Connect your own AI application
You can connect your own AI assistant to your roleALPHA account. It can then read and edit your organisational data — in the same conversation you are working in anyway, without switching windows and without copying data by hand.
Questions that become possible: “Which roles hang off our complaints process?” · “Who is responsible for supplier assessment, and which competences are missing there?” · “Draft a new role for the division lead and enter it as a proposal.”
Prerequisite: your organisation must allow it
Section titled “Prerequisite: your organisation must allow it”The feature is off by default. Only once an administrator enables it for your tenant does the Connected applications section appear in your profile. If you do not see it there, contact your administration (Enabling access).
How to connect
Section titled “How to connect”- Open Profile → Connected applications and copy the address shown there.
- Enter the address in your AI application as a new connection. Where exactly is described below — one section each for Claude, ChatGPT, Gemini, Langdock, Mistral Le Chat and developer tools.
- A browser window opens with the usual roleALPHA sign-in — passkey, e-mail code or company sign-in, depending on what your tenant allows (Sign-in methods).
- You then see a consent page: which application is asking, for which tenant, and what it may do. Check the name and click Allow access.
Done. Your application now sees the roleALPHA tools.
Copy the address, do not type it out. It depends on the domain your organisation runs roleALPHA under — an address typed from a guide may not match your access.
Three answers some applications ask for
Section titled “Three answers some applications ask for”Before you jump to your application: these three answers are the same everywhere.
| The question | The answer |
|---|---|
| SSE or HTTP? | HTTP (often called “Streamable HTTP” or “HTTP streamable”). There is no /sse endpoint here. |
| Which authentication? | OAuth. No API key, no hand-entered bearer token. |
| Client ID and client secret? | Enter nothing, leave the fields empty. Your application registers itself; roleALPHA does not issue secrets at all. An application that strictly requires both cannot connect today. |
As of September 2026. The menu paths below belong to other products and change there without our involvement. If an item is no longer where it is described, the vendor’s own documentation applies — the address and the three answers above stay the same.
Claude
Section titled “Claude”Works in Claude on the web, in Claude Desktop and in Cowork — always through the same place.
On Pro or Max: Settings → Connectors → + → Add custom connector → paste the address → Add.
On Team or Enterprise: someone with owner rights adds the connector once for the organisation — Organization settings → Connectors → Add → Custom → Web. After that, each person connects individually under Settings → Connectors via Connect.
Two notes:
- Do not open “Advanced settings”. That is where an OAuth client ID and secret would go. Neither exists here, and a value entered there makes the connection fail.
- Claude connects from Anthropic’s cloud, not from your computer. If your roleALPHA is only reachable inside the company network, Claude cannot reach it — ask your administration.
In a conversation you switch the connector on via the + at the bottom left.
ChatGPT
Section titled “ChatGPT”ChatGPT first needs Developer Mode; without it, custom connections cannot be added.
- Profile picture → Settings → Apps & Connectors → Advanced Settings → turn on Developer Mode. This requires Pro, Team, Enterprise or Edu.
- Settings → Connectors → Add custom connector.
- Give it a name, paste the address, choose OAuth as the authentication and confirm the trust prompt.
If ChatGPT asks about the kind of endpoint: the address ends in /api/mcp, which is HTTP streamable — not /sse.
Gemini
Section titled “Gemini”gemini.google.com → at the bottom Settings & help → Connected Apps → under Custom apps click Add a custom app → paste the address → Next → confirm in the browser.
Two prerequisites on Google’s side:
- A personal Google account. With a work or school account the option is not available.
- Activity saving must be on, otherwise Gemini will not connect.
You set it up on a computer; afterwards you can use the connection in the Gemini app on your phone as well. Disconnecting also happens under Connected Apps.
Langdock
Section titled “Langdock”Integrations → Add Integration → Start from scratch → choose the type Connect remote MCP → paste the address.
The choice of authentication is what matters here:
- Correct: “OAuth 2.0 (Dynamic Client Registration)”. Langdock then registers itself, and you are only taken through the sign-in.
- Wrong: “OAuth 2.0 Manual”. That path asks for a client ID, a client secret, an authorization URL and a token URL. roleALPHA does not issue secrets — the setup runs into a dead end here.
Langdock then reads the available tools and lets you pick which ones the integration may use (up to 60 per integration).
Mistral Le Chat
Section titled “Mistral Le Chat”Intelligence → Connectors → Add connector → tab Add custom connector → paste the address.
Le Chat tries the connection straight away and guides you through the sign-in. Nothing else is needed.
Developer tools
Section titled “Developer tools”Claude Code
claude mcp add --transport http rolealpha <address from your profile>Then type /mcp in a session, select the entry and confirm the sign-in in the browser.
VS Code
Open mcp.json via the command palette (MCP: Open User Configuration) and add:
{ "servers": { "rolealpha": { "type": "http", "url": "<address from your profile>" } }}The root key is servers. If it says mcpServers, VS Code ignores the entry — without any error message. Then sign in via Auth above the entry.
Cursor
An .mcp.json in the project directory with the same shape ("type": "http").
Any other application
Section titled “Any other application”If your application supports the Model Context Protocol, the address and the three answers above are enough: HTTP as the endpoint type, OAuth as the authentication, no client ID and no secret.
What your application receives after signing in is described in What your application learns about your model.
If it does not work
Section titled “If it does not work”There is no “Connected applications” section in the profile. Your tenant has not enabled the feature (Enabling access).
The consent page says “Your organisation has not enabled connecting external applications”. You are not in any tenant the feature is active for. If you work in several, pick the right one at the top of the consent page.
The application reports an error instead of showing the sign-in. Almost always the address is not the one from your profile. Copy it again, without a trailing space.
The application reports “missing permission”. It tried to create something in a module you may not write — for an assignment in both modules involved, because a connection changes both sides. This is the same barrier as in the interface; your administration grants the permission.
Fewer tools appear than expected. Which tools an application sees depends on three things: your tenant’s data release, the booked modules and your own permissions. There is no fixed number.
It worked, and suddenly nothing does. Either the connection was disconnected, the feature was switched off for the tenant, your account was deactivated — or the application is asking for the wrong tenant. In every case: connect again.
“Too many requests”. Each connection allows 120 calls per minute. That is plenty for any conversation, but not for a bulk synchronisation.
A sign-in is requested again after a break. Normal: access is renewed hourly, and an idle session ends after 30 minutes. Your application handles this itself as long as the connection exists — after 90 days without use you connect again.
The application says it created something — but nothing shows up in roleALPHA. It created a draft, not a record. It is waiting for approval on the drafts page.
What the application may see and do
Section titled “What the application may see and do”Exactly what you may — not one entity more, not one field more. The tenant boundary, visibility levels and your role permissions apply unchanged. If you lose a permission, the application loses it too, on its next call.
Two things you should know:
- It includes changing things. A connected application can create drafts and edit data as far as you are allowed to. Changes go through the same draft and approval path as always.
- One connection applies to exactly one tenant. If you work in several, you create several connections.
Linking your own drafts. An application can search specifically for your own drafts — for example to attach one to a meeting topic. It only receives the title, type, status and a link that opens the draft on the drafts page; drafts of other people are never included in this search, even if you would be allowed to see them.
Check the name of the application
Section titled “Check the name of the application”On the consent page and in the list, the note “Name not verified” appears next to the name. This is meant seriously: the name is supplied by the application itself — a foreign application could equally call itself “roleALPHA Support”.
Only allow access if you have just started the connection yourself. If you receive a consent page or a notification without having done anything, click Deny and report it to your administration.
Disconnecting
Section titled “Disconnecting”Under Profile → Connected applications you can disconnect any connection with one click. This takes effect immediately, including on a session currently in progress — not only the next time the application starts.
Your administration can also disconnect connections and switch the feature off for the entire tenant.
What is logged
Section titled “What is logged”Every call made by your connected application is recorded: tenant, person, name of the application, the function called, the time and the outcome. Calls that change something are additionally listed in the change history. This serves accountability towards your organisation — no content of your questions is stored.
Nor the values the application passes in. Of the call itself, the change history keeps only which fields were involved, not what they contained — First name: Anna therefore becomes First name plus the note “text, 4 characters”. The values stay with the responsible data node, which logs them in full anyway.
Where your data flows in the process
Section titled “Where your data flows in the process”What your AI application does with the data it reads is decided by that application, not by roleALPHA. If it sends content to an AI provider, this happens outside the platform and on the basis of the contract your organisation or you have with that provider. So only connect applications whose use your organisation permits.
Naming an application on this page is not a recommendation — which applications may be used is decided by your organisation.