Build on the records your team already uses.
A REST API, an MCP server for other AI tools, and webhooks through Automation. Every call acts as a person, under that person’s permissions, and lands in the same audit log.
All of this is built. Like the rest of Cyril, access opens with early access, organisation by organisation.
# Overdue invoices, as the person who owns the key curl "https://app.getcyril.com/api/finance/invoices?status=overdue&limit=2" \ -H "X-API-Key: $CYRIL_API_KEY" { "data": [ { "number": "ROWA-0998", "status": "overdue", "currency": "USD", "total": "50595.00", "amountPaid": "0.00" }, { "number": "ROWA-0997", "status": "overdue", "currency": "USD", "total": "5272.00", "amountPaid": "0.00" } ], "meta": { "page": 1, "limit": 2, "total": 2, "totalPages": 1 } }
# What can I call, and what does each tool need? curl "$CYRIL_MCP_URL/" # Search across Cyril as the key’s owner. # Records they can’t see are simply not returned. curl -X POST "$CYRIL_MCP_URL/tools/call" \ -H "X-API-Key: $CYRIL_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "tool": "search_cyril", "input": { "query": "Kestrel", "entityTypes": ["project", "ticket", "invoice"] } }'
One set of permissions, whoever is calling.
A key belongs to a person in your organisation. A script, another AI tool or an automation using it gets exactly that person’s access, and every change is logged against them.
X-API-Key- Reads and edits invoices
- Reads companies and contacts
- No access to HR records
- Can’t delete anything
403.A REST API with no surprises.
The same API the Cyril app is built on, with the same rules. Predictable paths, one response shape and errors you can act on.
- A reference that can’t driftGenerated from the same schemas the app validates against. Admins open it from Settings, under API keys.
- Keys you controlCreate, scope and revoke keys per organisation. Each key has its own rate limit.
- One path per resourceNested by app, like
/api/projects/tasks. A retired endpoint answers410and names its replacement. - Lists that page the same wayEvery list takes
pageandlimit, up to 100 at a time, and says how many there are. - A sandbox to build againstSpin up a separate sandbox organisation and test without touching live records.
Errors Every error has the same shape
| Status | Code | When |
|---|---|---|
| 400 | VALIDATION_ERROR | A field failed validation. The message names it. |
| 401 | UNAUTHORIZED | The key is missing, revoked or expired. |
| 403 | FORBIDDEN | The key is fine; its person isn’t allowed. |
| 404 | NOT_FOUND | Doesn’t exist, or belongs to another organisation. |
| 409 | CONFLICT | A duplicate, like an email already registered. |
| 410 | GONE | Retired. The message names the replacement. |
| 422 | UNPROCESSABLE | Valid, but breaks a business rule. |
| 429 | RATE_LIMITED | Slow down and retry. |
{ "error": "Cannot delete the last organisation owner",
"code": "UNPROCESSABLE" }Let other AI tools work with Cyril.
The MCP server gives assistants that speak the Model Context Protocol a set of Cyril tools. They read freely, create where it helps, and get the same answer a person would.
SalesCompanies, contacts, deals
- list_companies
- read_company
- list_contacts
- read_contact
- list_deals
- read_deal
- search_sales
- create_contact
- update_deal
- log_activity
- send_email
FinanceInvoices, estimates
- list_invoices
- read_invoice
- list_estimates
- read_estimate
- create_invoice
- create_estimate
ProjectsProjects, tasks
- list_projects
- read_project
- list_tasks
- read_task
- create_task
- update_task_status
SupportTickets, help centre
- list_tickets
- read_ticket
- search_kb
- create_ticket
Docs and toolsSpaces, custom tools
- list_doc_spaces
- read_doc_space
- list_custom_tools
- read_custom_tool
EverywhereOne search
- search_cyril
ReadsCreates and updatesA selection; the server lists every tool it offers.
- Nothing destructive
- There is no delete tool. Removing records stays with people, in Cyril.
- Rules up front
- Each tool says which permission it needs and whether it needs approval, before anyone calls it.
- Every call recorded
- Calls are logged and metered like the rest of Cyril’s AI, against the organisation that made them.
POST https://ops.rowanhill.example/hooks/paid
{ "invoice": "ROWA-0999",
"client": "Pemberton Foods",
"total": "66631.00" }Webhooks, without writing a server.
In Automation, any rule can end by sending a webhook to a URL you choose, with the payload you choose. An incoming webhook can start a rule, too.
Rules run on the same records and the same permissions as everything else. More on Automation.
Or skip the code.
Describe the tool you need and Cyril builds it, on sample data first, reviewed before it goes live. A calculator, a report or a small internal app, inside Cyril, under the same permissions.
Build your ownWhat’s ready.
Built means it exists and is tested today. It opens to you when your organisation gets early access. The full list is on what’s ready today.
- REST APIEvery app, module-nested paths, one response shape
- Built
- API referenceInteractive, generated from the app’s own schemas
- Built
- API keys and rate limitsPer organisation, scoped, revocable
- Built
- Sandbox organisationA separate tenant for testing
- Built
- MCP serverRead and create tools across Sales, Finance, Projects, Support and Docs
- Built
- Webhooks in AutomationOutgoing actions and incoming triggers
- Built
- Custom tools that write to your recordsTools you build in Cyril read today; writing back comes later
- Planned
Get a key when your place opens.
Cyril opens to founding members first. They keep their price and get help moving in, integrations included.
One email when your place opens. Nothing else.
