Lab08 MCP
Last updated: 14 September 2026
What is Lab08 MCP
Lab08 MCP is a remote MCP server operated by Lab08. It gives MCP clients the same product surface the Lab08 web app uses: search the pipeline, read a company’s workspace files, upload documents, move deals through stages, start outside-in due diligence, and put questions to the per-company Lab08 agent.
The server speaks Streamable HTTP and authenticates with OAuth 2.1 (authorization code + PKCE). When a client connects for the first time, it discovers the sign-in flow automatically and opens your browser to sign in with your Lab08 account — no API keys, no manually pasted tokens.
The one value you may have to supply yourself is the OAuth client ID: lab08-mcp.
Clients that register themselves with the server pick it up automatically; clients that ask for
a client ID in their connector settings need that value entered by hand.
Everything a connected client can read or change is exactly what your own Lab08 account can read or change. Access is confined to your workspace, and no tool on this surface can delete anything.
- Read. Pipeline search, company profiles, every workspace file section, due-diligence progress, saved agent conversations.
- Act. Add companies, upload documents, move stages, assign leads, review evidence, link findings to observations.
- Analyze. Start outside-in due-diligence scans and reason over a company’s workspace with the Lab08 agent.
Lab08 MCP implements the Model Context Protocol’s Streamable HTTP transport and OAuth 2.1 resource discovery. See the MCP specification and RFC 9728. The endpoint is:
https://api.lens.lab08.com/mcp
No destructive tools. Nothing in the catalog can delete data — removing files or companies is reserved for the Lab08 web app.
Available tools
Thirty-six tools, grouped by what they touch. Most are read-only; write tools are marked. There is no delete — files uploaded over MCP can only be removed in the Lab08 web app.
Long-running work returns immediately. chat_with_company and
start_company_outside_in_dd dispatch work and hand back an id; the answer arrives
through their paired read tools, get_lens_response and
check_company_dd_progress. A running status is normal — ask your client to check
again rather than treating it as a failure.
Workspace and identity · 2
-
whoami— Read. The workspace and user your session is signed in as. A natural first call. -
list_users— Read. The members of your workspace — the pool a company’s lead is drawn from.
Companies and pipeline · 6
-
list_companies— Read. Search and page through the companies in your pipeline; filter by name, stage, lead, or country. -
get_company— Read. One company’s full profile, including its current pipeline stage. -
list_company_statuses— Read. The pipeline stages configured for your workspace — read these before moving a company. -
create_company— Write. Add a company from a website or a pitch-deck PDF; Lab08 starts its automated overview and product scan. set_company_status— Write. Move a company to another pipeline stage.set_company_lead— Write. Assign the team member who owns the deal.
Files and evidence · 22
Sixteen of these list one workspace section each — there is no all-files tool, so ask for the section you want. Results are paged; large sections come back in batches.
list_company_evidence— Read. Evidence files captured for a company.-
list_company_observations— Read. Observations — analyst findings recorded on a company. -
list_company_outside_in_assessment— Read. Results of Lab08’s outside-in assessment. -
list_company_tech_dd_overview— Read. Technical due-diligence overview reports. -
list_company_uploaded_files— Read. Documents your team uploaded — decks, memos, data-room files. list_company_emails— Read. Email correspondence stored on the company.list_company_dms— Read. Direct-message threads stored on the company.-
list_company_meetings— Read. Meeting records — calendar details only; transcripts have their own tool. -
list_company_meeting_transcripts— Read. What was actually said in the meetings. list_company_user_notes— Read. Your team’s notes on the company.list_company_context— Read. Lab08’s compiled company-context resources.-
list_company_technology_assessment— Read. Lab08’s technology-assessment reports — the dependency graph is separate. -
list_company_dependency_graph— Read. Code-dependency and license-risk graph reports. list_company_tech_moat— Read. Tech-moat and defensibility analyses.list_company_compliance_framework— Read. Compliance-framework assessments.-
list_company_team_files— Read. Profiles of the startup’s founders and key hires. -
get_company_file— Read. One file’s details and a download link; short text files are returned inline. upload_company_file— Write. Add a document to a company’s workspace.upload_company_files_bulk— Write. Add up to 20 documents in one call.-
set_company_file_status— Write. Approve or reject an Evidence or Observation file. link_evidence— Write. Link an Evidence file to the Observation it supports.unlink_evidence— Write. Remove that link — both files are kept.
Due diligence · 2
-
start_company_outside_in_dd— Write. Start an outside-in due-diligence scan; returns a run id. -
check_company_dd_progress— Read. Progress of a company’s due-diligence runs — the poll target for a started scan.
Agent chat · 4
-
chat_with_company— Write. Put a question to the company’s Lab08 agent; returns immediately with a session id. -
get_lens_response— Read. The agent’s answer to a dispatched question — poll until its status is ready. list_company_chat_sessions— Read. Past agent conversations for a company.-
get_company_chat_transcript— Read. A full saved conversation, oldest message first.
Supported clients
Lab08 MCP works with MCP clients that support Streamable HTTP and OAuth 2.1. Sign-in always runs
through your browser against your existing Lab08 account. Wherever a client asks for an OAuth
client ID, it is lab08-mcp.
Claude (web and desktop). Add it as a custom connector:
- Open Settings → Connectors in Claude (on the web: claude.ai/settings/connectors).
- Select Add custom connector.
- Enter the name Lab08 and the server URL below.
-
In the connector’s OAuth settings, enter the client ID
lab08-mcp. - Select Add, then Connect, and sign in with your Lab08 account in the browser window that opens.
- Lab08 tools now appear in the conversation’s tools menu; enable them per conversation as needed.
https://api.lens.lab08.com/mcp
Claude Code. Add the server from the command line:
claude mcp add --transport http lab08 https://api.lens.lab08.com/mcp
Then run /mcp inside Claude Code and pick lab08 to complete sign-in in
your browser.
Client interfaces change between releases — menu names and steps may differ slightly in your version. Hosted AI platforms other than Claude are not currently enabled for Lab08 MCP.
What you can ask
Once connected, plain requests route to the right tools. A few that work well:
- “Move Acme Robotics to Term sheet.”
list_companies→list_company_statuses→set_company_status - “What did the tech DD find on Globex?”
list_company_tech_dd_overview→get_company_file - “Upload this deck to Vertex Robotics and start an outside-in scan.”
upload_company_file→start_company_outside_in_dd→check_company_dd_progress - “Ask the Helix Bio agent whether the current team can ship the roadmap.”
chat_with_company→get_lens_response - “Which deals in Screening have no lead?”
list_companies
Security best practices
A connected client acts as you. It holds the same access as your Lab08 sign-in — your workspace, and only your workspace.
Verify the endpoint. The only Lab08 MCP endpoint is
https://api.lens.lab08.com/mcp. Treat anything else claiming to be Lab08 as
untrusted.
Access maps to your account. Sign-in is OAuth 2.1 against your existing Lab08 account; there are no shared keys. Every call is scoped to your workspace, and workspaces are isolated from each other at the database level. Disconnecting the connector in your client’s settings revokes its access.
Nothing here can delete. The catalog contains no destructive tools. Files uploaded over MCP can be reviewed or linked, but removing them — like every hard delete — is reserved for the Lab08 web app.
Keep a human in the loop. Leave your client’s tool-confirmation prompts on for write tools. Review what the model proposes before approving it.
Treat stored content as untrusted input. A company’s workspace holds third-party material — decks, emails, meeting transcripts. A crafted document could try to steer a model that reads it. That is another reason to confirm write actions rather than auto-approving them, and to prefer read-only sessions when you only need answers.
Troubleshooting
- The connector is added but sign-in never opens. Your client must support
OAuth 2.1 resource discovery (RFC 9728). Update the client, or connect through a bridge such as
mcp-remote. - Sign-in fails with an invalid or unknown client error. The client sent no
OAuth client ID, or one the server does not recognise. Enter
lab08-mcpin its connector settings. - 406 Not Acceptable from a custom client. Requests must send an
Acceptheader listing bothapplication/jsonandtext/event-stream. Responses arrive as server-sent-event frames. - 405 on GET or DELETE. Expected — the server is stateless and answers POST only.
- A chat or DD tool returns running. Not an error. The work was dispatched; poll
get_lens_responseorcheck_company_dd_progressuntil it completes. - 401 after a period of use. The token expired. Clients normally refresh on their own; if not, disconnect and reconnect the connector.
- Claude answers without using Lab08. Name the company or say “in Lab08” explicitly, and check the connector’s tools are enabled for that conversation.
Verify the endpoint is reachable.
curl -s https://api.lens.lab08.com/.well-known/oauth-protected-resource/mcp
Returns the server’s resource-metadata document — proof you are talking to the real endpoint before any sign-in.