Skip to content
SpanDock

MCP

SpanDock is an MCP server, so chat tools such as Claude Code can ask questions about your telemetry: what a session cost, which traces failed, which models were used most this week. The tools are read-only. Every key has a scope, so a key only ever sees the data it is allowed to see.

Endpoint

SpanDock serves MCP over streamable HTTP at:

http://127.0.0.1:8787/mcp

Create a key and connect

  1. Open MCP & API keys and create a key.
  2. Copy the ready-made command. For Claude Code it looks like this:
claude mcp add --transport http spandock http://127.0.0.1:8787/mcp --header "Authorization: Bearer sdk_…"

The key is shown once. SpanDock stores only a hash of it, so copy it before you close the dialog. You can revoke a key at any time.

Other MCP clients connect the same way: point them at the endpoint and send the key as a bearer token in the Authorization header.

Tools

ToolWhat it doesWho can use it
get_statsTotals of spans, logs and metrics, plus hourly counts for the last 24 hoursEvery key, within its scope
query_activitySearches stored telemetry, newest first, with filtersEvery key, within its scope
get_traceAll spans of one trace as a treeEvery key, within its scope
list_sessionsRecent tool sessions with event and token totalsEvery key, within its scope
usage_summaryRequests, tokens, latency and errors by model, project, service, day or clientEvery key, within its scope
list_clientsThe paired clients, with their last reportAdministrator keys only
provider_dashboardLangfuse cost, token, latency and error analyticsAdministrator keys only
run_sqlOne read-only SQL query over all stored activity, up to 1,000 rowsAdministrator keys only

run_sql follows the same rules as the Database page: a single SELECT, with no way to change data, read files or reach the network.

Key scopes

  • Administrator keys see every client. They work only on the server machine itself, never over the tunnel.
  • Client-scoped keys are limited to one client and see only that client's data.

The client is always taken from the key, never from the request, so a key can't ask for another client's data.

MCP on a client machine

Chat tools on a laptop can't reach the server's tunnel directly. Turn on the MCP proxy on the client (or manage it from the server under Clients → Edit settings) and create a local key under MCP & API keys. Chat tools on that machine then connect to the client's own /mcp, and the client forwards their requests to the server over the encrypted tunnel. The server limits the answers to that client's data.

The proxy accepts requests only from the local machine.

The built-in assistant

The server (and a standalone install) also has an Assistant page. It answers questions such as "which models cost the most this week?" by querying your telemetry with the same read-only tools, and it can also query Langfuse through Langfuse's own MCP server.

Set it up under Settings → AI assistant: choose a provider (for example Claude, OpenAI, Google Gemini, Mistral, OpenRouter, or a local model through Ollama or LM Studio), add an API key, and pick a model. The key is kept in the OS credential store.

The assistant's own usage and cost are recorded in SpanDock and forwarded to your destinations like any other tool's. Prompt and answer text are recorded only when you turn on Record chat content. Chats are kept on the server machine until you delete them, and the assistant is available only on the server machine itself, never over the tunnel.