## Ironclad integration Ironclad is a contract lifecycle management platform for creating, negotiating, signing, and searching contracts and records. Agen.co connects to Ironclad through Ironclad's own hosted MCP server as an **Official** connector. Each user signs in with their own Ironclad account, and every call runs with that account's user and group permissions. Ironclad does not support dynamic client registration, so an Ironclad admin first creates an OAuth app in Ironclad and gives Agen.co its client ID and secret. Prerequisites - An Ironclad account that can open **Company Settings** and create apps under the **API** tab. Ironclad only shows the **API** tab when the API add-on is enabled for your instance. - To use the obligation tools, the Obligations add-on must be enabled in Ironclad. - Know which Ironclad environment hosts your tenant: **na1** (NA1 production), **eu1** (EU1 production), or **demo** (demo / sandbox). The OAuth app must be created in that same environment. ### Get the callback URLs from Agen.co 1. In the Agen.co portal, go to **Connectors** → **My connectors** and click **Add connector**. 2. In the **Select connector** drawer, search for `Ironclad` and select it. The **Add Ironclad** panel opens. 3. Under **Ironclad environment**, select the environment that hosts your tenant. 4. Copy both read-only URLs shown in the panel: - **Callback URL** — completes the initial OAuth handshake between Agen.co and your Ironclad app. - **Gateway callback URL** — used by the Agen.co MCP gateway for per-user authorization at runtime. Leave this panel open — you return to it after creating the app in Ironclad. ### Create the OAuth app in Ironclad 1. Sign in to Ironclad in the environment you selected. Open your profile menu in the top right, then select **Company Settings** → **API**. 2. Click **Create new app**, enter a name for the app, and click **Create app**. 3. Copy the **Client ID** and **Client Secret**. Ironclad shows the secret only once, so store it before you close the dialog. 4. Complete the app details: | Ironclad field | What to enter | | --- | --- | | **Title** | A name your users will recognize. Ironclad shows it on the consent screen. | | **Grant Types** | Select the Authorization Code grant. | | **Redirect URIs** | Add **both** callback URLs from Agen.co, one entry each. | | **Requested Resource Scopes** | Select the scopes in the table below. | 5. Click **Save Changes**. Ironclad's MCP server advertises these scopes. Select all of them so every tool works: | Scope | Used for | | --- | --- | | `public.search.conversational` | Natural-language contract search | | `public.workflows.readWorkflows` | Reading workflows | | `public.workflows.readSchemas` | Reading workflow schemas | | `public.workflows.readSignStatus` | Reading signature status | | `public.workflows.readDocuments` | Reading workflow documents | | `public.workflows.createWorkflows` | Creating workflows | | `public.records.readRecords` | Reading records | | `public.entities.readRelationshipTypes` | Reading entity relationship types | | `public.entities.readEntities` | Reading entities | | `public.obligations.readObligations` | Reading obligations | | `public.obligations.createObligations` | Creating obligations | | `public.obligations.updateObligations` | Updating obligations | | `public.obligations.readTypes` | Reading obligation types | A listed tool can still fail Ironclad can list a tool that the session cannot use yet. A tool works only if the session was granted the scopes it needs. If a tool is missing a scope, add the scope to the Ironclad app and reconnect. ### Connect Ironclad in Agen.co Return to the open **Add Ironclad** panel and fill in the fields: | Field | Required | Description | | --- | --- | --- | | **Instance Slug** | Yes | Namespaces this instance — it prefixes each imported tool as `slug__tool`, so several instances of the same MCP can coexist. Prefilled with `ironclad`. Use lowercase kebab-case. You can change it later from the connector's settings. | | **Ironclad environment** | Yes | The Ironclad environment hosting your tenant: `na1` (NA1 production), `eu1` (EU1 production), or `demo` (demo / sandbox). Defaults to `na1`. | | **Client ID** | Yes | The OAuth client ID from your Ironclad app. | | **Client Secret** | Yes | The OAuth client secret from your Ironclad app. | | **Callback URL** | — | Read-only. Add it as a redirect URI in your Ironclad app. | | **Gateway callback URL** | — | Read-only. Also add it as a redirect URI — the MCP gateway uses it for per-user authorization at runtime. | 1. Click **Connect**. Ironclad opens in a new tab, and the panel shows **Waiting for authorization — complete it in the opened tab…** 2. Sign in to Ironclad and approve the requested scopes. 3. Back in Agen.co, the panel switches to **Select the tools to import from Ironclad.** Every tool is toggled on; turn off any you don't want to import, then click **Add**. The connector is created and its tools imported only when you click **Add**. If you close the panel before that, nothing is saved, even if the Ironclad tab reported success. One instance connects to one Ironclad environment, and the OAuth app belongs to that environment. To connect a second environment, for example a sandbox next to production, add Ironclad again with a different **Instance Slug**, that environment, and its own app's client ID and secret. ### What it covers Everything runs as the signed-in user: agents only reach contracts and records that user can already access in Ironclad. Ironclad's server needs a signed-in session to list tools, so the table below comes from Ironclad's MCP documentation (checked 2026-10-08), and the tool selection screen after **Connect** shows exactly what your account serves. | Area | What it covers | | --- | --- | | Contract search | `conversational_search` runs natural-language searches, for example NDAs governed by California law that expire in the next 12 months. It is read-only | | Obligations | Create, read, list, and update obligations tied to Ironclad records, and list obligation types. Requires the Obligations add-on | Enabling the Ironclad connector isn't enough on its own. Tool calls remain denied until you create a [policy](/agen-for-work/policies/overview) that grants access to the specific tools you want to expose. ### Additional resources - [Connect an MCP client to the Ironclad MCP server](https://support.ironcladapp.com/hc/en-us/articles/39887632957463-Connect-an-MCP-Client-to-Ironclad-MCP-Server) - [Register an OAuth client in Ironclad](https://developer.ironcladapp.com/reference/register-oauth-client)