This page is about the OAuth path. Workspace API keys are scoped to a single workspace by design — see Workspace API key for that path.
Just use workspace names
You don’t need to know any UUIDs. Ask the AI to list your workspaces once at the start of a session, then refer to them by name from then on:list-my-workspaces and gets back something like:
b8c2…, passes it as the workspaceId argument on the crm-search call, and you get the right result. No copy-paste, no config edit.
If you don’t ask first, the AI will call
list-my-workspaces itself the moment it needs to disambiguate. The explicit list-at-session-start trick is just a way to front-load the lookup so the first real request doesn’t pause to discover.Default workspace
If you don’t name a workspace in your prompt, the request uses the default — the one you picked on the consent screen when you first authorized. This is what makes casual use frictionless: most prompts don’t need to name a workspace at all. “Draft a reply to the latest email” uses your default. “…in Acme Sales” uses Acme. To change the default, revoke the grant from Settings → Connected apps and re-authorize — the consent screen lets you pick a different default.Discovering workspaces
Already covered above, but worth restating as a one-liner reference:list-my-workspaces returns name, UUID, and your role on each — useful for sanity-checking access after a permissions change.
Permissions
The OAuth grant does not expand what you can access. It inherits whatever workspace memberships your account already has — nothing more. If you ask a tool to act on a workspace you aren’t a member of, the worker returns:Advanced: hard-pin a workspace
Most users should ignore this section. The natural-language pattern above is the right default. If you have a specific reason to lock one MCP server entry to one workspace — e.g. a high-stakes prod workspace where you want a hard guardrail that cannot be inferred away by the AI — pin the workspace ID into the URL:workspaceId arguments are still respected (so the AI can broaden the scope), but if the AI omits the argument it goes to the pinned workspace, not your OAuth default.
Trade-off: you lose the fluid-multi-workspace property OAuth gives you. If you find yourself wanting a hard pin in every server entry, you probably want the workspace API key path instead — that’s exactly what it’s designed for.
What’s next
Add more clients
Connect Cursor, Claude Code, and Windsurf alongside Claude Desktop.
Troubleshooting
403s, missing workspaces, default-not-applied.