Skip to main content

Connecting an AI client to Floxar

Floxar has a Model Context Protocol (MCP) server, so you can work in Floxar from your own AI client: find and read your flows, steps, references and trails, run trails, and create or edit flows. You sign in with your usual Floxar login, and the client can only do what you approve and what your role in the account allows.

If Floxar's sign-in page sent you here, it also said why the connection stopped. Find its message under "If sign-in stops" at the end of this article.

This article covers what every client has in common. Each verified client has its own short guide with the exact steps:

Software that acts on its own, under an identity of its own, is not an AI client: it is an agent. See Registering an agent and Agents and AI clients.

Which clients can connect​

Any MCP client that follows the MCP authorization specification can connect to a Floxar account whose administrator has turned MCP on. That means OAuth 2.1 with PKCE, and a client that identifies itself in one of two ways:

  • A Client ID Metadata Document. The client's identifier is the HTTPS address of a small JSON document its maker publishes. Most clients work this way and need nothing from you but your account URL.
  • An identifier Floxar publishes. Some clients publish no document but let you enter a client ID in their configuration. Floxar publishes one identifier per such client; today cursor and grok-build. There is never a client secret.

Floxar does not offer dynamic client registration, which the MCP specification has deprecated. A client that can only register itself, with no place to enter an identifier and no published document, cannot connect.

Floxar has read the registration of each client in the list above and connected it end to end. At sign-in, those clients appear under Floxar's own label for them. A client that is not on the list connects the same way, as long as it publishes a Client ID Metadata Document and sends your account URL as the resource it is asking for; the difference is what the consent page shows (see "Any other client" below).

Before you start​

  • MCP must be turned on for your account. It starts off for every account. An account admin turns it on under MCP Connections in the account settings.
  • You need your account URL. Every Floxar account has its own MCP URL, of the form https://mcp.floxar.com/a/<account_id>. You find it on the MCP page of the Floxar application (under Automations, then Agents), which also shows whether MCP is on for your account. Account admins also see it on the MCP Connections page. It is the only URL you need: there are no API keys or tokens to copy.
  • Some clients need a client ID. If your client asks for one, use the identifier Floxar publishes for it, shown in that client's guide. Leave any client-secret field empty.

How connecting works​

The first time a client connects, it opens a browser window on Floxar's sign-in:

  1. Sign in with your usual Floxar login.
  2. Confirm the account. The page shows who you are signed in as, the account your account URL belongs to, and that URL. The connection works in that account only. If the page shows a login that is not the one you meant, choose Deny, sign out of Floxar, and start the connection again from your client.
  3. Read who is asking. For a verified client, the page shows Floxar's label for it, the domain it identifies itself with (or its vendor, for a published identifier) and where the connection returns to. For any other client, it shows the client's domain as the heading, its full identifier beneath, the name the client declares for itself marked as the client's own claim, where it returns to, and the notice "Floxar has not reviewed this client." A client running on your own computer returns to a local address, and the page says so: an identifier names a client, not the program on your machine that is listening.
  4. Allow the connection. The page lists what the client will be able to do, limited to what your account allows MCP clients, and says whether the connection can stay connected without signing in again, for up to 7 days of inactivity. Choose Allow, or Deny to stop. You allow or deny the connection as listed; there is no per-capability choice.

What the capabilities mean​

A client asks for capabilities, which OAuth calls scopes. There are three:

ScopeWhat the consent page says
floxar.readRead your flows, steps, references and trails.
floxar.executeRun and update trails on your behalf.
floxar.authorCreate and edit flows, steps and references on your behalf, including archiving steps and references, removing connections and changing a flow's status.

A client may also ask for offline_access, which is how it asks to stay connected.

  • A capability is a ceiling, not a grant. What the connection can do is the capabilities you allowed, intersected with your role in the account. A client never gets more than your role allows.
  • Reading comes with the others. A connection allowed to run trails or to author can also read, even if the client did not ask for it.
  • The client only sees what it may use. The tool list a client receives leaves out every tool the connection's capabilities do not cover, so a read-only connection never sees a write tool.
  • The account can narrow what is offered. An account admin sets which capabilities MCP clients may have in the account; the consent page lists what the client asked for, narrowed by that setting.

Any other client​

  1. In your client, add a remote MCP server (HTTP) and paste your account URL as its URL.
  2. A client that publishes a Client ID Metadata Document needs nothing else: it identifies itself, and its browser window opens for you to sign in. A client that asks for a client ID needs one Floxar publishes; if Floxar publishes none for your client, it cannot connect that way yet.
  3. Sign in to Floxar, then read the consent page: it names the client's domain and the account, and marks a client Floxar has not reviewed. Allow the connection only if you started it yourself and you trust that domain.

If you build an MCP client, see Publishing a client metadata document.

More than one account​

A connection works only in the account whose account URL you added it with. To work in a second account, add Floxar again with that account's URL, under a different name, for example acme-floxar and globex-floxar. Clients tell servers apart by name, not by URL, so each account needs a distinct server name: some clients refuse a duplicate name, and others replace the earlier entry.

What an account admin controls​

An account admin manages MCP on the account's MCP Connections page in the Floxar application (Account Settings, then MCP Connections):

  • Turning MCP on or off. It starts off. Turning it off revokes every connection in the account.
  • The capability ceiling. Which of reading, running trails and authoring MCP clients may be granted, for example read-only. A narrower ceiling applies from the next sign-in; it revokes nothing already connected.
  • Which clients the account accepts. An account that has said nothing accepts any client that follows the specification, reviewed by Floxar or not; each person's reading of the consent page is the check. An admin can deny a client from a connection's row in the inventory, which also revokes that client's connections in the account, or keep an allow list of the only clients the account accepts (set through Floxar's API). An allow list does not change when Floxar verifies a new client.
  • The connected-applications inventory. Every connection in the account: the person, the client and whether Floxar has reviewed it, the access it was allowed, its status and, when revoked, the reason, when it was connected and when access was last issued. Any one of them can be revoked from there.

Separately, Floxar keeps a platform-wide block list for clients that abuse the platform. A blocked client is refused in every account and its connections are revoked. Report a client to security@floxar.com.

Disconnecting and revoking​

Disconnecting inside a client does not end the connection on Floxar's side. Removing the connector in Claude or ChatGPT, claude mcp logout or codex mcp logout, disconnecting in Cursor's or grok.com's settings, signing out in VS Code: each stops that client using the connection, but the connection stays active in Floxar until you or an admin end it there.

  • Your own connections. In the Floxar application, open your profile's Security page and choose Disconnect applications. This ends every AI client you have connected, in every account.
  • An account admin can revoke any one connection from the account's MCP Connections inventory, deny the client for the account, or turn MCP off for the account, which revokes every connection in it.

A revoked connection stops working within about 3 minutes. To use the client again, connect it again and allow the connection. Signing out of Floxar, even everywhere, does not disconnect AI clients.

Good to know​

  • Staying signed in. A connection renews its access on its own, whether or not the client asked to stay connected, as long as the client's registration allows it. After 7 days without use, or 30 days in total, the client asks you to sign in again.
  • Everything is attributed to you. Actions taken through a connection are recorded under your name, marked as made through MCP, together with the client that made them.
  • Adding access later means reconnecting. A connection keeps the capabilities it was allowed. If it was made read-only and you later want the client to run trails or author, connect again and allow the connection; the new consent lists the capabilities the connection gets. Each client's guide says how.
  • Your role still applies. A tool that answers PERMISSION_DENIED needs a role you do not have; reconnecting does not change your role.
  • One connection per person, per client, per account. Connecting the same client to the same account again replaces your earlier connection; it never touches a colleague's.
  • Starting a trail can pause the one you had open. You have one active trail at a time, so a trail your client starts for you pauses the trail you were working on in the application. Resume it from the application.

Troubleshooting​

  • The client says it needs to authenticate (HTTP 401) after it was working. Your sign-in expired or the connection was revoked. Authenticate again from the client. Some clients report a revoked connection in their own words; each client's guide lists what it shows and how to reconnect.
  • The client sees fewer tools than you expected. The connection has only the capabilities it was allowed, and your role limits it further. Reconnect to allow more, or ask an account admin about your role or the account's capability ceiling.
  • A tool answers PERMISSION_DENIED. Your role in the account does not allow that action. Reconnecting does not help; ask an account admin.
  • Disconnecting one client ended another. Some clients share one connection with a sibling client from the same vendor (Codex with ChatGPT, Grok Build with grok.com). Revoking that connection disconnects both.
  • The sign-in itself was refused. See the next section.

If sign-in stops​

When a connection cannot be made, Floxar's sign-in page says why. Find the message you were shown:

  • "MCP connections are not enabled for this account": MCP is off for the account. Ask an account admin to turn it on under MCP Connections in the account settings.
  • "You are not a member of this account": the account URL belongs to an account you are not in. Use your own account's URL, or ask that account's admin to add you.
  • "This account does not accept this client" (the page may name the account): an administrator of the account decides which clients it accepts, and this one is not among them. Ask an account admin, or connect a client the account accepts.
  • "This account already has connections from 25 clients Floxar has not reviewed": the account has reached its limit of unreviewed clients. An account admin can revoke one of them to make room.
  • "This account allows none of the capabilities the client asked for": the client asked only for capabilities the account does not allow MCP clients. Ask an account admin which capabilities MCP clients may have.
  • "This account requires a stronger sign-in": sign in the way the account requires, for example with an authenticator app, a passkey or your organization's own sign-in, then connect again.
  • "The account is no longer active": connect to the URL of an account you can use.
  • "This client has been blocked": Floxar has blocked the client for every account.
  • An invalid-client message: Floxar could not accept the client. A client ID may not be typed exactly as its guide shows, or the client's metadata document could not be read or breaks one of the rules in Publishing a client metadata document.
  • An invalid-scope message: the client asked for no capability Floxar offers. Check any scopes set in the client's configuration against its guide.
  • An invalid-target message: the client did not send your account URL as the resource it is asking for, or the URL is not an active account's. Check that the URL you added is exactly your account URL.
  • "Temporarily unavailable": the client's document could not be fetched right now, or a client Floxar has not reviewed is not being admitted at the moment. Try again in a few minutes.

The messages about the account and your membership always appear on Floxar's page. Some of the other errors are passed back to a client Floxar has verified, which may show them in its own words; for any other client they stay on Floxar's page and are never sent back to it. For anything else, contact help@floxar.com.

Last reviewed: 2026-09-30