RoofKit MCP
Connect Cursor, Codex, or Claude Code to your RoofKit workspace with OAuth. Install, authorize, use tools, and revoke access.
Before you connect
RoofKit uses Model Context Protocol (MCP) to connect your desktop agent to your workspace. It is for signed-in workspace members. Your role, approved access, plan, and available credits still apply.
Review MCP Access
Sign in at https://app.roofkit.ai and select the workspace you want to connect. Open Settings, then MCP Access. New workspaces start with access on. An administrator who can manage integrations can turn access off.
Choose a connection
Direct MCP connects the tools without a plugin. A RoofKit plugin also adds workflow skills for setup, CRM, sites, reports, analytics, and automations. Both use https://api.roofkit.ai/mcp and require a separate OAuth approval. Choose one connection per client to avoid duplicate tools.
Use a current client release with HTTP MCP and static OAuth client ID support. If a command or setting below is unavailable, update the client first. These recipes do not certify a particular desktop version.
Cursor desktop
Merge this entry into ~/.cursor/mcp.json for personal use, or .cursor/mcp.json for this project. Preserve your other servers. Open Cursor MCP settings, connect roofkit, and complete the browser authorization. This recipe is for desktop, not Cursor web agents.
{
"mcpServers": {
"roofkit": {
"url": "https://api.roofkit.ai/mcp",
"auth": {
"CLIENT_ID": "roofkit-cursor"
}
}
}
}Codex
Run these commands in the Codex CLI. They add a remote server and start OAuth sign-in. If adding the server already completes sign-in, skip the login command. Restart your Codex session after connecting.
codex mcp add roofkit --url https://api.roofkit.ai/mcp --oauth-client-id roofkit-codex
codex mcp login roofkitClaude Code
Run the command below for a personal connection. Open Claude Code, run /mcp, select roofkit, and authenticate in the browser. Do not add --client-secret.
claude mcp add --transport http --scope user --client-id roofkit-claude roofkit https://api.roofkit.ai/mcpOptional pilot plugin
Ask your RoofKit pilot contact for the client-specific package or private installation source. Do not clone the private application repository. If you do not have a package, use the direct connection above. A public marketplace installation is not required.
- Cursor: place the supplied Cursor package in ~/.cursor/plugins/local/roofkit, then reload Cursor. Your organization must allow local plugin imports.
- Codex: open /plugins in the CLI, select the private marketplace supplied for the pilot, and install RoofKit. Start a new session. If no marketplace is supplied, use direct MCP.
- Claude Code: launch claude --plugin-dir /absolute/path/to/roofkit-claude with the supplied package folder. Replace the example path with your extracted folder.
A plugin does not grant workspace access. If its bundled connection cannot complete OAuth, disable that MCP connection and use the direct recipe with the fixed client ID. Keep only one active RoofKit connection.
What you can ask your agent to do
| Area | Example request | What stays in RoofKit |
|---|---|---|
| CRM | List my latest leads and pipeline stages. Show records from a Data Object. | Supported lead tools can create, update, and archive leads with your permission. Review changes before requesting them. |
| Sites | List my landing pages and create a draft for a new campaign. | Visual editing, publishing, and custom domain setup open the app. |
| Reports | Find a measurement report and summarize its available details. | Import, PDF export, approval, and geometry editing open the report editor. |
| Analytics | Show my campaigns, marketing spend, and custom report definitions. | Spend changes open the app. Do not assume every dashboard metric is exposed. |
| Automations | List my lead-table automations and help me find a run to retry. | Retries open the automation interface. Listing does not create or configure a routine. |
Long jobs and retries
If a tool returns job_id, keep that ID and ask the agent to check roofkit.jobs.get until the job finishes or fails. Use the returned result or artifact link. A queued job is not a completed result.
For a retry that accepts idempotency_key, reuse the original key. Do not repeat a create or credit-consuming operation to check its status. If the outcome is unclear, inspect the existing record or job first.
Revoke, update, or remove
In the connected workspace, open Settings → MCP Access. Find the client under Grants and select Revoke. Members can revoke their own grants. Administrators with integration management permission can revoke any workspace grant. Subsequent calls from that grant lose access.
Revoking a grant does not uninstall a plugin. Uninstalling or disabling a client does not replace grant revocation. Revoke first when you want to stop access. To reconnect, start OAuth authorization again.
For pilot plugin updates, use the replacement package or private marketplace supplied by RoofKit and restart the client. Remove the plugin through its plugin manager, or remove a local package you installed. For direct MCP, remove only the roofkit entry from Cursor or use the commands below.
codex mcp remove roofkit
claude mcp remove --scope user roofkitTroubleshooting
- Access unavailable: confirm pilot access and the workspace MCP Access switch with your administrator. Changing a local client setting cannot enable service access.
- OAuth or registration error: check the fixed client ID in the recipe, update your client, and start authorization from the client again. Do not substitute an API key.
- Missing or forbidden tools: confirm the selected workspace, approved permissions, current role, and plan. Ask your administrator about access. A plugin cannot expand your permissions.
- For other failures, give your RoofKit contact the client name, version, error code, and request_id if shown. Do not send tokens, API keys, callback URLs, or customer records.