Ways to connect
There are two ways to connect, and the difference is only which projects the agent can reach. Both authenticate the same way - OAuth: the first time your client connects it opens a browser to Duraton, you sign in, and access is bound to your account and the scopes you grant.Workspace - the whole account
dev / staging / prod set of projects, or letting an agent set a workspace up
from scratch.
Single project - pinned by URL
Whichever you use, access is enforced per request against your live workspace membership and role -
losing access to a project immediately closes it off, even mid-session.
Add it to your client
- Claude Code
- Cursor
- VS Code
- Windsurf
- Config file
/mcp in a session and follow the OAuth flow. Append /<projectId> to the URL to pin the
connection to a single project.Claude Desktop adds a remote server through Settings -> Connectors -> Add custom connector,
pointed at the URL above. Codex authenticates a remote server with a bearer token rather than the
interactive OAuth flow, so it cannot sign in to this server from config alone.
Working with projects
Every other tool is scoped to one active project, so a run or event id from another project reads back as not-found. In workspace mode the agent manages that itself:
In single-project mode the active project is fixed by the URL, so
select_project has no effect
there.
What an agent can do
The full, current set of tools is whatever the server advertises to your client on connect (tools/list) - that is the source of truth, and it grows as Duraton does. At a high level the tools
cover:
- Runs - list and inspect runs and their steps; cancel, pause, resume, replay, or retry from a step; bulk-cancel or bulk-replay by filter; and get a model-written diagnosis of a failure.
- Events - browse the event log and emit events to trigger workflows.
- Workflows, apps, and runners - inspect what is registered, the live flow-control state, and trigger a run manually - works even for a cron-only workflow.
- Approvals - list human-in-the-loop approvals and approve or deny them. Reading is always available; deciding can be restricted above a risk floor that only a person can clear.
- Webhooks - manage inbound and outbound webhook endpoints and sources, inspect outbound delivery health, and browse the inbound source delivery log and replay a verified delivery.
- Metrics - run counts, timeseries, AI spend, and session rollups.
The exact tool set is deployment- and access-dependent. Write tools appear only when you connect
with write access; some tools (the webhook tools) are registered only when the engine is wired
for them. Your client always shows what is actually available rather than offering a
capability that would only answer “unavailable”.