How to connect an approved MCP client to Decoda with a signed-in user account.
MCP clients can connect to Decoda after a user signs in and approves the connection. The client receives short-lived access for the selected tenant, so it can only use the Decoda tools available to that tenant.Any AI assistant that supports MCP connectors can connect to Decoda — the steps below use Claude as the example, but the same connector URL works in other assistants.
Prerequisites: Use an MCP client that supports custom connectors and sign in with a Decoda account that has access to the tenant you want to connect.
Open the MCP client and choose the Decoda connection. The client opens a Decoda sign-in page if you are not already signed in.
2
Sign in if prompted
Sign in with your Decoda account. After sign-in, Decoda sends you to the connection approval screen for the same MCP client, so you can finish the request without starting over.
3
Review the request
Decoda shows the client name and the access it is requesting. Confirm that the client name is one you recognize. To allow access to settings that contain protected health information (PHI), select I have a Business Associate Agreement (BAA) with [client] and consent to PHI access for this MCP. Leave it clear to keep those settings unavailable to the client.
4
Approve the connection
Click Connect to Decoda. Decoda records your choice and sends you back to the MCP client.
A connected client can use Decoda’s MCP tools for the tenant included in the connection. Decoda checks the tenant on each request and blocks access to other tenants.Access tokens are short-lived. Decoda hides settings that contain PHI unless the user confirms the BAA and PHI option during connection. If a token expires, the client must send the user through the connection flow again.
The current MCP connection uses short-lived access tokens. A revoke request is recorded for audit history, but existing access tokens are not immediately invalidated yet. Tokens stop working when they expire.