Architecture
How it works
The LeadSponsor MCP server is a protocol adapter: it translates MCP tool calls from your AI client into authenticated requests to the LeadSponsor platform, and returns the results. It holds no business logic of its own — all the intelligence lives in the LeadSponsor platform.
Your AI client (claude.ai, ChatGPT, Cursor, custom agent)
│
│ MCP over HTTPS (Streamable HTTP transport)
│ Authorization: Bearer <OAuth 2.1 access token>
▼
mcp.leadsponsor.io
│
▼
LeadSponsor platform (intelligence · data · AI tools)
Workspace isolation
Each access token is bound to exactly one workspace (the ws claim). The server reads that workspace at the start of every request and scopes all data access to it — a token for workspace A can never reach workspace B's data.
Authentication
Authentication is OAuth 2.1. The MCP server is a resource server: it only verifies access tokens — signature, issuer, audience, and expiry — and the audience is pinned to the MCP URL so a token can't be replayed against another service. Sign-in and token issuance are handled by the LeadSponsor authorization server. See Authentication for the full flow.
Deployment
The MCP server and this documentation site are hosted on Google Cloud Run behind managed TLS certificates.
| Service | URL |
|---|---|
| MCP server | https://mcp.leadsponsor.io/mcp |
| Documentation | https://docs.leadsponsor.io |