Skip to contentleitvik

Documentation

Leitvik MCP connector

Leitvik is a follow-up CRM for consultants and small B2B teams. Its MCP connector lets an AI assistant read your workspace (companies, leads, today's agenda, tasks and opportunities) and, only if you allow it, update tasks, opportunities and next steps. No tool sends email or messages.

Endpoint

https://app.leitvik.com/api/mcp

Remote server over Streamable HTTP, stateless, with JSON responses. Every request is authenticated. A GET for an event stream returns 405, which the protocol allows.

What you need

  • A Leitvik workspace. Leitvik is an invite-only pilot: request access at leitvik.com.
  • To be an owner or admin of that workspace. Members cannot connect an assistant or create API tokens.

Authentication

The same endpoint accepts two kinds of credential. Both are issued by your own workspace, act only there and can be revoked from Leitvik at any time.

OAuth 2.1

For assistants that sign in on their own: Claude and ChatGPT connectors and other directory clients.

  • Leave any client ID and secret fields empty. The assistant discovers Leitvik's authorization server from the endpoint and registers itself with a client ID metadata document or dynamic client registration.
  • Authorization code with PKCE S256 only; there is no client-credentials grant.
  • On the consent screen you choose one workspace and the scopes. Requested reads are preselected; writes stay off until you turn them on. Every authorization asks again.
  • Access tokens last one hour. Refresh tokens last 30 days and rotate on every use.
  • To disconnect, open Settings > API tokens > Connected applications.

API token

For clients configured with a header: Cursor, Grok Bot and the command line.

  • An owner or admin creates it in Settings > API tokens, with only the scopes the assistant needs, an expiry and a requests-per-minute limit.
  • The value (qre_…) is shown once. Leitvik keeps only its hash.
  • Send it as the header Authorization: Bearer qre_…. Never put it in a URL, a prompt, a repository or a screenshot.
  • Revoke it in Settings > API tokens when you no longer need it; the next call fails at once.

Discovery

An unauthenticated request receives 401 with a WWW-Authenticate header that points to the protected resource metadata (RFC 9728). The authorization server metadata (RFC 8414) is served for the issuer /api/auth.

https://app.leitvik.com/.well-known/oauth-protected-resource/api/mcp
https://app.leitvik.com/.well-known/oauth-authorization-server/api/auth

Scopes

Each credential carries the scopes chosen when it was created or authorized. A write scope also allows the matching read. captures:write has no read form.

ScopeAllowsTools
companies:readRead companies.
  • leitvik_companies_list
  • leitvik_company_get
  • leitvik_relationship_brief
contacts:readRead the contacts of a company.
  • leitvik_contacts_list
leads:readRead the lead pipeline and today's agenda.
  • leitvik_leads_list
  • leitvik_today
  • leitvik_relationship_brief
touches:readRead recorded conversations.
  • leitvik_touches_list
  • leitvik_relationship_brief
signals:readRead buying signals and their sources.
  • leitvik_signals_list
  • leitvik_relationship_brief
dossiers:readRead research dossiers.
  • leitvik_dossiers_list
tasks:readRead tasks.
  • leitvik_tasks_list
opportunities:readRead opportunities.
  • leitvik_opportunities_list
companies:writeCreate or update companies by domain.
  • leitvik_companies_list
  • leitvik_company_get
  • leitvik_relationship_brief
  • leitvik_company_upsert
contacts:writeCreate or update contacts.
  • leitvik_contacts_list
  • leitvik_contact_upsert
leads:writeChange a lead's state and next step.
  • leitvik_leads_list
  • leitvik_today
  • leitvik_relationship_brief
  • leitvik_lead_update
touches:writeRecord a conversation that already happened.
  • leitvik_touches_list
  • leitvik_relationship_brief
  • leitvik_touch_record
signals:writeRecord a cited buying signal.
  • leitvik_signals_list
  • leitvik_relationship_brief
  • leitvik_signal_record
dossiers:writeReplace a company's research dossier.
  • leitvik_dossiers_list
  • leitvik_dossier_write
tasks:writeCreate, complete, snooze, dismiss, reopen and edit tasks.
  • leitvik_tasks_list
  • leitvik_task_create
  • leitvik_task_complete
  • leitvik_task_snooze
  • leitvik_task_dismiss
  • leitvik_task_reopen
  • leitvik_task_edit
opportunities:writeCreate and update opportunities.
  • leitvik_opportunities_list
  • leitvik_opportunity_create
  • leitvik_opportunity_update
captures:writePreview, apply and undo reviewed conversation captures.
  • leitvik_capture_preview
  • leitvik_capture_apply
  • leitvik_capture_undo

Read-only by default

The connector starts read-only. Write tools appear only when writing is enabled on the Leitvik service and the credential has the matching write scope. Enabling a feature in the assistant never adds permissions on the server.

What the connector does with your data

It can read
Companies, contacts, the lead pipeline, today's agenda, recorded conversations, signals, dossiers, tasks, opportunities, and the workspace identity and scopes of the connection. It does not return private captured emails or provider credentials.
It can write, with write scopes
Companies, contacts, lead state and next step, recorded conversations, signals, dossiers, tasks and opportunities. Pasted call notes become a proposal you review before it applies, and the next step it replaced can be restored. Other writes apply at once within the credential's scopes and are recorded in the audit log.
What it never does
Send email or messages, charge anyone, invite people, manage tokens or team permissions, or delete records. leitvik_dossier_write replaces a dossier's text; nothing else removes data.

Every tool result carries a notice telling the assistant that CRM text is untrusted data, never instructions.

Rate limits

  • API tokens: 60 requests per minute by default, set between 1 and 600 when the token is created. The REST API and the connector share the limit.
  • OAuth connections: 60 requests per minute per connection.
  • Over the limit, a tool returns rate_limited with retryAfterSeconds.
  • Lists return up to 100 items per page. A result larger than about 240 KB is withheld with result_too_large, never truncated silently.

Support

Write to hello@pharosyne.tech. Leitvik is operated by Pharosyne Tech SLU, Spain.