Connect Attorly to Claude, ChatGPT and other apps with OAuth
The MCP server speaks the 2026-07-28 protocol and is an OAuth 2.1 resource, so apps connect with a sign-in and a consent screen instead of a pasted key. The REST API accepts OAuth tokens too.
- OAuth 2.1 authorization server: discovery (RFC 8414, RFC 9728), dynamic client registration (RFC 7591) and Client ID Metadata Documents, authorization code with PKCE (S256), refresh-token rotation with reuse detection, and revocation (RFC 7009).
- A consent screen shows what the app may do, lets you narrow it and pick the organization, and warns about apps Attorly has not verified. Settings › Developers › Connected apps lists the apps you allowed and disconnects them.
- Tokens are bound to the resource they were issued for (RFC 8707): ask for resource=https://attorly.ai/api/mcp for MCP or https://attorly.ai/api/v1 for REST.
- MCP tool results follow the 2026-07-28 specification: Markdown content, structuredContent checked against each tool’s outputSchema, and isError for business failures. Initialize-era clients keep the shape they had.
- Long-running MCP tools run as durable operations: with the Tasks extension the call returns a task; otherwise it streams progress and answers with an operation that operations_get resolves.
- New tools and endpoints: documents_search (GET /api/v1/documents/search), analyses_get and analyses_list (GET /api/v1/analyses/{analysisId}, GET /api/v1/documents/{documentId}/analyses), due_diligence_list_projects and due_diligence_get_project, workflows_list_executions, and organization_get_context (GET /api/v1/organization).
- documents_upload takes an https url; the download is checked against private networks, pinned to the address it resolved to and capped at 10 MB.
- Organization keys (atly_…) work on the MCP server as well, including test-mode keys, which run every tool on test data.