Metal MCP server icon

Metal

by Metal

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity45 tools

Search a private-capital firm's deals, companies, people and documents from an AI agent, and run or author its workflows. Metal documents 45 tools; Anthropic's directory lists 24, omitting every write tool.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Metal via MCP

https://mcp.metal.ai/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Metal Tools & Capabilities (45)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Anthropic's directory listing is incomplete by 21 tools. It omits every write tool, the only delete tool, and the entire screenings-and-scoring group. Judge this connector's surface from Metal's tools reference, not from the directory entry.
  • The documentation URL Anthropic publishes is dead. The directory nominates support.metal.ai/articles/7775630687-connecting-to-the-metal-mcp-server; that host returns HTTP 404 with a Vercel DEPLOYMENT_NOT_FOUND body on every path including the site root, so the subdomain is gone rather than the article moved. The live documentation is on docs.metal.ai, which the vendor's own site links to.
  • run_workflow has no fixed blast radius. It executes a firm-authored pipeline whose step types include executeCode, so what one approval permits depends entirely on your workflows.
  • No tool can observe spend. Nothing in the 45 names a credit, quota or billing operation, and Metal publishes no per-run cost for a workflow. The price of a run is unpredictable from outside, not zero.
  • review_workflow_hitl_step can clear a human checkpoint. An agent holding it can approve the step a workflow author added so that a person would review the output.
  • write:workflows does not separate editing from deleting. One scope covers create_workflow, update_workflow_step and delete_workflow_step alike, so no OAuth boundary falls between the routine write and the irreversible one.
  • Four scopes have no documented tool. write:lists, read:dashboards, write:dashboards, read:programmatic and read:org appear in the OAuth descriptor but match no tool in either enumeration. We could not establish what grants them reach.
  • We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter-level detail or readOnlyHint value is published here. Metal's reference states the live tools/list response is the authority for those.
  • An admin gate stands in front of everything. Without Allow access to the Metal MCP server enabled for the organization, no client can connect regardless of user permissions.
  • Rate limits are described twice and differently. Metal's MCP reference shows a per-user limit; its REST documentation describes a per-organization budget that depends on your plan. Metal publishes no numeric MCP limit beyond an example value of 60.

Frequently asked questions

Forty-five, not the 24 Anthropic's directory lists. Metal's own tools reference publishes an alphabetical index headed All 45 tools, and its overview page states a connected client discovers 45 tools. The directory's 24 are a strict subset of that list with no names of their own, so the listing is stale rather than wrong.

Yes, though no tool name in Anthropic's listing suggests it. Metal documents ten tools the directory omits that create, update, reorder and delete workflow steps, including create_workflow and delete_workflow_step. It also documents review_workflow_hitl_step, which approves or rejects a pending human-in-the-loop decision inside a running workflow.

It starts a firm-authored pipeline, so its reach is whatever your firm built. Metal's workflow documentation lists step types including agent, tool, generateDocument and executeCode, arranged in branches and iterators. The tool takes only a workflowId and an input object, meaning one tool call can trigger many downstream operations that no tool name describes.

Eighteen, and four of them are writes. Metal's RFC 9728 resource descriptor advertises write:lists, write:dashboards, write:workflow_runs and write:workflows alongside fourteen read scopes. The boundary is per-object, so a token can be granted reading companies without writing workflows, but write:workflows covers authoring and deletion together.

An admin has to switch the server on first. Metal documents that an organization admin must enable Allow access to the Metal MCP server under Settings, Organization, API and MCP Access. You then add it in Claude as a custom connector and sign in through OAuth, choosing an organization if your account belongs to more than one.

No. Metal states that MCP access is scoped to your Metal user and organization and respects the same permissions you hold in the app. The Context Graph is described as permission-aware, and its technical documentation says Metal inherits and enforces existing source-system permissions, so an agent inherits your visibility rather than the firm's.

Usually because MCP was never enabled for the organization. Metal's troubleshooting tells you to confirm an admin turned on Allow access to the Metal MCP server, then clear your tool's saved Metal connection and reconnect so it completes a fresh OAuth sign-in. Connecting to the wrong organization is fixed the same way.

Yes, and MCP counts them per user rather than per organization. Metal's tools reference shows a rate-limit error carrying limit, remaining and retry_after fields, with an example limit of 60. Its REST API documentation describes a separate organization-level budget shared by all keys, so the two surfaces are throttled differently.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
Metal
Tools
45
Domain
mcp.metal.ai

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.