AdisInsight
Query Springer Nature's drug-pipeline and trial database from an AI agent.
Search Synapse research datasets and read entity metadata, annotations and provenance.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Synapse.org MCP server connects Synapse — Sage Bionetworks' collaborative research data platform — to Claude, ChatGPT and any MCP-compatible agent. Five tools search for datasets and read entity metadata, annotations and provenance across genomics, imaging and clinical projects. Every tool is read-only in source, and the OAuth grant asks for metadata viewing without download permission.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
view scope and the downloadFile=False calls both stop at metadata. To read a file you still download it through Synapse's own clients, having met that dataset's conditions for use.docs.synapse.org corpus — 415 KB of llms-full.txt, roughly 50,000 words — and found zero occurrences of "MCP" or "Model Context Protocol". Every piece of connector-specific documentation lives in the third-party GitHub repository, not on Sage's documentation site.github.com/susheel/synapse-mcp. Sage Bionetworks maintains a Sage-Bionetworks GitHub organization referenced elsewhere in its own docs. We could not establish the governance relationship between the two, and state the discrepancy rather than resolving it.synapse-mcp name on PyPI. That package, version 1.3.0, is a "persistent MCP server — session memory, engineering pipeline" tool from an unrelated author and repository. It is not this connector. Installing it would get you something else entirely.get_entity_children works on projects and folders only. Anything else returns a stated error rather than a result.has_scope helper is defined in source and never called by anything, and the auth middleware's own documentation describes 403 responses for insufficient permissions as "handled at tool level" — a layer that is not there. Authorization is entirely Synapse's, applied to your token. This does not widen what you can reach, but the server enforces no second boundary of its own.get_file_content_url, query_table, get_table_columns and get_dataset_items are defined and called by no tool. They are dead code today, and get_file_content_url in particular is a file-download path with no tool wired to it. Nothing exposes them — but they indicate a direction of travel that a future release could reach, and a view-scoped token should not be assumed sufficient for it.tools/list response. The endpoint returned 401 to an anonymous request, so the annotations reported here come from the server's source at the version the deployment reports, not from a handshake.@mcp.prompt decorator.It can reach the metadata, not the files. Synapse defines the view permission as seeing that an entity exists plus its annotations, explicitly not file contents. The connector requests only view, and its entity reads pass downloadFile=False in source. Controlled-access governance still applies to metadata, which Synapse warns must not be emailed or redistributed.
No. Synapse's authorization server advertises nine scopes including download, modify and authorize, and the MCP server requests two of them: openid and view. That is a real boundary between the routine read and the consequential one, and it is one of the few connectors we have checked where the narrow scope was actually taken.
No. All five tools declare readOnlyHint true and destructiveHint false in the server's source, and no code path calls a Synapse write endpoint. The one POST request is hardcoded to the search endpoint, where POST carries the query rather than a change. The view scope would not authorize a write in any case.
The server's own maintainers say to be careful. Its compliance notice lists consumer cloud AI services under use with caution, because Synapse Terms of Service prohibit redistribution and provider-side storage may count as that. It recommends enterprise deployments with data-retention guarantees or self-hosted models instead.
Five, and this is one of the rare cases where two independent enumerations agree exactly. Anthropic's directory lists five names, the repository README documents the same five, and the source registers exactly five tool decorators. The deployed server reports the same version as the commit we read, so the match is verified rather than assumed.
One resource, which the directory does not list. The source registers synapse://feeds/blog, returning live RSS XML from the Sage Bionetworks publication feed. It fetches a third-party URL and passes the response into agent context unparsed, so treat that feed as untrusted input rather than as Synapse data.
Yes. The endpoint returned HTTP 401 to an anonymous request on 2026-08-22 with a Bearer challenge, so every session authenticates. Sign-in is OAuth through Synapse by default. What you can see is whatever your own Synapse account can see, since the server applies no permission filter of its own.
Anthropic's directory attributes it to Sage Bionetworks, and the linked repository is a personal GitHub account rather than the Sage Bionetworks organization. The code is MIT licensed and its last commit was 2025-10-20. Beware a name collision: the synapse-mcp package on PyPI is an unrelated project by a different author.
a81ef9d698969847c20b77cfab4defe4ac2b65e5, dated 2025-10-20: src/synapse_mcp/tools.py, resources.py, app.py, oauth/factory.py, oauth/jwt.py, connection_auth.py, entities/. · retrieved 2026-08-22llms.txt and llms-full.txt — · (retrieved 2026-08-22). docs.synapse.org/robots.txt is Allow: / with no Content-Signal directive. · retrieved 2026-08-22initialize returned HTTP 401 with a www-authenticate Bearer challenge naming its resource metadata; RFC 9728 descriptor at https://mcp.synapse.org/.well-known/oauth-protected-resource/mcp declaring scopes_supported as ["openid", "view"]; authorization server metadata at https://mcp.synapse.org/.well-known/oauth-authorization-server; deployed version read from https://mcp.synapse.org/health (2026-08-22). Control probes at bogus paths returned matching 404 bodies, so the descriptors are genuine rather than a catch-all. · retrieved 2026-08-22synapse-mcp 1.3.0, confirmed to be an unrelated project (retrieved 2026-08-22) · retrieved 2026-08-22Connect Synapse.org once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.