MCP · EMPLOYER
Employer connector
Once connected, you can ask Claude or ChatGPT about your company's jobs, talent pool, campaigns and API usage. Every tool is read-only — it can look, but not change anything.
Endpoint
https://mcp.wport.me/enterprisePaste this URL and leave other fields empty — no API key needed. For per-platform setup paths see connector setup.
The old API-key route into MCP has been retired. The enterprise CLI (wport enterprise …) uses a separate REST interface and is unaffected.
Authorization: one extra step
Same standard OAuth, but the consent page adds a “choose representing company” step:
- The consent page lists the companies you currently belong to; if there's only one it's pre-selected
- Companies you've left are not listed
- One grant binds one company. To switch, remove the connector and reconnect
You must be signed in as the enterprise account
wport.me has no account switcher. If your browser is currently signed in as a personal account, connecting the employer line will fail with “no enterprise identity”. Sign out first, then sign in with the enterprise account (the sign-in path is /auth).
Leaving the company revokes access
The grant re-checks your employment on every token refresh. Once you leave the company, the next refresh revokes the whole grant and the connector must be re-authorized to work again.
The 11 tools
| Tool | What it does | Scope |
|---|---|---|
| auth_status | Connection status: whether it's authorized, which connector, and which scopes were granted | — |
| enterprise_whoami | Confirm which enterprise account and representing company is connected | enterprise.identity.read |
| jobs_list | Your company's job list | enterprise.jobs.read |
| jobs_view | A single job's content | enterprise.jobs.read |
| talents_list | Talent pool list | enterprise.talents.read |
| talents_view | A single talent's resume | enterprise.talents.read |
| campaigns_list | Campaign list | enterprise.campaigns.read |
| campaigns_view | A single campaign | enterprise.campaigns.read |
| company_view | Company profile (OWNER / ADMIN roles only) | enterprise.company.read |
| keys_list | API key list (masked) | — |
| usage | Your company's API usage | — |
keys_list only ever returns masked keys, never plaintext. Both usage and keys_list work once identity is verified — no extra scope required.
Scopes and role limits
enterprise.identity.read enterprise.jobs.read enterprise.talents.read enterprise.campaigns.read offline_accessOWNER / ADMIN roles additionally receive enterprise.company.read, which company_view requires.
A JOB_MANAGER cannot reach company_view: consent never issues that scope, and the backend rejects the call regardless. The fix takes both steps — have an OWNER / ADMIN change your role first, then remove the connector and reconnect. Scope is frozen into the grant, so a role change alone does nothing.
Try asking
How many of our jobs are currently published?
Put the recent backend applicants in our talent pool into a table.
How much API quota is left this month?Revoking access
Pressing Disconnect on the platform does not revoke anything — the grant on WPORT stays alive. The only self-service route today is the CLI; run this with the same account you connected with:
# Check which account the CLI is currently signed in as
wport whoami
# Not the account this connector uses? Sign in again (--force is required
# once you are already logged in)
wport login --force
# Find that connection's enc_id and revoke only that one
wport sessions list
wport sessions revoke <enc_id>The list shows only device names and timestamps — it does not label job-seeker vs employer grants, so match by authorization time before revoking. If you revoke the wrong one, just reconnect.
Note: the wport login here is the job-seeker OAuth flow, not the wport enterprise login you normally use (that one takes an API key and has no sessions command). If your enterprise account cannot sign in with it, or the grant does not appear in the list, contact the platform to have it revoked. Avoid --all-others as well: it also revokes your other MCP connector and CLI sign-ins on other devices.
What it can't do
- Create, edit or publish jobs
- Reply to applicants
- Update company info or upload a logo
- Rotate API keys
These write operations are CLI-only for now — see employer commands.