Holarch

Settings & AI

API and AI Tools (MCP)

Scripts read and change your projects through the Holarch API with a personal access token. AI assistants that speak the Model Context Protocol (MCP), such as Claude Code, connect to the MCP endpoint with the same token: they read the model, and changes from AI clients arrive as a proposal you review in Holarch.

Where to find it

  • The account button (your initials) at the right of the top bar → Account Settings → API tokens.

Main actions

  • Create a token: under New token, enter a name, choose Read only or Read and write, when it expires (in 30 days, 90 days, 1 year, or never) and which projects (all your projects or selected ones), then Create Token. Copy the token from the dialog: Holarch shows it only once. An email tells you about every new token.
  • What a token can do: it acts as you, within your role in each project. Viewers and reviewers only read; editors and owners also create, change and delete entities and relationships. A read-only token never changes anything.
  • API: https://app.holarch.app/api/v1/ with the header Authorization: Bearer hol_…: projects, the schema, entities (search, read, create, change, delete), relationships, documents, Model Checks, the requirement quality check and versions.
  • MCP: the endpoint https://app.holarch.app/mcp. In Claude Code: claude mcp add --transport http holarch https://app.holarch.app/mcp --header "Authorization: Bearer hol_…". The tools list projects, search and read entities and documents, and run Model Checks and the quality check. With read and write access they propose creations, changes, relationships and deletions.
  • Proposals from AI clients: an AI client never changes the project itself. When it sends its proposal, the token's owner and the project's owners get a notification, and ✦ AI ▾ → Review “…”… opens it: each change with a checkbox (deletions and changes to approved, baselined or locked items start unticked), editable names, numbers and descriptions, and the current and proposed values. Apply Selected applies the ticked changes as one undo step; Reject discards the proposal. Applying needs the editor or owner role. A proposal expires after 7 days.
  • Changes through the API are live: edits through the REST API appear at once for everyone with the project open and are recorded in its history under your name. Deleted entities go to the project's Trash. Plan limits apply as in the app.
  • Revoke: Revoke next to a token ends its access at once. A token also stops working when it expires or when the account is disabled or deleted.
  • Organizations: an org admin can turn API access off for the organization's projects under Organization Settings. Tokens are then refused there.

Tips

  • Give each script or tool its own token, read only where it only reads, and limited to the projects it needs.
  • Keep tokens out of shared files and source code: anyone with a token acts as you.
  • Model Checks and quality results through the API are returned, not stored in the project.
  • The API works on the hosted service only.

Related

Your Account · Organization Settings · AI Settings and Keys