Hyperus OEE MCP
MCP (Model Context Protocol) server that lets AI assistants query Hyperus OEE data in read-only mode.
Summary for IT
| Server URL | https://mcp.hyperus.com.br/mcp |
|---|---|
| Transport | Streamable HTTP over HTTPS |
| Authentication | OAuth 2.1 with PKCE and Dynamic Client Registration (DCR). Sign-in with the Hyperus account, including the company's MFA policy |
| Scope | oee.read (read-only) |
| Writes | None. The server does not create, change or delete data |
| Data access | Exactly what the user already sees in the Hyperus OEE dashboard: same machines, devices and permissions |
| Revocation | By the user or an administrator, in the Hyperus dashboard. Takes effect immediately |
| Compatible clients | Microsoft 365 Copilot (Copilot Studio), Claude, ChatGPT, Cursor, VS Code |
What the server does
The server exposes tools that the AI assistant calls to answer questions about the plant, for example: “What was line 2's OEE yesterday?” or “What were the main stop reasons this week?”.
- Real time: current machine status, timeline and unjustified stops.
- OEE: OEE summary and trend, availability, performance and quality.
- Stops: stop reason Pareto, breakdown and occurrences.
- Production: production by product and by hour, production orders and product search.
- Maintenance: MTBF, MTTR and failure metrics.
- Quality and people: SPC summary and operator performance, when the user has permission.
- IoT: device list and telemetry.
- Master data: machines, shifts and stop reasons.
All tools are read-only and are annotated with readOnlyHint in the MCP protocol.
Microsoft 365 Copilot
In Microsoft 365 Copilot the server is added as a tool of an agent, built in Copilot Studio (recommended) or in the Microsoft 365 Agents Toolkit. Once published, the agent is available in Copilot and Teams to the users allowed by the administrator.
Option 1: Copilot Studio (recommended)
- Open the agent in Copilot Studio (or create a new one).
- Go to Tools → Add a tool → New tool → Model Context Protocol.
- Fill in:
- Server name:
Hyperus OEE - Server description:
Read-only access to machines, OEE, stops, production, maintenance and quality data in Hyperus OEE. - Server URL:
https://mcp.hyperus.com.br/mcp
- Server name:
- Under Authentication, select OAuth 2.0 and the type Dynamic discovery. No client ID, secret or URLs are needed: Copilot discovers everything and registers itself.
- Select Create, then Next.
- In Add tool, choose Create a new connection. The Hyperus sign-in screen opens: sign in with the email, password and MFA of your Hyperus account.
- Select Add to agent.
- Publish the agent and enable the Teams and Microsoft 365 Copilot channel.
Each agent user signs in to Hyperus the first time the agent uses the server, and sees only their own data.
Option 2: Microsoft 365 Agents Toolkit
For developers: create a declarative agent with an MCP plugin in the Agents Toolkit (version 6.12 or later), enter the URL https://mcp.hyperus.com.br/mcp and choose OAuth (with dynamic registration) authentication. The Toolkit registers the client and configures authentication automatically.
Reference: Microsoft Learn: connect your agent to an existing MCP server.
How to connect
Use the URL https://mcp.hyperus.com.br/mcp. The client opens the Hyperus sign-in screen, the user signs in with email, password and MFA (if required by the company) and authorizes access.
| Client | How to connect |
|---|---|
| Microsoft 365 Copilot | Copilot Studio → Tools → Model Context Protocol → OAuth 2.0, dynamic discovery (step by step) |
| claude.ai / Claude Desktop | Settings → Connectors → Add custom connector → URL |
| Claude Code | claude mcp add --transport http hyperus https://mcp.hyperus.com.br/mcp |
| ChatGPT | Settings → Connectors → Create → URL, OAuth authentication |
| Cursor / VS Code | mcp.json with {"url": "https://mcp.hyperus.com.br/mcp"} |
Security and access control
- Same rules as the dashboard: sign-in uses the password rules, lockout after failed attempts and MFA configured by the company.
- Mirrored permissions: users can only query the machines and devices assigned to them. Tools that require a specific permission (products, SPC, operators) are not even listed for users without it.
- Access re-evaluated continuously: if a user's access changes or is revoked in the dashboard, the server applies it within 60 seconds.
- Tokens: access token valid for 1 hour; refresh token for 30 days, rotated on every use. Reusing a refresh token revokes the whole connection. The company's maximum session time also applies.
- Token storage: tokens are opaque and stored only as SHA-256 hashes.
- Sensitive data: operator PINs and company security settings are never exposed.
- Limits: per-user rate limit, maximum time per query and maximum period per query.
- Transport: HTTPS only.
How to revoke access
Each connection appears in the user's device/session list in the Hyperus OEE dashboard, identified by client (Microsoft 365 Copilot, Claude, ChatGPT, Cursor, etc.).
- The user or an administrator can end the session there. The client loses access immediately.
- Deactivating the user, resetting the password or disconnecting everyone in the permission group also ends connections.
- The connector can also be removed in the AI client's own settings.
Data and privacy
Query results are sent to the AI client the user connected and are then subject to that provider's privacy policy. Details on what Hyperus processes and stores are in the Privacy Policy.
Support
Questions or requests: suporte@hyperus.com.br.
