Approveit MCP Server Guide: Connect Claude, Cursor and AI Agents to Your Approvals

Approveit MCP Server Guide: Connect Claude, Cursor and AI Agents to Your Approvals

Approveit MCP Server Guide: Connect Claude, Cursor and AI Agents to Your Approvals

Approveit MCP Server Guide: Connect Claude, Cursor and AI Agents to Your Approvals

Overview: What Is the Approveit MCP Server?

Approveit runs a remote Model Context Protocol (MCP) server. It lets an AI host such as Claude Desktop, Claude Code or Cursor, or an agent you build yourself, work with Approveit directly: list workflows, read approval requests, submit new ones and record approval decisions, without building anything against the REST API first.

Everything the server exposes runs as one specific person in one specific workspace, fixed by the credential the AI host connects with. A connected app sees exactly what that person sees in the Approveit web app, because every tool goes through the same role permissions and per-request access rules as the UI. There is no way to act as another user and no way to read another workspace.

For the full technical reference, see the official documentation: Approveit MCP server reference.

Before You Start

  • The MCP server is enabled per workspace. If yours is not enabled yet, ask your Approveit administrator or write to support@approveit.today.

  • You must be an active member of the workspace. Suspending a member cuts off their AI connections along with their web access.

  • Use the endpoint for your region. A credential issued in one region does not work in the other.

Endpoint

  • US: https://api.approveit.today/mcp

  • EU: https://api-eu.approveit.today/mcp

  • Transport: Streamable HTTP with JSON responses, POST only

  • Protocol versions: 2025-06-18 and 2025-03-26

  • Server name: approveit

The endpoint is stateless and re-authenticates every request, so revoking access takes effect on the very next call.

How to Connect Your AI Assistant

Option 1: OAuth (recommended)

OAuth needs no credentials created up front. The server supports discovery and dynamic client registration, so any compatible AI host can offer a simple "Connect" button.

  • In your AI host (for example Claude), add a remote MCP server using the endpoint URL for your region.

  • The host opens Approveit in your browser. Sign in the way your workspace already does: password, Google, Microsoft, Slack, Webex, SAML SSO or MFA.

  • On the consent screen, check which application is asking and choose which workspace the connection should act in, if you belong to more than one.

  • Approve, and the host is connected. Access tokens last one hour and refresh tokens last 30 days, rotating on every use.

To review or remove a connection, open the Approveit web app and go to Profile settings → Connected AI apps. Disconnecting revokes the application's tokens immediately.

Option 2: API key

For a server-side agent, a script or anywhere no browser is available, Approveit can issue a long-lived key bound to one person in one workspace. Keys look like apit_mcp_us_..., carry read or read + write access, and can be given an expiry.

Keys are currently issued on request. Contact support with the workspace, the member the key should act as, and whether it needs write access. Then add it to your host as a bearer token:

{
  "mcpServers": {
    "approveit": {
      "url": "https://api.approveit.today/mcp",
      "headers": { "Authorization": "Bearer apit_mcp_us_..." }
    }
  }
}
{
  "mcpServers": {
    "approveit": {
      "url": "https://api.approveit.today/mcp",
      "headers": { "Authorization": "Bearer apit_mcp_us_..." }
    }
  }
}
{
  "mcpServers": {
    "approveit": {
      "url": "https://api.approveit.today/mcp",
      "headers": { "Authorization": "Bearer apit_mcp_us_..." }
    }
  }
}

The key is shown only once, so store it somewhere safe. If a key leaks, ask support to revoke it. Revocation is immediate and permanent.

Scopes and Permissions

  • read: every listing, lookup and reporting tool.

  • write: the action tools (submit, update, approve, reject, cancel, invite, create or activate a workflow). Includes read.

A scope is a ceiling, never a grant. Every tool call is also checked against the connected person's role permissions and the per-request access rules. A write credential held by someone who is not the current approver on a request still cannot approve it. Read-only connections are never even shown action tools.

What Your AI Assistant Can Do

The server publishes 21 tools, grouped into four areas:

  • Identity: get_user_context returns the name, email, role, department and workspace the connection acts as.

  • Workflows: list and describe workflows and templates, see approval steps and routing, create a workflow from a template and activate it.

  • Approval requests: list and filter requests (for example, those awaiting your approval), read details and the audit trail, summarize what was approved, analyze field values, and submit, update, approve, reject or cancel requests.

  • Lookups and team: resolve vendors, customers, departments, cost centers and other entities, search team members and invite new ones.

Some example prompts you can try once connected:

  • "What approval requests are waiting for me?"

  • "Summarize everything I approved last month by currency."

  • "Submit a purchase request for 10 laptops from Dell under the IT cost center."

  • "Show me the approval history for AR-15."

The full tool list, with the permission each tool requires, is in the MCP server reference.

Built-In Safety

  • Actions are real and confirmed. Approving, rejecting, cancelling, submitting and inviting notify real people and are recorded against the connected person. AI hosts are instructed to show you what will happen and get your explicit confirmation first.

  • Duplicate writes are absorbed. An identical write call within 90 seconds returns the first result instead of running again, so a retry never creates a second purchase order.

  • You are notified by email. When a connected app approves, rejects, cancels or submits on your behalf, Approveit emails you with what happened and how to disconnect it.

  • Everything is logged. Every tool call is recorded with the credential, person, tool and outcome. Admins can review AI activity on the Actions page in the web app.

Rate Limits

  • 120 calls per minute per credential

  • 20 write calls per minute per credential

  • 300 calls per minute per workspace across all credentials

When a limit is reached, the tool tells the AI how many seconds to wait, so it can pause and continue instead of failing.

Test the Connection with curl

To check an API key from the command line, list the tools it can call:

curl -s https://api.approveit.today/mcp \
  -H "Authorization: Bearer $APPROVEIT_MCP_TOKEN" \
  -H "Content-Type: application/json" \
  -H "MCP-Protocol-Version: 2025-06-18" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
curl -s https://api.approveit.today/mcp \
  -H "Authorization: Bearer $APPROVEIT_MCP_TOKEN" \
  -H "Content-Type: application/json" \
  -H "MCP-Protocol-Version: 2025-06-18" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
curl -s https://api.approveit.today/mcp \
  -H "Authorization: Bearer $APPROVEIT_MCP_TOKEN" \
  -H "Content-Type: application/json" \
  -H "MCP-Protocol-Version: 2025-06-18" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'

You can also inspect the server interactively with npx @modelcontextprotocol/inspector.

MCP Server vs. REST API

The REST API uses a workspace-level token and acts as the workspace, which is right for server-to-server integrations. Approvals, however, need to be attributable to a person and checked against that person's permissions. MCP credentials are per person by design, which is why the MCP server is the surface an AI assistant should use.

Conclusion and Next Steps

The Approveit MCP server lets your team review, submit and approve requests from the AI tools they already use, with the same permissions, audit trail and controls as the Approveit web app. Claude Desktop and Claude Code are tested end to end, and other MCP hosts that follow the specification should work as well.

For error codes, the complete tool reference and current limitations, read the official documentation: https://approveit.readme.io/reference/mcp-server.

To trigger workflows from external systems, see the Approveit Inbound API Guide. To send request data to other systems, see the Approveit API Guide for Webhooks.

If you have any questions or need further assistance, feel free to reach out to our

support team.

Tags