Skip to main content
Telara

MCP Clients / Connection paths

Which platforms can connect, and what each one needs

Every platform below speaks to the same endpoint. What differs is who has to approve it — and for most of them, the answer during a pilot is nobody.

Admin
Rollout

One endpoint, two transports

Streamable HTTPhttps://api.telara.dev/v1/mcp
SSEhttps://api.telara.dev/v1/mcp/sse
AuthOAuth 2.1 + PKCE + dynamic client registration

Prefer Streamable HTTP for hosted platform connectors — it is what Copilot Studio requires, and what the hosted connectors generally expect. SSE remains supported for clients that ask for it.

The matrix

The distinction that matters for planning: a per-user path needs nothing from your administrators and is how a pilot starts. A managed rollout is what you need to push the connection to everyone and enforce it centrally.

PlatformPer-user path todayManaged rollout needsAudit client_type
Claude (desktop, web, Claude Code)Select Telara from the Connectors Directory after approval, then complete OAuth 2.1 + PKCE once.Anthropic Team/Enterprise directory access is required to submit and manage the public listing.claude
CursorInstall Telara from Cursor Marketplace after approval and complete OAuth once.A Cursor Team Marketplace can provide an immediate customer-specific one-click rollout while global Marketplace review proceeds.cursor
GitHub Copilot in VS CodePer-user .vscode/mcp.json, transport type http. No tenant admin.GitHub org owner plus Copilot Business/Enterprise to manage a shared MCP registry.vscode / github_copilot
OpenAI CodexSupported and documented end to end — see the Codex guide.Nothing extra.codex
ChatGPTSelect Telara after the OpenAI directory review is approved and complete OAuth once.The published OpenAI connector uses the same OAuth flow; no API key or MCP configuration is part of employee onboarding.chatgpt
Microsoft 365 Copilot / Copilot StudioNo per-user path. VS Code Copilot above is the per-user route for developers.M365 tenant admin, Copilot Studio entitlement, Entra app registration. Copilot Studio requires Streamable HTTP, which Telara serves.m365_copilot
GeminiSelect Telara from the Gemini Enterprise agent catalog after Marketplace approval and complete OAuth once.Google Cloud Marketplace vendor onboarding and Producer Portal AI-agent review are required for the public listing.gemini / agentspace
PerplexitySelect the centrally available Telara connector and complete OAuth once.Perplexity Enterprise administrators configure and share the OAuth remote connector; a curated listing remains a separate provider path.perplexity
GleanNo direct employee setup. Glean users select the approved Telara action pack after their admin publishes it.A Glean Admin imports Telara as an OAuth remote-MCP action pack, enables approved tools, and assigns access controls.glean

ChatGPT applies different tool rules per surface

This is the detail that decides whether a ChatGPT rollout works, and it is not about your workspace tier. Telara's tools are named telara_knowledge_search, telara_archive_read and siblings — not search and fetch.

SurfaceTool-name ruleTelara
Responses API mcp toolAny tool names.Works.
Connector without Developer ModeServer rejected unless it exposes both search and fetch.Refused.
Developer Mode chatAny tool names.Works — this is the documented path.
Deep ResearchUses only search and fetch, even with Developer Mode on. Other tools are ignored, not fallen back to.Not called.

So: enable Developer Mode before creating the app, and treat Deep Research as out of scope for Telara until search and fetch aliases ship. Neither is something you can fix from your workspace.

How to confirm a connection actually works

Do not trust the client's “connected” badge. It reports that a handshake succeeded, not that a tool ran.

Ask the assistant something answerable only from your indexed Telara data — a cross-repository question, or one naming a ticket that exists nowhere public. Then read GET /v1/mcp/audit/log.

Every tool invocation writes a row carrying client_type, client_name, source_client_name, success, and gate_result. That is one place to confirm which platform invoked which tool and what came back, whichever client called.

If the assistant answers without a matching audit row, it answered from its own knowledge and never called Telara. That is a routing problem in the tool descriptions, not a connection failure — and every transport check will still look green while it happens.

What the endpoint advertises

A platform connector walks this chain on first contact. You can exercise all of it before touching any platform, which is the cheapest way to rule out our side.

401 + WWW-Authenticate on an unauthenticated call
→ /.well-known/oauth-protected-resource (RFC 9728)
→ /.well-known/oauth-authorization-server (RFC 8414)
→ dynamic client registration at /oauth2/register
→ PKCE (S256) authorize

Public clients are supported, so a connector that cannot hold a secret can still register. Both transports advertise the same chain.