Configure AI Connectors for Benchling AI

Stuart
Stuart
  • Updated

Quick Reference:

  • AI Connectors Help Pages
  • MCP URLs
    • Benchling MCP Server URL format: https://<tenant>.mcp.benchling.com/mcp
    • Benchling MCP Redirect (or callback) URI format: https://<tenant>.benchling.com/1/api/llm/mcp/oauth/callback 

Overview

AI Connectors allow Benchling AI to access data from external systems like Microsoft Teams, SharePoint, Slack, and other platforms that support the Model Context Protocol (MCP). This extends the abilities of Chat and Deep Research to provide comprehensive answers by incorporating information from multiple sources across your organization's data ecosystem. AI Connectors work by establishing secure connections between Benchling and external MCP servers, allowing Chat and Deep Research to retrieve relevant information while respecting your authentication and permissions in those systems.

Chat or Deep Research must be enabled on your tenant to use AI Connectors.

Note: AI Connectors currently work with Chat or Deep Research only. These agents automatically determines which connected systems to query based on your prompt.

Install AI Connectors from the Directory as an admin

Connect to out-of-the-box AI Connectors from the directory — Benchling has done the setup work for you, so you can get connected faster.

To install an AI Connector from the directory:

  1. Click Browse directory
  2. Select the AI Connector you want to install
  3. Click Install in the top right corner
  4. Authenticate 
  5. Manage which tools are available to your end users
  6. Click Save

As your needs change, you may need to update your AI Connectors.

To update an AI Connector:

  1. Click the "..." for the relevant AI Connector
  2. Click Manage tools to change the available tools for an AI Connector
  3. Click Uninstall to make this AI Connector unavailable for the tenant

Tip: At least 1 tool must be enabled for an AI Connector for end users to be able to use it.

 

Install Custom AI Connectors as an admin

If the AI Connector you need isn't available in the directory, a custom AI Connector can be configured. Before Custom AI Connectors are available for users to enable, tenant admins must first install the AI connector for the tenant. 

To configure a Custom AI connector:

  1. Navigate to the Tenant admin console > Settings
  2. Click AI Connectors
  3. Click Add AI Connector
  4. Complete the AI Connector configuration:
    • Name: Enter a descriptive name for the AI Connector (this is the name that will be visible to users)
    • Server: Enter the MCP server URL (typically ends in /mcp for HTTP connections or /sse for SSE connections)
    • Type: Select the connection type
      • [Default] Use HTTP for most connections (URLs ending in /mcp)
      • Use SSE for server-sent events connections (URLs ending in /sse)
      • If you're unsure, start with HTTP and try SSE if the connection doesn't work
  5. Review the available tools from the MCP server and select which tools users can access
  6. Click Save

To connect Chat in one tenant to another tenant, you can use the Benchling MCP url format like https://<tenant>.mcp.benchling.com/mcp

See Benchling MCP for more on setting up and using Benchling's MCP Server.

 

Common settings:

  • Benchling MCP Redirect (or callback) URI or URL: https://<tenant>.benchling.com/1/api/llm/mcp/oauth/callback 

 

Manage Custom AI Connectors

After creating a Custom AI Connector, admins can adjust settings or remove access. Note, the settings for admins to adjust the behavior for their tenant and to adjust the behavior for themselves as a user are both managed through this page. These settings will be present for tenant admins only:

  • Admin settings: Adjust configuration settings for the connector for the entire tenant, including which tools are available to users
  • Delete: Remove the connector for all users on the tenant

Instructions for setting up AI Connectors as a user can be found in the Deep Research article. 

 

Set up AI Connectors as a user

After an admin installs an AI Connector, you can set up your personal AI Connector to authenticate and select which tools you want to use.

To set up your AI Connector:

  1. In the Navigation bar, click AI
  2. Click the Settings icon
  3. Click the AI Connectors tab
  4. Click Connect the AI Connector you want to use
  5. In the pop-up window, click Connect 

    Screenshot 2026-01-20 at 2.42.31 PM.png

  6. Complete authentication in the new tab or window that opens

    Screenshot 2026-01-20 at 2.48.18 PM.png
  7. Return to Benchling and finalize the AI Connector
  8. Select which tools you want to enable from the options the admin has made available
    Screenshot 2026-01-20 at 2.43.50 PM.png
  9. Click Save

Your selected AI Connectors are now available to Chat. When you use Chat, it automatically determines whether to query your connected systems based on your prompt.

 

Frequently asked questions

  • What types of external systems can I connect?
    • You can connect to any system that provides an MCP server. Common examples include Microsoft Teams, SharePoint, Slack, and other collaboration or data platforms. The system must provide an MCP server URL for the connection.
  • Why am I getting an authentication error?
    • If you encounter authentication errors when setting up your connection, the external system may require pre-registration of the connection on the MCP server side. Contact Benchling Support for assistance with authentication issues.
  • Which Benchling features work with AI Connectors?
    • AI connectors currently work with Chat and Deep Research. You cannot use AI Connectors with Ask or other AI features at this time.
  • Do AI Connectors require additional licensing?
    • AI Connectors don't require additional licensing beyond your existing Benchling license. However, your tenant must have Chat or Deep Research enabled to use AI Connectors. Depending on the AI Connector, you may be required to have a license to the external system. 

 

Example Setup Process

 

Set up the Sharepoint AI Connector 

  • Important notes:
    • Microsoft offers many MCP options. As of July 2026 the Work IQ API endpoints (A2A, remote MCP, REST) are generally available, but several surfaces - including the consolidated single-server MCP endpoint used in Option A - are still rolling out and are marked preview / "coming soon" in Microsoft's documentation. Validate the Option A endpoint in your tenant before relying on it; Option B is the more battle-tested path today.
    • Your SharePoint / Entra administrator may need to work with Microsoft to have specific MCP servers or features enabled before setup.
    • Microsoft currently limits file operations to files ≤5 MB. Larger files may be discoverable through the Copilot (Search) tools, but their full contents may not be retrievable through the SharePoint tools. (Re-confirm this limit, as it may change post-GA.)
    • This is a walkthrough of the steps required to set up the Microsoft "Work IQ MCP" server for SharePoint
      • It is recommended that you set up at least the Work IQ Sharepoint, Work IQ Copilot, and Work IQ Word (provides additional features specifically for Word documents) servers. 
        • You can optionally also enable any of the other MCP servers(e.g. User, Mail, Calendar, Teams, OneDrive) that may be valuable for your users
    • Work IQ MCP server URLs are formatted like:
https://agent365.svc.cloud.microsoft/agents/tenants/{tenant-id}/servers/{server-name}
  • {server-name} = mcp_SharePointTools for Sharepoint, mcp_M365Copilot for Copilot search; mcp_WordServer for Word

     

    Connecting Microsoft 365 (Work IQ / Agent 365 MCP servers)

  • This walkthrough covers connecting Benchling AI to Microsoft 365 through Microsoft's Work IQ MCP servers, which expose SharePoint, OneDrive, Word, Microsoft 365 Copilot (Search), and other Microsoft 365 data to Chat and Deep Research.

  • There are two ways to connect, and you can use either:
    • Option A (recommended) - a single "universal" Work IQ MCP connector. One connector exposes a small set of generic tools that reach across Microsoft 365. Introduced with the Work IQ API general availability on June 16, 2026.
    • Option B - one connector per workload. A separate connector for each Microsoft 365 workload (SharePoint, Copilot Search, Word, etc.). This is the original approach and remains fully supported.
  • Both options require a bring-your-own Microsoft Entra app registration (Benchling registered as an OAuth client in your tenant). They differ only in the endpoint URL, the OAuth scope, and how many Benchling connectors you create.
     

    Requirements (both options)

  • For a user to use any Work IQ MCP server with Benchling AI, the tenant needs:
  • A Microsoft 365 Copilot license (per user). Standard M365 E3 or E5 licenses alone are not sufficient. After assignment, features may take up to 24 hours to propagate.
  • Tenant eligibility. Microsoft has gated Agent 365 / Work IQ MCP servers to tenants enrolled in the Microsoft 365 Copilot Frontier program. Confirm your tenant's eligibility with Microsoft, as GA may be relaxing this.
  • Microsoft Entra ID admin consent for the required scopes.
  • A service principal provisioned in the tenant for the Work IQ resource (see the per-option steps below).
  • Office update channel set to Current Channel or Monthly Enterprise Channel. Semi-Annual is not supported.
  • Security baseline: Unified Audit Logging and Multi-Factor Authentication enabled tenant-wide; Conditional Access configured as appropriate.
  • Your Benchling admin and Entra admin will work together on the OAuth registration. The Benchling admin should ask the Entra admin for the tenant ID if they don't already have it.
     

    Option A - Single Work IQ MCP connector (recommended)

  • The universal Work IQ MCP server exposes ~10 generic tools (for example ask, fetch, search_paths) that operate across Microsoft 365 rather than one server per workload. This means one Benchling connector instead of several.

    A1. [Entra Admin] Enable Work IQ in the tenant

  • Provision the Work IQ service principal once. Either:
  • Run the PowerShell enablement scripts from Microsoft's Work IQ repo (Enable-WorkIQToolsForTenant.ps1, then Verify-WorkIQTenant.ps1) at https://github.com/microsoft/work-iq, or
  • Create the service principal manually:
  •   az ad sp create --id fdcc1f02-fc51-4226-8753-f668596af7f7
  • (fdcc1f02-... is the Work IQ API application; its application ID URI is api://workiq.svc.cloud.microsoft.)

    A2. [Entra Admin] Register Benchling as an OAuth client

  • Microsoft Entra admin center → App registrationsNew registration. Name it something like Benchling AI Connector.
  • Set the redirect URI provided by your Benchling admin (format https://{your-subdomain}.benchling.com/1/api/llm/mcp/oauth/callback).
  • Under Certificates & secrets, generate a client secret and copy the value immediately (it is shown only once).
  • Note the Application (client) ID from the Overview page.

    A3. [Entra Admin] Grant the Work IQ permission

  • In the app registration, go to API permissionsAdd a permission.
  • Add the Work IQ delegated permission WorkIQAgent.Ask (OAuth scope value api://workiq.svc.cloud.microsoft/WorkIQAgent.Ask). This grounds Chat / Deep Research answers in Microsoft 365 data on behalf of the signed-in user.
    • Work IQ exposes a small set of broad permissions; WorkIQAgent.Ask covers the ask/reason path used by Benchling Chat and Deep Research. If you later need direct entity-retrieval tools, review the full permission set in Microsoft's Work IQ API permissions reference and add as needed.
  • Grant admin consent for the tenant.
  • Work IQ uses delegated Entra authentication only (application-only auth is not supported), which matches Benchling's per-user connector model.

    A4. [Benchling Admin] Add the Custom AI Connector

  • Benchling → avatar (bottom left) → Tenant Admin ConsoleSettingsAI ConnectorsAdd AI Connector.
  • Name: a clear label your users will see, for example Microsoft 365 (Work IQ).
  • Server URL: https://workiq.svc.cloud.microsoft/mcp
  • Transport Type: leave the default Streamable HTTP.
  • Expand Manual OAuth registration:
    • Redirect URI: pre-populated by Benchling. Confirm it matches the URI you registered in step A2.
    • Client ID: the Application (client) ID from A2.
    • Client Secret: the secret value from A2.
  • Expand OAuth provider overrides:
    • Authorization URL: https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/authorize
    • Token URL: https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/token
    • Suppress resource parameter: check this box.
  • Click Save, then enable the tools you want to make available to users.
  • Token refresh: to keep the connection alive past access-token expiry, the OAuth request should include offline_access alongside the Work IQ scope. If your Benchling configuration does not expose a scopes field, this is handled by the admin-consented app permissions; if users are repeatedly re-prompted to sign in, confirm offline_access is included.
     

    Option B - Per-workload Work IQ / Agent 365 MCP servers

  • Use this when you want to enable specific Microsoft 365 workloads individually. You create one Benchling connector per server. As of setup it is recommended to enable at least SharePoint & OneDrive, Copilot (Search), and Word; you can optionally add others (User Profile, Mail, Calendar, Teams, SharePoint Lists).
  • Per-workload servers use this tenant-scoped endpoint format:
  • https://agent365.svc.cloud.microsoft/agents/tenants/{tenant-id}/servers/{server-name}

    Server URLs and scopes

  • Each server has its own {server-name} path segment and its own delegated scope on the Agent 365 Tools resource app (application ID ea9ffc3e-8a23-4a7d-836d-234d7c7565c1).
  • Workload {server-name} (verify) Delegated scope
    SharePoint & OneDrive mcp_SharePointTools McpServers.OneDriveSharepoint.All
    Microsoft 365 Copilot (Search) mcp_M365Copilot McpServers.CopilotMCP.All
    Word mcp_WordServer McpServers.Word.All
    SharePoint Lists (optional) mcp_SharepointListsTools McpServers.SharepointLists.All
    Mail / Calendar / Teams / User Profile (optional) mcp_MailTools / mcp_CalendarTools / mcp_TeamsTools / mcp_MeServer McpServers.Mail.All / McpServers.Calendar.All / McpServers.Teams.All / McpServers.Me.All
  • Verify the exact {server-name} segments against Microsoft's per-server references (for example the SharePoint MCP server reference) or by listing servers via the Management MCP server's tool catalog. Microsoft's own naming is inconsistent (some segments end in Tools, others in Server), so do not assume a uniform pattern.

    B1. [Entra Admin] Provision the Agent 365 Tools service principal

  • There is a single resource application - Agent 365 Tools (ea9ffc3e-8a23-4a7d-836d-234d7c7565c1) - that exposes all the McpServers.*.All scopes. Provision it once (it will not appear in Enterprise applications until it exists in the tenant):
  • Use Microsoft's Work IQ enablement scripts at https://github.com/microsoft/work-iq, or create it manually:
  •   az ad sp create --id ea9ffc3e-8a23-4a7d-836d-234d7c7565c1
  • You do not create a separate service principal per workload - you consent the individual scope for each server on this one resource.

    B2. [Entra Admin] Register Benchling as an OAuth client

  • Same as Option A step A2 (App registrations → New registration → redirect URI → client secret → note the Application (client) ID).

    B3. [Entra Admin] Grant admin consent for the workload scopes

  • Microsoft Entra admin center → Enterprise applications → search for Agent 365 Tools.
    • If it does not appear by name, search for its app ID ea9ffc3e-8a23-4a7d-836d-234d7c7565c1.
  • On your Benchling app registration → API permissions, add the delegated scopes for the servers you are enabling (from the table above), then grant admin consent. For the recommended set:

    • McpServers.OneDriveSharepoint.All
    • McpServers.CopilotMCP.All
    • McpServers.Word.All

    B4. [Entra Admin] Configure governance in the Microsoft 365 admin center

  • Microsoft 365 admin center → Agents & tools (the section that lists activated MCP servers; confirm the exact label in your tenant).
  • Review activated Work IQ MCP servers, allow or block specific servers per organizational policy, and apply scoped permissions.

    B5. [Benchling Admin] Add one Custom AI Connector per server

  • For each server you enabled, repeat:
  • Benchling → Tenant Admin ConsoleSettingsAI ConnectorsAdd AI Connector.
  • Name: a clear label, for example SharePoint or Copilot.
  • Server URL: the full tenant-scoped URL, for example https://agent365.svc.cloud.microsoft/agents/tenants/{tenant-id}/servers/mcp_SharePointTools
  • Transport Type: leave the default Streamable HTTP.
  • Expand Manual OAuth registration:
    • Redirect URI: pre-populated by Benchling; confirm it matches the URI registered in B2.
    • Client ID / Client Secret: from the same Benchling Entra app (reused across all servers).
  • Expand OAuth provider overrides:
    • Authorization URL: https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/authorize
    • Token URL: https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/token
    • Suppress resource parameter: check this box.
  • Click Add. Repeat for each additional server (Copilot Search, Word, ...) using the same Client ID and Client Secret but a different Server URL and Name.
  • Scope value format (if your configuration requests scopes explicitly): Work IQ scopes must be prefixed with the resource app ID and space-separated, for example ea9ffc3e-8a23-4a7d-836d-234d7c7565c1/McpServers.OneDriveSharepoint.All offline_access. Include offline_access so tokens refresh automatically; without it, users are re-prompted to sign in when the access token expires.

 

Was this article helpful?

Have more questions? Submit a request