Connect AI agents to databases, data warehouses, cloud storage, and SaaS apps to query, analyze, join, validate, and transform data across multiple sources.
Encrypted at rest, isolated from the model
Resolved from an AES-256-GCM vault at the moment of the call and attached to the request — the model never sees the secrets.
Try asking
Run a shell command in the persistent /workspace runtime. Use for all agent-side work: query authoring, analytics, DuckDB joins, workspace files, scripts, git, diagnostics, and cron. The `connection` and `cron` CLIs exist only inside this runtime and must be invoked through this tool.
List visible Marcopolo connections and their provider authorization state. Use only entries with `queryable: true` for `data_query`. Entries with `authorization_state: "authorization_required"` need user authorization from Connections in Marcopolo; follow `next_actions`. Capabilities and workspace paths describe supported commands for authorized connections.
Run a bounded governed query against a visible connection. Use this tool in generated code that re-queries live data at view or load time: Remote Artifacts, external web apps, scheduled scripts, and any other programmatic interface that fetches fresh data on each run. Do NOT use it for agent-side analytics or one-off snapshot visualizations — use the `workspace_shell` tool with the connection query CLI instead. Pass the full workspace-relative `query_file` path including the connection prefix, e.g. `connections/<name>/queries/<file>`. Paths resolve from `/workspace`, not from any current directory. Author new query files through `workspace_shell` before calling this tool so query text is durable and reusable. Returns `rows` as a parsed list of record dicts and `row_count` as the total — no JSON parsing needed. Results are capped by `max_rows` (1–5000).
Create a browser setup URL for a credentialed connection. Use a canonical `type` when known; otherwise pass `intent_text`. For hosted demo data with no credentials, use `install_demo_connection`.
Install hosted demo data with no user credentials. Pass a demo id or natural-language request. Use `connection_setup` for real user-owned connections.
One endpoint, the same key, whichever client you use.
~/Library/Application Support/Claude/claude_desktop_config.json (Mac) · %APPDATA%\Claude\claude_desktop_config.json (Windows)
Replace API_KEY with your own key.
Already have an "mcpServers" section in your config? Just add the server entry inside it.
Discovery, routing, credentials, tool scoping and execution logs all happen at the gateway→connections stay ACTIVE with no work from you
Marcopolo MCP runs through a gateway that holds the credentials, scopes the access and records every call.
Managed auth, hosted MCP servers, and every Gmail tool your agent needs.
Free to start.