Connect an assistant
Desk is one OAuth-protected policy desk for ChatGPT, Claude, Gemini, Grok, Cursor, and any other MCP client that speaks Streamable HTTP. Support tools require your Desk account with Pro or an active 14-day trial. Billing stays in the workspace. No assistant can change your plan, and Desk does not print a price.
Shared connection
MCP address:
https://desk-mcp-continuity2.vercel.app/mcp
Transport: Streamable HTTP. Sign in with your own Desk account when the assistant opens OAuth. Do not paste an API key, access token, or password into a header or chat. Revoke a host at any time from connected applications.
- Sign in to the workspace and open or create a desk you will recognize by name.
- Add the MCP address in your assistant using the steps below. Choose dynamic registration / OAuth when the host asks how to authenticate.
- Approve Desk, then ask the assistant to look up the approved answer before it replies. It must refuse a refund, feature, or timeline that is not approved.
1. ChatGPT and Codex
Connect Desk as a custom app. A public directory listing is not required.
- On workspace plans, an admin enables developer mode under Workspace settings, then Permissions and roles, then Connected data developer mode or Create custom MCP connectors. Personal accounts that already offer custom apps can skip that toggle.
- Open Apps, then Create. Workspace admins use Workspace settings, Apps, Create. Other authorized users use Settings, Apps, Create.
- Enter the MCP address, choose OAuth, scan tools, and approve the Desk sign-in.
- Enable the app in the conversation. Developer-mode apps are labeled Dev and are not OpenAI-verified.
Codex can use this same MCP address. Request offline_access when the host offers refresh. Desk’s authorization server advertises that scope.
2. Claude
Claude.ai, Claude Desktop, Cowork, and the mobile apps use a remote connector. Claude’s servers call Desk. You do not install a local plugin.
- Free, Pro, and Max: Customize, Connectors, Add custom connector. Team and Enterprise: an owner adds it under Organization settings, Connectors, Add, Custom, Web. Each member then chooses Connect.
- Name it Desk and paste the MCP address.
- Choose sign-in (OAuth). For the OAuth client, choose Register automatically (dynamic client registration). Leave client id and secret empty. Do not put a token in request headers.
- Approve Desk in the browser, then turn the connector on from the chat plus menu, Connectors.
Claude Code, from a terminal:
claude mcp add --transport http desk https://desk-mcp-continuity2.vercel.app/mcp
Do not pass --header Authorization. Claude Code opens the same OAuth flow. In a JSON config, set "type": "http" next to url.
3. Gemini
Gemini Apps
Google’s Gemini Apps can add an MCP server URL in the Gemini web app. Google requires you to be 18 or older, in the US, signed in with a personal Google Account, with Keep Activity on. Work and school accounts cannot use this path. Custom apps are English-only. Connect on the web. The link then works in the Gemini mobile app too.
- On a computer, open gemini.google.com, Settings, Connected apps. If you do not see Connected apps, open Personal Intelligence, then Connected apps.
- Under Custom apps, add a custom app and paste the MCP address.
- Leave advanced credentials empty. Desk supports dynamic client registration, so a client id is not required.
- Finish Google’s sign-in, then type
@and choose Desk when you want that chat to use it.
Gemini CLI
gemini mcp add --transport http --scope user desk https://desk-mcp-continuity2.vercel.app/mcp
That writes ~/.gemini/settings.json. Do not set an Authorization header. If the CLI reports a missing issuer (iss) on the callback, Google is enforcing RFC 9207 and the authorization server did not return that parameter. Desk cannot add it from this app. Use Gemini Apps, or another host, until that redirect includes iss.
Not available yet
- Gemini API, including Gemini 3 in the Interactions API. Google’s Interactions API docs say Gemini 3 does not support remote MCP yet. There is no Desk function-calling schema to paste into AI Studio. Do not paste a Desk access token into a managed-agent tool.
- Gemini Enterprise custom MCP. The admin form requires a client id and secret for an OAuth app whose redirect URL is
https://vertexaisearch.cloud.google.com/oauth-redirect. Desk does not publish that client. The public authorization and token URLs are on the Supabase issuer advertised at/.well-known/oauth-protected-resource/mcp. The scopes areemailandoffline_access. An owner has to register the Enterprise client in Supabase before that form can be saved.
4. Grok
Grok on the web
- Open grok.com/connectors.
- Choose New connector, then Custom.
- Paste the MCP address and finish the sign-in Grok presents.
On Grok Business and Enterprise, an admin provisions connectors before members can use them. The server must be reachable on the public internet. Grok discovers the tools after you connect.
Grok Build
grok mcp add --transport http desk https://desk-mcp-continuity2.vercel.app/mcp
OAuth runs in the browser on first use. The equivalent user config is:
[mcp_servers.desk]
url = "https://desk-mcp-continuity2.vercel.app/mcp"
in ~/.grok/config.toml. Do not set an Authorization header. In the Grok Build UI, /mcps then i starts sign-in.
xAI API
The xAI API remote-MCP tool accepts a static bearer token. Desk does not issue API keys or long-lived tokens for that field. Use grok.com or Grok Build, which perform OAuth, instead of pasting a session token into an API request.
5. Cursor and other MCP clients
Cursor speaks remote Streamable HTTP with OAuth. In ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project):
{
"mcpServers": {
"desk": {
"url": "https://desk-mcp-continuity2.vercel.app/mcp"
}
}
}
Do not add headers or a static client id. Cursor registers a client and opens sign-in. Restart Cursor or enable the server under Customize, MCPs.
Any other MCP client uses the same address when it supports Streamable HTTP, OAuth 2.0 with PKCE, and dynamic client registration (RFC 7591). An unauthenticated call returns 401 with a WWW-Authenticate challenge pointing at /.well-known/oauth-protected-resource/mcp. Ask for the email scope. Add offline_access when the client can refresh tokens. Clients that call from their own servers should not send a browser Origin. Browser calls are accepted only from Desk and the assistant sites listed in the server allowlist.
After it connects
“Use Desk on [desk name]. Look up the approved answer before you reply. Do not promise a refund, a feature, or a timeline unless Desk approves that exact wording.”
Approved answers are replies the team has saved. Refund rules name a situation and the only wording allowed. Escalation limits say which channel may promise anything, and how far a case may move. Commitments are the only feature statements and timelines an assistant may repeat.
The assistant calls tools only when you and the host allow it. Disconnecting an application stops future access. It does not delete the desk or cancel billing.