Skip to content

Administration

Rivolq Connect and MCP Apps

Use Rivolq Connect to let Claude, ChatGPT, Cursor, and other MCP-compatible clients ask scoped questions about your workspace and stage guarded work-order proposals.

Updated September 15, 2026

What Rivolq Connect is

Rivolq Connect is Rivolq's external AI connector. It uses the Model Context Protocol (MCP) so clients such as Claude, ChatGPT, Cursor, and future MCP-compatible agents can ask scoped questions about a Rivolq workspace once a user connects and grants access.

It is a protocol adapter, not a second CMMS and not a second assistant. It wraps existing Rivolq endpoints; the main app keeps business logic, tenant isolation, roles, entitlements, and audit records. It is separate from the built-in AI assistant.

Entitlement, clients, and URLs

Rivolq Connect is controlled by the External AI Connector feature. Workspaces without it can still use the in-product assistant, but external MCP clients need this entitlement.

  • ChatGPT and OpenAI Apps SDK clients use https://connect.rivolq.com/mcp/
  • Claude and Cursor-compatible MCP clients use the SSE URL, https://connect.rivolq.com/sse

Available tools

The MCP registry currently exposes 17 tools: 12 read tools covering work orders, assets, facilities, analytics, risk, and parts; 3 propose-only work-order tools (create, assign, and approve completion); and 2 private ChatGPT widget tools for confirming or rejecting a proposal. Tool visibility follows the OAuth scopes granted during consent.

Guarded write proposals

Write tools are propose-only. A client can stage a proposed work order, assignment, or completion approval, but nothing is applied until a human confirms it. In ChatGPT, proposals render an embedded Rivolq review widget with confirm and reject controls; other MCP clients use the Rivolq confirm URL. An external AI client never silently creates, assigns, approves, deletes, publishes, emails, messages, or purchases anything in Rivolq.

Security and revoking

Connect uses OAuth 2.1 with PKCE, server-side scope enforcement, entitlement checks, short-lived sessions, normal role and tenant checks, rate limits, and per-call audit logging. A scope the user or workspace should not have is hidden or denied before any business logic runs. To revoke access, open Connected apps in Rivolq and disconnect the app; the client must re-consent before calling tools again. See OAuth apps and connected app access.

Troubleshooting

If a client connects but shows no tools, confirm the workspace includes External AI Connector access. If a tool is missing, check OAuth scopes and the user's role. If a proposed write does not apply, open the widget or confirm URL and review the proposal status or expiry.

Still need help?

Reach out for broken behavior, account-specific help, or billing questions.

Contact support
Rivolq
Book a demo