Skip to documentation

Integration guide

MCP Connector

Use Bounded's authenticated MCP server to work with your Entries, Shared Spaces, and Contacts from compatible AI agents and MCP clients.


Server endpoint

Add this public Streamable HTTP endpoint to your MCP client:

https://bounded.bayonai.com/mcp

This is a protocol endpoint, not a web page. Opening it directly in a browser sends a GET request and returns “Method not allowed.” MCP clients communicate with it using POST requests.

Client protocol

Modern clients use protocol 2026-07-28. Send Accept with both application/json and text/event-stream, MCP-Protocol-Version, Mcp-Method, and Mcp-Name for tool calls. The method, tool name, and protocol version must match the request body. Each request includes its protocol version and client capabilities in params._meta; client identity is recommended. Missing or conflicting required headers are rejected.

Existing clients can initialize with protocol 2025-06-18 and send that version header on subsequent requests. Responses can be JSON or a finite SSE stream. No session ID or persistent GET stream is required. Modern discovery lists modern versions; legacy negotiation uses initialize. Tool catalogs are private and immediately revalidated.

Connect an AI agent

The exact labels vary by product, but any AI agent or client that supports remote Streamable HTTP MCP servers can use the same setup:

  1. Open the agent's integrations, tools, connectors, or MCP server settings.
  2. Add a remote MCP server named “Bounded.” Choose Streamable HTTP if the client asks for a transport.
  3. Enter https://bounded.bayonai.com/mcp as the server URL, then review the discovered tools and requested permissions.
  4. Continue to Bounded, sign in, and approve the requested access. Return to the agent after authorization completes.
  5. Confirm that the Bounded tools are available before asking the agent to read or change account data.

Permissions and capabilities

Connections that omit permissions receive read-only access. Unsupported permissions are rejected. Write access requires an explicit approval on the Bounded consent page, which identifies the registered client and its return address. Reconnect and approve write access when a read-only connection needs to change records.

bounded.read allows the connector to read the Private Space entries, Shared Spaces, and Contacts available to your Bounded account.

bounded.write allows the connector to create and manage Entries, Containers, and Contacts. Bounded repeats account, ownership, visibility, and entitlement checks on the server; only contact merging requires a paid plan.

You can also read shared-space activity and notifications, mark notifications as read, archive them, and restore them. Notification lists contain up to 50 active items per page; archived items are omitted, so retain an archived notification’s ID if you want to restore it. Shared-space activity shows the latest 100 events.

Profile and account tools let you read your profile and linked account summaries in pages of up to 50. Follow the account list’s nextCursor until it is null. Saving a profile requires every profile field and confirmation of the replacement and audience. Account visibility changes also require confirmation; private accounts remain visible only to their owners. These tools cannot change login credentials.

  • Entries: create private Entries, update titles or descriptions, move them to Delete, and restore them.
  • Containers: create private Containers, rename them, move them to Delete, and restore them. After confirmation, creators can add or remove participants, and invited participants can accept, ignore, block, or leave according to their current membership.
  • Contacts: create private Contacts, move them to Delete, and merge eligible duplicate records.

MCP tools do not permanently delete records. Participant and invite management stays in the Bounded app for now.

Reading entries

Private Space lists return small summaries, with at most 50 results. Follow nextCursor until it is null; a page can be empty while the server continues past deleted or unavailable records. Full content is available through bounded.private_space.entries.get using an entry ID.

Large entries return serializedEntryChunk and nextCursor. Retrieve each page, concatenate the chunks in order, then parse the combined JSON. If the entry changes during retrieval, restart without a cursor. Bounded checks current access on every page.

Workspace tools

bounded.workspace.search searches entries, containers, and contacts. Choose a result type or search all three. Follow every continuation cursor, including empty pages, to finish a search.

Contact and container lists now support pagination and text queries. Their detail tools return current roles, contact notes, tags, and other application details. Use confirmed contact edits/restoration or complete container settings replacement after reading the current record.

bounded.entries.edit supports ordinary content and settings edits with current revisions and semantic before/after values. Review audience changes with the user. Reconcile any reported conflicts before retrying.

Reading entries

bounded.entries.list lists and searches entries with text, visibility, entry type, date, and custom-field filters. Text search includes readable content. Each page scans up to ten candidates; keep following nextCursor even when a page has no matches. Cursors expire after an hour and require unchanged filters. Results contain title previews; read entry detail for complete data.

bounded.entries.get reads entries available to you through the app, including shared and inherited entries. Access is checked on every request. The response includes current revisions and custom-field values for editing.

For large entries, follow nextCursor as cursorwith the same entry ID, concatenate serializedEntryChunk, and parse the completed JSON. If content changes, restart without a cursor. The private-space detail tool remains available.

Custom fields

Use bounded.custom_fields.list to read definitions and options for an entry or container you can manage. Read entry detail for its current values and revision before editing.

bounded.entries.custom_fields.update requires confirmation, the entry revision, and complete before/after value maps. Preserve unchanged values. If the response contains an entry conflict, read the entry again before retrying. Field templates and layouts remain managed in the app.

Exporting your data

After you explicitly request an export, bounded.privacy.export reads the data you are authorized to export for an entity you own. It uses one record per data page by default, with a maximum limit of ten. Small replies contain exportPage directly.

For a large page, follow nextContentCursor using contentCursor and the same entity, limit, and data cursor. Concatenate serializedExportChunk values and parse the completed JSON to recover exportPage. Then use exportPage.nextCursor as cursor for the next data page, omitting contentCursor. Finish when no data cursor remains. Every request checks current access; restart a data page if its content changes. No records are truncated.

Privacy and support

The connector requires Bounded authentication before it can access account data. Review the tools and requested scopes before approving the connection, and connect only from an AI agent, MCP client, and device environment you trust.

Need help? Email appsupport@bayonai.com.