Connect an AI agent (MCP server)
Spider exposes a remote Model Context Protocol server at
https://<your-spider>/mcp. Agents such as claude.ai, Claude Desktop, ChatGPT and Claude Code connect
to it with OAuth: no binary to install, no API key to distribute.
Requirements
- The
MCPlicence capability (TEAM tier and above). - Helm:
customers.oauth.enabled: trueandglobal.flips.mcp: true. - For claude.ai and ChatGPT: the instance must be reachable from the internet.
Connect
Find the URL in the Analysis UI: Settings → Connected apps → Connect an AI agent.
| Client | How |
|---|---|
| claude.ai / Claude Desktop | Settings → Connectors → Add custom connector → paste the URL |
| ChatGPT | Settings → Apps & Connectors → Developer mode → Create → paste the URL |
| Claude Code | claude mcp add --transport http spider https://<your-spider>/mcp |
The first call opens Spider's consent screen. Approved agents are listed on the same Settings tab, where one click revokes them; a revoked agent is cut off within 30 seconds.
Which agent platforms may connect, and how they identify themselves (dynamic registration or Client ID Metadata Documents), is an administrator decision: see Connecting agents with OAuth.
What an agent can do
| Tool | Purpose |
|---|---|
spider_whoami, spider_list_teams, spider_select_team | Identity and team selection (per session) |
spider_fields | Field reference for a data type - agents call it before querying |
spider_search, spider_stats, spider_outliers, spider_aggs | Query HTTP, PostgreSQL, MySQL, Redis, gRPC, Kafka, DNS, SSE/WebSocket, TCP, packets, network usage, hosts |
spider_get | One document, optionally with truncated content |
spider_resources | Whisperers, controllers, gociphers, users, attachments |
spider_link | A private Network-View link |
spider_list_namespaces, spider_list_workloads, spider_list_sidecars | Kubernetes discovery |
spider_attach, spider_detach | Time-boxed capture - only when enabled by the operator |
An agent acts with the full rights of the user who approved it, limited to the whisperers that user owns or the selected team grants.
Operator settings
| Helm value | Default | Effect |
|---|---|---|
global.flips.mcp | false | Deploys the MCP server and its routes |
mcpServer.captureControl.enabled | false | Registers spider_attach/spider_detach |
mcpServer.captureControl.defaultTtl / maxTtl | PT30M / PT2H | Capture duration default and cap; the controller detaches automatically (requires Controller 3.2.1 or later) |
Content (request/response bodies, Redis values, Kafka records) is never returned by searches, only by
spider_get on request, truncated and labelled as untrusted data. Set allowPayloads: false in the
mcp Config document to forbid content through MCP entirely.
Tokens are checked against the server's own resource identifier (RFC 8707). By default a token with no
audience, from a client that never sent resource, is still accepted; set requireResourceBinding: true
in the mcp Config document to accept only tokens bound to this server. A token bound to a different
resource is always refused.
Security notes
- Captured traffic can contain text written by anyone. Agents are told to treat it as data, and the tools that change state are narrow: links are private only, captures are off by default and always time-boxed.
- Public links remain available from the Analysis UI and the
spiderCLI, not through MCP.