Skip to content
MCP Server

MCP Server

Dango exposes the same project-enrichment operations as MCP tools, for LLM agents and clients like Claude Desktop: no separate binary to install, no separate process. The MCP server is mounted on the same host and port as the ConnectRPC API, over Streamable HTTP:

https://api.dangofish.com/mcp

See the MCP Reference for the full list of tools and their input/output schemas.

Two ways to authenticate

  • Organization API key: the same dk_org_... key used for the REST API. Send it as a bearer token; the organization is resolved from the key automatically. This is the simplest path for a script or automated agent.
  • OAuth (sign in with your Dango account): for interactive clients such as Claude Desktop, which can’t hold an organization API key. The client discovers Dango’s authorization server, takes the user through a normal login, and calls tools with the resulting access token. Because a user token doesn’t carry an organization by itself, every tool call must also name the target organization explicitly (an org parameter, see the reference).
Authorization: Bearer dk_org_...        # API key path
Authorization: Bearer eyJhbGciOi...     # OAuth path (JWT access token)

A request without a recognizable bearer token gets a 401 carrying a WWW-Authenticate header that points at Dango’s OAuth discovery document, so a spec-compliant MCP client can start the login flow on its own, with no manual configuration beyond the server URL.

Connecting Claude Desktop

Add a remote MCP server pointing at https://api.dangofish.com/mcp. Claude Desktop will discover the OAuth flow automatically and prompt you to sign in; once connected, it can call create-project, add-project-activities, submit-project, get-project-progress, and get-project-result on your behalf, for whichever organization you name. It also exposes 4 canned prompts (e.g. /mcp__dango__new-project) for common entry points, see the MCP Reference.

Bulk CSV import/export aren’t exposed as MCP tools; use the RPC API (ImportCSV, ExportCSV) for those instead.

Scopes

Each tool requires the same scope as its RPC counterpart (create project, update/stage lines, view progress). An organization API key always carries the full set. A user authenticated via OAuth is checked against their own role in the target organization: missing the required scope for that org returns a PermissionDenied-style tool error.