Connect an AI coding agent (MCP)
Tarkflo runs an MCP server at the same address as the REST API, so an AI coding agent building your integration can read the contract and make live calls without a separate install.
https://api.tarkflo.com/mcp
It takes the same API key as the REST API (see Authentication), sent the same way. There is nothing else to install: no package, no local process, no second key.
Add it to your agent
- Claude Code
- Claude Desktop
- Cursor
claude mcp add --transport http tarkflo https://api.tarkflo.com/mcp \
--header "Authorization: Bearer $TARKFLO_API_KEY"
Settings → Connectors → Add custom connector, or add this to your config file directly:
{
"mcpServers": {
"tarkflo": {
"url": "https://api.tarkflo.com/mcp",
"headers": { "Authorization": "Bearer tf_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" }
}
}
}
Settings → MCP → Add new MCP server, same JSON shape as Claude Desktop's config above.
As with any API key, read it from an environment variable rather than pasting it into a config file you might commit.
What it can do
Eight tools, each calling the exact same code the matching REST endpoint does:
| Tool | Same as | Needs |
|---|---|---|
list_jobs | List jobs | jobs:view |
get_job | Get a job | jobs:view |
get_job_stats | Get a job's counts | jobs:view |
list_workflows | List workflows | templates:view |
get_workflow | Get a workflow | templates:view |
list_templates | List templates | templates:view |
get_template | Get a template | templates:view |
submit_candidates | Submit candidates | candidates:create |
Plus one resource, tarkflo://openapi.yaml: the full OpenAPI contract, every endpoint, field and error code, for the agent to read instead of guessing a shape.
CV upload stays a REST call. Extract candidate details takes multipart file uploads, and an MCP tool call is JSON — sending CVs as base64 arguments would blow past the API's request size limit after a file or two. An agent building your integration calls that endpoint directly (it's in the openapi resource above); submit_candidates then takes the cv_id it returns.
A call outside a tool's permission answers the same forbidden shape REST does, naming the permission in required — see Authentication for the full scope table. Errors, rate limits and idempotency all work the same as REST, since it's the same server.
Why one tool call can be slower than the equivalent curl
The MCP connection is stateless: every call is its own request, with no session held open between them, so the agent reconnects for each tool call. For a one-off call this is not noticeable; if you're scripting many calls in a loop, REST directly is faster.