Connect to Reviso MCP

Connect an MCP client using the hosted JSON-RPC endpoint with OAuth authorization-code authentication and S256 PKCE.

Quick start

Run claude mcp add -s user --transport http reviso https://reviso.work/mcp, then authenticate through the browser OAuth flow.

Client setup

Authentication

Permissions

Agent connections are account-level. They inherit the team spaces and documents your account can reach, and tool visibility is filtered by the same capability checks used at call time. full is the default for complete workflows; core offers 15 common tools to reduce catalog context, including writes. Restrict permissions with connection capabilities, never with a profile.

What agents can do

Session rules

Inspect support, edit and confirm

Set document and individual link behavior

Synchronize names and organize saved versions

Public documentation redaction

Choose a workspace, create and search

Make a precise Markdown edit

Create a version with a whole-document update

Review and address comments

Share and manage access

Edit a heading

Insert an explanation before a block

Delete a paragraph

Split a paragraph into two

Troubleshooting

Protocol compatibility

Reviso implements MCP 2025-06-18, 2024-11-05. Initialize preserves a supported requested version and proposes 2025-06-18 for older or unknown versions. Clients must check the returned version. The stdio and hosted HTTP transports share this policy; no legacy HTTP+SSE endpoint is provided. Hosted requests use stateless POST JSON responses, without Mcp-Session-Id. Send MCP-Protocol-Version after initialization; explicit unsupported headers return 400. Missing headers remain accepted for older clients. Authenticated GET/HEAD stream probes return 405; unauthenticated probes carry a 401 OAuth challenge. Tools return matching structuredContent and serialized text, and tools/list declares an outputSchema for each tool, including error envelopes.

OAuth registration policy

Reviso supports authorization_code and refresh_token for public MCP clients with S256 PKCE and token_endpoint_auth_method: "none". Registration accepts authorization_code alone or with refresh_token and returns both supported grants. Other grant sets and unsupported response/authentication methods return 400 invalid_client_metadata; unsafe redirects return 400 invalid_redirect_uri. New OAuth access tokens expire after one hour on both client and server. Refresh tokens expire thirty days after the original authorization and rotate on every use without extending that deadline. Send client_id and the originally approved resource with every refresh. Serialize refreshes: replaying a consumed refresh token revokes the connection. Revocation and same-client reauthorization invalidate its refresh credentials too. Existing client-bound OAuth tokens honor their previously advertised 365-day lifetime; reauthorize to obtain the new pair. Manual keys keep their existing policy. Register an exact HTTPS or loopback HTTP callback before authorization. Wildcards, userinfo, queries and fragments are rejected. Client, callback, response type, S256 PKCE and resource are checked before redirecting to login.