Connect the Claude connector

Add Dalea as a custom connector on claude.ai (web, Desktop, mobile).

Add Dalea as a custom connector in Claude (claude.ai on the web, Claude Desktop and mobile) so Claude can search, read and — if you allow it — update your workspace during a conversation. This is the one-URL "connector" flow. If you use Claude Code or another CLI/config-based client, see Connect Claude Code instead.

The flow at a glance:

  1. Add connector in Claude → Settings → Connectors → Add custom connector → https://dalea.app/mcp
  2. OAuth challenge — Claude discovers Dalea's authorisation server and opens the login page.
  3. Pick workspace + role. Choose which workspace Claude sees, and, on a first link, the role the connector holds there.
  4. Consent — approve the requested scopes (mcp:read, optionally mcp:write).
  5. Tool calls start flowing — every call is scoped to that workspace, rate-limited and audited.

Prerequisites

  • A Dalea account with the ws:connect_oauth_clients permission in the workspace you want to connect. Every default role holds it, so any member can connect their own connector. A workspace owner can remove it from a role under Settings → Workspaces → your workspace → Roles.
  • A Claude plan that supports custom connectors: Pro, Max, Team or Enterprise (Free is limited to a single custom connector).
  • Team / Enterprise: an Owner adds the connector once under Organization settings → Connectors; members then connect and authenticate individually.
  • Your Dalea organisation on a plan that includes the mcp feature. It is on by default for Free, Pro and Enterprise, and off for Academic. See Troubleshooting.
  • Your Dalea MCP URL: https://dalea.app/mcp (Enterprise customers use the URL provided by their administrator).

Step-by-step

  1. Add the connector in Claude

    On claude.ai go to Settings → Connectors → Add custom connector, and paste the server URL:

    https://dalea.app/mcp
    

    On Team/Enterprise an Owner adds it under Organization settings → Connectors so the whole org can enable it. You do not need to enter a client ID or secret — Claude registers itself automatically (Dynamic Client Registration, PKCE).

  2. Authorise

    Click Connect. Claude reads Dalea's discovery metadata and opens Dalea's sign-in page in your browser. Sign in if you are not already.

  3. Pick a workspace and role

    Choose the workspace you want Claude to see. On a first link you also assign the application a role in that workspace, picked from the roles whose permissions are a subset of your own. Nothing is preselected unless exactly one role qualifies. If the connector is already linked to that workspace, the existing application role is reused and no picker appears; that role belongs to the application in the workspace, not to you individually. The consent screen then lists the scopes Claude is requesting: mcp:read and (for the write tools) mcp:write.

  4. You are connected

    Dalea issues an access token valid for 1 hour plus a refresh token valid for 30 days, and Claude refreshes silently. Every tool call re-checks the workspace scope and the application's role on the server, is rate-limited per user, and is written to the audit log.

  5. Try a real query

    Back in Claude, ask something that needs your data:

    • "Search my Dalea workspace for the ELISpot assay and summarise the latest results."
    • "List the freezers and show me what is stored in Box 12."
    • "Draft a methods section in the Study DLA-7 report from the recorded qPCR results."

    Claude invokes Dalea MCP tools (for example search_all, result_data_read, document_markdown_write) and streams the results into its answer.

What Claude can do — reads vs writes

Dalea exposes its tools with reads and writes as separate, clearly-labelled tools, so you (and Claude) always know when a call only reads your workspace versus when it changes it. Read tools are marked read-only; the three write tools that can delete or irreversibly overwrite data (document_markdown_write, data_environments_write, dalea_bash) are also marked destructive.

The connector sees 43 tools, or 45 when workspace code execution is enabled (that adds code_execution and attach_files_to_sandbox, both gated on the mcp:code-exec scope). The full list:

GroupRead toolsWrite tools
Search & navigationsearch_all, related_entities, workspace_infoNone
Documents & versionsdocument_markdown_read, document_versions_read, entity_versions_readcreate, document_markdown_write, document_versions_write, entity_versions_write
Projectsmanage_projects_readmanage_projects_write
Data (schema & rows)data_environments_read, data_tables_read, data_columns_read, data_objects_read, data_queries_readdata_environments_write (commit), data_tables_write, data_columns_write, data_objects_write, data_queries_write
Resultsresult_data_readresult_data_write
Inventoryinventory_types, inventory_containers_read, inventory_items_readinventory_containers_write, inventory_items_write
Files & translatorsdownload_file, translators_readtranslators_write
Templatestemplates_readtemplate_insert
Provenanceprovenance_readrecord_external_run
Marketplace & addonsmarketplace_packages, addons_readaddons_write
Skills & exampleslist_skills, load_skill, get_tool_examplesNone
Workspace shellNonedalea_bash

That is 25 read tools and 18 write tools. translators_write is a write because apply lands rows in tables and export materialises a file in workspace storage; translators_read (list, get, inspect, draft, preview) never writes. dalea_bash is one destructive tool: some of its subcommands only read, but the tool as a whole can create, move and delete. addons_write can create, edit and build workspace addon source, so treat it like any other code-writing capability.

The tool list is the same for every role

All 43 tools are advertised on every connection. Giving the application the Viewer role does not hide the write tools, and granting only mcp:read does not restrict Claude to reads: those calls are simply refused downstream with a permission error. mcp:code-exec is the one scope enforced per tool, on the two sandbox tools. Some irreversible actions (hard file deletes, schema-destroying edits) are not exposed to the connector at all and stay in the Dalea UI under human review.

Security model

Token lifetime
Access token 1 hour, refresh token 30 days, refreshed silently. Signing out of Dalea does NOT revoke them.
Revoking
Settings → Developer → Connected Applications, then Revoke on the application. Dalea asks for a reason, then deletes the consent along with the access and refresh tokens.
Audience
Tokens carry an audience naming this MCP resource and are validated on every call, so they will not work against another service.
Workspace scope
One workspace per connection. Switching workspaces requires re-authorising the connector.
Least privilege
On a first link you choose the role the application holds in the workspace, from the roles whose permissions are a subset of your own. It bounds what the calls may do, not which tools are offered.
Audit
Every tool call is logged with the actor, workspace, tool name, MCP client name and version, auth method and a correlation id.
Rate limits
Per-user request budgets, shared across all your workspaces: 120 requests per minute and 10,000 per day by default. Overage returns a rate-limit error with a retry-after.
Data handling
Dalea reads only the workspace data needed for each request. See the Privacy Policy at dalea.app/privacy.

Troubleshooting

  • Workspace selection shows "No workspaces available". The page names the cause. Either your role lacks ws:connect_oauth_clients in every workspace, in which case a workspace owner has to grant it to your role, or the organisation does not have the mcp feature. That flag comes from the plan (on for Free, Pro and Enterprise, off for Academic). Organisation admins can see its state under Settings → Organizations → Features but cannot change it: a Dalea platform administrator has to.
  • "You don't have permission to grant this application access." No role in that workspace is a subset of your own permissions, so there is nothing you can assign to the connector. Ask a workspace owner to review your role.
  • The login loops back to workspace selection. The selection is held for 90 seconds; if it lapses, start the connect flow again.
  • Tools do not appear. Some clients cache the tool list — disconnect and reconnect the connector.
  • "No workspace context" errors. Your connection was revoked. Remove and re-add the connector, then pick a workspace and role again.

What's next