Skip to content
Last updated

Ironclad integration

Ironclad is a contract lifecycle management platform for creating, negotiating, signing, and searching contracts and records.

Agen.co connects to Ironclad through Ironclad's own hosted MCP server as an Official connector. Each user signs in with their own Ironclad account, and every call runs with that account's user and group permissions. Ironclad does not support dynamic client registration, so an Ironclad admin first creates an OAuth app in Ironclad and gives Agen.co its client ID and secret.


Prerequisites

  • An Ironclad account that can open Company Settings and create apps under the API tab. Ironclad only shows the API tab when the API add-on is enabled for your instance.
  • To use the obligation tools, the Obligations add-on must be enabled in Ironclad.
  • Know which Ironclad environment hosts your tenant: na1 (NA1 production), eu1 (EU1 production), or demo (demo / sandbox). The OAuth app must be created in that same environment.

Get the callback URLs from Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. In the Select connector drawer, search for Ironclad and select it. The Add Ironclad panel opens.
  3. Under Ironclad environment, select the environment that hosts your tenant.
  4. Copy both read-only URLs shown in the panel:
    • Callback URL — completes the initial OAuth handshake between Agen.co and your Ironclad app.
    • Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.

Leave this panel open — you return to it after creating the app in Ironclad.

Create the OAuth app in Ironclad

  1. Sign in to Ironclad in the environment you selected. Open your profile menu in the top right, then select Company Settings → API.

  2. Click Create new app, enter a name for the app, and click Create app.

  3. Copy the Client ID and Client Secret. Ironclad shows the secret only once, so store it before you close the dialog.

  4. Complete the app details:

    Ironclad fieldWhat to enter
    TitleA name your users will recognize. Ironclad shows it on the consent screen.
    Grant TypesSelect the Authorization Code grant.
    Redirect URIsAdd both callback URLs from Agen.co, one entry each.
    Requested Resource ScopesSelect the scopes in the table below.
  5. Click Save Changes.

Ironclad's MCP server advertises these scopes. Select all of them so every tool works:

ScopeUsed for
public.search.conversationalNatural-language contract search
public.workflows.readWorkflowsReading workflows
public.workflows.readSchemasReading workflow schemas
public.workflows.readSignStatusReading signature status
public.workflows.readDocumentsReading workflow documents
public.workflows.createWorkflowsCreating workflows
public.records.readRecordsReading records
public.entities.readRelationshipTypesReading entity relationship types
public.entities.readEntitiesReading entities
public.obligations.readObligationsReading obligations
public.obligations.createObligationsCreating obligations
public.obligations.updateObligationsUpdating obligations
public.obligations.readTypesReading obligation types

A listed tool can still fail

Ironclad can list a tool that the session cannot use yet. A tool works only if the session was granted the scopes it needs. If a tool is missing a scope, add the scope to the Ironclad app and reconnect.

Connect Ironclad in Agen.co

Return to the open Add Ironclad panel and fill in the fields:

FieldRequiredDescription
Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with ironclad. Use lowercase kebab-case. You can change it later from the connector's settings.
Ironclad environmentYesThe Ironclad environment hosting your tenant: na1 (NA1 production), eu1 (EU1 production), or demo (demo / sandbox). Defaults to na1.
Client IDYesThe OAuth client ID from your Ironclad app.
Client SecretYesThe OAuth client secret from your Ironclad app.
Callback URL—Read-only. Add it as a redirect URI in your Ironclad app.
Gateway callback URL—Read-only. Also add it as a redirect URI — the MCP gateway uses it for per-user authorization at runtime.
  1. Click Connect. Ironclad opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…
  2. Sign in to Ironclad and approve the requested scopes.
  3. Back in Agen.co, the panel switches to Select the tools to import from Ironclad. Every tool is toggled on; turn off any you don't want to import, then click Add.

The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even if the Ironclad tab reported success.

One instance connects to one Ironclad environment, and the OAuth app belongs to that environment. To connect a second environment, for example a sandbox next to production, add Ironclad again with a different Instance Slug, that environment, and its own app's client ID and secret.

What it covers

Everything runs as the signed-in user: agents only reach contracts and records that user can already access in Ironclad. Ironclad's server needs a signed-in session to list tools, so the table below comes from Ironclad's MCP documentation (checked 2026-10-08), and the tool selection screen after Connect shows exactly what your account serves.

AreaWhat it covers
Contract searchconversational_search runs natural-language searches, for example NDAs governed by California law that expire in the next 12 months. It is read-only
ObligationsCreate, read, list, and update obligations tied to Ironclad records, and list obligation types. Requires the Obligations add-on

Enabling the Ironclad connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Additional resources