Connect the Claude connector
Add Dalea as a custom connector on claude.ai (web, Desktop, mobile).
Add Dalea as a custom connector in Claude (claude.ai on the web, Claude Desktop and mobile) so Claude can search, read and — if you allow it — update your workspace during a conversation. This is the one-URL "connector" flow. If you use Claude Code or another CLI/config-based client, see Connect Claude Code instead.
The flow at a glance:
- Add connector in Claude → Settings → Connectors → Add custom connector →
https://dalea.app/mcp - OAuth challenge — Claude discovers Dalea's authorisation server and opens the login page.
- Pick workspace + role. Choose which workspace Claude sees, and, on a first link, the role the connector holds there.
- Consent — approve the requested scopes (
mcp:read, optionallymcp:write). - Tool calls start flowing — every call is scoped to that workspace, rate-limited and audited.
Prerequisites
- A Dalea account with the
ws:connect_oauth_clientspermission in the workspace you want to connect. Every default role holds it, so any member can connect their own connector. A workspace owner can remove it from a role under Settings → Workspaces → your workspace → Roles. - A Claude plan that supports custom connectors: Pro, Max, Team or Enterprise (Free is limited to a single custom connector).
- Team / Enterprise: an Owner adds the connector once under Organization settings → Connectors; members then connect and authenticate individually.
- Your Dalea organisation on a plan that includes the
mcpfeature. It is on by default for Free, Pro and Enterprise, and off for Academic. See Troubleshooting. - Your Dalea MCP URL:
https://dalea.app/mcp(Enterprise customers use the URL provided by their administrator).
Step-by-step
- Add the connector in Claude
On claude.ai go to Settings → Connectors → Add custom connector, and paste the server URL:
https://dalea.app/mcpOn Team/Enterprise an Owner adds it under Organization settings → Connectors so the whole org can enable it. You do not need to enter a client ID or secret — Claude registers itself automatically (Dynamic Client Registration, PKCE).
- Authorise
Click Connect. Claude reads Dalea's discovery metadata and opens Dalea's sign-in page in your browser. Sign in if you are not already.
- Pick a workspace and role
Choose the workspace you want Claude to see. On a first link you also assign the application a role in that workspace, picked from the roles whose permissions are a subset of your own. Nothing is preselected unless exactly one role qualifies. If the connector is already linked to that workspace, the existing application role is reused and no picker appears; that role belongs to the application in the workspace, not to you individually. The consent screen then lists the scopes Claude is requesting:
mcp:readand (for the write tools)mcp:write. - You are connected
Dalea issues an access token valid for 1 hour plus a refresh token valid for 30 days, and Claude refreshes silently. Every tool call re-checks the workspace scope and the application's role on the server, is rate-limited per user, and is written to the audit log.
- Try a real query
Back in Claude, ask something that needs your data:
- "Search my Dalea workspace for the ELISpot assay and summarise the latest results."
- "List the freezers and show me what is stored in Box 12."
- "Draft a methods section in the Study DLA-7 report from the recorded qPCR results."
Claude invokes Dalea MCP tools (for example
search_all,result_data_read,document_markdown_write) and streams the results into its answer.
What Claude can do — reads vs writes
Dalea exposes its tools with reads and writes as separate, clearly-labelled
tools, so you (and Claude) always know when a call only reads your workspace
versus when it changes it. Read tools are marked read-only; the three write
tools that can delete or irreversibly overwrite data
(document_markdown_write, data_environments_write, dalea_bash) are also
marked destructive.
The connector sees 43 tools, or 45 when workspace code execution is enabled
(that adds code_execution and attach_files_to_sandbox, both gated on the
mcp:code-exec scope). The full list:
| Group | Read tools | Write tools |
|---|---|---|
| Search & navigation | search_all, related_entities, workspace_info | None |
| Documents & versions | document_markdown_read, document_versions_read, entity_versions_read | create, document_markdown_write, document_versions_write, entity_versions_write |
| Projects | manage_projects_read | manage_projects_write |
| Data (schema & rows) | data_environments_read, data_tables_read, data_columns_read, data_objects_read, data_queries_read | data_environments_write (commit), data_tables_write, data_columns_write, data_objects_write, data_queries_write |
| Results | result_data_read | result_data_write |
| Inventory | inventory_types, inventory_containers_read, inventory_items_read | inventory_containers_write, inventory_items_write |
| Files & translators | download_file, translators_read | translators_write |
| Templates | templates_read | template_insert |
| Provenance | provenance_read | record_external_run |
| Marketplace & addons | marketplace_packages, addons_read | addons_write |
| Skills & examples | list_skills, load_skill, get_tool_examples | None |
| Workspace shell | None | dalea_bash |
That is 25 read tools and 18 write tools. translators_write is a write because
apply lands rows in tables and export materialises a file in workspace
storage; translators_read (list, get, inspect, draft, preview) never writes. dalea_bash is one destructive tool:
some of its subcommands only read, but the tool as a whole can create, move and
delete. addons_write can create, edit and build workspace addon source, so
treat it like any other code-writing capability.
All 43 tools are advertised on every connection. Giving the application the Viewer
role does not hide the write tools, and granting only mcp:read does not
restrict Claude to reads: those calls are simply refused downstream with a
permission error. mcp:code-exec is the one scope enforced per tool, on the two
sandbox tools. Some irreversible actions (hard file deletes, schema-destroying
edits) are not exposed to the connector at all and stay in the Dalea UI under
human review.
Security model
- Token lifetime
- Access token 1 hour, refresh token 30 days, refreshed silently. Signing out of Dalea does NOT revoke them.
- Revoking
- Settings → Developer → Connected Applications, then Revoke on the application. Dalea asks for a reason, then deletes the consent along with the access and refresh tokens.
- Audience
- Tokens carry an audience naming this MCP resource and are validated on every call, so they will not work against another service.
- Workspace scope
- One workspace per connection. Switching workspaces requires re-authorising the connector.
- Least privilege
- On a first link you choose the role the application holds in the workspace, from the roles whose permissions are a subset of your own. It bounds what the calls may do, not which tools are offered.
- Audit
- Every tool call is logged with the actor, workspace, tool name, MCP client name and version, auth method and a correlation id.
- Rate limits
- Per-user request budgets, shared across all your workspaces: 120 requests per minute and 10,000 per day by default. Overage returns a rate-limit error with a retry-after.
- Data handling
- Dalea reads only the workspace data needed for each request. See the Privacy Policy at dalea.app/privacy.
Troubleshooting
- Workspace selection shows "No workspaces available". The page names the
cause. Either your role lacks
ws:connect_oauth_clientsin every workspace, in which case a workspace owner has to grant it to your role, or the organisation does not have themcpfeature. That flag comes from the plan (on for Free, Pro and Enterprise, off for Academic). Organisation admins can see its state under Settings → Organizations → Features but cannot change it: a Dalea platform administrator has to. - "You don't have permission to grant this application access." No role in that workspace is a subset of your own permissions, so there is nothing you can assign to the connector. Ask a workspace owner to review your role.
- The login loops back to workspace selection. The selection is held for 90 seconds; if it lapses, start the connect flow again.
- Tools do not appear. Some clients cache the tool list — disconnect and reconnect the connector.
- "No workspace context" errors. Your connection was revoked. Remove and re-add the connector, then pick a workspace and role again.