MCP servers and API for your self-hosted apps

Connect Claude, Cursor or your own agents to the apps you run through Model Context Protocol servers. Sign-in over OAuth, your permissions, every call on record.

Start with one workloadBook a 30-minute briefing

Protocol
Model Context Protocol, over HTTPS
Sign-in
OAuth through your identity provider
Permissions
The user's own, never broader
Record
Every tool call in the audit log

AI assistants that reach your apps, on your terms

An assistant is only as useful as the systems it can read and act on. MCP gives it a standard way in. Pilae runs that way in on your infrastructure, behind your sign-in, with a log of every call.

An MCP server per app

We deploy and operate an MCP server next to each app you choose: your wiki, your database, your workflows, your files.

OAuth, not shared keys

Each person signs in through Keycloak or Entra ID. The assistant acts as that person, and disabling the account in your directory cuts off its access too.

Your permissions apply

A tool call can do only what the signed-in user can already do in the app. Write tools can be switched off per app.

Every call on record

Who called which tool, on which app, with which arguments and what came back, kept in the console and exportable to your SIEM.

On your private network

MCP servers answer on your private mesh by default. Publishing one through the gate on port 443 is a decision you make per server.

An API for the control plane

Deploy apps, read backups, pull logs and export the audit trail from your own scripts and pipelines, with scoped tokens.

Give AI assistants access without giving away the keys

Teams already paste data from internal tools into AI assistants by hand. It is slow, and nobody can say afterwards what went where. An MCP server replaces the copy and paste with a defined set of tools, a sign-in and a record.

Pilae operates those servers for the apps in your estate. Each one runs next to its app, on your premises or on your dedicated machines in Pilae Cloud. Sign-in goes through your identity provider, set up as part of our identity service. Each call lands in the audit log of the control plane.

Read only first, write when you are ready

Most teams start with read-only tools: search the wiki in Outline, query a table in NocoDB, list files in Nextcloud. Write tools, such as creating a record or triggering an n8n workflow, are switched on per app once your security team has reviewed the log. Our security page sets out the controls behind both.

Keep the model inside your perimeter

An MCP server decides what an assistant can reach. The client decides which model does the thinking. For data that must not leave your organisation, pair your MCP servers with a model you host, as described on our private AI page. When you want to try it, book a scoping call.

How an assistant gets connected

  1. Choose the apps

    We agree which apps get an MCP server and which tools each exposes: read only, or read and write.

  2. Deploy

    The Pilae Agent plans the MCP server alongside the app, waits for your approval and applies it in your window.

  3. Connect sign-in

    The server is registered as an OAuth client with your identity provider, with the groups allowed to use it.

  4. Add the client

    Your people add the server URL to Claude, Cursor or your own agent and sign in with their usual account.

  5. Watch and review

    Calls appear in the audit log. You adjust tools, groups and limits from the console.

What your contract includes

Servers
The apps with an MCP server and the tools each exposes, listed per app.
Authentication
OAuth through your identity provider for every MCP server. No static shared keys.
Audit log
Every tool call and API request retained for the length of the contract and exported on request.
Exposure
Private mesh only unless you approve publishing a server, in writing, per server.
Updates
MCP servers patched and monitored like every other app we operate, under the same availability commitment.

The apps behind it

Questions

What is an MCP server?

Model Context Protocol is an open standard that lets an AI assistant discover and call tools in another system. An MCP server exposes an app, such as a wiki or a database, as a set of tools the assistant can use, for example search pages or run a read-only query.

Which AI clients can connect?

Any client that supports remote MCP servers, including Claude, Cursor and agents you build yourself. The server does not care which model sits behind the client, so you can change assistants without changing your apps.

Can the assistant see data the user cannot?

No. The assistant signs in as the user through OAuth and inherits that user's permissions in the app. If the user cannot open a record, neither can the assistant acting for them.

Does my data go to the AI provider?

Only what the assistant retrieves to answer a request travels to the model behind the client you use. If that must not leave your perimeter, connect a model you host yourself, for example through Open WebUI on your own machines.

What does the control plane API cover?

The same actions as the console: apps, machines, deployments, backups, logs and the audit trail. Tokens are scoped per action and per app, and every request is recorded.

Related

Connect your assistant to your own apps.

Thirty minutes with an engineer: we pick one app, expose a read-only tool and call it from your client.