Early Access — The MCP server is available to organizations with AI features enabled. Reach out to your Sessionboard account manager if you’d like it turned on.
- Connect Claude — including Sessionboard’s listing in Claude’s connector directory
- Connect ChatGPT — via a developer-mode connector
- Connect Microsoft Copilot — via a Copilot Studio agent
- Connect Google Gemini — Gemini app, Gemini Enterprise, or the Gemini CLI
What is MCP?
Model Context Protocol is an open standard that enables AI assistants to securely connect to external data sources and tools. Instead of copying data into prompts, MCP lets the AI query and update your data on demand through a structured interface.Server URLs by region
Each Sessionboard region runs its own MCP server. Use the one matching where your organization is hosted:
The server uses the streamable HTTP transport and supports OAuth 2.0 with PKCE and dynamic client registration — most clients discover the sign-in flow automatically.
Prerequisites
Setup
1
Connect your AI client
Most assistants (Claude, ChatGPT, Copilot Studio, Gemini) connect through their own UI — follow the Help Center guides above. For clients configured by file (Claude Code, Cursor, and similar), add:Swap in the EU or Middle East URL from the table above if that’s where your organization is hosted.
2
Sign in
On first use the client walks you through Sessionboard’s OAuth sign-in and organization consent automatically — no token to copy. A client that cannot complete that sign-in cannot use the hosted MCP URL. Scripts call the public API with an API token instead.
3
Start querying
Ask your AI assistant questions about your event data in natural language. The assistant uses the MCP tools to query Sessionboard and return results.
Available Tools (38)
The MCP server exposes 38 tools in four groups. Write operations use amanage_* pattern — one tool per entity with an action parameter to pick the operation (e.g., action: "create").
All tools include MCP annotations for safe AI behavior — read tools are marked readOnlyHint: true, every manage_* tool is marked destructiveHint: true because each can overwrite an existing record through its update action (even the ones with no delete), and all are openWorldHint: false because every tool is bounded to your organization’s data. Clients such as Claude and ChatGPT use these hints to ask for confirmation before a write runs.
Search & Discovery (10 tools)
Find events, search your data, ask questions in plain English, and explore your schema.Read Details (4 tools)
Fetch sessions and contacts. All read-only and paginated.Read-Only Lists (9 tools)
Read counterparts to themanage_* tools — safe to call without any write scopes.
Create & Manage (15 tools)
Eachmanage_* tool handles all operations for an entity — create, update, delete, and more — using an action parameter. For example, manage_session with action: "create" creates a session, while action: "update" updates one.
Parameter Conventions
- Event scoping — All event-scoped tools require
event_id(snake_case string). - Action selection — Consolidated tools use
actionto pick the operation (e.g.,action: "create"). - Entity IDs — snake_case:
session_id,contact_id,entity_id,draft_id,widget_id,query_id. - Optimistic concurrency — Update actions require
updated_at(ISO 8601 timestamp from the last read). Returns409 Conflictif the entity was modified since.
Result Size Safety
All results are automatically truncated to prevent context window overflow:- List results — Capped at 50 items. When truncated, the response includes
truncated: true,total_count, and ahintwith guidance on pagination. - Query results — Capped at 100 rows with truncation metadata.
- SbQL queries —
execute_sbqlandquery_datadefault to a 50-row limit. Use thelimitparameter for more.
Resources
The MCP server also exposes two MCP resources that AI clients can load into context:Prompt Templates
Pre-built templates that structure the AI’s approach to common report types:Security
- Org isolation — The SbQL compiler injects
org_idinto every query from the authenticated token. Prompt injection cannot access other organizations’ data. - PII masking — OAuth connections always mask PII in query results: emails become
j***@a***.com, phone numbers become***-***-4567. For API-token calls to the query routes, masking follows that token’s PII Obfuscation setting (off by default — turn it on for any token a third party will use). See privacy details in the Help Center. - Scoped access — Tokens are restricted to specific scopes and optionally to specific events.
- Audit logging — Every API call is recorded with source, method, response time, and token ID.
Example Conversations
Once connected, you can ask questions like:- “How many sessions are accepted for this year’s conference?”
- “Show me the top 10 speakers by number of sessions.”
- “What’s the breakdown of sessions by track and status?”
- “List all sessions that don’t have a room assigned yet.”
- “Create a new track called ‘AI & Machine Learning’ with color #4F46E5.”
- “Build a dashboard showing session counts by status and track.”
- “Create a draft agenda and schedule the keynote in the Main Hall at 9am.”

