Connect your AI assistant to Sedna

Give Claude, Microsoft Copilot, ChatGPT and other AI assistants secure, scoped access to your Sedna workspace over MCP.

Sedna's MCP server lets AI assistants such as Claude, Microsoft Copilot and ChatGPT work directly with your Sedna workspace. Ask a question in your assistant and it pulls up a contact, gathers everything filed against a voyage, reads an attachment, or searches your team inboxes, then answers in context.

It uses the open Model Context Protocol, so any MCP-compatible assistant can connect. Nothing is copied out of Sedna: the assistant queries your workspace live.

What it can do

  • Read messages and full email bodies, teams, users, contacts, job references, category tags, and attachments, including authenticated download links.
  • Summarise a job reference, returning activity, key participants, tags applied and recent traffic, in a single request.
  • File and classify by applying category tags to a message and linking job references to it, so what the assistant finds gets filed where your team will find it again.
  • Search your mail, with full-text search across sender, recipient, subject, body, dates, attachments, tags and job references. Part of the Enhanced MCP Server.

It cannot send email, or delete, archive, move or edit a message. See the capability reference for the full list.

📘

Enhanced MCP Server

Message search is part of the Enhanced MCP Server. Everything else on this page works on the standard product. To trial Enhanced or get pricing, speak to your account manager or customer success manager.


What you control

Before connecting anything, it's worth knowing what you can restrict. Three controls sit with you, and one is a request to us.

1. Scope it to each person's own teams

Where your assistant lets you set custom headers, add:

X-Sedna-User-Email: [email protected]

Sedna then narrows every response to the teams that person belongs to. It applies to message reads, search results, and attachment downloads alike, and it stacks on top of the exclusions below rather than replacing them. If the address doesn't match a Sedna user, or that user has no teams left after exclusions, the assistant gets nothing rather than everything.

This is the tightest configuration available and we'd recommend it for any per-person deployment, where each colleague's own configuration file carries their own address. Note that the header is supplied by the assistant rather than verified against your credential, so use it where you control the configuration; it's a way to keep each person's assistant to their own teams, not a barrier against a tool deliberately configured with someone else's address.

2. What the credential is allowed to do

The connection uses an API credential issued to your organisation, and you choose its permissions when you create it, per API and per operation. Credentials also carry an expiry of up to a year and can be revoked at any time. See API Credential Management & OAuth Authentication for how to create, scope and revoke them.

For the Sedna MCP server, these are the permissions to grant:

APIReadWriteNeeded for
Message✓optionalReading messages and email bodies. Add Write only if you want the assistant to apply tags and job references
Category Tag✓Listing your tag vocabulary
Job Reference✓Voyages, bookings and deals, and their message history
Team✓Listing teams
User✓Looking up colleagues, and per-user scoping
Contact✓Address book lookups
Document✓Attachment details and download links

Leave everything else unselected. No Delete permission is needed for any Sedna MCP feature. Grant Read only and you have a strictly read-only assistant: the two filing tools will return a permission error and nothing in Sedna changes. Note that Message Write is a general API permission covering message creation too, so grant it only if you want the filing tools.

Message search additionally requires the Search permission, which comes with the Enhanced MCP Server. Your account manager or CSM can arrange it.

3. Personal inboxes are always excluded

Solo (personal) inboxes are never returned by the MCP server, whether in message results, search results or attachment downloads. This applies regardless of credential permissions and isn't something you need to configure.

4. Teams you want kept private

If there are teams the assistant must not read, send the team names to [email protected] before you go live and we'll exclude them server-side, including any documents attached to their messages. These exclusions always apply, even when per-user scoping is in use.


Before you connect

  1. Find your tenant name. It's the first part of your Sedna web address. If you use maritimedemo.sednanetwork.com, your tenant name is maritimedemo.
  2. Create an API credential. In Sedna, go to Settings → API Credentials Management and create a credential with the permissions above. You'll get a Client ID and Client Secret. The Secret is shown only once, so store it safely. If you don't see that page, an IT Support user needs to enable the Manage API Credentials role on your profile; the credential management guide covers this.
  3. Send us any teams to exclude, and decide whether you're scoping per user, as described above.

Connect your assistant

Every method needs the same server address:

https://sednamcp.com/mcp

Then choose how your assistant authenticates:

MethodYou needUse it when
Client ID and Secret (recommended)Tenant name, Client ID, Client SecretYour assistant supports MCP or OAuth natively, such as Claude, ChatGPT, Copilot Studio, Cursor or VS Code
Basic auth (API key)Tenant name and an API key from Sedna SupportYour tool authenticates with custom headers rather than OAuth

The Client ID and Secret method uses OAuth 2.0. It's self-service and issues short-lived tokens that refresh automatically, which is why we recommend it. Basic auth works equally well where that's what your tool supports. Request a key from [email protected], and store it as you would any other credential.

📘

Include the /mcp

The address must end in /mcp. https://sednamcp.com on its own will not connect.

Claude (web and Desktop)

  1. Open Settings → Connectors and choose to add a custom connector.
  2. Enter https://sednamcp.com/mcp as the server URL.
  3. Claude opens the Sedna connect page. Enter your tenant name, Client ID and Client Secret.
  4. You're returned to Claude, connected. The Sedna tools appear in the connector's tool list.

No configuration file needed. To use an API key, or to scope the connection to one person's teams, see Tools that use a configuration file below.

Microsoft Copilot Studio

Use the built-in MCP connector:

  1. Open your agent and go to the Tools page.
  2. Select Add a tool → New tool → Model Context Protocol.
  3. Fill in the server details:
FieldValue
Server nameSedna
DescriptionSearch messages, look up contacts, find job references and access team inbox data in Sedna
Server URLhttps://sednamcp.com/mcp
  1. Set Authentication type to OAuth 2.0 and OAuth type to Dynamic discovery.
  2. Select Create, then Create a new connection.
  3. On the Sedna connect page, enter your tenant name, Client ID and Client Secret.
  4. Back in Copilot Studio, select Add to agent.

Dynamic discovery lets Copilot Studio configure the OAuth endpoints itself. If your environment doesn't complete discovery, you can supply the authorization and token URLs manually. Contact [email protected] for the values.

Copilot Studio via Power Apps custom connector

Use this only if the MCP connector above isn't available in your environment. It's also the route to take if you want to pass the signed-in user's address for per-user scoping.

  1. On the Tools page, select Add a tool → New tool → Custom connector. You'll be taken to Power Apps.
  2. Select New custom connector and import the schema below.
  3. Enter your tenant name and API key when prompted, then select Continue.
swagger: '2.0'
info:
  title: Sedna MCP Server
  description: MCP Server for Sedna API integration
  version: 1.0.0
host: sednamcp.com
basePath: /
schemes:
  - https
consumes:
  - application/json
produces:
  - application/json
securityDefinitions:
  api_key:
    type: apiKey
    in: header
    name: X-Sedna-Api-Key
  tenant:
    type: apiKey
    in: header
    name: X-Sedna-Tenant
security:
  - api_key: []
    tenant: []
paths:
  /mcp:
    post:
      summary: MCP Endpoint
      x-ms-agentic-protocol: mcp-streamable-1.0
      operationId: InvokeMCP
      responses:
        '200':
          description: Success

This route uses an API key rather than a Client ID and Secret. Request one from [email protected]. To scope results per user, add X-Sedna-User-Email as a further header and populate it with the signed-in user's address.

VS Code and Cursor

In VS Code, create .vscode/mcp.json in your workspace. In Cursor, use Settings → MCP.

{
  "servers": {
    "sedna": {
      "type": "http",
      "url": "https://sednamcp.com/mcp",
      "headers": {
        "X-Sedna-User-Email": "[email protected]"
      }
    }
  }
}

On first connection your editor opens the Sedna connect page for your tenant name, Client ID and Client Secret, then handles tokens from then on. The user-email header is optional. Omit it and the assistant sees every team it has access to. Cursor uses the same structure under an mcpServers key.

Claude Code

claude mcp add --transport http --scope user sedna https://sednamcp.com/mcp \
  --header "X-Sedna-User-Email: [email protected]"

Claude Code prompts for authorization on first use. Drop the header to give the connection access to every team. To use an API key instead, add --header "X-Sedna-Tenant: your-tenant-name" and --header "X-Sedna-Api-Key: your-api-key".

Tools that use a configuration file

For Claude Desktop's claude_desktop_config.json and similar files, using an API key. Requires Node.js.

{
  "mcpServers": {
    "sedna": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://sednamcp.com/mcp",
        "--header", "X-Sedna-Tenant: ${SEDNA_TENANT}",
        "--header", "X-Sedna-Api-Key: ${SEDNA_API_KEY}",
        "--header", "X-Sedna-User-Email: ${SEDNA_USER_EMAIL}"
      ],
      "env": {
        "SEDNA_TENANT": "your-tenant-name",
        "SEDNA_API_KEY": "your-api-key",
        "SEDNA_USER_EMAIL": "[email protected]"
      }
    }
  }
}

Keeping credentials in env rather than inline makes them easier to rotate. Each person's own file carries their own address, which is the simplest way to keep every assistant to its user's teams. Remove the user-email lines to give the connection access to every team.

Any other MCP-compatible tool

Enter https://sednamcp.com/mcp as the server URL. If the tool supports OAuth it will open the Sedna connect page automatically. Otherwise add these headers:

HeaderValue
X-Sedna-TenantYour tenant name. Required with an API key
X-Sedna-Api-KeyYour API key. Required with an API key
X-Sedna-User-EmailOptional. Scopes results to that person's teams

Check it works

Ask your assistant:

"List my Sedna teams"

You should get your team names back, and if you're using per-user scoping, only the teams that person belongs to. That confirms authentication, permissions and scoping in one call, on every tier. Then try something real:

  • "Summarise everything filed against job reference [your reference]"
  • "Who at [company] is in our contacts?"
  • "What attachments came in on [message]?"
🚧

Check before you act

AI assistants can be wrong, including about your Sedna data. Verify anything you'll act on commercially.


Capability reference

Once connected, your assistant can use these tools.

What you can ask forToolsNotes
Find messagessearch_messagesEnhanced only. Full-text across sender, recipient, subject, body, dates, attachments, tags and job references
Read a messageget_messageFull HTML body, not just the summary
Work with attachmentsget_message_attachments, get_document_details, download_documentInline images filtered out; download links are authenticated and checked against team exclusions and per-user scoping
Follow a voyage, booking or dealget_job_references, get_job_reference_by_id, get_job_reference_messages, get_job_reference_summaryget_job_reference_summary returns statistics, participants, tags and recent activity from the latest 50 messages in one call
Browse by classificationget_category_tags, get_category_tag_by_id, get_messages_with_category_tagYour own tag vocabulary, such as Urgent, Charter Party or Invoice
Look up peopleget_contacts, get_contact_by_id, get_users, get_user_by_idAddress book and internal users; search by name, email or company
Look up teamsget_teams, get_team_by_idExcluded teams and solo inboxes never appear; per-user scoping narrows this further
File and classify mailadd_category_tag_to_message, add_job_reference_to_messageNeeds Message write permission on the credential. Both are reversible in Sedna

List tools return summarised fields with pagination to keep responses inside the assistant's context window. Use the matching get_..._by_id tool for the full record.


Troubleshooting

What you seeWhat to do
missing_credentials or "Unauthorised"Supply either a Client ID and Secret or an API key. With API keys, both headers are required and neither can be truncated.
ambiguous_credentialsYou've sent an API key and a Client ID and Secret. Use one or the other.
invalid_tenant_formatUse the tenant name only: letters, numbers, hyphens or underscores. Not the full URL.
user_not_found_in_tenantThe address in X-Sedna-User-Email doesn't match a Sedna user. Check it against the user's Sedna profile, including their SSO address.
Empty results, but the connection worksIf you're using per-user scoping, that person may have no teams left once exclusions are applied. Check their team memberships in Sedna.
Connects, then no tools appearConfirm the address ends in /mcp, then restart your assistant so it re-reads the tool list.
"Search is not enabled"Message search is part of the Enhanced MCP Server. Speak to your account manager or CSM about a trial. Meanwhile the assistant can still browse by team, tag or job reference.
Permission errors on some requestsYour credential may not have the permissions in the table above. Check it in Settings → API Credentials Management; permissions can't be edited after creation, so create a new credential if needed.
Stopped working after monthsCredentials expire after up to a year. Check the credential's status in Settings → API Credentials Management and create a replacement if it's expired.
Was working, now "invalid session"Disconnect and reconnect the integration to re-authenticate.
Truncated or partial resultsLarge responses are trimmed to keep the assistant responsive. Narrow the request with a date range, a team or a tag.
Team or user changes not reflectedTeam and user details are cached for about five minutes. Wait and retry.
Connect page won't loadCheck your network allows sednamcp.com. If it's blocked, ask IT to allow it.
npx or Node not foundInstall Node.js, or connect with your Client ID and Secret instead, which needs no local tooling.

Still stuck? Contact [email protected] with your tenant name, the assistant you're using, and the exact error text.


Keeping it secure

  • Grant only the permissions in the table above, and no Delete permissions.
  • Where you can set headers, scope each person's assistant to their own teams with X-Sedna-User-Email.
  • Treat a Client Secret or API key like a password. Don't paste it into shared documents or commit it to a repository.
  • Create a separate credential per assistant, so you can revoke one without affecting the others.
  • Connect only assistants your organisation has approved.
  • If a credential may be exposed, revoke it in Settings → API Credentials Management, or contact [email protected] for API keys.