Model Context Protocol

Your desk, from inside ChatGPT or Claude

Inco speaks MCP over Streamable HTTP with OAuth 2.1. Point any host at the server URL, approve a desk, and the same tools the in-app assistant uses answer there.

https://www.incoapp.com/mcp

One endpoint. Dynamic client registration; no credentials to request from us.

Connecting

Every host does the same three things: register itself, send the broker here to approve a desk, then call tools with the token it gets back.

ChatGPT

Add it yourself
  1. In ChatGPT, open Settings → Connectors → Add.
  2. Paste the Inco server address and continue.
  3. Sign in here and pick which desk it may see.

A listing in the ChatGPT app directory is in review. Until then this works today.

Claude

Add it yourself
  1. In Claude, open Settings → Connectors → Add custom connector.
  2. Paste the Inco server address and continue.
  3. Sign in here and pick which desk it may see.

In Claude Code, `/plugin install inco@stellar-trading` installs the connector and the desk workflows together.

Gemini

Custom app link
  1. Open gemini.google.com/apps and choose to add a custom app.
  2. Paste the Inco server address.
  3. Sign in here and pick which desk it may see.

Gemini draws no cards, so answers arrive as text. Nothing is missing from them.

Discovery, in full

  1. POST /mcp with no token returns 401 with WWW-Authenticate: Bearer resource_metadata=… (RFC 9728).
  2. /.well-known/oauth-protected-resource names the resource and the authorization server.
  3. /.well-known/oauth-authorization-server gives the endpoints; POST /oauth/register is RFC 7591 dynamic registration.
  4. Authorization code with PKCE, and an RFC 8707 resource indicator. The broker picks which desk the token speaks for.

GET /mcp answers 405 — there are no server-initiated streams, and advertising one we do not serve is worse than not offering it.

What a connection may do

Three permissions, granted separately at consent. A broker sees these words, not the scope strings.

Read your desk

desk:read

See your opportunities, deals, briefs, counterparties and what has come in. It sees exactly what your own screens show you, and nothing from any other desk.

Create and update records

desk:write

Add an opportunity, log a deal, write a note, create a task. Changes appear in your desk's activity trail with the app that made them named.

Prepare things to send — you approve each one

desk:send

Draft a follow-up, a brief for counterparties, a message to another desk. Nothing leaves your desk without you pressing send.

45 tools

Generated from the server's own catalogue, so this table cannot describe a tool we have since renamed. Annotations are what your host shows a person before allowing a call.

Reads 33

ToolWhat it doesArguments
check_recurrenceCheck for a repeat offersubmission_uid
find_matchesMatch opportunities to listings–
get_brief_pdfGet a brief as a PDFbrief_uid
get_checklist_statusGet a deal's checklistdeal_uid
get_deal_documentsA deal's documentsdeal_uid
get_deal_economicsGet what a deal earnsdeal_uid
get_desk_digestWhat changed on the desksince
get_escrow_statusCheck an escrowdeal
get_queueWhat is waiting on the desk–
get_recordGet one recordtype, uid
get_trust_pathGet a desk's track recorddesk
list_access_requestsList access requests–
list_attestationsList trade confirmationsanswered
list_briefsList briefsstate
list_checklist_templatesList checklist templatescommodity
list_companiesList companies–
list_connectionsList connected desksstate
list_dealsList dealsstate, stuck_for_days
list_duplicatesList possible duplicateskind
list_intake_queueList the inbox–
list_mandatesList mandatesstate
list_marketplace_listingsList marketplace listings–
list_network_inboxList cargo from other desksinclude_declined, unanswered
list_opportunitiesList opportunitiesstate
list_peopleList people–
list_record_filesList a record's filestype, uid
list_record_notesRead a record's notestype, uid
list_saved_viewsList saved viewsresource
list_tasksList tasks due–
relationship_strengthRank counterparties by contactband, company
search_helpSearch help articlesquery
search_recordsSearch desk recordsquery, types
summarize_pipelineSummarize the pipelineclosing_within, group_by, include_closed

Writes 12

ToolWhat it doesArguments
approve_draftApprove a draftdraft_uid
capture_offerCapture an offersender_contact, sender_name, source_hint, text
create_companyCreate a companydescription, name, website
create_dealCreate a dealname, opportunity_uid, owner_uid, value
create_opportunityCreate an opportunitycategory, description, looking_for, name
create_personCreate a personcompany_uid, email, name, phone, title
create_taskCreate a taskassignee_uids, description, due_on, record_uids, title
discard_draftDiscard a draftdraft_uid
distribute_briefDistribute a briefbrief_uid, desk_uids
draft_deal_documentDraft an NCNDA or IMFPAdeal_uid, kind
draft_noteDraft a notenote, type, uid
move_deal_stageMove a deal's stagedeal_uid, event, lost_reason, note

Resources and prompts

Tools answer questions. Resources make a desk browsable, and the prompts are ours — written so the first thing somebody asks a connected model is worth asking.

Resources

inco://deskWhere the book stands — Counts, live briefs, open deals, offers awaiting review.
inco://intakeOffers awaiting review — Captured from email and WhatsApp, not yet confirmed or discarded.
inco://opportunity/{uid}One opportunity — Its fields, what it is linked to, its open tasks and its recent history.
inco://deal/{uid}One deal — Its fields, what it is linked to, its open tasks and its recent history.
inco://company/{uid}One company — Its fields, what it is linked to, its open tasks and its recent history.
inco://person/{uid}One person — Its fields, what it is linked to, its open tasks and its recent history.
inco://brief/{uid}One brief — Its fields, what it is linked to, its open tasks and its recent history.
inco://record/{uid}Any id — Resolves an id from a link to whatever it is on that desk. Ids from another desk resolve to nothing.

Every body is returned twice: text/markdown, then application/json at the same URI with .json appended.

What to try first

  • “What changed on my desk since yesterday?”
  • “Log this offer onto my book”
  • “Where does the Trafigura deal stand?”

Prompts

What changed on my deskmorning_digest

The morning read: what moved since you last looked, and the three things worth doing about it.

Log an offer onto the booklog_offer(offer)

Paste an offer as it arrived and put it in the desk's Inbox, extracted and checked for recycled cargo.

Where a deal standsdeal_status(deal_uid)

Economics, checklist and the next action on one deal.

Questions a review asks first

What can an AI app see?
Exactly what the person who connected it sees on their own screens, on the one desk they picked, and nothing from any other desk. A token is bound to (person, desk) at consent and cannot widen itself by refreshing.
Can it send a message to a counterparty?
No. Records — an opportunity, a deal, a contact — are created directly and come back with a link. Anything that would leave the desk is prepared as a draft and returns a URL where the broker reads it and presses send. That is structural, not a request in a prompt: there is no tool that dispatches.
What do you store about what an app did?
The shape of it: which tool, whether it worked, how long it took, and the one record id when a call concerned exactly one. Never the arguments and never the results — those carry cargo, counterparty and price. Those rows are deleted after 90 days.
How does a broker cut an app off?
Settings → AI apps, in Inco. Disconnect ends it at the next request rather than at the next login. Removing somebody from a desk, or suspending them on it, does the same to everything they had connected.
What happens to text a counterparty wrote?
It is delimited and labelled as quoted data wherever it reaches a model — brief summaries, enquiries, pasted offers, notes. We do not attempt to sanitise prose; the guarantee is that nothing sends without a person, so an instruction hidden in a cargo description cannot act on its own.
Which plans include it?
Desk and Desk Plus, and any trial. A free Network desk can complete the connection and will be offered no tools until the plan changes — the app is told why, so asking it returns the reason rather than a shrug.

Anything not answered here: support@incoapp.com. What we hold and for how long is in the privacy policy.