Lab08 MCP

Last updated: 14 September 2026

What is Lab08 MCP

Lab08 MCP is a remote MCP server operated by Lab08. It gives MCP clients the same product surface the Lab08 web app uses: search the pipeline, read a company’s workspace files, upload documents, move deals through stages, start outside-in due diligence, and put questions to the per-company Lab08 agent.

The server speaks Streamable HTTP and authenticates with OAuth 2.1 (authorization code + PKCE). When a client connects for the first time, it discovers the sign-in flow automatically and opens your browser to sign in with your Lab08 account — no API keys, no manually pasted tokens.

The one value you may have to supply yourself is the OAuth client ID: lab08-mcp. Clients that register themselves with the server pick it up automatically; clients that ask for a client ID in their connector settings need that value entered by hand.

Everything a connected client can read or change is exactly what your own Lab08 account can read or change. Access is confined to your workspace, and no tool on this surface can delete anything.

Lab08 MCP implements the Model Context Protocol’s Streamable HTTP transport and OAuth 2.1 resource discovery. See the MCP specification and RFC 9728. The endpoint is:

https://api.lens.lab08.com/mcp

No destructive tools. Nothing in the catalog can delete data — removing files or companies is reserved for the Lab08 web app.

Available tools

Thirty-six tools, grouped by what they touch. Most are read-only; write tools are marked. There is no delete — files uploaded over MCP can only be removed in the Lab08 web app.

Long-running work returns immediately. chat_with_company and start_company_outside_in_dd dispatch work and hand back an id; the answer arrives through their paired read tools, get_lens_response and check_company_dd_progress. A running status is normal — ask your client to check again rather than treating it as a failure.

Workspace and identity · 2

Companies and pipeline · 6

Files and evidence · 22

Sixteen of these list one workspace section each — there is no all-files tool, so ask for the section you want. Results are paged; large sections come back in batches.

Due diligence · 2

Agent chat · 4

Supported clients

Lab08 MCP works with MCP clients that support Streamable HTTP and OAuth 2.1. Sign-in always runs through your browser against your existing Lab08 account. Wherever a client asks for an OAuth client ID, it is lab08-mcp.

Claude (web and desktop). Add it as a custom connector:

https://api.lens.lab08.com/mcp

Claude Code. Add the server from the command line:

claude mcp add --transport http lab08 https://api.lens.lab08.com/mcp

Then run /mcp inside Claude Code and pick lab08 to complete sign-in in your browser.

Client interfaces change between releases — menu names and steps may differ slightly in your version. Hosted AI platforms other than Claude are not currently enabled for Lab08 MCP.

What you can ask

Once connected, plain requests route to the right tools. A few that work well:

Security best practices

A connected client acts as you. It holds the same access as your Lab08 sign-in — your workspace, and only your workspace.

Verify the endpoint. The only Lab08 MCP endpoint is https://api.lens.lab08.com/mcp. Treat anything else claiming to be Lab08 as untrusted.

Access maps to your account. Sign-in is OAuth 2.1 against your existing Lab08 account; there are no shared keys. Every call is scoped to your workspace, and workspaces are isolated from each other at the database level. Disconnecting the connector in your client’s settings revokes its access.

Nothing here can delete. The catalog contains no destructive tools. Files uploaded over MCP can be reviewed or linked, but removing them — like every hard delete — is reserved for the Lab08 web app.

Keep a human in the loop. Leave your client’s tool-confirmation prompts on for write tools. Review what the model proposes before approving it.

Treat stored content as untrusted input. A company’s workspace holds third-party material — decks, emails, meeting transcripts. A crafted document could try to steer a model that reads it. That is another reason to confirm write actions rather than auto-approving them, and to prefer read-only sessions when you only need answers.

Troubleshooting

Verify the endpoint is reachable.

curl -s https://api.lens.lab08.com/.well-known/oauth-protected-resource/mcp

Returns the server’s resource-metadata document — proof you are talking to the real endpoint before any sign-in.