Skip to main content
EUM’s MCP server lets an AI assistant (Claude, ChatGPT, and any MCP-compatible client) talk directly to EXTRACTOS EUM®. Instead of pasting keys or tokens, you click Connect / Authenticate, sign in to EUM once, and your AI is connected with exactly your account’s permissions. Connector URL: https://mcp.extractoseum.com/mcp Type: Integration. Audience: consumers, retailers, and sellers using an AI. Status: v1 (2026-08-31, verified end-to-end). Prefer machine-to-machine with an API key? That’s a different surface — go to API and Automation. MCP is for people using an AI; the API is for systems.

What it is (and why you don’t handle tokens)

MCP (Model Context Protocol) is the standard AI assistants use to connect to external services via tools. EUM’s server speaks that protocol, so your AI can verify a COA, search a product, or build a cart as real actions — not as made-up text. Authentication is «Sign in with EUM» (OAuth 2.1), just like signing into an app with your Google account. You never copy or paste a token. You click connect, sign in with your usual EUM account (OTP / magic link / password), approve the permissions, and you’re done. Your session stays alive on its own — it won’t ask you to log in again every hour.

How to connect

  1. In your AI client, add a connector / MCP server by URL: https://mcp.extractoseum.com/mcp
  2. The client shows a Connect / Authenticate button (it appears on its own, via the server’s OAuth discovery).
  3. Click it to open EUM sign-in. Sign in with your account (or create one if you’re new).
  4. You’ll see a consent screen with the permissions being granted. Approve it.
  5. You’re back in your AI, connected. Your account’s tools are ready to use.
Every tool activates after the single sign-in above (one click on “Authenticate”; no tokens to copy). Your account decides which tools you see — there is no anonymous mode for now.

What your AI can do

Permissions are auto-detected from your account at sign-in: if you’re a Collective retailer, you get the retailer tools; if you’re a marketplace seller, the seller tools; and everyone gets the consumer tools. One account can hold several roles at once.

Base — any user (verification, knowledge and docs)

Your account — any signed-in user

Collective retailer — if your account has a store

Marketplace seller — if you publish products on EUM


Security

  • OAuth 2.1 with PKCE — the modern standard. EUM’s server is the authority; your AI never sees your password.
  • No tokens to handle — you don’t copy, paste, or store keys. Everything goes through sign-in.
  • Visible permissions — the consent screen shows exactly what’s granted, before you approve.
  • Session that persists — your connection securely refreshes itself; it won’t log you out hourly.
  • Revocable — you can disconnect the connector anytime and the session dies.
  • The server doesn’t replace the controls — every purchase, cart, or mutation still goes through the same backend business rules (minimums, availability, data ownership). The permission only enables; the backend decides.

If it stops responding

Sometimes your AI stops seeing EUM’s tools — almost always right after we update the connector. It’s not an error with your account or your connection: the client (Claude, etc.) loses the session and the server has to be re-registered. What to do:
  • Re-enable EUM in THIS chat’s connectors (at the conversation level, not your organization’s — that’s already fine), or
  • Start a new conversation with EUM selected, which arrives with a fresh tool manifest.
The connector re-registers on its own within a couple of minutes.

Compliance

The compliance tools (compliance_guide, compliance_area) exist so your AI can answer about how to operate legally — not to claim effects. EUM positions its products as food / supplement, never as medicine, and neither the tools nor the answers make claims about effects or medical properties. If your AI drafts copy or messages, that’s the line: describe what the product is (COA-verified composition), never what it produces.
The API key path (machine-to-machine, signed webhooks) stays live for lab systems and sellers integrating server-to-server: go to API and Automation. MCP is additive, it doesn’t replace it.