @@ provenance: locator: https://login.salesforce.com/packaging/installPackage.apexp?p0=04tdM000000cNGXQA2 name: Speakeasy Salesforce application installation and mandatory support OAuth handoff observed_at: "2026-09-17T16:15:46Z" + - source: endpoint-observation + locator: https://api.salesforce.com/.well-known/oauth-protected-resource/platform/mcp/v1/sandbox/platform/sobject-reads + name: Salesforce sandbox protected-resource metadata (issuer test.salesforce.com) + classification: official + observed_at: "2026-09-30T21:25:35Z" + - source: endpoint-observation + locator: https://login.salesforce.com/.well-known/openid-configuration + name: Salesforce production OpenID configuration (registration endpoint, no CIMD) + classification: official + observed_at: "2026-09-30T21:25:35Z" + - source: endpoint-observation + locator: https://login.salesforce.com/services/oauth2/register + name: Salesforce anonymous dynamic client registration (401 invalid_client) + classification: official + observed_at: "2026-09-30T21:25:35Z" diff --git a/go/generated/guides/salesforce/speakeasy.md b/go/generated/guides/salesforce/speakeasy.md index 7bfc63a..fdd1d86 100644 --- a/go/generated/guides/salesforce/speakeasy.md +++ b/go/generated/guides/salesforce/speakeasy.md @@ -5,49 +5,58 @@ Follow these steps after [creating your own Salesforce app](external.md#create-y ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Select **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **Hosted remotely**. -4. On the **New remote MCP server** page, paste the URL recorded in [Enable the selected MCP server](external.md#enable-sobject-server) into **MCP server URL**. -5. Select **Verify connectivity**, then **Save**. +4. On **New remote MCP server**, paste the URL recorded in [Enable the selected MCP server](external.md#enable-sobject-server) into **MCP server URL**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity**. The page preselects **No Identity** for Salesforce URLs, so change it. +8. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. +Speakeasy cannot register a Salesforce client automatically. It keeps the server **Disabled** and says to finish setup in **Settings > Identity**. This is expected. - + ### Connect your credentials {#connect-speakeasy-credentials} -From the server's **Overview**, open **Settings**. +Open the server's **Settings** and find the **Identity** section. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Confirm that **User Identity** is selected. +2. Under **Choose an identity provider**, confirm the preselected provider is `https://login.salesforce.com` for a production URL or `https://test.salesforce.com` for a sandbox URL. A provider badged **Will be created** is expected. If a sandbox URL shows `https://login.salesforce.com`, open the picker (**Search identity providers…**) and choose `https://test.salesforce.com`. +3. Under the provider, choose **Manual**. The dashboard preselects **Auto-Configure**, which fails for Salesforce. If an earlier Salesforce server already uses this app, **Existing client** is preselected instead: pick that client under **Client** and skip to step 7. +4. Paste the [**Consumer Key**](external.md#copy-consumer-key) into **Client ID**. +5. Leave **Client secret** empty. +6. Open **Advanced** and enter this value in **Scope**. Do not leave it blank. -#### Select the identity provider + ``` + mcp_api refresh_token + ``` -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). +7. Click **Save**. If asked to confirm, click **Save changes**. -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. +If a sandbox URL offers no `https://test.salesforce.com` provider, create one, then return to step 7: -If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. +1. Open the picker and click **Create a custom identity provider**. This opens **Remote Identity Providers**. +2. Click **New Remote Identity Provider**. +3. Enter `https://test.salesforce.com` in **Issuer URL**. +4. Click **Discover** and keep the derived **Slug**. +5. Click **Create**. +6. On the new provider, click **Add Client**. +7. Set **Client Type** to **Manual**. +8. Paste the **Consumer Key** into **Client ID** and leave **Client Secret (optional)** empty. +9. Enter `mcp_api,refresh_token` in **Scope (override)**. +10. Confirm the displayed **Redirect URI** matches the **Callback URL** you [entered in Salesforce](external.md#configure-oauth-settings). +11. Click **Create**. +12. Return to the server's **Settings > Identity** and select that provider. +13. Choose **Existing client** and pick the new client under **Client**. -#### Select the session client +Turn the server on: -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: +1. In **Settings > Danger Zone > Server Availability**, turn on **Enable MCP server**. +2. Confirm it shows **Enabled**. -1. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. +When a person first uses the server, Salesforce asks them to sign in and allow access. If sign-in fails right after you created the app, wait out Salesforce's 30-minute activation window before retrying. Do not change the OAuth settings. -The sheet shows the **Redirect URI** with a copy button. It is the callback URL registered in Salesforce as `{{ gram.oauth.callback_url }}`. - -1. Paste the [**Consumer Key**](external.md#copy-consumer-key) into **Client ID**. -1. Leave **Client Secret (optional)** empty. - -#### Verify the callback and attach - -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. - -For the provider-side callback setting, see [**Callback URL**](external.md#configure-oauth-settings). - -If attachment still fails after the app's 30-minute activation window, stop and escalate; do not change the OAuth settings. - - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Salesforce's MCP documentation](https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html). diff --git a/go/generated/guides/slack/meta.yaml b/go/generated/guides/slack/meta.yaml index ef6973a..51a5fc4 100644 --- a/go/generated/guides/slack/meta.yaml +++ b/go/generated/guides/slack/meta.yaml @@ -38,22 +38,26 @@ remotes: - source: provider-documentation locator: https://docs.slack.dev/ai/slack-mcp-server/ classification: official - observed_at: "2026-09-17T00:05:11Z" + observed_at: "2026-09-30T00:00:00Z" provenance: - source: provider-documentation locator: https://docs.slack.dev/ai/slack-mcp-server/ name: Slack MCP server overview classification: official - observed_at: "2026-09-17T00:05:11Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.slack.dev/ai/slack-mcp-server/developing/ name: Developing a sample app with the Slack MCP Server classification: official - observed_at: "2026-09-17T00:05:11Z" + observed_at: "2026-09-30T00:00:00Z" - source: endpoint-observation locator: https://mcp.slack.com/.well-known/oauth-authorization-server classification: official - observed_at: "2026-09-17T00:05:11Z" + observed_at: "2026-09-30T00:00:00Z" + - source: endpoint-observation + locator: https://mcp.slack.com/.well-known/oauth-protected-resource + classification: official + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.slack.dev/reference/app-manifest/ classification: official diff --git a/go/generated/guides/slack/speakeasy.md b/go/generated/guides/slack/speakeasy.md index 1255c78..0131281 100644 --- a/go/generated/guides/slack/speakeasy.md +++ b/go/generated/guides/slack/speakeasy.md @@ -2,51 +2,49 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste `https://mcp.slack.com/mcp` - into **Remote MCP server URL**. -5. Click **Add server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: -This creates the hosted MCP server and opens its **Overview** page. + ```text + https://mcp.slack.com/mcp + ``` - +5. Optionally enter a **Display name (optional)**. +6. Leave **User session issuer** at its default. +7. Click **Verify connectivity**. +8. Under **Identity**, confirm that **User Identity** is selected. +9. If **Guardrails** appears, leave it off. +10. Click **Save**. + +Speakeasy keeps the new server **Disabled** and says to finish setup in **Settings > Identity**. This is expected for Slack; the next section finishes it. + + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**, or **Use Discovered** - when offered. -3. If the issuer is not already known, enter `https://mcp.slack.com` as the - **Issuer URL**. Under **Endpoints**, click **Discover**. -4. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -5. Paste the [Slack Client ID](external.md#copy-client-credentials) into **Client ID**. -6. Paste the [Slack Client Secret](external.md#copy-client-credentials) into - **Client Secret (optional)**. Slack requires this secret. -7. Set the token-endpoint authentication method to `client_secret_post` using - the authentication-method control. Do not use `client_secret_basic`. -8. Configure the scopes to match your [Slack user permissions](external.md#set-user-permissions): - `channels:read`, `groups:read`, `im:read`, and `mpim:read` for listing channels. - If an issuer-level scope override is configured, make it match this selection. -9. Click **Attach Identity Provider**. -10. Confirm that the sheet's **Redirect URI** matches - `{{ gram.oauth.callback_url }}`, registered under Slack's - [Redirect URLs](external.md#register-callback). - -Slack's discovered authorization endpoint is -`https://slack.com/oauth/v2_user/authorize` and its token endpoint is -`https://slack.com/api/oauth.v2.user.access`. Use these user-token endpoints, -not the bot-token OAuth endpoints. Slack does not support Dynamic Client -Registration. Each user must complete Slack consent when connecting; attaching -the client credentials does not grant access to everyone's Slack data. - -If your deployment does not expose the authentication-method or scope controls, -ask the Control Plane administrator to configure these values before connecting. -This configuration is based on Slack's documentation and the Control Plane's -OAuth implementation; it has not been tested end to end with a Slack workspace. - - - +Open the server's **Settings** and find the **Identity** section. + +1. Select **User Identity**. +2. In **Choose an identity provider**, confirm that the preselected provider is Slack's issuer, `https://mcp.slack.com`. It is badged **Will be created** when the project has no Slack provider yet. If another provider is selected, open the picker, search in **Search identity providers…**, and choose the Slack provider. +3. Under the provider, choose **Manual**. If **Existing client** is preselected, switch to **Manual**. +4. Paste the [Slack Client ID](external.md#copy-client-credentials) into **Client ID**. +5. Paste the [Slack Client Secret](external.md#copy-client-credentials) into **Client secret**. Slack requires the secret even though the field shows "Optional". +6. Open **Advanced**. In **Scope**, enter the scopes from [Set user permissions](external.md#set-user-permissions) on one line. Do not leave **Scope** blank: a blank value requests every scope the Slack server advertises, which your app does not grant, and Slack consent fails. + + ```text + channels:read groups:read im:read mpim:read + ``` + + If your app owner added more user-token scopes, add them to this line, separated by spaces. + +7. Click **Save**. If Speakeasy asks you to confirm, click **Save changes**. +8. Open **Settings > Danger Zone > Server Availability**. +9. Turn on **Enable MCP server** so the switch shows **Enabled**. + +When a person first uses the server, Slack's browser authorization prompt appears. Each person authorizes with their own Slack account; saving the client does not grant access to anyone's Slack data. + + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Slack's MCP documentation](https://docs.slack.dev/ai/slack-mcp-server/). diff --git a/go/generated/guides/snowflake/meta.yaml b/go/generated/guides/snowflake/meta.yaml index f6053f4..25e214e 100644 --- a/go/generated/guides/snowflake/meta.yaml +++ b/go/generated/guides/snowflake/meta.yaml @@ -53,7 +53,7 @@ provenance: locator: https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp name: Snowflake-managed MCP server classification: official - observed_at: "2026-08-11T18:36:01Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://docs.snowflake.com/en/sql-reference/sql/create-mcp-server name: CREATE MCP SERVER @@ -73,7 +73,7 @@ provenance: locator: https://docs.snowflake.com/en/user-guide/oauth-custom name: Configure Snowflake OAuth for custom clients classification: official - observed_at: "2026-08-11T18:36:01Z" + observed_at: "2026-09-30T21:30:00Z" - source: provider-documentation locator: https://docs.snowflake.com/en/user-guide/oauth-snowflake-overview name: Snowflake OAuth overview @@ -143,4 +143,4 @@ provenance: locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-11T18:36:01Z" + observed_at: "2026-09-30T21:30:00Z" diff --git a/go/generated/guides/snowflake/speakeasy.md b/go/generated/guides/snowflake/speakeasy.md index 16d19aa..8663fba 100644 --- a/go/generated/guides/snowflake/speakeasy.md +++ b/go/generated/guides/snowflake/speakeasy.md @@ -3,46 +3,64 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **Hosted remotely**. -4. On the **New remote MCP server** page, paste the account-specific URL retained in [Create the Cortex Agent MCP server](external.md#create-cortex-agent-mcp-server) into **MCP server URL**. -5. Click **Verify connectivity**, then **Save**. +4. On **New remote MCP server**, paste the account-specific URL retained in [Create the Cortex Agent MCP server](external.md#create-cortex-agent-mcp-server) into **MCP server URL**. +5. Leave **User session issuer** at its default. +6. Click **Verify connectivity**. +7. Under **Identity**, select **User Identity** if it is not already selected. +8. Click **Save**. -This creates the hosted MCP server and opens its **Overview** page. +Snowflake does not support automatic client registration, so Speakeasy keeps the server **Disabled** and says to finish setup in **Settings > Identity**. This is expected. - + ### Connect your credentials {#connect-speakeasy-credentials} -From the server's **Overview**, open **Settings**. +Open the server's **Settings** and find the **Identity** section. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Confirm that **User Identity** is selected. +2. Under **Choose an identity provider**, confirm the preselected provider is on your Snowflake account hostname (``). A provider badged **Will be created** is expected. If no Snowflake provider is offered, follow the custom provider steps below instead. +3. Under the provider, choose **Manual**. +4. Paste the [**Client ID**](external.md#copy-oauth-credentials) into **Client ID**. +5. Paste the [**Client Secret**](external.md#copy-oauth-credentials) into **Client secret**. The secret is required even though the field says "Optional". +6. Open **Advanced** and enter `session:role:all` in **Scope**. Do not leave it blank. +7. Click **Save**. If asked to confirm, click **Save changes**. -#### Select the identity provider +If no Snowflake provider is offered, create one: -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). +1. Open the picker and click **Create a custom identity provider**. This opens **Remote Identity Providers**. +2. Click **New Remote Identity Provider**. +3. Enter `https://` in **Issuer URL**, using the public account hostname from [Create the Cortex Agent MCP server](external.md#create-cortex-agent-mcp-server). +4. Under **Endpoints**, enter this value in **Authorization Endpoint**: -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + ``` + https:///oauth/authorize + ``` -If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. +5. Enter this value in **Token Endpoint**: -#### Select the session client + ``` + https:///oauth/token-request + ``` -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: +6. Keep the derived **Slug** and click **Create**. +7. On the new provider, click **Add Client**. +8. Set **Client Type** to **Manual**. +9. Paste the **Client ID** into **Client ID** and the **Client Secret** into **Client Secret (optional)**. +10. Enter `session:role:all` in **Scope (override)**. +11. Confirm the displayed **Redirect URI** matches the `OAUTH_REDIRECT_URI` you set in [Create the OAuth integration](external.md#create-oauth-integration). +12. Click **Create**. +13. Return to the server's **Settings > Identity** and select that provider. +14. Choose **Existing client**, pick the new client under **Client**, and click **Save**. -1. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. -1. Paste the [**Client ID**](external.md#copy-oauth-credentials) into **Client ID**. -1. Paste the [**Client Secret**](external.md#copy-oauth-credentials) into **Client Secret (optional)**. +Turn the server on: -#### Verify the callback and attach +1. In **Settings > Danger Zone > Server Availability**, turn on **Enable MCP server**. +2. Confirm it shows **Enabled**. -1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. -2. Click **Attach Identity Provider**. +When a person first uses the server, Snowflake's OAuth flow opens in a browser. Each user signs in with their own Snowflake credentials and consents to the non-privileged default role. The resulting session uses that user's `DEFAULT_ROLE`. -For the provider-side callback setting, see [Create the OAuth integration](external.md#create-oauth-integration). - - - -When a client first requests Snowflake access, Snowflake's OAuth flow opens in a browser. Each user signs in with their own Snowflake credentials and consents to the non-privileged default role. The resulting session uses that user's `DEFAULT_ROLE`. + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Snowflake's MCP documentation](https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp). diff --git a/go/generated/guides/x-docs/meta.yaml b/go/generated/guides/x-docs/meta.yaml index 673aa39..7c7b7d1 100644 --- a/go/generated/guides/x-docs/meta.yaml +++ b/go/generated/guides/x-docs/meta.yaml @@ -27,7 +27,7 @@ remotes: classification: official version: 1.0.0 status: reachable-without-authentication - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" provenance: - source: provider-runtime locator: https://docs.x.com/mcp @@ -35,26 +35,26 @@ provenance: classification: official version: 1.0.0 status: reachable-without-authentication - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://x-preview.mintlify.app/tools/mcp + locator: https://docs.x.com/tools/mcp name: MCP servers for the X API and X developer docs classification: official - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation - locator: https://x-preview.mintlify.app/llms.txt + locator: https://docs.x.com/llms.txt name: X Developer Platform documentation index classification: official - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" - source: pulsemcp locator: com.pulsemcp.mirror/x-docs name: X Docs classification: mirror scope: tenant status: present - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" - source: speakeasy-product-documentation locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-07-29T20:05:42Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/x-docs/speakeasy.md b/go/generated/guides/x-docs/speakeasy.md index f5e86f3..88ea8eb 100644 --- a/go/generated/guides/x-docs/speakeasy.md +++ b/go/generated/guides/x-docs/speakeasy.md @@ -3,20 +3,20 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} 1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. -2. Click **Add new** to open the **Add MCP server** page. +2. Click **Add new** to open **Add MCP server**. 3. Choose **From the catalog**. 4. On the **MCP Catalog** page, enter `X Docs` in **Search MCP servers...**. -5. Open the **X Docs** entry. -6. Click **Add**. -7. In the **Add to Project** dialog, click **Add to Project**. +5. Open the **X Docs** entry and click **Add**. This opens the **Add to Project** dialog. +6. Under **Identity**, keep **No Identity** selected, and add no **Upstream headers**. +7. Click **Add to Project**. +8. If the dialog shows a **Guardrails** step, finish it or click **Skip for now**. +9. After **Server added successfully**, click **Configure MCP settings** to open the server. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - - + ### Connect your credentials {#connect-speakeasy-credentials} -No credential connection is required because the X Docs MCP Server is public. Do not add an upstream header or attach an identity provider. +X Docs is public, so there is no credential to connect. In the server's **Settings**, the **Identity** section stays on **No Identity**. diff --git a/go/generated/guides/x/meta.yaml b/go/generated/guides/x/meta.yaml index 0eb8186..43d3114 100644 --- a/go/generated/guides/x/meta.yaml +++ b/go/generated/guides/x/meta.yaml @@ -35,18 +35,18 @@ remotes: locator: https://docs.x.com/tools/mcp.md name: MCP servers for the X API and X developer docs classification: official - observed_at: "2026-08-06T23:21:18Z" + observed_at: "2026-09-30T00:00:00Z" provenance: - source: provider-documentation locator: https://docs.x.com/tools/mcp.md name: MCP servers for the X API and X developer docs classification: official - observed_at: "2026-08-06T23:21:18Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.x.com/llms.txt name: X Developer Platform documentation index classification: official - observed_at: "2026-08-06T23:21:18Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.x.com/x-api/getting-started/getting-access.md name: Getting Access @@ -91,9 +91,9 @@ provenance: locator: doctrine/speakeasy-setup.md name: Speakeasy setup canonical section classification: official - observed_at: "2026-08-06T23:21:18Z" + observed_at: "2026-09-30T00:00:00Z" - source: pulsemcp locator: com.pulsemcp.mirror/xdevplatform-xmcp name: X classification: mirror - observed_at: "2026-08-06T23:21:18Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/x/speakeasy.md b/go/generated/guides/x/speakeasy.md index e460d2e..eaa9f36 100644 --- a/go/generated/guides/x/speakeasy.md +++ b/go/generated/guides/x/speakeasy.md @@ -2,26 +2,32 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open the **Add MCP server** page. - -Choose **From the catalog**. On the **MCP Catalog** page, enter `X` in **Search MCP servers...**, open the X result, and click **Add**. If the **Add to Project** dialog requests headers during installation, enter `Bearer ` followed by your saved [**Bearer Token**](external.md#copy-bearer-token) in the provided `Authorization` value field under **Upstream headers**. The dialog supplies the header name and secret handling; it does not show the Settings editor's controls. If no header field is offered, follow [Connect your credentials](#connect-speakeasy-credentials) after installation. In the **Add to Project** dialog, click **Add to Project**. - -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - - +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **From the catalog**. +4. On the **MCP Catalog** page, enter `X` in **Search MCP servers...**. +5. Open the X catalog entry and click **Add**. This opens the **Add to Project** dialog. +6. Under **Identity**, select **Service Account**. +7. Select **Bearer**. +8. In **Token**, paste the [**Bearer Token**](external.md#copy-bearer-token) you saved. Paste the token only, without `Bearer ` in front of it. Speakeasy adds the prefix and sends the value as the `Authorization` header. +9. Click **Add to Project**. +10. If the dialog shows a **Guardrails** step, finish it or click **Skip for now**. +11. After **Server added successfully**, click **Configure MCP settings** to open the server. + + ### Connect your credentials {#connect-speakeasy-credentials} -If you configured headers in the **Add to Project** dialog, skip this section. Otherwise, select **Configure MCP settings** on the completion screen: +The Bearer Token you entered in the **Add to Project** dialog is already the server's credential. To confirm it, or to add it to an X server created without it: + +1. Open the server's **Settings** and find the **Identity** section. +2. Select **Service Account**. +3. Under **Service Account credential**, select **Bearer**. +4. In **Token**, paste the [**Bearer Token**](external.md#copy-bearer-token), without `Bearer ` in front of it. +5. Click **Save**. -1. Open **Settings**. -2. Under **Upstream Headers**, select **Add header**. -3. Enter `Authorization` in **Header name**. -4. Leave **Value source** set to **Static value**. -5. In the value field, enter `Bearer ` followed by the [**Bearer Token**](external.md#copy-bearer-token) you saved. -6. Select **Secret**. -7. Select **Save**. +Do not add the token under **Custom Headers**. - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [X's MCP documentation](https://docs.x.com/tools/mcp). diff --git a/go/generated/guides/zapier/meta.yaml b/go/generated/guides/zapier/meta.yaml index b3601d6..00d8e63 100644 --- a/go/generated/guides/zapier/meta.yaml +++ b/go/generated/guides/zapier/meta.yaml @@ -34,7 +34,7 @@ provenance: observed_at: "2026-08-11T18:36:07Z" - source: provider-documentation locator: https://docs.zapier.com/mcp/get-started/connect - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.zapier.com/mcp/get-started/authentication observed_at: "2026-08-11T18:36:07Z" @@ -46,22 +46,22 @@ provenance: observed_at: "2026-08-11T18:36:07Z" - source: provider-documentation locator: https://docs.zapier.com/mcp/features/usage - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://docs.zapier.com/mcp/manage/security - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://help.zapier.com/hc/en-us/articles/36265392843917-Use-Zapier-MCP-with-your-client observed_at: "2026-08-11T18:36:07Z" - source: provider-documentation locator: https://mcp.zapier.com/api/v1/connect - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://mcp.zapier.com/.well-known/oauth-protected-resource/api/v1/connect - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://mcp.zapier.com/.well-known/oauth-authorization-server - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" - source: provider-documentation locator: https://zapier.com/llms.txt observed_at: "2026-08-11T18:36:07Z" @@ -70,4 +70,4 @@ provenance: observed_at: "2026-08-11T18:36:07Z" - source: doctrine locator: doctrine/speakeasy-setup.md - observed_at: "2026-08-11T18:36:07Z" + observed_at: "2026-09-30T00:00:00Z" diff --git a/go/generated/guides/zapier/speakeasy.md b/go/generated/guides/zapier/speakeasy.md index 822ea0e..b26f467 100644 --- a/go/generated/guides/zapier/speakeasy.md +++ b/go/generated/guides/zapier/speakeasy.md @@ -8,71 +8,26 @@ 4. On the **MCP Catalog** page, enter `Zapier` in **Search MCP servers...**. 5. Open the **Zapier** entry. 6. Select **Add**. -7. In the **Add to Project** dialog, select **Add to Project**. +7. In the **Add to Project** dialog, under **Identity**, keep **User Identity** selected. +8. Select **Add to Project**. If the dialog offers a **Guardrails** step, select **Skip for now**. +9. After **Server added successfully**, select **Configure MCP settings**. -After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. +When it adds the server, Speakeasy discovers Zapier's identity provider and registers a client automatically. There is no **Client ID** or secret to paste. If that cannot complete, the server is kept **Disabled** and the result says to finish setup in **Settings > Identity**. - + ### Connect your credentials {#connect-speakeasy-credentials} -Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. +Open the server's **Settings** and find the **Identity** section. It normally shows **User Identity** with the `https://mcp.zapier.com` provider and **Auto-Configure** already set; skip to step 5. -Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. +1. Select **User Identity**. +2. Under **Choose an identity provider**, confirm the preselected provider is `https://mcp.zapier.com`. A provider that does not exist yet shows **Will be created**. +3. Keep **Auto-Configure** selected. +4. Select **Save**. +5. If the server shows **Disabled**, open **Settings > Danger Zone > Server Availability** and turn on **Enable MCP server** so it shows **Enabled**. -#### Select the identity provider +When a person first uses the server, they sign in to Zapier with the account whose app connections should be available and complete Zapier's on-screen authorization prompts. -In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). - -For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. - -For a new provider, enter **Issuer URL** `https://mcp.zapier.com` and keep the auto-derived **Slug**. If discovery does not populate **Endpoints**, enter: - -Authorization endpoint: - -```text -https://mcp.zapier.com/oauth/authorize -``` - -Token endpoint: - -```text -https://mcp.zapier.com/api/v1/oauth/token -``` - -Registration endpoint: - -```text -https://mcp.zapier.com/api/v1/oauth/register -``` - - - -1. Keep the auto-derived **Slug**. -1. Keep the auto-derived **Display name (optional)**. -1. Under **Endpoints**, wait for automatic discovery of the seeded issuer. After typing or changing **Issuer URL**, select **Discover** only if offered, then confirm the authorization, token, and registration endpoints. - -#### Select the session client - -Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Attach the provider** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: - -1. Under **Session Client**, keep **Client Type** set to **Dynamic Client - Registration (DCR)**. -1. Keep **Token Endpoint Auth Method** at its discovered default. -1. Leave **Scope (override)** empty. -1. Leave **Audience (optional)** empty. - -#### Attach the provider - -Click **Attach Identity Provider**. DCR handles client registration; you do not need to register a callback URL manually. - -For a new DCR client, the Speakeasy AI Control Plane registers the OAuth client with Zapier. You do -not need to paste a **Client ID** or **Client Secret**. - -1. When provider access is first requested, sign in to Zapier with the account - whose app connections should be available. -2. Complete Zapier's on-screen authorization prompts. - - + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Zapier's MCP documentation](https://docs.zapier.com/mcp/get-started/connect). diff --git a/go/index_gen.go b/go/index_gen.go index 33ef99a..621a13f 100644 --- a/go/index_gen.go +++ b/go/index_gen.go @@ -79,7 +79,7 @@ var generatedGuides = map[GuideSlug]generatedGuide{ SetupRequired: true, Aliases: []string{}, Remotes: []generatedRemote{ - {ID: "rovo", URL: "https://mcp.atlassian.com/v1/mcp/authv2", Transport: "streamable-http", Tenanted: false}, + {ID: "rovo", URL: "https://mcp.atlassian.com/v2/mcp", Transport: "streamable-http", Tenanted: false}, }, CredentialOptions: []generatedCredentialOption{ {ID: "oauth-dcr", Kind: "oauth", ClientRegistration: "dynamic", UpstreamSetup: "provider-steps", SpeakeasySetup: "dcr"}, @@ -131,7 +131,7 @@ var generatedGuides = map[GuideSlug]generatedGuide{ Slug: "google-big-query", Title: "Google BigQuery", Summary: "Query and manage BigQuery data through Google's hosted BigQuery MCP server.", - SpeakeasyAddServer: "", + SpeakeasyAddServer: "catalog", SetupRequired: true, Aliases: []string{"com.pulsemcp.mirror/google-bigquery"}, Remotes: []generatedRemote{ @@ -242,7 +242,7 @@ var generatedGuides = map[GuideSlug]generatedGuide{ "hubspot": { Slug: "hubspot", Title: "HubSpot", - Summary: "Connect HubSpot's hosted MCP server using an MCP auth app and OAuth.", + Summary: "Connect HubSpot's hosted MCP server using an MCP connector and OAuth.", SpeakeasyAddServer: "catalog", SetupRequired: true, Aliases: []string{"com.pulsemcp.mirror/hubspot"}, @@ -470,7 +470,7 @@ var generatedURLToRefs = map[string][]ServerRef{ "https://mcp.asana.com/v2/mcp": { {Guide: "asana", Remote: "hosted"}, }, - "https://mcp.atlassian.com/v1/mcp/authv2": { + "https://mcp.atlassian.com/v2/mcp": { {Guide: "atlassian", Remote: "rovo"}, }, "https://mcp.box.com": { @@ -552,10 +552,10 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Atlassian Rovo MCP server": { {Guide: "atlassian", Remote: "rovo"}, }, - "Atlassian authorization-server metadata with DCR registration endpoint": { + "Atlassian base authorization-server metadata": { {Guide: "atlassian", Remote: "rovo"}, }, - "Atlassian base authorization-server metadata": { + "Atlassian path-issuer authorization-server metadata (https://auth.atlassian.com/VCeDsk8ZHncYF1g234fKtc4lNipbBhu3)": { {Guide: "atlassian", Remote: "rovo"}, }, "Authenticate to Google and Google Cloud MCP servers": { @@ -574,6 +574,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Authentication and authorization": { {Guide: "atlassian", Remote: "rovo"}, }, + "Authorize user": { + {Guide: "box", Remote: "hosted"}, + }, "Authorizing OAuth apps": { {Guide: "github", Remote: "hosted"}, }, @@ -589,7 +592,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "BigQuery MCP endpoint": { {Guide: "google-big-query", Remote: "hosted"}, }, - "BigQuery MCP endpoint (tools/list 200 unauthenticated; tools/call 401)": { + "BigQuery MCP endpoint (initialize and tools/list 200 unauthenticated; tools/call 401)": { {Guide: "google-big-query", Remote: "hosted"}, }, "BigQuery MCP protected-resource metadata": { @@ -607,6 +610,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Box Model Context Protocol Server": { {Guide: "box", Remote: "hosted"}, }, + "Box authorization server metadata": { + {Guide: "box", Remote: "hosted"}, + }, "Box docs index": { {Guide: "box", Remote: "hosted"}, }, @@ -637,7 +643,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Compute Engine IAM roles and permissions": { {Guide: "google-compute-engine", Remote: "hosted"}, }, - "Compute Engine MCP endpoint (tools/list 200 unauthenticated, tools/call 401)": { + "Compute Engine MCP endpoint (initialize and tools/list 200 unauthenticated, tools/call 401)": { {Guide: "google-compute-engine", Remote: "hosted"}, }, "Compute Engine MCP protected-resource metadata": { @@ -662,6 +668,12 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "salesforce", Remote: "tableau-next-production"}, {Guide: "salesforce", Remote: "tableau-next-sandbox"}, }, + "Configure NetSuite as OIDC Provider": { + {Guide: "netsuite", Remote: "mcp-standard-tools"}, + }, + "Configure OAuth 2.1": { + {Guide: "atlassian", Remote: "rovo"}, + }, "Configure Postman": { {Guide: "salesforce", Remote: "data360-production"}, {Guide: "salesforce", Remote: "data360-sandbox"}, @@ -687,6 +699,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Configure an email channel for OAuth with Gmail": { {Guide: "google-big-query", Remote: "hosted"}, }, + "Configure authentication via API token": { + {Guide: "atlassian", Remote: "rovo"}, + }, "Configure security for Google Workspace MCP servers": { {Guide: "google-docs", Remote: "hosted"}, {Guide: "google-people", Remote: "hosted"}, @@ -728,12 +743,6 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Configuring Box AI": { {Guide: "box", Remote: "hosted"}, }, - "Configuring OAuth 2.1": { - {Guide: "atlassian", Remote: "rovo"}, - }, - "Configuring authentication via API token": { - {Guide: "atlassian", Remote: "rovo"}, - }, "Configuring the GitHub MCP Server for GitHub Enterprise": { {Guide: "github", Remote: "hosted"}, }, @@ -882,6 +891,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Get Started with the NetSuite AI Connector Service": { {Guide: "netsuite", Remote: "mcp-standard-tools"}, }, + "Get started with the Atlassian MCP server": { + {Guide: "atlassian", Remote: "rovo"}, + }, "Get started with the Google Auth Platform": { {Guide: "google-big-query", Remote: "hosted"}, }, @@ -891,9 +903,6 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Getting Started with Managed Snowflake MCP Server": { {Guide: "snowflake", Remote: "cortex-agent-mcp"}, }, - "Getting started with the Atlassian Rovo MCP Server": { - {Guide: "atlassian", Remote: "rovo"}, - }, "GitHub MCP Server": { {Guide: "github", Remote: "hosted"}, }, @@ -906,6 +915,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Giving an Employee Access to NetSuite": { {Guide: "netsuite", Remote: "mcp-standard-tools"}, }, + "Gmail MCP protected-resource metadata": { + {Guide: "gmail", Remote: "gmail"}, + }, "Google Calendar MCP protected-resource metadata": { {Guide: "google-calendar", Remote: "hosted"}, }, @@ -942,6 +954,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "google-drive", Remote: "hosted"}, }, "Google OAuth authorization-server metadata": { + {Guide: "gmail", Remote: "gmail"}, {Guide: "google-calendar", Remote: "hosted"}, }, "Google People API MCP protected-resource metadata": { @@ -961,6 +974,11 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ }, "Google Workspace Developer Preview Program": { {Guide: "google-calendar", Remote: "hosted"}, + {Guide: "google-docs", Remote: "hosted"}, + {Guide: "google-drive", Remote: "hosted"}, + {Guide: "google-people", Remote: "hosted"}, + {Guide: "google-sheets", Remote: "hosted"}, + {Guide: "google-slides", Remote: "hosted"}, }, "Google Workspace developer release notes": { {Guide: "google-sheets", Remote: "hosted"}, @@ -981,6 +999,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Grant an IAM role by using the Google Cloud console": { {Guide: "google-big-query", Remote: "hosted"}, {Guide: "google-calendar", Remote: "hosted"}, + {Guide: "google-docs", Remote: "hosted"}, {Guide: "google-drive", Remote: "hosted"}, {Guide: "google-people", Remote: "hosted"}, {Guide: "google-sheets", Remote: "hosted"}, @@ -1324,6 +1343,54 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "salesforce", Remote: "tableau-next-production"}, {Guide: "salesforce", Remote: "tableau-next-sandbox"}, }, + "Salesforce anonymous dynamic client registration (401 invalid_client)": { + {Guide: "salesforce", Remote: "data360-production"}, + {Guide: "salesforce", Remote: "data360-sandbox"}, + {Guide: "salesforce", Remote: "headless-360-production"}, + {Guide: "salesforce", Remote: "headless-360-sandbox"}, + {Guide: "salesforce", Remote: "sobject-all-production"}, + {Guide: "salesforce", Remote: "sobject-all-sandbox"}, + {Guide: "salesforce", Remote: "sobject-deletes-production"}, + {Guide: "salesforce", Remote: "sobject-deletes-sandbox"}, + {Guide: "salesforce", Remote: "sobject-mutations-production"}, + {Guide: "salesforce", Remote: "sobject-mutations-sandbox"}, + {Guide: "salesforce", Remote: "sobject-reads-production"}, + {Guide: "salesforce", Remote: "sobject-reads-sandbox"}, + {Guide: "salesforce", Remote: "tableau-next-production"}, + {Guide: "salesforce", Remote: "tableau-next-sandbox"}, + }, + "Salesforce production OpenID configuration (registration endpoint, no CIMD)": { + {Guide: "salesforce", Remote: "data360-production"}, + {Guide: "salesforce", Remote: "data360-sandbox"}, + {Guide: "salesforce", Remote: "headless-360-production"}, + {Guide: "salesforce", Remote: "headless-360-sandbox"}, + {Guide: "salesforce", Remote: "sobject-all-production"}, + {Guide: "salesforce", Remote: "sobject-all-sandbox"}, + {Guide: "salesforce", Remote: "sobject-deletes-production"}, + {Guide: "salesforce", Remote: "sobject-deletes-sandbox"}, + {Guide: "salesforce", Remote: "sobject-mutations-production"}, + {Guide: "salesforce", Remote: "sobject-mutations-sandbox"}, + {Guide: "salesforce", Remote: "sobject-reads-production"}, + {Guide: "salesforce", Remote: "sobject-reads-sandbox"}, + {Guide: "salesforce", Remote: "tableau-next-production"}, + {Guide: "salesforce", Remote: "tableau-next-sandbox"}, + }, + "Salesforce sandbox protected-resource metadata (issuer test.salesforce.com)": { + {Guide: "salesforce", Remote: "data360-production"}, + {Guide: "salesforce", Remote: "data360-sandbox"}, + {Guide: "salesforce", Remote: "headless-360-production"}, + {Guide: "salesforce", Remote: "headless-360-sandbox"}, + {Guide: "salesforce", Remote: "sobject-all-production"}, + {Guide: "salesforce", Remote: "sobject-all-sandbox"}, + {Guide: "salesforce", Remote: "sobject-deletes-production"}, + {Guide: "salesforce", Remote: "sobject-deletes-sandbox"}, + {Guide: "salesforce", Remote: "sobject-mutations-production"}, + {Guide: "salesforce", Remote: "sobject-mutations-sandbox"}, + {Guide: "salesforce", Remote: "sobject-reads-production"}, + {Guide: "salesforce", Remote: "sobject-reads-sandbox"}, + {Guide: "salesforce", Remote: "tableau-next-production"}, + {Guide: "salesforce", Remote: "tableau-next-sandbox"}, + }, "Scope Filtering": { {Guide: "github", Remote: "hosted"}, }, @@ -1380,6 +1447,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "google-sheets", Remote: "hosted"}, {Guide: "google-slides", Remote: "hosted"}, }, + "Set up clients": { + {Guide: "atlassian", Remote: "rovo"}, + }, "Set up the MCP server": { {Guide: "box", Remote: "hosted"}, }, @@ -1387,9 +1457,6 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "intercom", Remote: "eu"}, {Guide: "intercom", Remote: "us"}, }, - "Setting up clients": { - {Guide: "atlassian", Remote: "rovo"}, - }, "Setting up the GitHub MCP Server": { {Guide: "github", Remote: "hosted"}, }, @@ -1430,10 +1497,10 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ "Speakeasy callback and catalog-path observations": { {Guide: "atlassian", Remote: "rovo"}, }, - "Speakeasy identity-provider attachment sheet": { + "Speakeasy catalog Add to Project dialog": { {Guide: "google-big-query", Remote: "hosted"}, }, - "Speakeasy identity-provider form fields": { + "Speakeasy remote MCP Identity section": { {Guide: "google-big-query", Remote: "hosted"}, }, "Speakeasy setup canonical file": { @@ -1445,6 +1512,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "atlassian", Remote: "rovo"}, {Guide: "github", Remote: "hosted"}, {Guide: "google-big-query", Remote: "hosted"}, + {Guide: "google-compute-engine", Remote: "hosted"}, {Guide: "google-docs", Remote: "hosted"}, {Guide: "google-drive", Remote: "hosted"}, {Guide: "google-people", Remote: "hosted"}, @@ -1493,6 +1561,12 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "salesforce", Remote: "tableau-next-production"}, {Guide: "salesforce", Remote: "tableau-next-sandbox"}, }, + "Step One GET Request to the Authorization Endpoint": { + {Guide: "netsuite", Remote: "mcp-standard-tools"}, + }, + "Step Two POST Request to the Token Endpoint": { + {Guide: "netsuite", Remote: "mcp-standard-tools"}, + }, "Submitting your app for verification": { {Guide: "google-big-query", Remote: "hosted"}, }, @@ -1520,7 +1594,7 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "salesforce", Remote: "tableau-next-production"}, {Guide: "salesforce", Remote: "tableau-next-sandbox"}, }, - "Troubleshooting and verifying your setup": { + "Troubleshoot and verify your setup": { {Guide: "atlassian", Remote: "rovo"}, }, "Try BigQuery using the sandbox": { @@ -1545,6 +1619,9 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "salesforce", Remote: "tableau-next-production"}, {Guide: "salesforce", Remote: "tableau-next-sandbox"}, }, + "Use Atlassian Rovo MCP Server": { + {Guide: "atlassian", Remote: "rovo"}, + }, "Use the BigQuery MCP server": { {Guide: "google-big-query", Remote: "hosted"}, }, @@ -1559,9 +1636,6 @@ var generatedProvenanceToRefs = map[string][]ServerRef{ {Guide: "google-compute-engine", Remote: "hosted"}, {Guide: "google-drive", Remote: "hosted"}, }, - "Using with other supported MCP clients": { - {Guide: "atlassian", Remote: "rovo"}, - }, "V2 MCP server now generally available": { {Guide: "asana", Remote: "hosted"}, },