Ironclad is a contract lifecycle management platform for creating, negotiating, signing, and searching contracts and records.
Agen.co connects to Ironclad through Ironclad's own hosted MCP server as an Official connector. Each user signs in with their own Ironclad account, and every call runs with that account's user and group permissions. Ironclad does not support dynamic client registration, so an Ironclad admin first creates an OAuth app in Ironclad and gives Agen.co its client ID and secret.
Prerequisites
Prerequisites
- An Ironclad account that can open Company Settings and create apps under the API tab. Ironclad only shows the API tab when the API add-on is enabled for your instance.
- To use the obligation tools, the Obligations add-on must be enabled in Ironclad.
- Know which Ironclad environment hosts your tenant: na1 (NA1 production), eu1 (EU1 production), or demo (demo / sandbox). The OAuth app must be created in that same environment.
- In the Agen.co portal, go to Connectors → My connectors and click Add connector.
- In the Select connector drawer, search for
Ironcladand select it. The Add Ironclad panel opens. - Under Ironclad environment, select the environment that hosts your tenant.
- Copy both read-only URLs shown in the panel:
- Callback URL — completes the initial OAuth handshake between Agen.co and your Ironclad app.
- Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.
Leave this panel open — you return to it after creating the app in Ironclad.
Sign in to Ironclad in the environment you selected. Open your profile menu in the top right, then select Company Settings → API.
Click Create new app, enter a name for the app, and click Create app.
Copy the Client ID and Client Secret. Ironclad shows the secret only once, so store it before you close the dialog.
Complete the app details:
Ironclad field What to enter Title A name your users will recognize. Ironclad shows it on the consent screen. Grant Types Select the Authorization Code grant. Redirect URIs Add both callback URLs from Agen.co, one entry each. Requested Resource Scopes Select the scopes in the table below. Click Save Changes.
Ironclad's MCP server advertises these scopes. Select all of them so every tool works:
| Scope | Used for |
|---|---|
public.search.conversational | Natural-language contract search |
public.workflows.readWorkflows | Reading workflows |
public.workflows.readSchemas | Reading workflow schemas |
public.workflows.readSignStatus | Reading signature status |
public.workflows.readDocuments | Reading workflow documents |
public.workflows.createWorkflows | Creating workflows |
public.records.readRecords | Reading records |
public.entities.readRelationshipTypes | Reading entity relationship types |
public.entities.readEntities | Reading entities |
public.obligations.readObligations | Reading obligations |
public.obligations.createObligations | Creating obligations |
public.obligations.updateObligations | Updating obligations |
public.obligations.readTypes | Reading obligation types |
A listed tool can still fail
A listed tool can still fail
Ironclad can list a tool that the session cannot use yet. A tool works only if the session was granted the scopes it needs. If a tool is missing a scope, add the scope to the Ironclad app and reconnect.
Return to the open Add Ironclad panel and fill in the fields:
| Field | Required | Description |
|---|---|---|
| Instance Slug | Yes | Namespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with ironclad. Use lowercase kebab-case. You can change it later from the connector's settings. |
| Ironclad environment | Yes | The Ironclad environment hosting your tenant: na1 (NA1 production), eu1 (EU1 production), or demo (demo / sandbox). Defaults to na1. |
| Client ID | Yes | The OAuth client ID from your Ironclad app. |
| Client Secret | Yes | The OAuth client secret from your Ironclad app. |
| Callback URL | — | Read-only. Add it as a redirect URI in your Ironclad app. |
| Gateway callback URL | — | Read-only. Also add it as a redirect URI — the MCP gateway uses it for per-user authorization at runtime. |
- Click Connect. Ironclad opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…
- Sign in to Ironclad and approve the requested scopes.
- Back in Agen.co, the panel switches to Select the tools to import from Ironclad. Every tool is toggled on; turn off any you don't want to import, then click Add.
The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even if the Ironclad tab reported success.
One instance connects to one Ironclad environment, and the OAuth app belongs to that environment. To connect a second environment, for example a sandbox next to production, add Ironclad again with a different Instance Slug, that environment, and its own app's client ID and secret.
Everything runs as the signed-in user: agents only reach contracts and records that user can already access in Ironclad. Ironclad's server needs a signed-in session to list tools, so the table below comes from Ironclad's MCP documentation (checked 2026-10-08), and the tool selection screen after Connect shows exactly what your account serves.
| Area | What it covers |
|---|---|
| Contract search | conversational_search runs natural-language searches, for example NDAs governed by California law that expire in the next 12 months. It is read-only |
| Obligations | Create, read, list, and update obligations tied to Ironclad records, and list obligation types. Requires the Obligations add-on |
Enabling the Ironclad connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.