Agentfront
Docs Book a demo
Private MCP endpoint for your business

Make your business reachable by AI agents.

A private, hosted MCP endpoint with scoped access tokens, so Claude, ChatGPT, Cursor and your own agents can work inside your ERP, inventory and booking systems. Every write is approved, idempotent and logged. Hosted in Canada.

Book a demo See how it works

Launch systems: Odoo and Dynamics 365 Business Central. Public directory listings, including Meta Muse, are available on request.

The Cloud Architect, a rounded cobalt blue robot holding a floating data cube
The Cloud Architect Your ERP, held safely
What an agent sees
A private URL, a scoped token, a short tool list, and a receipt for every write.

This is what Claude, ChatGPT or Cursor sends to your private endpoint. The token carries the user and role; six tools exposed out of 212, because this user is an A/P clerk.

POST https://mcp.agentfront.ca/t/acme-8f21/mcp · private URL
Authorization: Bearer af_live_…c9e2 · dana@acme.ca · ap-clerk
→ 200 session opened · token expires in 30d · revocable
tools/list (role: ap-clerk · 6 of 212 tools exposed)
erp.search_invoices read
erp.get_vendor read
erp.post_bill write · approval required
tools/call erp.post_bill vendor=Northwind amount=4812.50 CAD
→ held approval A-1187 sent to dana@acme.ca
→ posted BILL-2041 idempotency 7f3c…e1
→ logged ca-central-1 · 14 ms
Reaches agents on
Claude ChatGPT Claude Code Cursor LangGraph OpenAI Agents SDK Any MCP client Meta Muse · via listing, on request
How it works

Three steps from “we have an ERP” to “agents can place orders with us.”

01

Connect your systems

Point us at your ERP, inventory, catalog or booking system. We map it to a normalized schema and decide, with you, which operations agents may read and which they may write.

Odoo · Business Central · NetSuite · SAP Business One · Sage · QuickBooks · any REST or OData API

02

We host your private endpoint

One MCP endpoint per tenant at a private URL, on our domain or yours. Bearer access tokens for most clients; OAuth 2.1 with PKCE for the agents that insist on it. A tool router exposes only what each task needs.

Streamable HTTP · private URL · bearer tokens or OAuth 2.1 · Canada region

03

You hand out access tokens

Issue a scoped token per person or per agent from the dashboard. They paste the private URL and token into Claude, ChatGPT, Cursor or their agent framework and are connected. Rotate or revoke any token instantly. Nothing is published anywhere unless you ask.

Per-user tokens · role scopes · expiry and revocation · public directory listing on request

Governed writes

Reads are easy. Writes into a ledger are the part nobody has solved.

Most agent gateways stop at read-only for ERPs. Agentfront treats every write as a transaction with a lifecycle, an owner and a receipt.

Lifecycle, not fire-and-forget
Draft → pending approval → approved → posted. Policy decides which writes auto-approve and which wait for a human.
Idempotent by construction
Content-hash keys mean a retried or duplicated agent call cannot post the same invoice twice.
Untrusted input stays out of write parameters
Values that came from an email, a PDF or a web page are tainted; they cannot reach a write without a human confirming them.
Every call logged, exportable
Who asked, which agent, which user, what changed, in an append-only log you can ship to your SIEM.
draft pending approval approved posted
Approval A-1187 2 min ago
Post vendor bill — Northwind Traders
Amount
$4,812.50 CAD
GL account
5100 · Cost of goods
Requested by
Claude · token dana@acme.ca
Source of amount
Vendor PDF · untrusted
ERP connectors

Built for the systems small and mid-size Canadian businesses actually run.

Request a connector
OdooLaunch
Odoo 16+ · Online, .sh and on-prem · JSON-2 and XML-RPC
Read all models · gated writes on sales, purchase, invoicing, inventory
Business CentralLaunch
Dynamics 365 · OData v4 · Entra ID delegated auth
Customers, items, sales orders, purchase orders, invoices · gated posting
NetSuiteNext
Bridges Oracle's AI Connector Service · SuiteQL · token-based auth
Saved searches, records, reports · gated writes
SAP Business OnePlanned
Service Layer REST
Business partners, items, orders, A/P and A/R documents
Sage IntacctPlanned
Web Services and REST
GL, A/P, A/R, order entry
QuickBooks OnlinePlanned
REST · OAuth 2.0
Customers, invoices, bills, items

Anything outside your systems of record (email, calendars, CRMs, chat) is proxied to a catalog gateway rather than rebuilt, so you are not paying us to re-implement Gmail.

Why Agentfront

The alternatives are a build project or a catalog that stops at your ERP’s front door.

Capability Build it yourself Catalog gateway Agentfront
Private MCP endpoint per tenant Weeks of work Shared endpoint, their account Private URL, your domain if you want
Scoped access tokens per user and agent You build issuance and revocation Platform API keys Issue, scope, expire, revoke from the dashboard
Public directory listing (Muse, ChatGPT, Claude) You file and chase Not offered On request
ERP writes with approvals and idempotency You design it Mostly read-only Built in
Canadian data residency Your cloud Varies Canada by default
How you pay Engineering time Per-call overages Flat monthly plan, from $99
Pricing

Flat monthly plans, not per tool call.

Agents retry. You should not be billed for it. All plans in CAD, billed monthly, cancel any time.

Starter
Get one system in front of agents
$99 /month*
  • 1 connected system
  • Private endpoint URL
  • Up to 5 seats
  • Token expiry and revocation
  • Audit log, 90-day retention
Start with Starter
Most teams
Business
Governed writes across your stack
TBD /month*
  • Unlimited connected systems
  • Write tools with approval inbox
  • Unlimited tokens, role-based scopes
  • Endpoint on your own domain
  • Audit log, 1-year retention, SIEM export
Book a demo
Enterprise
Your controls, your region
Custom
  • Unlimited systems and custom connectors
  • Private deployment in your Canadian VPC
  • SSO and SCIM, custom approval policies
  • Public directory listings filed and managed
  • Named support, uptime SLA
Talk to us

* Some data sources or heavy services may cost more depending on resource requirements. We tell you before you connect them.

Security and residency

Your credentials never reach a model. Your data never leaves the country.

Canada-hosted
Endpoint, tokens and logs run in Canadian regions. Private VPC on Enterprise.
Credential isolation
ERP secrets are encrypted at rest and injected server-side. Agents see tool results, never tokens.
Least privilege
Scopes per user and role; the tool router exposes only what the current task needs.
Compliance
SOC 2 Type II: [STATUS]. PIPEDA-aligned data handling. Zero data retention option for payloads.
FAQ

Questions operators and IT ask first.

How do our people actually connect?

You get a private URL. You issue each person or agent a scoped access token from the dashboard. They paste the URL and token into the MCP settings of Claude, ChatGPT, Cursor or their own framework, and they are connected. Nothing is listed publicly. The one exception is consumer Meta Muse, which cannot take a pasted URL; if you want Muse users reaching you, we file a directory listing on request.

What stops an agent from posting the wrong invoice?

Policy. Each write tool declares whether it auto-approves (below a threshold, from a trusted source) or waits for a named approver. Amounts and identifiers sourced from untrusted content are flagged and cannot post without confirmation. Idempotency keys stop duplicates on retry.

Our ERP is on-premises. Does that work?

Yes, through an outbound connector you run inside your network. No inbound ports are opened; the hosted endpoint relays through the tunnel and your database never becomes internet-facing.

Do you replace our existing integration platform?

No. Agentfront is the agent-facing door to your systems of record. Existing syncs, iPaaS recipes and catalog gateways keep running; tools outside your ERP can be proxied through them rather than rebuilt.

See your ERP answer an agent in a 30-minute call.

Bring a sandbox login. We connect it live, show the approval flow, and leave you with a private URL and your first access token.

No credit card. We reply within one business day, Pacific time.