A compliance specialist your agent can call.
https://account.ismscopilot.com/v1/account/mcp
Claude Code, Cursor, Codex or any MCP client. Ask ISMS Copilot mid-task and get an answer grounded in curated framework knowledge, on your existing subscription.
Claude Code, one line
claude mcp add --scope user --transport http ismscopilot https://account.ismscopilot.com/v1/account/mcp --header "Authorization: Bearer pat-isms-..."Works with
- Claude CodeOne line
The one-line install above. Restart, then /mcp to verify.
- CursorConfig
HTTP MCP server entry: the URL plus the Authorization header.
- CodexConfig
Same URL, same Bearer header.
- OpenCode and GrokConfig
Same URL, same Bearer header in the client's MCP config.
- Hermes and any HTTP MCP clientConfig
Streamable HTTP transport, Bearer token.
- Claude Desktop and claude.ai connectorsNot yet
OAuth-only connectors cannot use personal access tokens yet.
- ChatGPT connectorsNot yet
OAuth-only clients cannot use personal access tokens yet.
Your agent is the harness, ISMS Copilot is the specialist
Keep your agent doing what it does well: reading the repo, running tools, editing files. When a step turns on ISO 27001, SOC 2, GDPR, NIS 2, DORA or the EU AI Act, it hands that step to ISMS Copilot over MCP and carries on with the answer.
Set up with your agent →Any other client
{
"mcpServers": {
"ismscopilot": {
"url": "https://account.ismscopilot.com/v1/account/mcp",
"headers": { "Authorization": "Bearer pat-isms-..." }
}
}
}The same endpoint and header in the JSON shape most clients accept.
Tools
Seventeen tools on the live server, grouped by plane. Each needs the matching scope on the token.
- create_conversation, send_message, get_replyConversations
Ask the specialist. Fast by default, think on paid plans.
- get_account_info, list_workspacesAccount
Who you are, which client workspaces exist.
- create_workspaceAccount
Create a personal workspace (workspaces:write). It starts unshared and does not inherit organization Advanced Data Protection; share it in the web app. Up to 10 new workspaces per 24 hours.
- list_documentsAccount
Generated documents, metadata only. No download by id.
- list_memories, create_memory, update_memoryAccount
What your agent learns stays with your account.
- get_company_context, set_company_contextAccount
Read or replace the company profile set under Customize. set_company_context is a full replace: read it first.
- list_api_keys, create_api_key, revoke_api_keyModel API
Manage sk-isms keys for the model API from your agent.
- get_api_credit_balance, create_api_credit_checkoutModel API
Balance and top-up checkout links.
Auth
- Token
- pat-isms-... shown once, optional expiry
- Where
- chat.ismscopilot.com, Settings, Connected apps
- Scopes
- Per token: account, workspaces (read; workspaces:write to create), documents (list), memories (read, write), company_context:read, company_context:write, conversations (create, send), api_keys:read, api_keys:write, api_credits:read, api_credits:checkout
- Revoke
- Instantly, from the same screen
- Billing
- Your chat subscription. No separate agent plan.
- Logging
- Every call is logged against the token that made it
Limits
- Rate
- About 120 requests a minute per token
- Conversations
- Concurrent conversations capped per account
- Chat window
- Shared 4-hour window with the chat app. On the cap, create_conversation and send_message return reset_at (plus upgrade_url for solo accounts and organization owners). When the cap response carries fallback_available (solo paid accounts with Advanced Data Protection off, never a team pool), the agent can continue on the same up-to-2x overflow as the web app with overflow_consent, after your go-ahead. Read tools keep working.
- Modes
- fast (default), think (paid), beyond (paid, 10/UTC day, 50 on Unlimited; agent must set mode, not auto-selected)
Replies are asynchronous
send_message -> { "status": "generating", "conversation_id": "conv_..." }
get_reply -> { "status": "generating" } // poll every 2 to 5 seconds
get_reply -> { "status": "complete", "reply": "..." }Poll get_reply until complete or error. Do not open parallel think turns on one conversation.
Not available over MCP
- Agent Tasks (not generally available anywhere as of 2026-09-28)
- Advanced Data Protection toggle (web app only)
- Document download by id (list only)
- Delete operations: destructive actions stay in the app where you can see them
- heyGRC pull request reviews (separate product)
Not the same thing as the API
The ISMS Copilot API gives your code our compliance model: you send prompts, you get completions, you build your own product on top (sk-isms keys, prepaid credits). ISMS Copilot for Agents gives your tools your account: your conversations, workspaces, memories and documents (pat-isms tokens, chat subscription). Different jobs, different keys.
Building a product instead? See the ISMS Copilot API →Status: live
Account MCP is live. Create a pat-isms token in chat Settings, Connected apps, then connect your client. Docs: docs.ismscopilot.com/docs/agents. Machine summary: GET /api/public/agents/v1.
Frequently Asked Questions
Which tools will work?
Any client that can connect to an HTTP MCP server with a Bearer header: Claude Code, Codex, Cursor, OpenCode, Grok, Hermes and others. The endpoint is account.ismscopilot.com/v1/account/mcp. OAuth-only connectors, such as Claude Desktop and claude.ai connectors or ChatGPT connectors, cannot use personal tokens yet.
Will it cost extra?
No separate agent plan. Usage is covered by your existing chat subscription and its 4-hour window. Think mode needs a paid plan.
What happens to my data?
Your account data stays in your account. Access from outside happens only through tokens you issue, scope and revoke yourself, and every call is logged against the token that made it.
How is this different from the model API?
Agents use pat-isms tokens and act as you inside your account. The model API uses sk-isms keys and prepaid credits to call the OpenAI-compatible text-only completions endpoint as a developer product.
Give your agent the specialist
Create a personal access token in Settings, Connected apps, paste the one-line install, ask your first question.
