generated: '2026-08-14' method: searched status: published source: https://help.spekit.com/hc/en-us/articles/53977808268699-Spekit-MCP-Overview-Setup sources: - https://help.spekit.com/hc/en-us/articles/53977808268699-Spekit-MCP-Overview-Setup - https://help.spekit.com/hc/en-us/articles/53992263664539-Spekit-MCP-FAQs - https://help.spekit.com/hc/en-us/articles/53991678945435-Spekit-MCP-Data-Privacy-Security-FAQs - https://help.spekit.com/hc/en-us/articles/53991371723035-Troubleshooting-Spekit-MCP - https://www.spekit.com/platform/mcp server: name: spekit display_name: Spekit MCP description: The Spekit MCP connector exposes governed Spekit GTM content — Speks, topics, templates, companies and Deal Rooms — to any AI tool that supports a custom MCP connector by URL with dynamic client registration. Every call runs as the signed-in user and is scoped to that user's existing Spekit role; the connector grants no access the user does not already have in the Spekit web app, and enforcement is at the backend API layer, not in the connector. transport: http url: https://mcp.spekit.co/mcp compatible_clients: - Claude (Pro, Max, Team, Enterprise) - ChatGPT (Pro, Business, Enterprise, Education — writes limited to Business/Enterprise/Education) - Gemini CLI - Codex CLI - Gong cost: Included with every Spekit account at no extra cost; no separate seat or add-on. marketplace_listings: none yet — Spekit states it is in the submission queue for the AI tool marketplaces. deployment: mode: remote verified: searched checked: '2026-08-12' source: catalog MCP census authorization: model: OAuth 2.0 authorization code with PKCE (S256 required) dynamic_client_registration: true registration_endpoint: https://mcp.spekit.co/register authorization_endpoint: https://mcp.spekit.co/authorize token_endpoint: https://mcp.spekit.co/token issuer: https://mcp.spekit.co/ scopes: - openid - profile - email - read machine_to_machine: false note: Spekit states there is no client-credentials / machine-to-machine path — every connection requires an interactive sign-in and consent with the user's own Spekit login. access_token_lifetime: 24 hours refresh_token_lifetime: 30 days, rotating on every use (prior token cancelled on refresh) token_format: RS256-signed JWT verified against the IdP JWKS, checking issuer and audience tools_schema_status: AUTH-GATED. tools/list returns HTTP 401 invalid_token anonymously, so the live inputSchema for each tool could not be introspected. The tool set below is the provider's OWN published list from the Spekit MCP Overview & Setup help article — names and behaviour are verbatim from Spekit; the machine-readable input schemas require an authenticated introspection. tools: - name: Get authenticated user category: identity access: read description: Returns your identity so the calls that follow are scoped to your account. - name: List topics category: knowledge access: read description: Returns the topics you can access, with their direct subtopics. - name: Get topic category: knowledge access: read description: Returns a topic's parents and subtopics, so you can go deeper. - name: Search content category: knowledge access: read description: Keyword search across all Speks you can access. - name: List topic content category: knowledge access: read description: Returns the Speks filed under a specific topic. - name: Get content category: knowledge access: read description: Returns a single Spek's full body and its topic assignments. - name: Get asset content category: knowledge access: read description: Returns the text contents of a file asset by id. - name: Get content style guide category: authoring access: read description: Returns Spekit's design system rules, used before authoring. - name: List content templates category: authoring access: read description: Returns the content templates available to your company. - name: Get content template category: authoring access: read description: Returns a template's body and fill instructions. - name: List companies category: deals access: read description: Returns companies visible to you. You can filter by name. - name: List deal rooms category: deals access: read description: Returns deal rooms visible to you (id, name, share and internal links). Filterable by name. - name: Create topic category: knowledge access: write description: Creates a topic, optionally as a subtopic of an existing one. - name: Create content category: knowledge access: write description: Creates a new Spek, filed under one or more topics. - name: Create content from template category: authoring access: write description: Creates a new Spek from one of your company's templates. - name: Update content category: knowledge access: write description: Updates the title, body, or topic assignment of an existing Spek. - name: Create company category: deals access: write description: Creates a new company. - name: Create deal room category: deals access: write description: Creates a deal room under an existing company. - name: Create deal room content category: deals access: write description: Creates a Spek scoped to a specific deal room. tool_counts: total: 19 read: 12 write: 7 governance: write_confirmation: Every write tool is annotated as able to change data, and the calling AI tool prompts the user to confirm before it runs. The confirmation is enforced by the AI client via the MCP standard, not by a Spekit-side setting — Spekit's own docs recommend validating this per tool/session. read_only_mode: Not available. Access is bounded by the authenticated user's Spekit role only; there is no setting that forces the connector read-only independent of role. A company-level feature flag controls whether the connector is enabled at all; admins can control which tools users see inside their AI tool's Connectors section. scoping: Cannot be scoped to specific Topics or Deal Rooms — scope is the user's own visibility. rate_limited: true rate_limit_note: Enforced per session; quota enforcement validated across service instances. logging: Question and answer content is not logged. Operational metadata only — tool called, success/failure, response time, calling user identity. retention: access tokens 24h; refresh tokens 30d; logs 100d; traces 7d; metrics 180d training_on_customer_data: false hosting: Same AWS infrastructure and region as the core Spekit platform, under the existing DPA. penetration_tested: Not yet as a dedicated target — the MCP server is in scope for the next security assessment (testing planned Sept–Oct); the backend services it proxies were independently pen-tested within the past year. Spekit maintains a company-wide SOC 2 Type II report. limitations: - No delete of any kind through the connector. - Topics, companies and deal rooms are create-only — they cannot be renamed or edited after creation. - An existing Spek cannot be copied/attached into a Deal Room; only new content can be created there. - Cannot enable external Deal Room sharing, and cannot report whether sharing is already on. - Cannot manage users, roles or permissions. - Content created via the connector does not use Brand Studio styling yet. - Topic hierarchy is returned one level at a time; deeper levels need a follow-up call.