Yolm MCP Connector
Connect an MCP-compatible assistant to your Yolm systems through the Yolm-hosted gateway. Yolm is an AI Business Platform: the connector gives an authorized assistant access to the live systems and permissions you choose.
Before you can connect
MCP access is off until someone grants it. Two separate things are required, and neither is implied by the other.
- An account on the Yolm system you want to reach. The connector signs in as you, so there is no anonymous or application-wide access. A system you have no account on cannot be attached.
- MCP connection permission on that account, granted by an administrator of that system. Connecting read-only and letting an assistant act are separate permissions, so an administrator can allow reading without ever allowing writes. In Forge, development access additionally requires the ordinary code-editing permission, which means the connector can never do something you could not already do yourself in Yolm.
Connection details
- Remote MCP URL:
https://mcp.yolm.ai/mcp - Authentication: OAuth 2.0 with browser sign-in and consent. Complete the Yolm consent step when your assistant opens it.
- Transport: Streamable HTTP.
What the connector can do
After authorization, the connector can list systems attached to your connection, inspect Forge systems and Spark workspaces, create runtime sessions, and execute read-only or permissioned runtime operations. The available systems and actions are limited by your Yolm account and the grants you approve.
- Forge: Inspect application code, documentation and authorized operational data. Develop access also permits version changes, tests and previews. The Forge connector does not deploy applications or write production business data.
- Spark: Query authorized business data and read permitted files. Act access also permits the business actions and saved work exposed by the system. Actions an application defines as critical are held for approval in Yolm and change nothing until a person approves them. Other actions apply immediately and can be undone from their receipt.
Read access does not permit session creation or business actions. Develop and Act access are separate choices on the consent screen and remain limited by your current Yolm permissions. Actions can have lasting effects; reconnecting does not undo earlier work.
Safeguards on write access
Granting Develop or Act does not hand an assistant a free hand. The same controls that govern a person using Yolm govern the connector.
- MCP access is granted, not assumed: an account on the system is not enough. An administrator must also grant MCP connection permission, and permission to connect read-only is separate from permission to let an assistant act.
- Your permissions are the ceiling: the connector acts as you. It can only see and do what your Yolm account already allows, on the systems you have consented to. It cannot widen its own access, and a read-only grant cannot perform any write.
- Forge cannot deploy: development access can edit source and run tests, but it cannot release anything to production and cannot write production business data. Every source change is versioned and recoverable.
- Critical actions wait for a person: actions an application defines as critical are held for approval in Yolm. They change nothing until someone approves them, and the approval screen is rendered by the application, not by the assistant.
- Everything is recorded: every action is written to an audit log with a receipt showing what ran and what it changed.
- Changes can be undone: actions that applied immediately can be reversed from their receipt.
- Access is scoped and revocable: each system needs its own sign-in and consent, an assistant reaches only the data an application exposes to it, and you can revoke a connection at any time from Connected assistants.
Recommended first use
- Connect the remote MCP URL in your assistant.
- Select the system and Forge or Spark surface, then sign in on the Yolm login screen. Do not paste your password into the assistant.
- Review the requested access and approve the connection.
- Ask the assistant to list your attached Yolm systems.
- Inspect the selected system before asking it to perform work.
API reference and documentation
The gateway exposes the Yolm Forge API and Yolm Spark API.yolm_list_systems lists attached systems; forge_inspect and spark_inspect return their current API references and available capabilities. Execution tools take JavaScript code and a system domain. Read-only execution is separate from permissioned write execution, and sessions retain saved work.
Static documentation, packages, JavaScript modules and selected examples are available in the public Yolm reference repository. Assistants can read or clone that repository without tenant credentials. The MCP API reference describes the execution contracts. Public references may lag a deployed tenant version; authorized documentation search and reads remain available through Forge MCP. Live schemas, tenant source and private business data still require your authorized connection.
Multiple systems and connection troubleshooting
Each system requires its own consent. The assistant can request another consent link with yolm_attach_system. A direct connection to a tenant's MCP endpoint does not automatically attach it to the public gateway. If a sign-in or consent link expires, request a new connection link and complete the flow again. If access is denied, check the selected system and grant, and confirm your account holds MCP connection permission on that system. Being able to sign in to a Yolm system does not by itself allow an assistant to connect to it, and being allowed to connect read-only does not allow an assistant to act.
Disconnecting an assistant
Open Connected assistants in each authorized Yolm system and revoke the relevant grant. Also remove the connector in your assistant. Revocation prevents further authorized tenant requests; it does not undo completed actions, erase saved sessions or delete results already sent to your AI provider. Previously issued download links can remain usable until their 30-minute expiry.
Privacy, terms, and support
The connector uses the Yolm account and permissions you authorize. See the Yolm Privacy Policy and Terms of Use. For help, contact support@yolm.ai.