Ketryx MCP server icon

Ketryx

by Ketryx

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity9 tools

Query regulated medical-device lifecycle data — requirements, tests, risks and traceability — from an AI agent. All nine tools Anthropic lists are reads; nothing signs, approves or edits a compliance record. OAuth via Stytch, beta access by request.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Ketryx via MCP

https://app.ketryx.com/api/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Ketryx Tools & Capabilities (9)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Ketryx's documentation is not publicly readable. The URL Anthropic publishes, docs.ketryx.com/reference/ketryx-mcp-server, returns HTTP 307 to a GitBook login at app.ketryx.com/auth/gitbook. Every path on that host does, including llms.txt and robots.txt. This page is built from Ketryx's public marketing, press and support content instead.
  • Ketryx publishes no tool list. The nine names come from Anthropic's directory. Zero of them occur anywhere in the 272,281-word public corpus we searched, so no vendor enumeration exists to diff against — a weaker statement than "no undisclosed tools were found".
  • We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so we never saw a tools/list response and cannot report readOnlyHint or destructiveHint for any tool. The read-only classification is ours, derived from the names and from Anthropic's Read permissions field, not the server's own declaration.
  • No application scopes exist. The RFC 9728 descriptor declares no scopes_supported, and the Stytch authorization server advertises only OpenID identity claims plus offline_access. Nothing at the OAuth grant separates one kind of access from another. Since the listed surface is entirely read, there is no routine-versus-irreversible boundary to be missing — but there is also none to rely on if the surface grows.
  • full_access is unresolved. It appears in the OpenID discovery document and not in the OAuth authorization-server metadata on the same host. We could not determine whether the MCP server requests it or what it gates.
  • The connector is in beta and gated by a request form. Ketryx has published no general availability date, and no rate limits, quotas or pricing for MCP access that we could find.
  • Custom fields are invisible to the API. Ketryx documents that custom fields do not appear in standard API responses even when visible in the UI. If your compliance process depends on custom fields, an agent's view of an item is incomplete in a way it cannot detect.
  • Read-only is a property of this listing, not a guarantee. Ketryx's platform performs approvals, signatures and item exclusion through other surfaces, and Ketryx Agents act on records within the platform. A future tool carrying an approval verb would be a materially different connector; re-check the listing rather than assuming this page still holds.
  • Whether MCP access is itself logged in the Part 11 audit trail is unknown. Ketryx documents an organization audit log for system access and a per-item record history, but we found no statement about whether MCP tool calls appear in either. Treat it as unestablished.

Frequently asked questions

No tool among the nine Anthropic lists carries an approve, sign, submit or transition verb. Every name is a read: find, get, list, resolve or search. In a regulated quality system an electronic signature is a legally significant act under FDA 21 CFR Part 11, so this absence is the single most important fact about the connector, and we treat it as this listing's state rather than an architectural guarantee.

Not with the nine listed tools. None carries a create, update, write, delete or exclude verb, and Ketryx's directory listing records its permissions as Read. Requirements and test records mostly live in Jira, Polarion or Azure DevOps, and Ketryx documents editing and excluding items through those systems or its own web UI, not through this connector.

None that separate reading from writing. The server's RFC 9728 descriptor declares no scopes_supported at all, and its Stytch authorization server advertises five OAuth scopes that are OpenID identity claims plus offline_access. The OpenID discovery document on the same host adds a sixth, full_access, which names a breadth no listed tool exercises.

Ketryx announced the MCP server as a beta on 31 March 2026 and still routes prospective users through an access-request form rather than a self-serve toggle. Its press release describes the beta as open to organizations building regulated products across medical technology, digital health and robotics. Expect to request access before the endpoint will authenticate you.

Your design history file, effectively. The tools reach configuration items, requirements, test records, risks, version settings and item change history across Jira, Jama, GitHub, TestRail, Polarion and Azure DevOps. Ketryx documents that item change history records who changed what and when, which is the Part 11 audit trail an FDA inspector would examine.

Yes, and that is the point of the connector. Retrieved records enter your AI client's context. Ketryx documents that its own optional in-platform AI features route only to zero-data-retention endpoints, contractually barring providers from storing or training on the data. That control covers Ketryx's internal calls, not the separate client you connect over MCP.

No. We searched Ketryx's full 774-page public content mirror, 272,281 words, on 2026-08-23 and found zero occurrences of any of the nine tool names. The documentation URL Anthropic publishes redirects to a login wall. So the nine names come from Anthropic's directory with no vendor list to check them against.

Yes. A read-only surface removes the risk of an agent altering a record, not the risk of it reporting a gap that is not there or missing one that is. Ketryx documents that custom fields are absent from its standard API responses, so an agent may reason from an incomplete record. Verify a release-readiness answer against Ketryx before acting on it.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
Ketryx
Tools
9
Domain
app.ketryx.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.