Connect Any REST API to Langdock. For your whole team.
Your shop system, helpdesk, ERP module or vendor API has no MCP server. Building one takes an engineer days and leaves one token in a config file that everyone copies. Loopthink generates the MCP server from the API's OpenAPI spec or documentation, holds the one read-only key, gives every Langdock user in your team their own login, and applies your roles per endpoint.
Free for your own server · Team from €99 · EU-hosted
Any REST API in a chat client, today.
Today an internal or vendor REST API reaches a chat client only if somebody writes an MCP server for it. That server runs with one token, usually the one an engineer had at hand, and every person who copies the config gets that token's rights, write endpoints included. Nothing records who asked what, and the personal fields in every response go straight to the model.
One matrix for Any REST API. Roles across, tools down.
| Tool | Operations | Support | Management |
|---|---|---|---|
| List & filter records | Operations may use List & filter records | Support may use List & filter records | Management may use List & filter records |
| Get one record | Operations may use Get one record | Support may use Get one record | Management may not use Get one record |
| Reports & aggregates | Operations may use Reports & aggregates | Support may not use Reports & aggregates | Management may use Reports & aggregates |
| Related records | Operations may use Related records | Support may use Related records | Management may not use Related records |
| Write actions off by default | Operations may not use Write actions | Support may not use Write actions | Management may not use Write actions |
Masked for every role: names, emails and phone numbers in responses, addresses, free-text fields you mark as personal.
You set this once. Every Langdock user in your team gets exactly this.
Once on the Any REST API side, once in Langdock.
On the Any REST API side
The API's own key or service user, read-only where the vendor allows it
- 1
Collect the API's base URL and its OpenAPI spec, or the documentation of the endpoints your team needs.
- 2
In the system itself, create an API key or service user with the fewest rights that still read what you need. If the vendor has no read-only option, the roles in Loopthink are what limits it.
- 3
Paste URL, spec and key into Loopthink. Name the tools in your own business language and mark the personal fields; that is configuration, not code.
In Langdock
Custom connector, OAuth
- 1
Someone with the permission Create integrations (Editor or Admin by default) opens Integrations → Add integration → Start from scratch → Connect remote MCP.
- 2
Paste your Loopthink connector URL, choose OAuth 2.0 (Dynamic Client Registration), click Create and connect.
- 3
Share the integration with users, groups or the whole workspace. Each person signs in to Loopthink once; their calls carry their own name.
Langdock is a Berlin company hosted in the EU, like Loopthink, so the whole path from question to database stays inside the EU. OAuth connections are personal by design; that is what keeps the audit trail per person.
Steps checked against the vendor documentation on 17 September 2026: Loopthink pricing: what Team includes · MCP specification · Langdock: remote MCP servers · Langdock: MCP directory and adding a server · Langdock: workspace permissions
Loopthink sits in between: it holds the key, shows Langdock a normal login, and applies your roles on every call.
Four checks between Langdock and Any REST API.
- 01
Identify
OIDC/SSO against your own IdP, including Microsoft Entra. The call runs as the person who made it, never as a shared service account.
- 02
Authorize
Per-role, per-tool, read or write. Anything not explicitly granted never shows up in the tool list in the first place.
- 03
Mask
Field-level masking and pseudonymization applied on your side, before the result travels. The model never sees the raw field. Composio, AnythingMCP and both provider tunnels have no field-level masking at all.
- 04
Log
Who asked, which tool, which records, which fields were masked. One audit trail across every AI client, exportable for review.
What people actually ask Langdock about Any REST API.
- Operations
“Which orders in the shop system are still unshipped after three days?”
- Support
“Show me the last five tickets from customer 4711 in the helpdesk.”
- Management
“How many new contracts did the CRM record this month, by region?”
Each question runs as the person who asked it, with that person's role. A Support colleague asking the Operations question gets the tools their own role allows, not an error, not more.
Four ways to put Any REST API into Langdock.
| Native Any REST API connector | Build it yourself | Enterprise gateways1 | Loopthink | |
|---|---|---|---|---|
| Per-user identity | One personal login, all its rights | Only if you build it | Yes | Yes, every call runs as the person who asked |
| Tool-level roles | No | Your code | Yes | Yes, write off by default |
| Field masking | No | Your code | Not documented | Yes, before the model sees the data |
| Published price | Included in your Any REST API plan | Your engineers' time | Contact sales | Free, Team from €99 |
| EU company | Depends on the vendor | Whatever you are | Mostly US | Yes, Germany |
Native Any REST API connector: There is none. The nearest thing is an MCP server your engineers write and maintain, with one token in a config file.
1 MintMCP, MCP Manager, Pomerium
Coming from one of them? Composio alternative · MintMCP alternative · MCP Manager alternative · AnythingMCP alternative
Before you connect.
- Does every team member need their own Any REST API account?
- No. Loopthink holds one key or token for Any REST API. Your people sign in to Loopthink with their own identity, and every call to Any REST API is logged under their name. Seats in Any REST API stay where they are today.
- Who has to add the connector in Langdock?
- One person with the right to add connectors in your Langdock workspace, once. After that every team member enables it for themselves. Nobody pastes a key, nobody edits a config file.
- Where does the Any REST API key live?
- In Loopthink, encrypted, in the EU. It never reaches Langdock and never reaches the people using the connector. Rotate it in Any REST API whenever you like and paste the new one once.
- Can somebody write to Any REST API from the chat?
- Not unless you switch it on. Write actions are a separate row in the permission matrix and are off for every role by default. If a role needs one write tool, you grant that one tool to that one role.
- What does the model see?
- The result of the tool call, after masking. Fields you mark as personal, such as emails, names or card details, are masked before the answer travels to Langdock. The model gets the numbers, not the people.
- Is there an audit trail?
- Yes. Who asked, which tool, which parameters, which fields were masked, when. One log across every client your team uses, exportable for review.
- What does it cost?
- Free for one person and your own MCP server, forever. Team starts at €99 per month and covers the built connector, per-person identity, roles, masking and audit for the whole team. Prices are on the pricing page, no call needed.
- We already run our own MCP server for Any REST API. Does it still work?
- Yes. Point it at Loopthink and it inherits the same login, roles, masking and audit. Nothing on the server has to change.
Any REST API in Langdock, with rules.
One key in Loopthink, one login per person, one matrix that decides who may do what.
Free for your own server · Team from €99 · EU-hosted
