Every AI tool needs an API token and your region's endpoint to connect to Fulcrum MCP. This article shows you how to get both, and how to control what your AI assistant can do.
Prerequisites
An organization on the Elite or Enterprise plan.
A role that includes the Manage API Tokens permission. See Role Permission Definitions.
Choosing which member creates the token
An API token has the same permissions as the member who creates it. Your AI assistant can see and change exactly what that member can.
Full access: Create the token from a member whose role covers all the work you want the assistant to do.
Limited access: Create the token from a member with a restricted role. See Limiting what your AI assistant can do.
Creating the API token
Follow these steps to create a token in the Fulcrum web app.
Sign in to the Fulcrum web app as the member you chose.
In the navigation pane, under Organization, select API.
Select New API Token.
In the Create a new API token dialog, enter a descriptive name in the Name field, such as AI assistant.
Review the Expiration setting. It is set to No Expiration by default.
Select Generate.
Copy the token and store it in a secure place, such as a password manager.
Expected outcome: The new token appears in your list of API tokens.
Keep your token private. Anyone with your token can view and change data in your organization with that member's permissions. Never share it in emails, chat messages, shared documents, or code that others can see.
After you create the token, add it and your region's endpoint to your AI tool's MCP settings. For the setup format, see Fulcrum MCP & AI Toolkit (Labs).
Finding your region's endpoint
Use the endpoint for the region where your organization is hosted. Your physical location doesn't matter. Your assistant won't connect if the endpoint doesn't match your organization's region.
Region | Fulcrum MCP endpoint |
United States (default) | |
Australia | |
Canada | |
Europe |
Limiting what your AI assistant can do
To control your assistant's access, create the token from a member with a restricted role.
Create a custom role with only the permissions you want the assistant to have. The role must also include the Manage API Tokens permission, so the member can create the token. Learn how in How can I create custom roles with specific access rights?
Assign the custom role to a member.
Sign in as that member and create the token.
Expected outcome: Your assistant can only do what the custom role allows.
Notes
Removing a member from your organization deletes their API tokens. Any AI tool using one of those tokens stops working until you connect it with a new token.
API tokens don't transfer when an organization moves to a different region. Create new tokens after the move.

