The data gateway · as live connections

Create secure connections once. Share with all users.

Configure secure connections to 100+ live enterprise systems and control exactly which users and agents can access each one. No data copies, pipelines, or credentials in model context.

Controlled · Governed · Contextual access, per connection

Every system. A database.

One tool, six verbs, 100+ systems behind them. Instead of one server, tool definition, credential, and security review per system, every connection answers the same shape: schema you can describe, records you can query, files you can browse.

connectionslive
Caller · every surface
mcpclisdk
one connection · every caller
MarcoPolo gateway

Provisioned once · resolved for whoever calls

approved systems
Salesforcesales_read
Snowflakeanalytics_ro
Postgresapp_read
Jiraissues_read
01

Secure Connections

Provision Salesforce, Snowflake, Postgres, HubSpot, files, and internal databases once. Schema is seeded at provision time, not rediscovered on every query, and credentials stay in MarcoPolo.

Secure connections
workspace · liveconnectlive
# Every system answers the same six verbs.$ connection describe salesforce --table Opportunity→ 42 fields · schema seeded at provision$ connection query snowflake --filter "stage = 'Closed Lost'"✓ joined salesforce × snowflake   14 rows# One abstraction · not one integration per system.
02

Managed Database Execution Environment

Describe the schema, query the records, join across systems. Salesforce × Snowflake × Jira in one analysis, with large outputs kept as result handles.

Governed workspace
auditlive
tenantacmeconnectionsalesforcescopeshared · revopsverbqueryresultresult#7c21
connection.queryliveconnect

Same trail whether the caller was MCP, CLI, or SDK

req#a91csealed to your SIEM
03

Governance & Auditing

A connection is owned by one user, shared with named teammates, or shared company-wide. Every access is logged, and revoking takes effect immediately across every surface.

Trust and governance
Where it sits

Provisioned once. Used everywhere.

Access is provisioned for users, agents, and agents working on behalf of users. Pick the surface per use — no re-integration as standards change.

  1. Provision the connection once

    Authenticate the system, capture the intent of the task, and set the scope: user-owned, shared with a team, or company-wide.

  2. Query it like a database

    List, describe, query, browse, upload, download. The same six verbs everywhere, so workflows become data analysis across systems.

  3. Use it from any surface

    MCP-compatible assistants, agents working in code through the CLI, and the apps you ship through the SDK all read the same connection.

  4. Review and revoke in one place

    Credentials never enter the AI environment. Local development and production work the same way, and one trail covers every path.

Every system your team actually uses.

Cloud warehouses, databases, SaaS tools, and storage. All accessible through one governed interface.

Cloud Data Warehouses
Snowflake logo
Snowflake
Amazon Redshift logo
Amazon Redshift
Google BigQuery logo
Google BigQuery
Databricks logo
Databricks
Azure Synapse logo
Azure Synapse
Databases
PostgreSQL logo
PostgreSQL
MySQL logo
MySQL
Microsoft SQL Server logo
Microsoft SQL Server
Oracle logo
Oracle
MongoDB logo
MongoDB
Big Data & Analytics
Amazon Athena logo
Amazon Athena
Presto logo
Presto
Hive logo
Hive
Impala logo
Impala
Apache Kylin logo
Apache Kylin
Time Series & NoSQL
InfluxDB logo
InfluxDB
Prometheus logo
Prometheus
Cassandra logo
Cassandra
ScyllaDB logo
ScyllaDB
Amazon DynamoDB logo
Amazon DynamoDB
SaaS & APIs
Salesforce logo
Salesforce
QuickBooks logo
QuickBooks
HubSpot logo
HubSpot
Intercom logo
Intercom
Google Analytics logo
Google Analytics

Don't see your system? We're adding connectors weekly. Request one.

Scenarios

Provisioned by teams who own the systems.

One connection, three surfaces

RevOps provisions Salesforce and shares it with twelve teammates. An analyst reaches it from Claude, an agent reaches it from the CLI, and the product reaches it from the SDK.

Provisioned onceevery surfaceone audit trail

Cross-system analysis without a pipeline

A workflow describes the schema in Salesforce and Snowflake, then joins them on the fly. No warehouse job, no copy of the data, no new integration to review.

describequeryjoin

Private databases inside the VPC

Postgres and SQL Server reachable only from inside the customer's network are provisioned over private link. The same verbs apply; the data plane never leaves their cloud.

In-VPC connectiongoverned executionshared audit
100+ systems · Every AI surface

Same verbs. Every system. Every surface.

Book a demo
FAQ

What teams ask before they connect.

How does LiveConnect differ from native MCP servers?

Native MCPs expose each system's own API shape · one server, tool definition, credential, and security review per system. LiveConnect treats every system like a database instead: schema you can describe, records you can query, files you can browse · the same verbs everywhere. Provisioned once, reviewed once · not fifty times.

How is a connection scoped?

At provision time. A connection can be owned by one user, shared with named teammates, or shared company-wide · and an agent acts under the scope of the identity it works for. The intent of the task is captured when the connection is provisioned, so access maps to purpose · not to whatever a token happens to permit.

Which surfaces can use a provisioned connection?

All of them. MCP-compatible assistants · Claude, ChatGPT, Cursor, Copilot · through One MCP; agents that work in code through the connection CLI; the apps and agents you ship through the Agent SDK and API. Same connection, same scope, same audit trail on every path.

What's the authentication model?

Credentials live inside the workspace, encrypted at the boundary, scoped per identity. The LLM never sees a token or API key · LiveConnect handles auth at the workspace layer and returns only the data the caller's scope permits. SSO + SCIM cascades govern who can provision connections and who can use them.

Do you support OAuth-only systems?

Yes. OAuth flows are handled per user inside the workspace. Refresh tokens stay encrypted; access tokens never enter the model context. Revocation propagates instantly across every AI surface the user has access to.

How are credentials stored?

In your workspace, encrypted with your KMS keys (Enterprise tier) or our managed KMS (Team tier). For VPC deployments, credentials never leave your cloud · we operate the software, you own the data plane.

Can I build a custom connector?

Yes. LiveConnect is extensible · you can author connectors against any system with an API or database driver. For Enterprise customers we also build new connectors on request as part of the engagement.

Can I run connectors against my own database?

Yes. LiveConnect supports private databases reachable from inside your VPC · Postgres, MySQL, Mongo, SQL Server, and others · over SSH, private link, or direct in-VPC connection. For air-gap deployments, the entire workspace runs on your hardware.

Provision once. Use everywhere.

Start free. Provision your first three systems in minutes · and use them from every surface you ship or deploy.