RoofKit MCP

Connect Cursor, Codex, or Claude Code to your RoofKit workspace with OAuth. Install, authorize, use tools, and revoke access.

Before you connect

RoofKit uses Model Context Protocol (MCP) to connect your desktop agent to your workspace. It is for signed-in workspace members. Your role, approved access, plan, and available credits still apply.

Review MCP Access

Sign in at https://app.roofkit.ai and select the workspace you want to connect. Open Settings, then MCP Access. New workspaces start with access on. An administrator who can manage integrations can turn access off.

Choose a connection

Direct MCP connects the tools without a plugin. A RoofKit plugin also adds workflow skills for setup, CRM, sites, reports, analytics, and automations. Both use https://api.roofkit.ai/mcp and require a separate OAuth approval. Choose one connection per client to avoid duplicate tools.

Use a current client release with HTTP MCP and static OAuth client ID support. If a command or setting below is unavailable, update the client first. These recipes do not certify a particular desktop version.

Cursor desktop

Merge this entry into ~/.cursor/mcp.json for personal use, or .cursor/mcp.json for this project. Preserve your other servers. Open Cursor MCP settings, connect roofkit, and complete the browser authorization. This recipe is for desktop, not Cursor web agents.

Cursor MCP configuration
{
  "mcpServers": {
    "roofkit": {
      "url": "https://api.roofkit.ai/mcp",
      "auth": {
        "CLIENT_ID": "roofkit-cursor"
      }
    }
  }
}

Codex

Run these commands in the Codex CLI. They add a remote server and start OAuth sign-in. If adding the server already completes sign-in, skip the login command. Restart your Codex session after connecting.

Codex CLI commands
codex mcp add roofkit --url https://api.roofkit.ai/mcp --oauth-client-id roofkit-codex
codex mcp login roofkit

Claude Code

Run the command below for a personal connection. Open Claude Code, run /mcp, select roofkit, and authenticate in the browser. Do not add --client-secret.

Claude Code command
claude mcp add --transport http --scope user --client-id roofkit-claude roofkit https://api.roofkit.ai/mcp

Optional pilot plugin

Ask your RoofKit pilot contact for the client-specific package or private installation source. Do not clone the private application repository. If you do not have a package, use the direct connection above. A public marketplace installation is not required.

  • Cursor: place the supplied Cursor package in ~/.cursor/plugins/local/roofkit, then reload Cursor. Your organization must allow local plugin imports.
  • Codex: open /plugins in the CLI, select the private marketplace supplied for the pilot, and install RoofKit. Start a new session. If no marketplace is supplied, use direct MCP.
  • Claude Code: launch claude --plugin-dir /absolute/path/to/roofkit-claude with the supplied package folder. Replace the example path with your extracted folder.

A plugin does not grant workspace access. If its bundled connection cannot complete OAuth, disable that MCP connection and use the direct recipe with the fixed client ID. Keep only one active RoofKit connection.

Authorize and verify your workspace

  • Start authorization from the client. It opens a consent page on https://app.roofkit.ai. Sign in with your own RoofKit account. Do not open an empty consent URL manually or share the callback URL.
  • Verify the workspace shown on the consent screen and review the requested permissions. If the workspace is wrong, select the intended workspace in the RoofKit app and restart authorization from your client. Approve access, then return to the client.
  • Ask: “Show the company profile for my connected RoofKit workspace.” Confirm the company before requesting changes. This uses roofkit.workspace.profile.get and does not modify data.
  • Each authorization belongs to one user and one workspace. Changing the workspace in the RoofKit app does not move an existing connection. To switch, revoke the old grant and authorize again for the intended workspace.

What you can ask your agent to do

AreaExample requestWhat stays in RoofKit
CRMList my latest leads and pipeline stages. Show records from a Data Object.Supported lead tools can create, update, and archive leads with your permission. Review changes before requesting them.
SitesList my landing pages and create a draft for a new campaign.Visual editing, publishing, and custom domain setup open the app.
ReportsFind a measurement report and summarize its available details.Import, PDF export, approval, and geometry editing open the report editor.
AnalyticsShow my campaigns, marketing spend, and custom report definitions.Spend changes open the app. Do not assume every dashboard metric is exposed.
AutomationsList my lead-table automations and help me find a run to retry.Retries open the automation interface. Listing does not create or configure a routine.

Long jobs and retries

If a tool returns job_id, keep that ID and ask the agent to check roofkit.jobs.get until the job finishes or fails. Use the returned result or artifact link. A queued job is not a completed result.

For a retry that accepts idempotency_key, reuse the original key. Do not repeat a create or credit-consuming operation to check its status. If the outcome is unclear, inspect the existing record or job first.

Revoke, update, or remove

In the connected workspace, open Settings → MCP Access. Find the client under Grants and select Revoke. Members can revoke their own grants. Administrators with integration management permission can revoke any workspace grant. Subsequent calls from that grant lose access.

Revoking a grant does not uninstall a plugin. Uninstalling or disabling a client does not replace grant revocation. Revoke first when you want to stop access. To reconnect, start OAuth authorization again.

For pilot plugin updates, use the replacement package or private marketplace supplied by RoofKit and restart the client. Remove the plugin through its plugin manager, or remove a local package you installed. For direct MCP, remove only the roofkit entry from Cursor or use the commands below.

Remove a direct connection
codex mcp remove roofkit
claude mcp remove --scope user roofkit

Troubleshooting

  • Access unavailable: confirm pilot access and the workspace MCP Access switch with your administrator. Changing a local client setting cannot enable service access.
  • OAuth or registration error: check the fixed client ID in the recipe, update your client, and start authorization from the client again. Do not substitute an API key.
  • Missing or forbidden tools: confirm the selected workspace, approved permissions, current role, and plan. Ask your administrator about access. A plugin cannot expand your permissions.
  • For other failures, give your RoofKit contact the client name, version, error code, and request_id if shown. Do not send tokens, API keys, callback URLs, or customer records.

Client documentation