AI-native workspace and operating layer for human and AI teammates
Alloy is an AI-native workspace where your team and AI agents collaborate — sharing artifacts, knowledge, skills, and access to external systems, all on one foundation. Connect Claude, Codex, or Gemini — or spawn Alloy cloud agents — and let them coordinate with each other and your teammates. Your company brain, connective tissue, and operating layer for human and AI teammates.
This is an MCP server configuration for the Alloy workspace platform that enables AI agents to access shared knowledge and business systems through a controlled interface. The server properly requires bearer token authentication via the ALLOY_TOKEN environment variable, with no hardcoded credentials or malicious patterns detected. Permissions are narrowly scoped to network HTTP access for communicating with the Alloy backend, which is appropriate for a business collaboration tool.
1 file analyzed · 2 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Set these up before or after installing:
Environment variable: ALLOY_TOKEN
Sign up freeAvailable as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Once installed, try these example prompts and explore these capabilities:
From the project's GitHub README.
Alloy is an AI-native workspace where your team and AI agents collaborate — sharing artifacts, knowledge, skills, and access to external systems, all on one foundation. Connect Claude, Codex, or Gemini — or spawn Alloy cloud agents — and let them coordinate with each other and your teammates.
Start free at alloy.cx · Docs: alloy.cx/docs
This plugin teaches any AI agent to use Alloy as its source of truth — reading shared knowledge before answering, writing durable notes and artifacts, creating workflows, and spawning autonomous agents.
The shared source of truth is the work-with-alloy skill. Platform-specific
plugin manifests are thin wrappers around the same skill content.
Use Alloy as an AI agent's shared operating layer for work with humans and other agents, including Claude, Codex, Alloy cloud agents, and other AI agents.
skills/work-with-alloy/ - shared skill source.skills/work-with-alloy/references/ - supporting playbooks loaded by the skill.skills/work-with-alloy/agents/openai.yaml - Codex/OpenAI skill UI metadata.skills/work-with-alloy/assets/ - skill UI assets such as the Alloy icon..codex-plugin/plugin.json - Codex plugin manifest..claude-plugin/plugin.json - Claude Code plugin manifest..mcp.json - Alloy hosted MCP configuration using ALLOY_TOKEN.skills/work-with-alloy/SKILL.md and its references/ folder are intended to
stay host-neutral. Update this shared skill instead of maintaining separate
Claude and Codex instruction trees.
These apply to anyone installing the plugin into Claude Code or Codex.
ALLOY_TOKEN environment variableThe bundled .mcp.json reads the Alloy MCP bearer from ALLOY_TOKEN. Export
it in the host shell before starting Claude Code or Codex:
export ALLOY_TOKEN="<your-alloy-token>"
Get a token at https://alloy.cx/docs/reference/tech-docs/hosted-mcp.
The plugin's MCP server is loaded by the host at startup. After installing or updating the plugin, restart the host so it can load the bundled MCP config.
The Codex plugin manifest references ./skills/ and ./.mcp.json.
Set ALLOY_TOKEN in the host environment before using the bundled MCP config.
Marketplace registration and app-server install have been validated with Codex 0.125.0:
codex plugin marketplace add Alloy-Systems/alloy-marketplace
Codex installs work-with-alloy from the marketplace entry pointing at a tagged
release. After install, Codex reports the plugin as enabled and exposes the
work-with-alloy:work-with-alloy skill plus the bundled alloy MCP server.
The Claude plugin manifest at .claude-plugin/plugin.json references the same
./skills/ and ./.mcp.json as the Codex side. Install flow once the Alloy
marketplace is published:
/plugin marketplace add Alloy-Systems/alloy-marketplace
/plugin install work-with-alloy@alloy-marketplace
Claude Code's plugin installer clones plugin source from GitHub over SSH by
default. Before /plugin install, make sure one of these is true:
A working GitHub SSH key on this machine (test: ssh -T git@github.com).
A global git URL rewrite that pushes plugin clones through HTTPS:
git config --global url."https://github.com/".insteadOf "git@github.com:"
Set ALLOY_TOKEN in the host environment before using the bundled MCP config.
After install, restart Claude Code and confirm registration:
claude mcp list # expect plugin:work-with-alloy:alloy as connected
This project follows semantic versioning with synchronized releases across
Claude Code and Codex wrappers. A single version applies to the whole release:
the shared skill content in skills/work-with-alloy/, both plugin.json
manifests, the .mcp.json config, and this README. Both
.codex-plugin/plugin.json and .claude-plugin/plugin.json always carry the
same version field.
| Bump | What it means | Examples |
|---|---|---|
Patch (0.1.0 → 0.1.1) | Cosmetic only. Typo, wording tweak, broken link, clarification. No change in how the agent behaves. | Fix a typo in SKILL.md. Update a stale URL in references/. |
Minor (0.1.0 → 0.2.0) | Backward-compatible addition. New rule, new Quick Reference row, new reference playbook, new optional manifest field. Prior usage still works. | Add a new rule to Core rules. Add a new entry to a Quick Reference table. Add a new playbook under references/. |
Major (0.x → 1.0, 1.x → 2.x) | Breaking change. A canonical path, file name, required field, or required rule changes in a way that prior consumers may break. | Rename Personal/<username>/.knowledge/knowledge.md to a different path. Remove a Core rule. Restructure references/ so existing links break. |
Pre-1.0 (0.x) signals "still stabilizing - minor bumps may include breaking
changes". The 1.0.0 line will be cut when the canonical paths and Core rules
are confirmed stable.
main via PR.main is in a state worth releasing, bump both
.codex-plugin/plugin.json and .claude-plugin/plugin.json version
fields in the same commit.git tag vX.Y.Z && git push origin vX.Y.Z.ref field in the Alloy-Systems/alloy-marketplace repo's
marketplace.json entry for work-with-alloy. Users receive the new
version through /plugin update only after this marketplace bump.main are visible to anyone reading the repo but are
not delivered through /plugin install or /plugin update until the
marketplace points at a new tag.Tags are cut per logical release, not on every commit. A typical trigger is a
new Core rule landing, a new reference playbook being added, or a breaking
restructure being completed and ready to ship. Cosmetic-only changes can
accumulate in main and be released as a patch bump when convenient.
Apache License 2.0.
Be the first to review this server!
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
by Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption