The devlin.ai MCP server lets AI tools read and change a workspace directly: list and inspect simulations and coaches, pull results and exports, and (with write access) create drafts, edit fields, publish, and roll back. It can also publish a web page or front-end build on devlin.ai hosting and connect a custom domain. It uses the Model Context Protocol (MCP), which ChatGPT, claude.ai, Claude Code, Cursor, and many other tools support.
Who can use it
- The workspace's plan must include the MCP server. On a plan that does not, the MCP access section in settings is faded, marked "Not on this plan", and names the plans that include it. devlin.ai can also enable it for a pilot on other plans.
- Only workspace owners and admins can turn it on, create tokens, or connect apps. Members cannot.
- Everything an AI tool does over MCP happens as the owner or admin who connected it, with that person's permissions, and every change lands in the workspace audit log (for an organization, the Activity section of settings).
Turning it on (and off)
- With the workspace active, go to Settings → Integrations → MCP access. Integrations is in the settings sidebar for both a personal workspace and an organization (the sidebar shows the active workspace's sections). Settings → Workspaces lists every workspace you manage and switches to the one you pick. MCP access is a workspace setting, not an account setting, so it is not under Account.
- The MCP server switch is off by default. An owner or admin turns it on before anything can connect.
- Turning it off is the kill switch: every token and connected app for that workspace stops working immediately. They are kept, so turning it back on restores them; revoke anything unwanted from the lists first.
- Both flips are recorded in the audit log.
Connecting ChatGPT (no token needed)
- Follow OpenAI's guide "Developer mode and MCP apps in ChatGPT" (https://help.openai.com/en/articles/12584461-developer-mode-and-mcp-apps-in-chatgpt) to turn on Developer mode and add devlin.ai as an app. Whether this is available depends on the ChatGPT plan, and in a Team or Enterprise ChatGPT workspace a ChatGPT admin has to allow it first.
- When adding the app: MCP server URL
https://devlin.ai/api/mcp, Authentication OAuth, and leave client ID and client secret blank. ChatGPT registers itself with devlin.ai automatically. - Connect the app. Adding it does not sign anyone in. Open it in ChatGPT under Settings → Plugins → devlin.ai and click Connect. ChatGPT opens the devlin.ai sign-in (email code, Google, Microsoft, or SAML SSO; MFA applies as usual), then a consent screen.
- On the consent screen, pick one workspace to connect, choose whether to allow write access, and click Authorize. Only workspaces where you are an owner or admin and the MCP server is on are offered. A connection is bound to that single workspace; a personal-workspace connection never reaches an organization workspace. The screen also names the site you will be returned to; if it is not the app you started from, choose Deny.
- The connection appears under Connected apps in the workspace's MCP access section, where any owner or admin of the workspace can disconnect it. In a chat, mention
@devlin.aito use it.
Connecting claude.ai (no token needed)
- In claude.ai: Settings → Connectors → Add custom connector → URL
https://devlin.ai/api/mcp, then click Connect on the new connector. - The same devlin.ai sign-in and consent screen follow, and the connection appears under Connected apps in the same way.
Access issued this way is short-lived and refreshes automatically in the background; the user never handles a token. A connection that goes unused for a long stretch lapses and has to be connected again.
Connecting Claude Code, Cursor, or scripts (personal access token)
- In MCP access, under "Claude Code, Cursor, and scripts", create a token: give it a name, decide whether it gets write access (off by default), and pick when it expires (or no expiry).
- Copy the token immediately. It is shown once and cannot be retrieved later.
- Claude Code:
claude mcp add --transport http devlin-ai https://devlin.ai/api/mcp --header "Authorization: Bearer YOUR_TOKEN". Other tools: HTTP transport, the same URL, and the token as a Bearer header. A tool that can complete a browser sign-in can use the OAuth sign-in instead of a token. - A workspace has a cap on active tokens; revoke one to make room when the cap is reached. Owners and admins see every token for the workspace, including teammates', and can revoke any of them.
What a connected AI tool can do for you
- Hand you the right link at each step. After creating or editing a simulation or coach, the tool gives a test link. The test link works for any signed-in member of that workspace, does not expire, and is safe to paste in a chat because it contains no secret (it asks the person to sign in). After publishing, the tool gives the share link and can offer the embed code or a stakeholder review link.
- Host a page or a built website. If someone has HTML, or the build output of a front-end project, and nowhere to put it, the tool can publish it on devlin.ai hosting and return the live URL. Chat tools such as ChatGPT and claude.ai send the files directly, which suits small sites. Tools that can run shell commands, such as Claude Code and Cursor, can upload a zip up to the plan's single-upload limit. devlin.ai hosts finished build output; it does not run a build. The tool can check a package first and report every problem at once.
- Change the address. The tool can rename a project's devlin.host address. The old address keeps redirecting to the new one and can never be reused. After a rename there is a waiting period before the address can be changed again.
- Connect a custom domain. A workspace owner or admin can ask the tool to connect a domain they own, if the workspace's plan includes custom domains. The tool returns two DNS records to create at the domain's DNS provider (one proves ownership, one points the domain at devlin.ai), checks them when the person says they are in place, and then puts a project on the domain.
- Answer how-to questions from the documentation. The tool can search devlin.ai's product knowledge for how-to and troubleshooting answers. When a result comes from a published documentation page, it links that page, so the tool can point to where the answer came from.
- Ready-made workflows. Tools that support MCP prompts show shortcuts: build a simulation, improve a simulation, host my page, connect a custom domain, and review learner results. In a tool that does not show them, asking in plain words works the same.
Read-only versus write access
- Read-only connections and tokens can never change anything and never see the write tools.
- Write access lets the tool create drafts, edit content, publish, unpublish, and restore versions, and also host projects and manage custom domains. Draft edits apply immediately; changes to published content require an explicit confirmation from the tool and are re-screened by content moderation before going live. Every applied simulation and coach write is versioned and can be rolled back. Hosting is different: replacing a live project's files or deleting a project cannot be undone, so the tool must confirm first.
- Recommended practice: keep a read-only connection day to day and grant write access only when editing is the goal.
Requiring approval for changes to published content
- In MCP access, an owner or admin can click Require approval in the "Approval for live changes" row. It is off by default.
- When it is on, an AI tool can still edit drafts directly, but any change to live content is held instead of applied. That includes edits or version restores on a published or archived simulation or coach, and publishing or unpublishing a simulation or coach. The tool is told the change is waiting for approval and is given a link to the review page.
- Hosting and custom domain changes are held too: hosting a new project, replacing a live project's files, renaming or changing a project's settings, deleting a project, and adding, assigning, or removing a custom domain. Uploading a zip for a later hosting request and re-checking a domain's DNS records are not held, because neither puts anything live.
- Summarizing a very large source is not held as a request either, but an AI tool cannot start it while approval is on. The tool is told that a workspace member has to select Summarize on the source in the app, and nothing is spent. See Source materials.
- Owners and admins review these under MCP access → Pending changes: each card shows exactly what would change, who asked for it and through which tool, and any reason the tool gave. Approve and apply applies that exact change through the normal path (content moderation re-screens it first); Deny discards it.
- If the simulation or coach was edited between the request and the approval, the approval is refused and the tool has to re-read and ask again, so a stale change can never overwrite newer work.
- Requests expire if nobody decides them, and a workspace has a cap on how many can wait at once. Every request, approval, and denial is recorded in the workspace audit log.
- Turning the setting off again does not apply anything that is still waiting; those requests stay in the queue until someone decides them or they expire.
Common questions
- The AI tool says a change is "waiting for approval". The workspace requires approval for changes to live content. An owner or admin can approve or deny it under MCP access → Pending changes.
- "MCP access" is faded in settings and marked "Not on this plan". The workspace's plan does not include the MCP server. The section names the plans that do and links to the plans page.
- "MCP access" is not in settings at all. The person is not an owner or admin of the workspace (members do not see it).
- ChatGPT says the devlin.ai app "isn't exposing any tools", or cannot list simulations. The app was added but never connected, so ChatGPT is calling devlin.ai without signing in. Open the app under ChatGPT Settings → Plugins → devlin.ai, click Connect, and complete the devlin.ai sign-in and consent screen. The connection then shows under Connected apps in the workspace's MCP access section; if it is not listed there, the sign-in was not completed.
- The consent screen says "The MCP server is turned off" or "MCP access is not enabled". No workspace you own or administer can be connected yet. The first message means the MCP server switch is off: turn it on in that workspace's MCP access section and retry. The second means none of your workspaces has MCP access, or you are a member rather than an owner or admin of the one that does.
- A token or connection suddenly stopped working. The most common causes: the MCP server switch was turned off, the person who created it was removed or demoted to member, the token expired or was revoked, or the workspace's plan changed. Each of these takes effect immediately, by design.
- Can a connection reach more than one workspace? No. Each connection or token is bound to exactly one workspace. Connect again and pick a different workspace to work in another one.
- The AI tool says the domain is "not verified yet". The DNS records have not reached the wider internet yet. This can take from a few minutes to a few hours. Check that both records match exactly, then ask the tool to verify again later.
- The test link asks me to sign in, or shows "not found". The test link only works for signed-in members of the workspace that owns the simulation. Sign in with an account that belongs to that workspace.
- The AI tool rejected my website files. Hosting accepts static build output (HTML, CSS, JavaScript, images, fonts, media). Send the built folder (often called dist, build, or out), not the source code. Ask the tool for a dry run to see every problem at once; common junk files such as .DS_Store are skipped automatically.