AI and agents
Open Settings → AI & agents to connect an AI assistant — or a server of your own — to the active workspace over MCP. Connections are read-only.
Everything lives in one list. A row is a connection, and a connection is one key: it can be renamed, re-tagged and revoked on its own without touching any other. One person can run several connections of the same kind — two Claude Codes on two laptops are two rows.
Before you start
Only workspace owners and admins can create or revoke keys. Keep keys secret.
Connect an assistant
Two ways in, and which one you get depends on the assistant.
By URL, with no key to copy
Claude, ChatGPT and any other client that speaks OAuth connect by address. In
the assistant, add a custom MCP connector pointing at:
https://api.twelfth.ai/mcp
It will send you to Twelfth to sign in, then ask which workspace the connection
is for and which read tools to allow. Approve it and you are done — no key is ever created, copied or
pasted.
A connection made this way reads as you: your remits, your categories, and
nothing outside them. That is why any member can make one, not just owners and
admins. It also means it stops working the moment you stop being a member of
that workspace — there is no key left behind to find and revoke.
One connection reads one workspace. To connect the same assistant to a second
workspace, connect it again from that workspace.
By key, from the list
- Select Connect an agent and pick the assistant you already use.
- Select the read tools this connection may use, then create its key. Twelfth copies the key to your clipboard and starts waiting.
- Follow the prompt on the row: a one-click button for Cursor and VS Code, a paste-ready prompt or MCP configuration for everything else.
- The row flips to connected by itself the moment the assistant’s first request lands. Nothing to confirm.
Copy the key while it is on screen. Twelfth shows a newly created key only once.
Ending a connection
Open Settings → AI & agents and use the row’s menu. Ending an OAuth
connection takes effect on the assistant’s very next request — including one
that already holds a valid token, because every request re-checks the
connection before it reads anything.
You can always end your own connections. Owners and admins see, and can end,
every connection in the workspace.
Connect a server
Select Create an API key for anything that is not an assistant — a cron job, a script, your own backend. Name it, tag it Development, Staging or Production, choose its read tools, and the key is revealed once. The environment tag shows on the row, so an admin deciding what is safe to revoke can tell the production server from someone’s experiment.
The tool picker comes from the current server catalogue, so it only offers tools available to that workspace and credential type. A disabled tool is absent from MCP discovery and refused if a client calls it directly. Owners and admins can change a key’s selected tools from its row in AI & agents; the change takes effect on the next MCP request. An OAuth connection chooses tools during consent and must reconnect to change its selection. Older connections made before tool selection existed retain access to all currently eligible read tools until changed or reconnected. A new tool is not automatically added to a connection with an explicit selection.
What a connection reports
Each row shows the client that actually connected and its version — for example Claude Code 2.0.14 — rather than the choice made when the key was minted. It also shows whether the connection has an explicit tool selection. OAuth rows name the member whose access is being used. If a key has been used by more than one client, the row says so: that is usually a key that has been shared around and is worth splitting.
Ask menus
Separate from connections: the Ask button on pages and tables hands your prompt to an external AI chat. Choose which one under Ask menus. It grants no access to the workspace and involves no key.
Setup guides by assistant
Each assistant has a guide here:
- Claude — Claude.ai custom connector.
- ChatGPT — ChatGPT connectors.
- Gemini — Gemini extensions/MCP.
- Grok — Grok connectors.
- Glean — Glean MCP connection.
- Cursor — Cursor MCP config.
- Claude Desktop — desktop MCP config.
- VS Code / Copilot — VS Code MCP config.
- Generic MCP — any other MCP-capable client.
- Vercel Connect — connect a Vercel app or agent with OAuth or a workspace key.
- API keys — create, name, tag, and revoke keys.
Available MCP tools
Depending on its saved tool selection, entitlement, and the caller’s role and remits, a connection can:
- Get workspace identity and operating defaults.
- List workspace members and their roles.
- List open actions, including due dates, assignees, and available source context.
- Read stored workspace preferences. An OAuth connection can also read its own user and membership preferences; a workspace key cannot read anyone’s personal settings. This covers only settings stored in the preference registry, not every Settings page. Results list only readable keys and show whether the caller’s role permits editing them in the app; MCP writes remain unavailable. Operational alert contacts are shown only to owners and admins.
- List projects visible to the connection and the workflows available in the workspace.
- Page through Products with search, sort, category, remit and supplier filters. Product position figures come from the latest available snapshot; an unmeasured figure is null.
- List saved pricing tracked sets and read a bounded page of a set’s product and competitor-price rows. The set in a Products link such as
?set=<id>is thesetIdfortwelfth_get_tracked_set. Chooselivefor the last observed prices or 4, 8 or 12 weeks for rolling averages. Each call uses the connection’s readable remits and the saved set’s retailer selection. A set outside a member’s remits retains its name and link but returns no product lines. Pricing tools require the workspace’s Pricing intelligence capability. - Discover approved pricing sources with
twelfth_list_pricing_retailers, optionally for one saved set. It includes sources that have no matching products yet. Pass itssourceKeyvalues and up to eight product SKUs totwelfth_compare_pricing_skusto get matching and stock state, observed and basis-matched prices, competitor-minus-own gaps, product-page evidence and a short note. A SKU outside the connection’s remit or the selected set is reported as unreadable or untracked without exposing its details. These calls use stored observations, not a fresh scrape. - Read managed categories, aliases and remit ownership. An OAuth member sees only readable remit details; owners and admins can see the whole workspace. The result says whether the role permits category management in the app. Demand overrides are a separate Twelfth-staff control.
- See integration connection state, what each connector provides, whether the person’s role permits configuration in the app, and a link to its setup or manage page. The assistant cannot start a provider connection or handle its credentials.
- Read-only analysis tools for the visible work-unit snapshot and the caller’s readable catalogue: sales metrics, product ranking, inventory position, product master, similar products, supplier constraints, supplier lookup, entity profiles and context, and methodology. Connected workspaces can also offer competitor price intelligence. Arbitrary warehouse SQL is reserved for Twelfth’s staff-only diagnostic workspace.
Tools that only make sense inside the in-app chat (asking the buyer a clarifying question, rendering a table or chart) are not offered over MCP. Tool results include source_evidence_ids; a later call can pass them back to refer to the same rows.
An MCP key is a workspace credential, not a person: it reads the whole business, the way the owner or admin who created it does. It is not narrowed to any one buyer’s remit.
These tools cannot write data or make changes in Twelfth. Changing settings and creating projects still happen in the app. API keys, account sessions, sign-in methods, and leaving or deleting a workspace are app-only controls.
What Twelfth records about a connection
Every call is logged against the key that made it: the tool name, whether it succeeded, when, and how long it took — that is what the usage view under API keys shows. Tool results are never stored or sent to analytics; only their size is. Keys are stored hashed and shown once, at creation. Repeated failed authentication from one address is refused for a cooling-off period.