Talavine includes a Model Context Protocol (MCP) server for supported external clients. It provides tools for searching connected accounts, opening source records, and performing authorized actions. Claude Desktop, Cursor, and Codex connect in one click from Talavine; other MCP clients take a short config entry. Installing Talavine does not give every chatbot access: you choose which apps connect.
Claude Code and Codex each ship a Gmail connector: one account, no shared context across providers. Talavine sits above that: a single MCP exposing every account you own with thread context, person history, commitments, and grounded facts already extracted.
Runs locally, stdio by default
The server is Talavine.McpServer, a small .NET process speaking MCP over stdio. Logging goes to stderr; JSON-RPC owns stdin/stdout. An optional HTTP mode listens on this computer only (loopback) and requires a bearer token. No remote service to trust.
Reads the same data the app reads
Points at the Talavine data directory (env var Talavine_DATA_DIR if you want to override). Per-account SQLite databases, knowledge-claim store, context-fact projections. The MCP server is a read & write surface over the same files the desktop app uses.
Tools, not endpoints
~40 typed MCP tools, organized by capability. Read tools are marked ReadOnly so agents that respect MCP semantics can run them without confirmation. Mutations land in a durable outbox and replicate to the provider on the next sync.
Tool catalog
What your agent can actually do.
The catalog is grouped by intent. Tools return JSON strings the model can consume directly; most read tools accept account scoping when you need it and span every account when you don't.
Context: the flagship
Tool
What it returns
get_context_pack
Query → source-grounded facts with confidence scores, citations, and a redaction level chosen by the caller (Internal, PeerShareable, ExternalTool).
get_thread_context
Thread → participants, action items, commitments, and a last-N message rollup. The thread is JWZ-stitched across References / In-Reply-To, not just subject-matched.
get_person_context
Person → relationship history across every connected account at once. Common topics, last interaction, response patterns.
get_company_context
Company / domain → who you talk to there, what about, and what's currently in flight.
Search & read
Tool
What it returns
search_messages
Full-text search across every account in one call. Returns matches with thread, account, and source-ref.
search_messages_semantic
Vector search over enriched message embeddings. Use when the caller doesn't remember the words.
find_related_messages
Given a message, find its semantic neighbors. Good for "what else like this?" follow-ups.
Inspect Talavine's internal agent profiles, swap roles, request a cycle. Useful when you're orchestrating Talavine from a larger agent system.
get_recent_journal · list_agent_proposals
Read what Talavine's own agents have been doing and what they want to propose. Audit trail in, audit trail out.
Wire it up
One click for Claude Desktop, Cursor, and Codex.
In Talavine, open Settings → MCP Connectors and click Connect next to the app under Use your data hub in other AI apps. Talavine adds itself to that app's settings; quit and reopen the app and it can search and read the profile you have open. That connection can't send email or change anything in Talavine, and you can disconnect at any time.
Claude Code and other MCP clients use the config entries below. Talavine installs the MCP server binary alongside the app, so each entry only points the client at it.
Claude Desktop
Edit claude_desktop_config.json (on macOS at ~/Library/Application Support/Claude/, on Windows at %APPDATA%\Claude\), then fully restart Claude Desktop. It uses the same shape as Claude Code:
The transport is plain MCP stdio; any client that speaks the protocol can launch the binary. The server identifies itself as Talavine v1.0.0 on handshake and advertises the full tool catalog from WithToolsFromAssembly().
Redaction levels
One server. Three audiences. Three views.
Context tools take a redaction level so the same query returns the right amount of data for the right caller. The trust boundary is encoded in the context pack itself, not negotiated out-of-band.
Internal
For Talavine's own agents running on your machine. Sees everything: durable memories, knowledge claims, life facts, contacts, and message bodies.
PeerShareable
For trusted peer replicas: your other devices running Talavine in peer-to-peer mode. Wider than ExternalTool but excludes the most sensitive personal facts unless explicitly opted in.
ExternalTool
For agents and MCP clients outside Talavine's trust circle. PII stripped, internal identifiers redacted, only fields you've approved for external use are returned. This is the default for unfamiliar clients.
Trust model
The data layer enforces what the prompt can't.
An MCP server is only as safe as what flows back through it. Talavine's data-layer guards are the reason exposing inboxes to a remote agent isn't a footgun.
Knowledge promotion is gatedA single inbound message can create a KnowledgeClaim but never a durable UserMemory. Promotion requires user-authored, trusted-contact, or corroborated status. Agent queries that read UserMemory can't be poisoned by a single hostile email.
Sources travel with factsEvery durable record carries a SourceRef: kind, account ID, record ID, excerpt, observed-at. An agent that returns a fact can always be asked to surface the message. No hidden provenance.
Deletion cascades or tombstonesDelete a message and registered IMessageDeletionObserver implementations dispatch cleanup. Derived data either disappears or tombstones with a recorded source-was-deleted reason. Stale data doesn't accumulate.
Suppression survives resetIf you reject a claim, a KnowledgeSuppression row blocks the system from relearning it from a future message. The agent can't talk you back into it by quoting a duplicate.
Routing respects privacy classesLLM calls Talavine makes on the agent's behalf go through ILlmRouter. Set PrivacyClass = LocalOnly on sensitive function types and prompts never leave the machine, enforced before any cost / quality advisor runs.
Plug it in
Download Talavine, connect your accounts, point your agent at the MCP.
Your agent now reads, queries, and acts across every inbox you own, with citations, redaction, and a memory layer that won't quietly drift.