An MCP server lets an AI tool, such as Claude Code, Cursor, VS Code, Codex or Claude, search your knowledge base and ask it questions while it works. Each knowledge base can have several servers, each with its own address and sign-in type.

Set up

1

Create a server

Open the knowledge base and go to Integrations → MCP Server. Under Create a server, type the end of the address (for example acme), pick a sign-in type and click Create. The address is then https://app.kelu.dev/mcp/acme.
2

Install it

Under Install it, pick your tool and copy the command or config. For an API key server it already contains your key.
3

Ask

Ask your tool a question about your product. It calls the Kelu tools when they help.
The end of the address is 3 to 63 characters: lowercase letters, digits and hyphens, not starting or ending with a hyphen. It must be unused by anyone else. The name and the sign-in type cannot be changed later; delete the server and create another.

Sign-in types

TypeForHow callers get in
API keyAgents and backends you runAuthorization: Bearer <client key> on every request. The key needs Allow MCP access
PublicYour readers, in their own editorSign in with Google or GitHub on first use. Each reader gets 60 requests a minute and 500 a day
InternalYour team, on an internal knowledge baseSign in with their Kelu account. Only members who can chat in the knowledge base. Each gets 60 requests a minute and 2,000 a day
  • A normal (external) knowledge base offers API key and Public. An internal one offers Internal only.
  • API key and Public servers never return restricted documents. Internal servers do.
  • Everyone using one API key shares its rate limit. Create a key just for MCP if you hand it out.
Allowed origins on a client key do not apply to MCP. A public key with Allow MCP access works from any MCP client. Turn MCP access off on a key that should only work on your own site.
No server yet? https://app.kelu.dev/mcp works with any client key that has Allow MCP access, sent as Authorization: Bearer, an X-Client-Key header or ?client_key=.

Tools

ToolInputReturns
search_<name>_knowledge_sourcesquery, optional limit (default 8, max 20)The best-matching passages, with titles and URLs
ask_questionquestionAn answer with citations
list_sourcesnoneThe knowledge base’s sources
feedbackmessage, optional urlRecords a wrong answer or missing documentation. Read reports in Traces
get_documentsurls (max 10)Whole pages, up to 20,000 characters each. Off by default, and not listed while off
The search tool is named after the knowledge base: one called “Acme API” publishes search_acme_api_knowledge_sources. search_docs also works. Tools take no knowledge base or group argument; the server’s address decides what it searches. ask_question stops after 90 seconds, search after 30 seconds, and the other tools after 10.

Install it

Copy the exact snippet from Install it in the dashboard. For reference:
claude mcp add --transport http acme https://app.kelu.dev/mcp/acme \
  --header "Authorization: Bearer kl_pk_..."
For a Public or Internal server, leave out the header. The tool opens a browser to sign in the first time.

One server for your whole team

https://app.kelu.dev/mcp/portal signs in a person rather than a knowledge base. It reaches every knowledge base that person may chat in, across all their workspaces, restricted documents included. It is Ask in your editor.
claude mcp add --transport http kelu https://app.kelu.dev/mcp/portal
On first use a browser opens on the Kelu sign-in page. Under Knowledge bases this editor may read, untick any you want to leave out, then click Connect. Access is checked on every request, so a permission change applies straight away.
  • Tools: list_knowledge_bases, search_docs, ask_question, list_sources, and get_documents where a knowledge base allows it. The search and ask tools take optional knowledge_base_ids, group_ids and source_ids to narrow the search.
  • Limits: 60 requests a minute and 2,000 a day per person.
  • Browser sign-in works for tools running on your own computer. A web-based client is refused unless Kelu has allowed its host.

Scripts and CI

A client that cannot open a browser uses a personal access token. Create one under Profile → Access tokens, then send it as a header:
claude mcp add --transport http kelu https://app.kelu.dev/mcp/portal \
  --header "Authorization: Bearer kl_pat_..."
A token is shown once. It never expires unless you choose an expiry, you can have 10 at a time, and revoking one takes effect at once. It works on /mcp/portal and on Internal servers.

Troubleshooting

  • 403 with MCP_NOT_ENABLED: the client key does not have Allow MCP access. Turn it on, or create a key with it.
  • 403 with KNOWLEDGE_BASE_INTERNAL: client keys do not work on an internal knowledge base. Use an Internal server or /mcp/portal.
  • The tool never calls Kelu: ask about your product by name. The knowledge base’s name is in the tool name and the server’s instructions, which is what the model reads.
  • get_documents is missing: it is off for this knowledge base.