Scalekit MCP Server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_environmentsA | List all available environments in the workspace. Supports pagination via pageToken (a 1-based page number e.g. 1, 2, 3). Returns environment id, display name, type (PRD/DEV), domain, custom domain and status. Show the response in tabular structured manner. After fetching each page, ask if it should pull the next page. |
| get_environment_detailsB | Get the environment details by ID (e.g. env_123). After providing details of environment details, the client can prompt to invoke list-organizations tool to list all organizations under the selected environment. |
| get_environment_credentialsA | Get API credentials for a Scalekit environment. Returns SCALEKIT_ENVIRONMENT_URL, SCALEKIT_CLIENT_ID, and active secret info formatted as a .env block. The client secret is not available via API — the tool will tell the user where to find it in the dashboard. |
| list_environment_rolesA | List all roles in the specified environment. Requires environmentId parameter (format: env_). Show the response in tabular structured manner. |
| create_environment_roleC | Create a new role in the specified environment. Requires environmentId parameter (format: env_). The tool requires 4 parameters: roleName (name of the new role), displayName (name that will be displayed on dashboard), description (description of the role) and isDefault (boolean to indicate if the role is default or not). |
| create_environment_scopeC | Create a new scope in the specified environment. Requires environmentId parameter (format: env_). The tool requires 2 parameters: scopeName (name of the new scope) and description (description of the scope). |
| list_environment_scopesA | List all scopes in the specified environment. Requires environmentId parameter (format: env_). Show the response in tabular structured manner. |
| list_redirect_urisA | List allowed callback URLs (redirect URIs) for the specified environment. Requires environmentId (format: env_). Show the response in a structured list. |
| add_redirect_uriA | Add a callback URL to the allowed redirect URIs list for an environment. Requires environmentId (format: env_) and uri (the callback URL to add). |
| remove_redirect_uriA | Remove a callback URL from the allowed redirect URIs list for an environment. Requires environmentId (format: env_) and uri (the callback URL to remove). |
| set_initiate_login_uriA | Set the initiate login URI for an environment. This is the endpoint in your app that redirects to Scalekit's /authorize endpoint — required to handle login scenarios not initiated from your app (IdP-initiated SSO). Requires environmentId (format: env_) and uri (the full URL of your login initiation endpoint). |
| remove_initiate_login_uriA | Remove (clear) the initiate login URI for an environment. Requires environmentId (format: env_). |
| add_post_logout_redirect_uriB | Add a URL to the post-logout redirect URIs list for an environment. After a user logs out, they are redirected to one of these URLs. Requires environmentId (format: env_) and uri (the URL to add). |
| remove_post_logout_redirect_uriA | Remove a URL from the post-logout redirect URIs list for an environment. Requires environmentId (format: env_) and uri (the URL to remove). |
| create_organizationB | Create a new organization under the specified environment. Requires environmentId parameter (format: env_). |
| list_organizationsB | List all organizations under the specified environment. Requires environmentId parameter (format: env_). The tool requires 1 parameter: pageToken (received from response). Show the response in tabular structured manner. After fetching each page, client should ask if it should pull next page or not. |
| get_organization_detailsB | Get the details of an organization by ID (e.g. org_123). Requires environmentId parameter (format: env_). After providing details of organization details, the client can prompt to invoke list-members tool to list all members under the selected organization. |
| generate_admin_portal_linkB | Generate a link to the admin portal for the selected organization. Requires environmentId parameter (format: env_). The tool requires organization id to be passed (e.g. org_123). This link is also called admin portal magic link. |
| create_organization_userA | Create a new user in the selected organization. Requires environmentId parameter (format: env_). It needs the following parameters: organizationId, email, role (role name). The role can be fetched by using list_environment_roles tool. |
| list_organization_usersC | List all users in the selected organization. Requires environmentId parameter (format: env_). It needs the following parameters: organizationId, pageToken. Show the response in tabular structured manner. After fetching each page, client should ask if it should pull next page or not. |
| update_organization_settingsC | Update the settings of an organization. Requires environmentId parameter (format: env_). It needs the following parameters: organizationId, feature (valid json key-value pair array) {[{"name":"dir_sync","enabled":true}]}. |
| list_workspace_membersA | List all members in the current workspace. The tool requires 1 parameters: pageToken (1-based index). Show the response in tabular structured manner. After fetching each page, client should ask if it should pull next page or not. |
| invite_workspace_memberB | Invite a new member in the current workspace. The tool requires 1 parameter: email (email of the new member). |
| list_environment_connectionsA | List all connection for the specified environment. Requires environmentId parameter (format: env_). |
| list_connected_accountsA | List users (connected accounts) who have authorized with connectors in the given environment. Filter by connector type (e.g. "HUBSPOT") or specific connection ID. Returns accounts grouped by connector showing identifier, status, and auth details. |
| search_connectorsA | Search the connector catalog (e.g. Google, Notion, Slack) for the given environment. Returns matching connectors with their identifier, category, and type. When includeSetupStatus is true, each result is annotated with whether the connector has been set up in the environment. |
| create_connected_account_magic_linkA | Create a magic link to connect an OAuth connector account (e.g. Notion, Gmail) at the environment level. Requires environmentId (format: env_), identifier (a friendly name), and connector (e.g. "notion"). Returns link and expiry. |
| list_organization_connectionsB | List all connection for the selected organization. Requires environmentId parameter (format: env_). The tool also requires organization id to be passed (e.g. org_123) |
| enable_environment_connectionC | Enable an existing connection for the specified environment. Requires environmentId parameter (format: env_). This tool requires the following parameters:
|
| list_mcp_serversA | List all MCP servers in the specified environment. Requires environmentId parameter (format: env_). It needs pageToken parameter for showing further pages. Show the response in tabular structured manner. Always ask the client if it should pull next page or not. |
| register_mcp_serverA | Register a new MCP server in the specified environment. Requires environmentId parameter (format: env_). It needs the following parameters: name, description, url, access_token_expiry (in seconds), provider (the unique key_id which the customer has setup for connection - this is needed only when use_scalekit_authentication is chosen to be false), use_scalekit_authentication (this is a flag to indicate if the mcp server will be using scalekit authentication solution). The url that you provide will be made available in audience of token. The tool returns resource metadata of the registered MCP server. Show in a structured JSON format for resource metadata and prompt the user to make sure this resource metadata json is published on their mcp server with endpoint /.well-known/oauth-protected-resource. |
| update_mcp_serverB | Update an existing MCP server in the specified environment. Requires environmentId parameter (format: env_). It needs the following parameters: id (id of the MCP server), name (optional), description (optional), url(optional), access_token_expiry (optional) (in seconds), provider (the unique key_id which the customer has setup for connection and should be in capital letters - this is needed only when use_scalekit_authentication is chosen to be false), use_scalekit_authentication (this is a flag to indicate if the mcp server will be using scalekit authentication solution). The url that you provide will be made available in audience of token. |
| switch_mcp_auth_to_scalekitB | Switch the authentication of an existing MCP server to Scalekit authentication. Requires environmentId parameter (format: env_). It needs the following parameters: id (id of the MCP server). The tool will update the MCP server to use Scalekit authentication solution. |
| search_toolsA | Search available tools (actions) exposed by connectors in the given environment. Filter by connector name (e.g. "HUBSPOT") or search by action (e.g. "search contacts"). Returns tools grouped by connector. Set summary=false for full tool definitions including input schemas. Output schemas are not available — refer to the connector's official API documentation for response structures. |
| search_docsA | Search Scalekit documentation by keyword. Prefer reading docs:// resources directly — use this tool only when no specific docs:// resource clearly covers the topic. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| docs-index | Start here: maps all Scalekit docs — read to find which resource covers your question |
| docs-full-stack-auth | Implement full-stack auth: user login, sessions, RBAC, and access control for web apps |
| docs-agent-auth | Authenticate AI agents: OAuth token vault, connect to APIs, secure tool calling |
| docs-mcp-auth | Add auth to your MCP server, secure remote MCP, OAuth 2.1 and Dynamic Client Registration |
| docs-sso-scim | Set up enterprise SSO (SAML/OIDC) and SCIM directory sync for B2B customers |
| docs-quickstart | Get started with Scalekit: quickstart guides and initial setup |
| docs-api-sdk | API reference, SDK methods for Node/Python/Go/Java, and webhook event docs |
| docs-integrations | Connect identity providers: step-by-step guides for Okta, Google, Microsoft, and more |
| docs-m2m-auth | M2M auth: client credentials flow, API key management, service-to-service auth |
TDQS
Scored across 35 tools
Most tools map cleanly to distinct resource+action pairs (e.g., list_environment_roles vs list_environment_scopes). A few pairs are easy to confuse, particularly list_environment_connections vs list_organization_connections, and update_mcp_server vs switch_mcp_auth_to_scalekit both touch Scalekit auth.
Tool names overwhelmingly follow a consistent verb_noun pattern in snake_case (list_*, create_*, update_*, remove_*, add_*, set_*, get_*). The few action verbs like switch_, generate_, enable_, and search_ still read predictably and don't break the convention.
35 tools is well above the 25+ threshold and feels heavy for a single server. Many operations are granular (e.g., separate add/remove/list tools for each URI type) and could be consolidated without losing clarity.
The surface covers environments, organizations, roles, scopes, connections, and MCP servers broadly, but lifecycle coverage is uneven: roles and scopes are create/list only, MCP servers have no delete, and there is no list for initiate login or post-logout URIs. These gaps are noticeable but agents can often work around them.