Skip to content
LarkFlow.io home
Start 7-Day Free Trial

Connect MCP servers

Give LarkFlow’s AI agents read-only access to catalogue, price and stock data that lives in another system — a supplier catalogue, a PIM, an in-house inventory service — through the Model Context Protocol.

What it does

An MCP server exposes tools — functions another application can call. LarkFlow connects to your server from its own backend, lists its tools, and lets you decide which lookup tools each AI agent may use. Today the RFQ agent uses them: when a request mentions a product that isn’t in your LarkFlow catalogue, it can look it up on your server.

Note: MCP data is only ever used to propose a match and a price. A person always reviews the RFQ, and any quotation that uses MCP data needs approval before it can be sent. MCP tools can’t approve quotes, change final prices or message customers.

Before you start

  • You need to be a workspace owner or admin.
  • MCP integrations are in early access. If the page says they’re turned off, ask LarkFlow support to enable them.
  • The server must support the Streamable HTTP transport and be reachable on a public https:// address. Local, private-network and http:// addresses are refused.
  • Have the server’s MCP endpoint URL (often ending in /mcp) and, if it needs one, an API key — or be ready to sign in if it uses OAuth.
  • If an ERP is connected in LarkFlow, RFQ matching uses the ERP only; MCP lookups are used when no ERP is connected.

Settings lists these official servers with their address and sign-in method filled in. Click Use this, follow the setup notes, then connect.

ServerAddressWhat LarkFlow can use today
HubSpothttps://mcp.hubspot.comEnable search_crm_objects for the RFQ agent and fix objectType to "products".
Zapierhttps://mcp.zapier.com/api/v1/connectIn Zapier MCP, add a lookup action (e.g. Google Sheets “Lookup spreadsheet row”) for your price list, then enable it here and fix its spreadsheet inputs.
Notionhttps://mcp.notion.com/mcpUseful for RFQ lookups only if your products are a Notion database with SKU and name properties. You choose which pages to share when you sign in.
Stripehttps://mcp.stripe.comStripe’s tools read the API by method name rather than searching, so none can be enabled for RFQ lookups yet.
Squarehttps://mcp.squareup.com/mcpSquare exposes one general API tool that can also make changes, so LarkFlow won’t enable it for lookups.
Tip: Many tools need more than a search phrase — HubSpot’s search_crm_objects needs an object type, a spreadsheet lookup needs the sheet. Set those under Fixed inputs next to the tool; LarkFlow sends the same values on every lookup.

1. Connect a server

  1. Step 1: Open the page

    Go to Admin → MCP Servers (Settings → Integrations → MCP Servers).

  2. Step 2: Enter the server details

    Under Connect a server, give it a name your team will recognise and paste the endpoint URL.

  3. Step 3: Choose authentication

    • None — for servers that don’t need credentials.
    • API key / access token — sent as Authorization: Bearer …, or in a header you name. It’s stored encrypted and can’t be viewed again, only replaced.
    • OAuth — after you click Connect you’re sent to the server to sign in and approve access, then brought back. Some providers (HubSpot) need an OAuth app created on their side first; enter its client ID and secret.
  4. Step 4: Connect

    LarkFlow connects and lists the server’s tools. The status shows Connected when it worked, or the error if it didn’t.

2. Choose which agent may use which tool

Each tool is listed with a checkbox per agent. Nothing is enabled until you tick it and click Save permissions.

  • Only lookups can be enabled. Tools whose names describe an action — create, update, delete, send, approve, order and similar — are locked, whatever the server says about them.
  • Tools the server marks Read-only can be enabled directly. For a tool that isn’t marked, you must tick I confirm this tool only reads data.
  • Pick the Search argument — the tool input that should receive the product description. If the tool requires other inputs, fill them in under Fixed inputs (plain text, numbers or a choice from the tool’s list).
  • If the server later changes a tool so it no longer qualifies, LarkFlow stops calling it and logs the call as denied.

3. Test a lookup

Click Try next to a tool, enter a product description and Run lookup. You’ll see the products LarkFlow could read from the response, or why none were found. Test calls appear in Recent tool calls as agent admin_test.

How RFQs use MCP data

  1. Step 1: Matching

    For each requested line, the RFQ agent searches your LarkFlow catalogue and the MCP tools you granted it. LarkFlow scores every result with its own matching — scores or rankings from the server are ignored — and a catalogue product always wins over an MCP result with the same SKU.

  2. Step 2: Review

    If a line is matched to MCP data, the line is flagged and the whole RFQ waits for your team: LarkFlow doesn’t generate or send a quote on its own. The line shows External data from … with the server, tool, time, price and stock it saw.

  3. Step 3: Quotation

    When your team generates the quote, the MCP price is used as a proposal and recorded with its source and time. The quote always requires approval before it can be sent, and it is never sent automatically.

Response format

LarkFlow reads products from the tool’s structured content, or from JSON in its text output — an array of objects, or an object holding one:

[
  { "sku": "NG-BLU-M", "name": "Nitrile Gloves Blue M", "price": 12.5, "currency": "USD", "stock": 900 }
]

Common alternatives are recognised (for example code or id for the SKU, title for the name, unit_price, available). Each result needs a SKU and a name; price, currency and stock are optional. Plain prose is ignored.

Safety and limits

  • All calls run on LarkFlow’s servers; credentials and tokens never reach the browser.
  • Each call must finish within 15 seconds and return at most 512 KB. At most 20 products per call are read, and text fields are shortened and cleaned.
  • Tool output is treated as untrusted data. It is never given to an AI model as instructions.
  • Every call is logged with the workspace, agent, tool, result and duration, and kept after a server is disconnected.
  • Up to 10 servers per workspace; up to 3 tools are consulted for each RFQ line.

Troubleshooting

StatusMeaningWhat to do
ConnectedLarkFlow reached the server and read its tool list.—
Needs authorizationThe server uses OAuth and hasn’t been approved yet, or its approval expired.Click Authorize and sign in to the server.
ErrorThe last connection or call failed. The message under the server says why.Fix the cause, then click Test connection.
  • “That host is not reachable from LarkFlow” / “resolves to a private address” — the URL points at a local or internal network. Use the server’s public https endpoint.
  • A tool is locked — its name looks like an action, it’s marked destructive, or it needs inputs LarkFlow can’t supply. Ask the server’s provider for a read-only search tool.
  • “No products could be read” — the response isn’t JSON with SKU and name fields. See Response format.
  • Calls time out — the server took longer than 15 seconds. Check its health, or narrow the tool’s search.

Use LarkFlow from Claude, Cursor and other AI tools

The other direction: LarkFlow is also an MCP server, so an AI assistant you already use can look up your contacts, conversations, leads and products.

  1. Step 1: Create a key

    Go to Settings → Connect AI assistants and create an API key (needs a plan with API access). Copy it — it’s shown once.
  2. Step 2: Add LarkFlow to your client

    Add the server URL https://<your LarkFlow API>/api/v1/mcp to your client with the header Authorization: Bearer <key>. The page has ready-to-paste setup for Claude Code, Claude Desktop and JSON-config clients like Cursor.
  3. Step 3: Ask

    Ask things like “Which WhatsApp conversations are unread?” or “What’s the price of SKU NG-BLU-M?”.
  • Read-only: tools are search_contacts, get_contact, list_conversations, get_conversation_messages, list_leads and search_products. Nothing can be sent, changed or deleted.
  • A key only sees its own workspace. Product costs and internal notes are never returned.
  • Customer messages are marked as untrusted text so the assistant treats them as data, not instructions.
  • At most 50 rows per call (100 messages), 60 requests a minute. Revoking a key or downgrading the plan cuts access straight away.
Note: Claude.ai web connectors sign in with OAuth, which isn’t offered yet. Use Claude Code, Claude Desktop or another client that accepts a header.

Stuck? Email hello@bytelark.net or book a setup call.