---
title: Knock MCP server
description: Use the Knock MCP server to make Knock accessible to LLMs and AI agents via tool calling.
section: AI
---

Knock ships a remote MCP server at `mcp.knock.app/mcp` that exposes the primitives of Knock to LLMs and AI via the <a href="https://modelcontextprotocol.io/" target="_blank">Model Context Protocol (MCP)</a> so that your AI agents can discover and use Knock via tool calling. Reach for the MCP server when you need Knock tools available inside Claude, ChatGPT, Cursor, or any MCP-compatible client, or when you're building a product that needs Knock primitives behind an LLM.

Here are some examples of how you can use the MCP server in your workflow:

- **Create workflows using natural language.** "Create a welcome email workflow for my B2B SaaS app."
- **Trigger a specific workflow to test your integration.** "Trigger the comment-created workflow for Dennis Nedry."
- **Create a set of test user and tenant data in your account.** "Create a user called Dennis Nedry and a tenant called acme-corp."

## Get started

The Knock MCP server is a remote server—no local installation or Node.js setup is required. You connect to `https://mcp.knock.app/mcp` directly from your MCP client. Interactive clients authenticate with your Knock account via OAuth. For CI and other headless environments, you can authenticate with a [service token](#authenticate-with-a-service-token).

We've added setup instructions below for Claude, Claude Code, Cursor, and fx, but the same instructions apply to any other MCP client-compatible application.

### Claude

Knock is listed as a community connector in Anthropic's <a href="https://claude.ai/directory/connectors/knock" target="_blank" rel="noopener noreferrer">connectors directory</a>. Use the connector in Claude Cowork and Claude Desktop.

<ContentButton
  href="https://claude.ai/directory/connectors/knock"
  target="_blank"
  rel="noopener noreferrer"
  icon="Claude"
  text="Connect Claude to Knock"
/>

### Claude Code

1. Run the following command to add the Knock MCP server:

```bash
claude mcp add --transport http knock https://mcp.knock.app/mcp
```

2. Start Claude Code and run `/mcp` to authenticate with your Knock account.

### Cursor

1. Go to **Settings** > **Cursor Settings** and find the "Tools & Integrations" section.
2. Click "New MCP server" under **MCP Tools**.
3. Inside your `mcp.json` file under the `mcpServers` key, add the following:

```json
{
  "knock": {
    "url": "https://mcp.knock.app/mcp",
    "name": "Knock MCP Server"
  }
}
```

4. When Cursor prompts you to authenticate, sign in with your Knock account.

### fx

1. Start an interactive fx session, then run the following command to add the Knock MCP server:

```bash
/mcp add --transport http knock https://mcp.knock.app/mcp
```

2. Run the following command to authenticate with your Knock account:

```bash
/mcp auth knock --open
```

See the <a href="https://fx.sh/docs/capabilities/mcp" target="_blank" rel="noopener noreferrer">fx MCP docs</a> for more configuration options.

## Authenticate with a service token

For environments that cannot complete a browser OAuth flow, such as CI pipelines or unattended agents, pass a Knock [service token](/developer-tools/service-tokens) (`knock_st_…`) as a bearer credential. MCP clients that set an `Authorization` header skip OAuth.

This is token passthrough: the same Management API credential authenticates the MCP session and outbound Knock calls. Prefer OAuth for interactive use. Treat the service token as a secret.

Generate a service token from the dashboard under **Settings > Service tokens**, then add it to your MCP client config:

```json title="mcp.json"
{
  "mcpServers": {
    "knock": {
      "url": "https://mcp.knock.app/mcp",
      "headers": {
        "Authorization": "Bearer ${KNOCK_SERVICE_TOKEN}"
      }
    }
  }
}
```

Replace `${KNOCK_SERVICE_TOKEN}` with your token, or keep the environment variable if your client interpolates it.

Service-token sessions skip the consent screen and enable all MCP capabilities. Restrict access with the service token rather than MCP capability checkboxes.

<Callout
  type="info"
  title="OAuth remains the default for interactive clients."
  text="Claude, Cursor, and other GUI clients should keep using the OAuth sign-in flow. Service token authentication is a compatibility path for headless environments, not MCP-conformant OAuth."
/>

## Capabilities

When connecting to the Knock MCP server with OAuth, you can choose exactly which capabilities to enable. The MCP server exposes a curated subset of Knock functionality — focused on reading and managing resources, running the Knock agent, inspecting environments, and searching documentation. Limiting the active capabilities to only what you need keeps the tool list manageable and reduces the risk of unintended changes.

When you authenticate with a [service token](#authenticate-with-a-service-token), the consent screen is skipped and all capabilities are enabled.

| Capability           | Description                                                                                 | Enabled by default |
| -------------------- | ------------------------------------------------------------------------------------------- | ------------------ |
| **Read resources**   | Inspect Knock configuration via the Management API (GET requests)                           | Yes                |
| **Manage resources** | Create and update Knock configuration via the Management API (write requests)               | Yes                |
| **Knock agent**      | Use the Knock agent to create and manage workflows, broadcasts, guides, and other resources | Yes                |
| **Debug**            | Inspect environments and view sent message logs                                             | No                 |
| **Manage data**      | Manage users, tenants, and object data                                                      | No                 |
| **Documentation**    | Search Knock documentation                                                                  | No                 |

### Knock agent capability

The **Knock agent** capability enables tools that invoke the same [Knock agent](/ai/agent) available in the dashboard. When enabled, your MCP client can start agent sessions to create and manage workflows, broadcasts, guides, and other resources through a conversational interface.

This capability is useful when you want the agent to handle complex, multi-step tasks that benefit from its built-in knowledge of Knock best practices and resource relationships. For simpler, direct operations, the **Read resources** and **Manage resources** capabilities provide lower-level access through the Management API.

If you need capabilities the MCP server doesn't expose — such as local file scaffolding for new resources, validating them before push, or working entirely offline against a checked-in repo — reach for the [Knock CLI](/ai/cli) instead.

## What tools are available?

The MCP server ships with tools to interact with all Knock resources. You can find the full list of available tools in the [tools reference](/developer-tools/agent-toolkit/tools-reference) of the Knock Agent Toolkit, which the MCP server is built on top of.

Please note that at this time, the MCP server **does not** ship with any tools to delete resources. This is intentional to prevent the accidental deletion of resources in your Knock account.

### Workflow-specific tools

The Knock MCP server exposes a full suite of tools for creating and managing workflows. Using the MCP server you can:

- Create a workflow with natural language: "create a workflow that sends a welcome email to new users"
- Create a delay or batch step within your workflow: "delay for 3 days" or "batch for 10 minutes"
- Create an email step within your workflow: "create a credit card expiring email with a link back to the dashboard"
- Create an SMS, push, or in-app feed step within your workflow

Using these tools you can create a complex prompt that describes one or more workflows that you'd like to create with natural language.

## Workflows-as-tools

The Knock MCP server also supports exposing your workflows as individual tools. This gives the LLM a specific and precise interface for invoking workflow triggers, including describing the data trigger requirements for your workflows.

By default, the MCP server will **not** expose any workflows as tools. To opt into this behavior, contact us or refer to your MCP client's tool configuration options.

## Pair with skills

The MCP server gives an agent the tools to operate on Knock. [Skills](/ai/skills) give the agent the procedural knowledge to operate on Knock _well_. The two are complementary, and most teams using MCP install at least one skill alongside it.

Knock's [`notification-best-practices`](/ai/skills) skill pairs naturally with the MCP server. It teaches an agent how to write effective notification copy across email, SMS, push, and in-app channels — guidance that applies regardless of whether the agent reaches Knock through MCP, the CLI, or the dashboard agent.

Install it with:

```bash
npx skills add knocklabs/skills --skill notification-best-practices
```

See the [skills page](/ai/skills) for the full catalog of available skills and which surface each one complements.

## Related links

- [Knock AI overview](/ai/overview)
- [Knock agent](/ai/agent)
- [CLI](/ai/cli)
- [Skills](/ai/skills)
- [Claude plugin](/ai/plugins/claude)
- [ChatGPT plugin](/ai/plugins/chatgpt)
- [Cursor plugin](/ai/plugins/cursor)
- [Grok Bot plugin](/ai/plugins/grok-bot)
- [Service tokens](/developer-tools/service-tokens)
- [Building with LLMs](/developer-tools/building-with-llms)
- [Knock Agent Toolkit](/developer-tools/agent-toolkit/overview)

## Frequently asked questions

<AccordionGroup>
  <Accordion
    title="Why do I see a warning about having too many tools?"
    anchorSlug="faq-too-many-tools-warning"
  >
    Some MCP clients will warn you about having more than 50 tools. To address
    this, enable only the capabilities you need for the task at hand. For
    example, if you're only managing user data, enable the **Manage data**
    capability and leave the others disabled. Service-token sessions enable all
    capabilities, so you may see this warning in headless clients.
  </Accordion>
  <Accordion
    title="Why do I receive an error in Cursor when I try to use one of the available MCP tools?"
    anchorSlug="faq-cursor-mcp-tool-error"
  >
    If you see an error like _"The model returned an error. Try disabling MCP
    servers, or switch models,"_ check which model is selected for the Cursor
    agent. Make sure it's explicitly set to a supported model like
    `claude-sonnet-4` rather than relying on automatic model selection.
  </Accordion>
  <Accordion
    title="Can I use a service token instead of signing in with my account?"
    anchorSlug="faq-service-token-auth"
  >
    Yes. For CI and other headless environments, pass a service token as a
    bearer credential in your MCP client config. See [authenticate with a
    service token](#authenticate-with-a-service-token). Interactive clients
    should keep using OAuth.
  </Accordion>
</AccordionGroup>
