The LawVu MCP server connects LawVu LegalOS — the in-house legal operating system holding a corporate legal team's matters, contracts, spend and knowledge base — to Claude, ChatGPT and any MCP-compatible agent. Anthropic lists 51 tools that search and read legal records, and that create, update and delete them. Sign-in is OAuth 2.1 as the individual LawVu user.
Anthropic states this reflects the level of review a connector received, not a security audit.
LawVu tools (51)
add_contract_status_message
add_field_option
add_matter_status_message
create_contract
create_matter
create_matter_conversation
create_matter_conversation_message
create_matter_legal_note
create_task
delete_contract_status_message
delete_legal_note
delete_matter_conversation
delete_matter_conversation_message
delete_matter_status_message
explain_tool
get_article
get_contract
get_contract_creation_schema
get_matter
get_matter_creation_schema
get_my_profile
join_contract
join_matter
list_articles
list_contract_status_messages
list_contract_types
list_field_options
list_fields
list_knowledge_categories
list_matter_contracts
list_matter_conversation_messages
list_matter_conversations
list_matter_legal_notes
list_matter_status_messages
list_matter_tasks
list_matter_types
list_matters
read_file
search_all
search_contract_files
search_contracts
search_knowledge
search_knowledge_files
search_matter_files
search_matters
search_users
update_contract
update_legal_note
update_matter
update_matter_conversation
update_task
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
Limits
No OAuth scopes exist to narrow the grant. Neither the resource descriptor nor the authorization server metadata declares scopes_supported, so nothing at consent separates reading a matter from deleting a legal note.
LawVu names no individual tool. All 51 names come from Anthropic's directory. LawVu publishes capability groups instead, which is diffable at the capability level but means a renamed tool would be invisible to us.
One documented write capability has no matching tool name. LawVu lists "Trigger contract workflows" as something a connected AI tool can do; no name among the 51 carries a trigger, workflow or stage verb, so we cannot say which tool it is or what its arguments allow.
We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter detail appears here and no tool's readOnlyHint or destructiveHint could be read. The read/write/delete split is our classification of the names, not the server's declaration.
explain_tool is unclassified. Its name suggests a meta helper, but without a schema we cannot rule out that it forwards an argument, so it is excluded from the read count rather than assumed safe.
No invoice, spend or approval tool exists — and no accounting one either. The connector can neither authorise spend nor read it, so an agent cannot check a matter's budget or actual spend before creating work against it.
Delete tools are irreversible as far as LawVu documents. No undo, restore or trash tool appears among the 51, and LawVu publishes no retention window for a deleted legal note or conversation message.
The feature is gated commercially and administratively. Activation requires a Customer Success Manager or support request, then an Organisation Admin enabling the tile. LawVu also describes the tool set as one that "will expand over time", so today's 51 is a snapshot.
No rate limits are published. LawVu documents no request cap, no HTTP 429 behaviour and no retry guidance for the MCP server, so throughput is unpredictable.
LawVu publishes no privilege-waiver guidance. Recorded here as an absence, not an all-clear — see the section above.
No published term covers MCP at all. LawVu's AI Service Terms, AI Acceptable Use Policy and AI FAQ never mention MCP, and its AI Powered Products table lists seven Azure features that do not include it. So the no-training promise and the qualified-professional review requirement are not demonstrably binding on data sent to Claude or ChatGPT through this connector.
No term governs which AI account may connect. There is no enterprise-account requirement and no bar on a personal or free-tier AI account. A peer legal connector imposes both contractually.
Anthropic is not a LawVu subprocessor, by design. LawVu's subprocessor list, updated 4 August 2026, names Microsoft Azure, Intercom, Twilio, Cloudflare and others. Anthropic does not appear, and the only OpenAI entry is "Microsoft Corporation (Azure OpenAI)" under LawVu's own AI Services. MCP is framed as your relationship with the AI provider rather than LawVu's, so connector use triggers no subprocessor obligation.
LawVu publishes no retention statement for MCP data. Its DPA and privacy policy set a 12-month backup window for User Data generally, but nothing addresses what happens to data passing through the MCP server specifically.
Compliance evidence is gated. ISO 27001, SOC 1, SOC 2 and an AssuranceLab seal are claimed, but the artefacts sit in a "security pack" behind a request form and a confidentiality click-through rather than a public trust portal. ISO 42001 is described as being pursued, not held.
LawVu's robots.txt is truncated mid-directive. The file ends after User-agent: Bytespider with no Allow or Disallow line following it, so that group is empty and falls through to the wildcard. Cosmetic for this connector, but it indicates an edit that was cut off.
LawVu places the AI-side security posture on you. It states that it enforces permissions and maintains an audit trail on its side, but that "the security posture of the AI tool itself — and how it is deployed within your organization — is your responsibility."
The production host root serves a page titled "LawVu Local MCP".https://mcp.lawvu.com/ returns a one-line HTML page carrying that heading and directing clients to /mcp. The MCP endpoint itself behaves correctly; the stray "Local" in a production title is cosmetic, but it is what the host publishes.
Documentation is one article. LawVu's entire MCP documentation is a single help-centre page. There is no tool reference, no schema documentation, no error-code table and no security page specific to the connector.
Frequently asked questions
Can the LawVu connector approve an invoice or authorise legal spend?
No tool can. None of the 51 names carries an approve, decline, void, invoice, spend, budget or payment verb, and LawVu's MCP article omits invoices from both its read and write lists. That matters because approving an invoice batch in LawVu forwards it to Finance for payment, so an approval tool would have been a payment authorisation.
How many of the 51 LawVu tools can change or destroy data?
Twenty-one. Our reading of the names gives 29 read, 16 write, 5 delete and one meta tool. The five deletes remove status messages, legal notes, conversations and conversation messages. A narrow risky-verb scan finds only those five and misses all 16 writes, so the delete count alone understates the surface by three times.
Does LawVu warn that connecting an AI tool could waive attorney-client privilege?
No. We searched LawVu's entire public corpus — every help-centre article, every sitemap page and all eight published terms documents — and found no privilege, attorney-client or work-product language anywhere. Consilio's Aurora connector, in the same directory category, does warn. The absence of a warning is not a statement that no risk exists.
What OAuth scopes does the LawVu MCP server request?
None are published. The server's RFC 9728 resource descriptor and its authorization server metadata both omit scopes_supported entirely, checked live on 2026-08-23. So no consent screen can offer reading a matter without also granting the five delete tools. The only boundary is the signed-in user's existing LawVu permissions.
What can a connected AI tool read in LawVu?
Whatever the signed-in user can already open, which for an in-house lawyer is legal advice. The read tools reach matter legal notes, private conversation messages, contract and matter file contents, and the internal knowledge base. LawVu states the server grants no elevated permissions and cannot see a record the user cannot.
What do I need before connecting LawVu to Claude?
Two gates, one commercial and one administrative. LawVu states you must first contact your Customer Success Manager or support team to have the MCP Server feature activated on your account. A LawVu Organisation Admin then opens the Integrations screen, finds the MCP Server tile and enables it for users before anyone can connect.
Can the connector give someone access to a LawVu matter they could not see?
No, and the join tools are narrower than they look. LawVu documents Join as clicking join on a record a user can already access, which adds them as a member for notifications and participation. Restricted matters block self-joining entirely, so join_matter cannot reach a record the user was walled off from.
Does LawVu recommend letting an agent write to it unattended?
No, and it says so twice. LawVu's MCP article strongly recommends requiring human review and approval for any AI-initiated action that creates, modifies or deletes records, particularly early in deployment. Its recommendations list repeats the point and advises granting minimum access rather than enabling MCP organisation-wide.
Live auth posture check: anonymous initialize returned HTTP 401 with a www-authenticate Bearer challenge; RFC 9728 descriptor at https://mcp.lawvu.com/.well-known/oauth-protected-resource/mcp; authorization server metadata at https://mcp.lawvu.com/.well-known/oauth-authorization-server; a nonexistent well-known path returned 404 as a control (2026-08-23) · retrieved 2026-08-23
Product names and logos belong to their owners. Agentman is not affiliated with a connector's maker unless the page says the connector is built and run by Agentman.
Use it in an agent
Put LawVu to work.
Connect LawVu once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.