Skip to main content
Telara

Platform / MCP Configuration

MCP Configuration

The foundational building block that defines what data your AI agent can access, what actions it can take, and who can use it. Create one in minutes.

Data Sources
Search Tools
Permission Policies
Deployments
API Keys

Your Agent's Settings

What it is

A configuration bundles everything your AI agent needs into a single, manageable unit. It has four components: data sources, permission policies, deployments, and API keys.

Think of it as a permissions profile for your AI. You decide exactly what it can see, what it can do, and who gets access -- all in one place.

Configuration: "engineering-readwrite"
Data Sources
GitHub: repos [backend, frontend]Jira: project [PLATFORM]Slack: channels [#eng]
Permission Policies
github-readonly-policyjira-readwrite-policy
Deployments
team: engineering (default)user: luis (override)
API Keys
telara_mcp_... "luis-claude-code"
Zero-setup connection

Every new Telara organization comes with a default connection pre-configured. When your team members run telara login for the first time, their coding tools are automatically connected — no manual configuration needed. As an admin, you can add data sources and permissions at any time and they take effect immediately for all connected users.

Quick Start

Custom configurations

Beyond the default connection, you can create custom configurations to give different teams or projects specific data access and permissions. Set one up in four steps.

01
Create a configuration

Go to Capabilities > Configurations and click "Create Configuration." Give it a name that reflects its purpose -- for example, "engineering-readonly" or "support-team-full-access."

02
Add data sources

Select the integrations your agent should have access to. Choose specific repositories, projects, or channels -- or include everything from an integration. Your agent only sees what you explicitly allow.

03
Deploy to a scope

Assign the configuration to your organization, a specific team, or an individual user. This controls who can connect to this configuration from their IDE or other tools.

04
Generate an API key

Create an API key and add it to your tool settings (Claude Code, Cursor, etc.). The key is shown once at creation -- copy it immediately.

Data Access

Data sources

Data sources define what content your agent can search through in your knowledge base. Every integration you have connected to Telara can be added as a data source. You control the scope down to individual repositories, projects, or channels.

How It Works
GitHub -- add specific repositories or include all repos from a connection. Filter to just your backend, frontend, or infrastructure repos.
Jira -- select specific projects. Your agent can search issues, epics, and comments from only the projects you choose.
Slack -- pick specific channels. Keep sensitive channels out while giving access to engineering discussions.
Selection Modes
All -- include everything from this integration. New repos, projects, or channels are automatically included as they are added.
Include -- only include the specific items you select. Your agent sees nothing else from this integration.
Exclude -- include everything except the items you list. Useful for blocking sensitive repos while keeping the rest.
Important Distinction
Data sources = what your agent can search and read in your knowledge base
Permission policies = what your agent can do (live actions like creating issues or sending messages)

Adding GitHub as a data source lets your agent search code and issues. It does not let your agent create issues or open pull requests. For that, you need a permission policy.

Built-in Capabilities

Search tools

Every configuration comes with four built-in search tools at no extra setup. These tools work immediately once you add data sources -- no permission policies required. They are read-only by design, giving your agent powerful search and context capabilities without any risk of modifying your data.

Smart Search

Search across all your configured data sources using natural language. Ask "how does authentication work in the backend?" and get relevant results from code, issues, messages, and documents.

Use when your agent needs to find information across integrations without knowing exact file names or issue numbers.

Browse Connections

Navigate relationships between items in your knowledge base. Follow connections from a code file to the issues that reference it, the pull requests that modified it, and the Slack conversations that discuss it.

Use when your agent needs to understand how things connect -- tracing dependencies, finding related work, or mapping impact.

Deep Context

Get rich, structured context for a specific item. Returns the item itself along with its relationships, history, and surrounding context -- everything your agent needs to understand it fully.

Use when your agent has identified a specific item and needs comprehensive detail before taking action or answering a question.

Read Source Content

Access the full content of your indexed data. Read the complete text of documents, code files, and messages as they were when they were last synced.

Use when your agent needs the actual content of a file or document, not just search results or summaries.

Adding Actions

Permission policies

Want your agent to do things, not just search? Attach a permission policy to unlock live actions. Policies control which actions your agent can perform -- creating issues, posting messages, updating tickets, and more.

Without any policies, your configuration is read-only. Your agent can search and retrieve information using the built-in search tools, but it cannot modify anything. This is by design -- you opt in to write access explicitly.

How Policies Merge

You can attach multiple policies to a single configuration. When policies overlap on the same action, the most restrictive setting wins. This means you can layer policies safely -- adding more policies never loosens permissions.

Policy A: create_issue -- auto-approve
Policy B: create_issue -- require approval
Effective: create_issue -- require approval
Permission Levels
Auto-approve -- the agent can perform this action without any human intervention.
Require approval -- the agent pauses and waits for a human to review and approve before proceeding.
Blocked -- the agent cannot perform this action at all, even with approval.

Access Control

Deployments

Deployments control who can use a configuration. Deploy to your entire organization for a shared baseline, or target specific teams and users for tailored access.

More specific scopes override broader ones. If your organization has a default configuration but the engineering team has its own, engineers will get the team-level config. If a specific user has a personal override, that takes priority over everything.

Organization
Everyone in your org
Broadest
Team
Members of a team
Narrows
Project
Members of a project
Narrower
User
A specific individual
Most specific
Practical Example
org: "company-readonly" -- everyone gets search-only access
team: engineering -- "eng-readwrite" -- engineers can also create issues and PRs
user: lead-dev -- "eng-admin" -- the lead gets full admin-level actions

Connecting Your Tools

API keys

API keys connect your tools to a specific configuration. Generate a key, add it to your tool's settings, and you are ready to go. Works with Claude Code, Cursor, or any compatible tool.

Each key is tied to a user and a configuration. The raw key is shown exactly once when you create it -- copy it immediately and store it securely. You can revoke a key at any time, and it takes effect instantly.

Shown once
Copy the key when created -- it cannot be retrieved later
Optional expiration
Set an expiry so keys rotate automatically on your schedule
Instant revocation
Revoke at any time. Existing sessions are terminated immediately
Usage tracking
See when each key was last used to identify stale or compromised keys
Claude Code Example
// In your tool settings
{
"mcpServers": {
"telara": {
"url": "https://api.telara.dev/v1/mcp/sse",
"headers": {
"Authorization": "Bearer telara_mcp_..."
}
}
}
}

Access Model

API key permissions

Who can generate an API key depends on the scope the key is being created for. The scope must be within the deployment scope of the configuration -- you cannot generate a broader-scoped key than what the configuration is deployed to.

For example, if a configuration is deployed to a specific team, only members of that team (with owner, admin, or maintainer role) can generate keys for that team or for individual users. They cannot generate an organization-wide key for a team-scoped configuration.

Key ScopeWho Can GenerateRequired Deployment
organizationOrganization admin or security adminMust be deployed at organization scope
teamTeam owner, admin, or maintainerMust be deployed at organization or team scope
projectProject owner, admin, or maintainerMust be deployed at organization or project scope
userThe user themselves onlyAny deployment scope
Practical Example
config deployed to: team "engineering"
team member (owner): can generate team-scoped or user-scoped key
team member (viewer): cannot generate keys for this config
org admin: can generate org-scoped key only if config is deployed at org scope

How It Works

How your tools connect

When your tool connects, Telara resolves the right configuration automatically. It identifies you from the API key, finds the most specific deployment that applies, applies any permission policies, and makes the appropriate tools available -- all instantly.

Your Tool
Claude Code / Cursor
API Key
Authentication
Telara
Connection
Config Resolve
Settings + Permissions
Your Data
Search / Execute

Common Patterns

Use cases

Configurations are flexible enough to support anything from a simple search-only knowledge base to a fully interactive assistant with scoped permissions per team.

Configuration only, no policies
Search-only knowledge base
  • Add GitHub, Jira, and Confluence as data sources
  • No permission policies needed
  • Agent can search, browse, and read -- nothing else
  • Deploy to the whole organization as a safe default
Configuration + permission policies
Interactive assistant
  • Same data sources as above
  • Attach a policy that unlocks creating issues and adding comments
  • Set sensitive actions to require approval
  • Agent can search AND take action on your behalf
Scoped deployments
Team-specific config
  • Engineering team gets repos + Jira + read-write policy
  • Support team gets Zendesk + Slack + read-only policy
  • Each team sees only the data relevant to their work
  • Individual users can get overrides when needed

Recommendations

Best practices

Follow these guidelines to get the most out of your configurations while maintaining strong security.

Start with search-only

Create your first configuration without any permission policies. Verify that your agent can search and retrieve the right data before unlocking actions. This lets you validate data source filtering without risk.

Add policies gradually

When you are ready for write access, start with "require approval" on sensitive actions. Once you are confident in the agent's behavior, selectively move actions to "auto-approve." You can always tighten permissions later.

Use scoped deployments

Set a conservative organization-wide default, then create more permissive configurations for specific teams that need them. This ensures every user has a baseline while power users get the access they need.

Rotate API keys regularly

Set expiration dates on your API keys and rotate them on a regular schedule. Use the usage tracking to identify keys that have not been used recently -- they may be safe to revoke. Never share keys between users.