> ## Documentation Index
> Fetch the complete documentation index at: https://developer.jobmojito.com/llms.txt
> Use this file to discover all available pages before exploring further.

# JobMojito MCP server

> Connect an AI agent to JobMojito over the Model Context Protocol (MCP): endpoint, Supabase OAuth sign-in, and merchant scoping.

The **JobMojito MCP server** exposes the JobMojito hiring platform — interviews, candidates, invitations, pre-screening, knowledge bases, analytics — plus documentation search as **[MCP](https://modelcontextprotocol.io) tools**. Point any MCP-capable client (Claude, or your own agent built on an MCP SDK) at it and the model can create interviews, invite candidates, pull results, and search these docs on your behalf.

Every tool runs **as the signed-in user**: the server forwards your Supabase access token to the JobMojito API on each call, so results respect your own permissions. Listing the available tools works without signing in, so a client can show you what the server does first — but **calling** any tool requires a signed-in token. See [Data & privacy](/mcp/data-and-privacy) for exactly what is and isn't exposed before sign-in.

<Note>
  The MCP server is a convenience layer over the same [HTTP API](/how-the-api-works). For server-to-server integrations you usually want the API directly with a bearer token; use MCP when an **AI agent** should drive JobMojito interactively.
</Note>

## Endpoint

Connect your MCP client to:

```text theme={null}
https://mcp.jobmojito.com/mcp
```

It speaks **Streamable HTTP** and is served directly (not behind a proxy auth gateway) so it can carry your Supabase token end to end.

## Authentication (Supabase OAuth)

The server is an OAuth **resource server**; the authorization server is the JobMojito Supabase project. On first connection your client runs the standard OAuth flow:

1. The client discovers the auth server from `https://mcp.jobmojito.com/.well-known/oauth-protected-resource/mcp`.
2. You're sent to the JobMojito sign-in / consent screen (hosted by Supabase at `app.jobmojito.com`) to log in and approve access.
3. The client receives a token and attaches it to every MCP request.
4. The server forwards that token to the JobMojito API for each tool call.

If a tool returns an authentication error (`401` / `invalid_token`), the session isn't signed in — re-authorize the connection and retry. See [Authentication](/authentication) for how tokens map to environments and permissions.

### Before you connect

An agent with a signed-in connection can read candidate records, transcripts and scores, and that content is processed by whichever AI provider you connect. Read [Data & privacy](/mcp/data-and-privacy) before pointing this at a production account, and [Responsible use](/mcp/responsible-use) for the human-review and candidate-disclosure obligations that apply to AI in hiring.

## Connect your agent

Pick your platform for step-by-step setup. Every path uses the same endpoint (`https://mcp.jobmojito.com/mcp`) and the OAuth sign-in above — no API key.

<CardGroup cols={2} />

## Merchant scoping

Most tools accept an optional `merchant_id`. Omit it to act on your **own** account; set it to act on behalf of a merchant you manage (agencies, resellers, sub-accounts).

* MCP clients that can render UI get an interactive **`jobmojito_configuration`** picker — a searchable list of merchants. Pick one and it's applied to subsequent calls.
* Clients that can't render UI use **`list_my_merchants`** (plain text, supports a `search` filter) and then pass `merchant_id` explicitly.

## Availability

`GET https://mcp.jobmojito.com/healthz` returns a small JSON status document and never touches the upstream API — point an uptime monitor at it rather than at `/mcp`.

## What's next

* [Tools reference](/mcp/tools) — the full tool inventory and the recommended docs-first calling pattern.
* [Responsible use](/mcp/responsible-use) — human review, candidate disclosure, and what not to automate.
* [Data & privacy](/mcp/data-and-privacy) — what an agent can reach, and where that data goes.
* [Identifiers & admin links](/mcp/identifiers) — what each id means, which field wants it, and how to build admin app links. Read this if the model gets ids wrong.
* [Skills](/skills/overview) — reusable patterns and best practices for building reliable agent workflows on top of these tools.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.