Skip to main content
Agent gateway (MCP)

Connect Claude Code and Cursor
to your data pipelines.

rsync.ai runs an MCP server. Your AI agent reads pipelines, runs, schemas and models, explains why a run failed, and drafts pipelines, workflows and dashboards for a person to review. Metadata only, scoped tokens, every call audited.

TL;DR

The rsync.ai agent gateway is an MCP endpoint at /api/agent/v1/mcp. Agents connect with a scoped token that expires, act as the token's user, and read metadata, never rows. Anything they draft comes back as a link for a person to review, and they never run, edit or delete a pipeline or a connection.

  • Reads connections, schemas, pipelines, runs and models
  • Explains why a pipeline run failed
  • Drafts pipelines, workflows and dashboards for review
  • Scoped, expiring tokens; 120 calls a minute; every call audited

Your pipelines, in the agent you already use

One token, one endpoint, and your editor can answer questions about your data stack.

01

Make a token

In Settings → AI apps, under Connect your AI app, name the token, pick when it expires (30 days, 90 days or 1 year) and tick only what the agent may do besides read. It's shown once; rsync.ai keeps only its hash.

02

Add the endpoint

Point your client at your API address followed by /api/agent/v1/mcp, with the token as a bearer header. Claude Code, Cursor, Copilot in VS Code, Gemini CLI and Mistral Le Chat have documented configs.

03

Ask from your editor

"Why did last night's orders sync fail?" "Which model checks are failing?" The agent reads your pipelines, runs, schemas and models, and diagnose_run explains a failed run.

04

Review what it drafts

A proposed pipeline, workflow or dashboard comes back as a link. A person creates the pipeline, tests and turns on the workflow, or saves the dashboard.

Claude Code, in one command:

claude mcp add --transport http rsync-ai \
  https://<your-rsync-api>/api/agent/v1/mcp \
  --header "Authorization: Bearer rsat_..."

Settings shows the exact address for your workspace. Keep the token in a user-level config, never in a file you commit.

Useful to an agent, safe for your data

The agent gets enough to answer and to draft. A person decides what turns on.

It reads metadata, never your rows

Read tools cover connections and schemas, pipelines and run history, models and their checks, workflows, chart sources, dashboards and usage. Row values, sample rows, query results, row counts, connection settings and credentials are never returned.

It drafts; a person turns it on

plan_pipeline proposes a pipeline and creates nothing. plan_workflow and plan_dashboard draft a workflow or dashboard for an owner or admin to test or save. On rsync.ai Cloud, generate_connector adds a connector for a public API to the catalog without starting it.

Scoped tokens that expire

Every token can read. Each write tool needs its own scope, and the model scope lets an agent create, schedule, run, pause and resume models, so grant it on purpose. Tokens start with rsat_, every token expires, and a revoked one gets a 401 on its next call.

Guardrails you can audit

The agent acts as the token's user through the same handlers as the UI, never as a platform admin. Each call re-checks the token and your current role, tokens are bound to one workspace, calls are capped at 120 a minute, and every call is audited.

An agent that knows your pipelines without seeing your rows

Pointing an agent at a database connection hands it your rows. The rsync.ai gateway gives it the context around them instead: which pipelines exist, how their last runs went, what a schema looks like, which model checks failed, and why a run failed. That's what you need to debug a sync or plan the next one. The gateway calls no model of its own, and changes come back as drafts for a person. For the same tools inside the product, use Ask rsync.ai; to have an agent draft a report, see scheduled reports.

What it doesn't do

Some of these are limits for now; most are on purpose.

  • It never returns row data. For rows, use the Explorer or your database's own tools.
  • It never runs, edits or deletes a pipeline or a connection.
  • Clients that connect only through OAuth, such as the claude.ai and ChatGPT web connectors, can't use it; it accepts agent tokens only.
  • The Settings screen offers the pipeline, connector and model scopes. The workflow and dashboard scopes are granted only to tokens created through the API, by an owner or admin.
  • Connector generation is part of rsync.ai Cloud.
  • Self-hosted installs ship with the gateway off. Set RSYNC_AGENT_GATEWAY_ENABLED=true on the api-gateway service to turn it on.

The rsync.ai MCP server — frequently asked

What is the rsync.ai MCP server?

The agent gateway: an MCP endpoint at your API address followed by /api/agent/v1/mcp. Any AI client that speaks MCP over HTTP can use it to read your workspace's pipelines, runs, schemas and models, ask why a run failed, and draft pipelines, workflows and dashboards for a person to review. It authenticates with a token that starts with rsat_.

Can the agent see my data?

No. It reads metadata only. No row values, sample rows, query results, row counts, connection settings or credentials are ever returned. Names and error text from your systems are capped and passed to the agent as data, not instructions, and error text has quoted values, hosts, emails and credentials masked.

Can an agent change or delete my pipelines?

No. It never runs, edits or deletes a pipeline or a connection. It can propose a pipeline, workflow or dashboard, which a person creates, tests or saves. The one scope that acts directly is the model scope, which lets an agent create, schedule, run, pause and resume models; leave it unticked unless you want that.

Which AI clients work?

Claude Code, Cursor, Copilot in VS Code, Gemini CLI and Mistral Le Chat have documented setups. Any client that speaks MCP over HTTP and can send a bearer header should work. Clients that connect only through OAuth, such as the claude.ai and ChatGPT web connectors, can't use it.

How do I cut off an agent?

Revoke its token in Settings → AI apps; its next call gets a 401. Every token also expires after 30 days, 90 days or 1 year, and each call re-checks your role, so demoting the token's user stops the write tools that need an owner or admin.

Can I use it self-hosted?

Yes. The gateway is part of the self-hosted stack, which is source-available under the rsync.ai Source-Available License. It ships switched off; set RSYNC_AGENT_GATEWAY_ENABLED=true and restart the api-gateway service. The gateway calls no model of its own, so it needs no AI key. Connector generation stays on rsync.ai Cloud.

Ask your editor why the sync failed.

Start free on rsync.ai Cloud, make a token, and connect the agent you already use.

Live on rsync.ai Cloud today. Self-hosted installs ship with the gateway off; one environment variable turns it on.