본문으로 건너뛰기

Bandruption MCP Connector

Bandruption hosts a Model Context Protocol (MCP) server at https://mcp.bandruption.fun/mcp. Adding it as a connector lets Claude — or any MCP-aware assistant — read your artist context and run admin operations on your behalf, with you in the loop for every change.

Status: OAuth 2.1 + PKCE is live on the production MCP endpoint. Keep this page synchronized with the currently deployed transport, scope, and tool surface.

What you can do with it​

Once the connector is added and you've signed in, your assistant can:

  • Read your data — fetch artist context (profile, loyalty program, counts), event lists, affiliate summaries, and bounty details.
  • Run your fan-engagement programs — create, update, archive, and review claims on loyalty bounties for the artists or music-industry profiles you own.
  • Set up events and ticketing — create draft events, add ticket types with pricing, capacity, and member-only options.
  • Manage your storefront — create merch products with pricing, inventory, and variants.

Every write tool requires you to confirm the action in chat before it executes. Your assistant proposes the change first; you approve.

What you can't do (yet)​

The MCP exposes admin operations only — the same actions you could perform in Bandruption's web admin. It does not:

  • Transfer money, take card payments, or pay anyone out — the only spend is BANDS (Bandruption's in-app credit) from your own balance when you confirm social.publish_post, after a dry run that shows the cost
  • Generate AI images or audio
  • Access fan personal data outside your audit reach
  • Modify other artists you don't own

Add the connector to Claude​

Bandruption admits MCP clients by URL. Claude, Claude Code, and other MCP clients identify themselves with a Client ID Metadata Document (an https:// client ID hosted by the assistant's vendor); Bandruption's authorization server fetches, validates, and remembers that document. There is nothing to paste and there is no client secret. Clients that cannot present a metadata URL register automatically instead (RFC 7591). Either way the client is limited to the MCP server and the mcp:admin scope.

Claude.ai (web)​

  1. Open Settings → Connectors → Add custom connector.
  2. Enter https://mcp.bandruption.fun/mcp as the URL. Leave Advanced settings empty.
  3. Click Connect. You'll be redirected to Bandruption to sign in (or jump straight to consent if you signed in within the last 15 minutes; otherwise you sign in again). The consent page names the client Claude (claude.ai).
  4. Review the requested access (admin scope on the artists you own) and click Approve.
  5. The connector is now available in any chat. Try: "List my active bounties on <your-artist>."

A connector created earlier with the static client ID mcp_client_22199e09-0f81-4d37-bd57-84e48b36318f in Advanced settings keeps working; you can also remove it and add it again by URL alone.

Claude Code​

Run:

claude mcp add --transport http bandruption https://mcp.bandruption.fun/mcp

then type /mcp inside Claude Code and choose Authenticate. Claude Code opens your browser and receives the code on a loopback redirect; the consent page names the client Claude Code (claude.ai).

Claude Desktop​

  1. Open Settings → Developer → Edit Config.
  2. Add the Bandruption server to the mcpServers block:
    {
    "mcpServers": {
    "bandruption": {
    "url": "https://mcp.bandruption.fun/mcp"
    }
    }
    }
  3. Restart Claude Desktop. The OAuth flow runs in your browser the first time you call a Bandruption tool; Claude Desktop presents its metadata URL, so no client ID is needed. Connectors added on claude.ai are also available in Claude Desktop when you are signed in to the same account.

Other MCP-aware clients​

Any client that implements the MCP Authorization spec (OAuth 2.1 with PKCE) can connect. Clients that publish a Client ID Metadata Document are admitted by URL; clients that do not can register at the advertised registration_endpoint (RFC 7591) as a public client with PKCE. Registration is credential-free: send token_endpoint_auth_method as none (or private_key_jwt), because dynamically admitted clients are never issued a client secret. Loopback redirects (http://127.0.0.1:<port>/callback) and private-use schemes are recognised as native automatically, so bridges such as mcp-remote need no application_type; a private-use scheme must be a reverse-domain name with no naming authority (com.example.app:/callback, not com.example.app://callback). Both kinds are limited to the MCP server (resource=https://mcp.bandruption.fun/mcp) and the mcp:admin scope: they cannot request the platform API or machine-to-machine grants. A client that needs anything else still goes through a reviewed registration — ask support@bandruption.fun.

  • Server URL: https://mcp.bandruption.fun/mcp
  • Authorization Server discovery: the server returns WWW-Authenticate: Bearer resource_metadata="https://mcp.bandruption.fun/.well-known/oauth-protected-resource" on an unauthenticated request; that document names the authorization server https://auth.bandruption.fun, whose metadata lives at https://auth.bandruption.fun/.well-known/oauth-authorization-server
  • Required scope: mcp:admin, with resource=https://mcp.bandruption.fun/mcp

What the assistant sees​

The server exposes:

Read tools

  • bounty.list — list bounties for an artist or industry entity
  • bounty.get — fetch a single bounty by ID

Write tools (all require explicit confirmed: true)

  • uploads.create_signed_url — mint a Bandruption-managed upload URL and return the filePath you can reuse in later MCP calls
  • entity.update_profile — update an artist or music-industry profile, including avatar paths returned by uploads.create_signed_url
  • entity.update_tabs — update the enabled/default tab configuration for an artist or music-industry profile
  • event.create — draft an in-person or virtual event
  • ticket_type.create — add a ticket type to an event
  • merch.create — add a merch product to an artist's storefront
  • bounty.create — create a fan-engagement bounty
  • bounty.update — change an existing bounty (criteria/rewards may be replaced)
  • bounty.archive — hide a bounty from fans
  • bounty.add_criterion — append a criterion to a bounty
  • bounty.add_reward — append a reward to a bounty
  • bounty.approve_claim — approve a fan's bounty claim
  • bounty.reject_claim — reject a fan's bounty claim

Resources

  • bandruption://admin/artists/{username}/context — full artist + loyalty-program snapshot
  • bandruption://admin/artists/{username}/events — upcoming and past events
  • bandruption://admin/artists/{username}/affiliate-summary — affiliate offering, links, and recent attributions

Security and privacy​

  • OAuth 2.1 + PKCE. Every connection runs through Bandruption's standard sign-in, and access tokens are short-lived (15 minutes) and refreshable until you revoke them.
  • You're in control. Write tools never run without your explicit approval in chat. The server enforces a confirmed: true flag on every mutation.
  • Scope is yours. The connector can only act on artists or music-industry profiles you own. It can't read or modify other accounts.
  • Audit trail. Every tool call is logged to your Bandruption account's audit history. View it in the admin dashboard.
  • Privacy. See the Bandruption Privacy Policy for details on how your data is handled.

Revoke access​

Open Settings → Connectors → Bandruption → Disconnect in your assistant. The next refresh attempt will fail and the access token will expire within 15 minutes.

You can also revoke from Bandruption: Settings → Connected Apps, find the entry for your assistant, and click Revoke.

Support​