Skip to main content

Connect an AI agent (MCP server)

Spider exposes a remote Model Context Protocol server at https://<your-spider>/mcp. Agents such as claude.ai, Claude Desktop, ChatGPT and Claude Code connect to it with OAuth: no binary to install, no API key to distribute.

Requirements​

  • The MCP licence capability (TEAM tier and above).
  • Helm: customers.oauth.enabled: true and global.flips.mcp: true.
  • For claude.ai and ChatGPT: the instance must be reachable from the internet.

Connect​

Find the URL in the Analysis UI: Settings → Connected apps → Connect an AI agent.

ClientHow
claude.ai / Claude DesktopSettings → Connectors → Add custom connector → paste the URL
ChatGPTSettings → Apps & Connectors → Developer mode → Create → paste the URL
Claude Codeclaude mcp add --transport http spider https://<your-spider>/mcp

The first call opens Spider's consent screen. Approved agents are listed on the same Settings tab, where one click revokes them; a revoked agent is cut off within 30 seconds.

Which agent platforms may connect, and how they identify themselves (dynamic registration or Client ID Metadata Documents), is an administrator decision: see Connecting agents with OAuth.

What an agent can do​

ToolPurpose
spider_whoami, spider_list_teams, spider_select_teamIdentity and team selection (per session)
spider_fieldsField reference for a data type - agents call it before querying
spider_search, spider_stats, spider_outliers, spider_aggsQuery HTTP, PostgreSQL, MySQL, Redis, gRPC, Kafka, DNS, SSE/WebSocket, TCP, packets, network usage, hosts
spider_getOne document, optionally with truncated content
spider_resourcesWhisperers, controllers, gociphers, users, attachments
spider_linkA private Network-View link
spider_list_namespaces, spider_list_workloads, spider_list_sidecarsKubernetes discovery
spider_attach, spider_detachTime-boxed capture - only when enabled by the operator

An agent acts with the full rights of the user who approved it, limited to the whisperers that user owns or the selected team grants.

Operator settings​

Helm valueDefaultEffect
global.flips.mcpfalseDeploys the MCP server and its routes
mcpServer.captureControl.enabledfalseRegisters spider_attach/spider_detach
mcpServer.captureControl.defaultTtl / maxTtlPT30M / PT2HCapture duration default and cap; the controller detaches automatically (requires Controller 3.2.1 or later)

Content (request/response bodies, Redis values, Kafka records) is never returned by searches, only by spider_get on request, truncated and labelled as untrusted data. Set allowPayloads: false in the mcp Config document to forbid content through MCP entirely.

Tokens are checked against the server's own resource identifier (RFC 8707). By default a token with no audience, from a client that never sent resource, is still accepted; set requireResourceBinding: true in the mcp Config document to accept only tokens bound to this server. A token bound to a different resource is always refused.

Security notes​

  • Captured traffic can contain text written by anyone. Agents are told to treat it as data, and the tools that change state are narrow: links are private only, captures are off by default and always time-boxed.
  • Public links remain available from the Analysis UI and the spider CLI, not through MCP.