MCP Server
Dango exposes the same project-enrichment operations as MCP tools, for LLM agents and clients like Claude Desktop: no separate binary to install, no separate process. The MCP server is mounted on the same host and port as the ConnectRPC API, over Streamable HTTP:
https://api.dangofish.com/mcpSee the MCP Reference for the full list of tools and their input/output schemas.
Two ways to authenticate
- Organization API key: the same
dk_org_...key used for the REST API. Send it as a bearer token; the organization is resolved from the key automatically. This is the simplest path for a script or automated agent. - OAuth (sign in with your Dango account): for interactive clients such as Claude Desktop, which can’t hold an organization API key. The client discovers Dango’s authorization server, takes the user through a normal login, and calls tools with the resulting access token. Because a user token doesn’t carry an organization by itself, every tool call must also name the target organization explicitly (an
orgparameter, see the reference).
Authorization: Bearer dk_org_... # API key path
Authorization: Bearer eyJhbGciOi... # OAuth path (JWT access token)A request without a recognizable bearer token gets a 401 carrying a WWW-Authenticate header that points at Dango’s OAuth discovery document, so a spec-compliant MCP client can start the login flow on its own, with no manual configuration beyond the server URL.
Connecting Claude Desktop
Add a remote MCP server pointing at https://api.dangofish.com/mcp. Claude Desktop will discover the OAuth flow automatically and prompt you to sign in; once connected, it can call create-project, add-project-activities, submit-project, get-project-progress, and get-project-result on your behalf, for whichever organization you name. It also exposes 4 canned prompts (e.g. /mcp__dango__new-project) for common entry points, see the MCP Reference.
Bulk CSV import/export aren’t exposed as MCP tools; use the RPC API (ImportCSV, ExportCSV) for those instead.
Scopes
Each tool requires the same scope as its RPC counterpart (create project, update/stage lines, view progress). An organization API key always carries the full set. A user authenticated via OAuth is checked against their own role in the target organization: missing the required scope for that org returns a PermissionDenied-style tool error.