Connect

Connect Claude, Claude Code, and other MCP clients to your Solk installation step by step, and see how OAuth discovery works.

Claude

  1. 1

    Add the connector

    In Claude (web, desktop, or mobile), choose Customize → Connectors → + Add → Add custom connector. Name: Solk, URL: https://<company>.solk.app/mcp. Leave the client ID fields under the advanced settings empty — Claude registers itself automatically.

  2. 2

    Connect

    Click Connect next to the connector. Your Solk installation's sign-in page opens; after you sign in, the consent screen shows the permissions Claude is requesting:

    • Read records — companies, people, opportunities, actions, email threads, calendar, and dashboards
    • Create and update records — companies, people, opportunities, tasks, notes, and activity logs; completing tasks; changing stages

    Click Allow (İzin ver) to return to Claude.

  3. 3

    Use it

    Keep Solk enabled in the chat and type your question. Claude asks for permission the first time it uses a tool; for read tools, you can choose "always allow".

Team / Enterprise: The organization owner adds the connector under Organization settings → Connectors → Add → Custom → Web. Members see the connector in their own list and click Connect to connect with their own Solk accounts — each member's permissions are limited to their own Solk role.

Claude Code

claude mcp add --transport http solk https://ornek.solk.app/mcp

Then, in Claude Code, run /mcp → solk → Authenticate. Claude Code uses a local redirect URI (http://localhost:<port>/callback); for loopback addresses, Solk ignores the port number during matching.

To make the server available to everyone on the project, you can set the scope to project (--scope project, written to .mcp.json); each developer still grants access with their own account.

ChatGPT, Cursor, VS Code, and others

In clients that support remote MCP servers (Streamable HTTP), enter the same URL. Clients that support OAuth handle discovery themselves. For clients that don't, an admin can create an API key and provide it in an Authorization: Bearer sk_… header — in that case, tools run with the permissions of the admin who created the key and with both scopes.

How OAuth discovery works

Clients need no extra configuration; the flow follows the standards (MCP Authorization, OAuth 2.1):

  1. The client sends POST /mcp without a token → 401 and WWW-Authenticate: Bearer … resource_metadata="https://ornek.solk.app/.well-known/oauth-protected-resource/mcp".
  2. The client reads the protected resource metadata (RFC 9728) → authorization server https://ornek.solk.app.
  3. It reads the authorization server metadata (RFC 8414).
  4. It registers itself (RFC 7591) or uses the URL of its client metadata document (CIMD) as the client_id.
  5. It redirects the user to the consent screen with PKCE (S256) and exchanges the code for a token.
  6. It sends MCP requests with Authorization: Bearer mcp_… and refreshes the token when it expires.

Protocol details

Transport Streamable HTTP, JSON responses (no SSE streaming)
Protocol versions 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05
Methods initialize, tools/list, tools/call, ping, and notifications
GET /mcp 405 (no server-to-client streaming)
Session Stateless; Mcp-Session-Id is not required
Insufficient scope If a write tool is called without crm.write: 403 + WWW-Authenticate: … error="insufficient_scope"
curl https://ornek.solk.app/mcp \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'