# The Dienox MCP server.

> What the Dienox MCP server does, in plain words: which AI tools can connect, how sign-in works, what a tool may read and change, and what is recorded.

Source: https://dienox.com/mcp-server  
Last updated: 2026-10-01

The Dienox MCP server lets any AI tool that speaks MCP read and update an organisation's knowledge base in Dienox. A person adds it as a connector, signs in and picks an organisation. The tool can then search, read and write within that person's role, and every action leaves a trail.

## What it is.

The Dienox MCP server is how an AI tool reaches the knowledge base of an organisation on Dienox. It is one address:

`https://dienox.com/mcp`

The address is the same for everyone. Which organisation a tool reads is chosen when a person signs in, and that connection keeps it from then on. It is a remote MCP server: an AI tool reaches it over the internet, and there is nothing to install. In the Self-serve edition it is hosted by us, in the Netherlands.

MCP, the Model Context Protocol, is the open standard for connecting AI tools to data and systems. The [glossary](https://dienox.com/glossary#mcp) defines it in a few sentences, and the standard itself is published at [modelcontextprotocol.io](https://modelcontextprotocol.io/).

## Which AI tools can connect.

Any AI tool that speaks MCP. Dienox is used today from Claude, ChatGPT, Cursor, Windsurf and Gemini CLI, and from Microsoft Copilot through Copilot Studio. Claude Code and VS Code connect as well.

Each tool has its own word for what you add. Claude calls it a custom connector. ChatGPT calls it a custom app. Cursor calls it an MCP server. The steps per tool are on [connect your AI tools to your company knowledge](https://dienox.com/connect).

## How sign-in works.

1. A person adds the address in their AI tool. The tool sends them to Dienox.
2. They sign in with their own Dienox account and pick one organisation.
3. They click Allow. From then on, that tool works for that person, in that organisation.

The tool never sees the person's password. The access it gets lasts hours, not months, and can be revoked at any time. One connection is one person and one organisation.

A tool that supports it registers itself with Dienox at the first sign-in, so there is no key to request from us first. A tool that cannot sign in this way connects with a personal token instead. The person makes that token in Dienox, for one organisation, and it can be limited to reading.

## What a connected tool can do.

In plain words, a connected AI tool can:

- **Search the knowledge base.** By subject, or for an exact phrase.
- **Read a page.** The whole page, or the one part the question needs.
- **List what exists.** So it knows where to look before it answers.
- **See what changed.** What was changed, when and by whom.
- **Write back what was decided.** A decision, a number, who owns what. Or correct a fact that is wrong.
- **Ask an assistant.** One the organisation switched on, which answers by name.
- **Create an agent.** For a recurring stream of work, with only the actions that were switched on for it.

Every action has one of three levels. The level decides whether a person is asked first.

Table: What a connected tool can do, by level

|  | What it covers | Is a person asked first? |
| --- | --- | --- |
| **Read** | Searching the knowledge base, reading a page, listing what exists, seeing what changed. | No. Reading changes nothing, and every role may read. |
| **Write** | Writing back what was decided, correcting a fact. | No, when the person is an administrator or an editor. The change is recorded under their name and can be undone. |
| **Irreversible** | An action on a connected system that cannot be taken back, such as mailing the board or making a payment. | Yes. It waits in Dienox for a person with the right role, or it is switched off. |

## What it cannot do.

- **Nothing outside the person's role.** Administrator, editor or reader. A reader's tool reads, and cannot write.
- **Nothing in another organisation.** A connection belongs to one organisation. It cannot see or reach another, whoever asks.
- **No action that is switched off.** An action that is off is not in the toolbox, so it cannot be called, however the tool is asked.
- **Nothing irreversible by itself.** An irreversible action waits for a person, and an approval counts once.

That is "cannot", not "will not". [AI agents that cannot do what you did not allow](https://dienox.com/agents-with-limits) explains the difference, and the home page lists every control in [its security section](https://dienox.com#security). There is also a limit on how fast a tool may call. A runaway tool meets a clear error.

## What is recorded.

Every call a connected tool makes is recorded: which action, when, for which person and for which organisation. Every write is recorded under the person's name and kept in the history of the knowledge base. It can be undone.

So an organisation can always see what was read and what was changed, and by whom. And a person can always check an answer, because the tool names the source it used.

## Where the data lives.

In the Self-serve edition, the knowledge base lives in the Dienox cloud, which is hosted in the Netherlands. In the Enterprise edition, the same platform runs in the organisation's own environment: its own server, its Azure or its AWS. The knowledge does not leave it.

Either way the knowledge base belongs to the organisation, with its full history, and the organisation can take all of it with it. The [privacy policy](https://dienox.com/privacy), the [data processing agreement](https://dienox.com/data-processing-agreement) and the page on [security and responsible disclosure](https://dienox.com/security) give the details.

## Support.

Questions about connecting a tool go to [support@dienox.com](mailto:support@dienox.com). A vulnerability goes to [security@dienox.com](mailto:security@dienox.com), and the security page says what we promise in return.

Dienox is in beta. To connect an AI tool, your organisation needs a place on Dienox first: [join the beta](https://dienox.com/beta).

## Questions people ask.

### What is the Dienox MCP server?

The Dienox MCP server is the address an AI tool connects to in order to read and update an organisation's knowledge base in Dienox. A person adds it as a connector, signs in and picks an organisation. The tool then works within that person's role, and every action leaves a trail.

### Which AI tools work with it?

Any AI tool that speaks MCP, the open standard for connecting AI tools to data and systems. Dienox is used today from Claude, ChatGPT, Cursor, Windsurf and Gemini CLI, and from Microsoft Copilot through Copilot Studio. Claude Code and VS Code connect as well. If a tool speaks the protocol, it can read your knowledge base.

### How does a person sign in?

The person adds the address in their AI tool, and the tool sends them to Dienox. There they sign in with their own account, pick one organisation and click Allow. The tool never sees their password. One connection belongs to one person and one organisation, and its access can be revoked at any time.

### Can it change our knowledge base?

Yes, within the role of the person it works for. The tool of an administrator or an editor can write back what was decided or correct a fact. A reader's tool can only read. Every change is recorded under that person's name, kept in the history of the knowledge base, and can be undone.

### Can it see another organisation?

No. Every organisation has its own knowledge base, kept apart from every other. A connection from an AI tool belongs to one organisation, the one the person picked at sign-in. It cannot see or reach another, whoever asks and however the question is phrased. Nothing crosses from one organisation to another.

### What is a remote MCP server?

A remote MCP server is one that an AI tool reaches over the internet, at an address. Nothing runs on your own computer, so there is nothing to install: you add the address in the AI tool and sign in. The Dienox MCP server is remote. In the Self-serve edition it is hosted in the Netherlands.

### Knowledge base or MCP server: what is the difference?

A knowledge base is what your organisation knows, kept in one place. An MCP server is the door an AI tool uses to reach it. One without the other falls short: a knowledge base that no AI tool can reach is read by people only, and an MCP server needs your knowledge behind it. Dienox is both.

### Is there anything to install?

No. An AI tool reaches the server over the internet, at one address. There is no program to download and no extension to add. A person adds the address in their AI tool and signs in. It takes about a minute per person, and the next tool they connect reads the same knowledge base.

Sources

- [What is the Model Context Protocol?](https://modelcontextprotocol.io/)

The beta is open

Be one of the first organisations on Dienox.

We let organisations in a few at a time, so each one gets our full attention. Sign up in two minutes, and we come back to you within two working days.

[Join the beta](https://dienox.com/beta)
