Overview: An MCP server lets AI tools like Claude connect to Active and read (or, where allowed, change) your firm's data on your behalf, using user's own Active permissions and licensing. This guide walks you through enabling access in Active and connecting your firm's AI tool of choice.
Please refer to the Glossary for definitions of key terms used in this article.
Before you start
Three things need to be in place before you begin:
Active AI licensing for your firm, and the Active AI module ticked for the users who need it.
Active administrator access to user and license management. The AI Seetings screen is Owner only, so if you are an adminstrator rather than an Owner you will need an Owner for that part.
Admin access in the tool you are connecting, for example, organisation admin in Claude if you are installing our Claude plugin. That is a separate role from your Active admin role.
Step 1: Enable Access in Active
Whatever tool your plan to use, start here.
To access the MCP server, you must do the following things:
License Relevant Users
In user and license management, ensure that relevant users have Active AI ticked. If you do not see the Active AI module then you are not currently licensed for Active AI, please contact sales to discuss licensing.
Enable the MCP Server
In the Admin Centre, navigate to AI Settings, under Active AI.
Here you can enable the MCP server and define access levels.
MCP access is a Preview feature. Read the terms on that screen before you tick the box, because you are confirming that you are authorised to approve Preview access for your firm. Two points are worth calling out.
Enabling MCP access starts an MCP server that lets third-party AI tools, or anyone able to reach it with valid credentials, read your firm’s data, and change it where write tools are allowed.
Access is governed only by the allow and deny lists on that screen, and keeping those accurate is your firm’s responsibility.
Tool access still respects each user’s own Active permissions and licensing. A user cannot reach anything through the MCP server that they could not reach in the product.
Set the Access Level
The same screen controls what connected tools are allowed to do. Only an Owner can change these settings.
Default access level is the main choice, and it applies to everything unless you say otherwise.
Read-only: assistants can view firm data but cannot change anything.
Read and Write: assistants can also create, update and action records.
Tool overrides are the exceptions. Leave both lists empty unless you need one.
Always allowed: permitted even when the default is read-only.
Always blocked: blocked even when the write access is on.
Search for a tool by name to add it to either list. Tool names follow the pattern active-group-verb. For example, active-documents-documents-search.
Step 2: Connect your tool
How you connect depends on what your firm uses. Pick the one that applies, you do not need the others.
Claude: install our plugin. Do not add the MCP server by hand, the plugin sets up the connection for you and brings our skills with it.
Microsoft 365 Co-pilot: see below.
Anything else: Connect to our server directly using the details below.
Claude
In addition to the MCP server, our Claude plugin includes a range of skills designed to help you with common client query management and filling workflows. If your organisation is using Claude, we recommend using this, as it bundles everything you need.
You will need to be an appropriate organisation admin in Claude to perform these actions.
Add the Active Platform Marketplace
Go to Customise, select Plugins, and then click Add.
Then, click Add marketplace.
For the URL, set the below value:
https://github.com/Active-Platform/active-claude-marketplace
Leave Sync automatically on so the plugin stays up to date as we release changes.
Enable the Plugin
Once the marketplace is added, you can then go to organisation settings, then Plugins tab (left-hand side), and under Active-Platform/active-claude-marketplace you can ensure the Active Platform plugin is 'Available to Install' for all users.
After this, users can go to plugins and find the Active Platform available to add.
In some situations an administrator will need to open the plugin and connect the MCP server from there. Open the plugin, go to the Connectors tab, and confirm that active-mcp shows as Connected.
Microsoft 365 Copilot
There are two ways to connect Copilot to our MCP Server. Which one you want depends on whether you are connecting a single agent or registering Active across your whole tenant. Both are Microsoft screens, so they may look slightly different as Microsoft changes them.
Copilot Studio, One Agent at a Time
Use this if someone in your firm is building an agent in Copilot Studio and wants it to reach Active. You need to be able to edit that agent.
Open your agent, go to Tools, then Add a tool, New tool, and pick Model Context Protocol.
For Server URL enter https://mcp.businessfitness.com. Name it Active, and write a short description of what it does, something like "Active practice management: clients, documents and workpapers". Copilot reads that description to work out when to call us, so it is worth a sentence.
For authentication choose OAuth 2.0, then Manual. Do not pick Dynamic discovery or Dynamic. Both of those ask our server to hand out credentials on the fly, which is not how ours works, so they will not connect.
Manual asks for a handful of values. They are the same for every firm, so type them in exactly as below.
Client ID: active-mcp-server
Client secret: leave this blank. Our server does not use one.
Authorization URL: https://identity.businessfitness.com.au/connect/authorize
Token URL Template: https://identity.businessfitness.com.au/connect/token
Scopes: mcp-api core.read core.write documents.read documents.write offline_access
Click Create, then Next, then Create a new connection, and finally Add to agent.
After you click Create, Copilot Studio shows you a Redirect URL. Send that to us. We have to add it at our end before the sign-in will work.
Sign in with your own Active credentials when prompted. Everyone using the agent signs in as themselves, so their own Active permissions still apply.
Tip: For more information, see article Connect your agent to an existing MCP server for a walkthrough from Microsoft.
Microsoft 365 Admin Centre, Whole Tenant
Use this if you want Active registered once and governed centrally, so approved agents across your tenant can use it. Two things to know before you start. Microsoft has this in Preview, and the first step is a command-line registration, so it is a job for your IT provider or in-house developer rather than a practice administrator.
A developer registers our server with the Agent 365 CLI, supplying the server URL and the authentication type. The type to use is ExternalOAuth, and the values it needs come from us, so ask us before they run the registration.
The request then shows up in the Microsoft 365 admin centre under Agents, Tools, Requests. An AI admin or Global admin reviews it, clicks Approve, and consents to the Microsoft Entra permissions it asks for. It is not usable until that consent is given.
Allow up to 30 minutes for it to appear everywhere in the tenant.
Microsoft’s preview currently covers Copilot Studio, Visual Studio Code, Claude Code and the GitHub Copilot CLI. It does not yet cover Microsoft 365 declarative agents.
Tip: For more information, see article Manage tools for agents, bring your own MCP server for a walkthrough from Microsoft.
If you would rather we walked you through either route, get in touch and we will do it with you.
Any Other Agentic Tool
Our MCP Server is available in most agentic systems at:
https://mcp.businessfitness.com
The server authenticates each individual user with their own Active credentials, so every action is attributed to the person who performed it rather than to a shared service account.
If the tool you are connecting asks how it should register with our server, pick Client ID Metadata Documents (CIMD) if you are offered it. There is nothing for you to set up and no client ID or secret to enter. If CIMD is not on the list, get in touch before you go further and we will sort the sign-in details out with you.
Step 3: Whitelist Domains
If the tool you are using has an outbound domain allowlist, allow the domains below. This gets you the best experience out of our MCP Server, and in particular it is what makes document upload and download work.
*.businessfitness.com: Active platform and MCP server endpoints. The wildcard covers subdomains.
*.businessfitness.com.au: The .com.au equivalent, for AU-hosted endpoints.
adocssharedprd.blob.core.windows.net: Active Documents storage. Needed for document download and upload.
dvexportsprd.blob.core.windows.net: Dataverse export storage. Needed for data exports.
Where to Add Them in Claude
In organisation settings, navigate to Capabilities. Type each domain into the Additional allowed domains field as example.com or *.example.com and click Add. Only an organisation admin can change this list.
We recommend leaving the allowlist mode on Package managers only and adding the four domains above explicitly. That gives Claude what it needs to install packages and reach our storage, without opening up general outbound access.
Related Settings
Two settings on the same screen decide whether the skills work at all.
Cloud code execution and file creation: lets Claude run code and create or edit documents, spreadsheets, presentations and PDFs. Our skills need this. With it off, they will not run.
Allow network egress: lets Claude install the packages and libraries it needs for data analysis, custom visualisations and specialised file processing. With it off, package installs fail and the allowlist above has nothing to apply to.
Note: Network egress controls and the domain allowlist apply to the code sandbox. They do not apply to MCP connectors, web search or web fetch. Turning network egress off does not fence off an MCP server, so do not rely on it as your control over MCP access. Control that in Active, under Active | AI Settings.







