5 minMCPAgentsWialon API

Giving an AI agent read access to Wialon

Why the Wialon tools are one remote MCP endpoint rather than a package, what it does with your token, and why a skill comes with twelve tools.

Cover: “Wialon in your editor” — an editor, the endpoint between, and the fleet it reads

The question that started this: somebody wanted to ask about their fleet from Claude Code, in the repository they were already working in, without opening a browser tab. The fleet data is in Wialon. The agent is on their laptop. What goes in between?

One endpoint, not a package

The server is an address: https://ai.theassettrack.com/mcp. An MCP client — Claude Code, Codex, Cursor — connects to it over HTTP, lists the tools and calls them. There is nothing to install and no Node on the user’s machine to keep current.

The part worth protecting is the tools, not the transport. Reading Wialon correctly means knowing the traps that do not appear in any tool schema, and the answers depend on getting every one of them right. A package on every laptop is a hundred copies of that knowledge, each as old as the day it was installed. One endpoint is one copy: a fix to how trips are read reaches every client the moment it ships, with nobody having to update anything.

An exported report comes back inside the answer as a file, so nothing is written to the user’s disk behind their back and nothing waits on ours.

What the Worker does with your token

The cost is plain: the Wialon access token now travels to us. Every request carries it in its Authorization header, and the Worker uses it to sign in to Wialon and make the calls the tool needs. There is no account of ours to create — the token is the identity, and it is yours.

Nothing is written anywhere: no database, no log line with the token or the session in it. Between calls the Worker keeps the open Wialon session in memory for up to four minutes of quiet, so a run of questions does not sign in afresh for each one. After that it is gone.

Wialon lets you issue a token for exactly this. Give it a short lifetime and only the rights reading needs, use it for the MCP client and nothing else, and delete it in your Wialon user settings the day you stop. That is the whole of the trust the endpoint asks for, and you can take it back at any time.

Twelve tools, and one door to nineteen more

The first version exposed every operation as its own tool. Thirty-one schemas travel with every single request an agent makes, whether it needs them or not, and a smaller model handed thirty-one similar names picks the wrong one more often than you would like.

So twelve tools answer the questions people actually ask — where is this vehicle, who is low on fuel, how far did each truck drive last week — and everything else in Wialon sits behind one wialon_api tool with a catalogue of nineteen operations. Call an operation with no arguments and it answers with its own schema, so the agent never has to guess and never pays for nineteen schemas it will not use.

Tools are reach. Judgement is a separate thing.

An agent with the tools can read the account. That is not the same as being able to answer correctly, and the gap is not about intelligence — it is about knowing how this particular system lies to you.

A speed of 13 km/h is not a moving truck if the position behind it is from April. A null fuel level is an unreadable sensor, not an empty tank. A report has to be run and exported in one operation, because Wialon keeps one result per session and anything running in between replaces it. None of that is discoverable from a tool schema.

So a skill comes with the server — the rules that say which tool answers what, and what the answers mean. The endpoint hands it to the agent as its instructions when the client connects, so there is nothing to copy into a project, and it is as current as the tools it describes.

Read-only, and it stays that way

Every tool in the set reads. Nothing creates, edits or deletes anything in the account — not a geofence, not a notification, not a unit setting. Running a report is the closest it comes to a write, and that touches only the session’s own result.

That is a deliberate ceiling rather than a first version. An agent that can read your fleet and get something wrong wastes your afternoon. An agent that can change your fleet and get something wrong is a different kind of product, and it should be a decision rather than a default.

Setup for each client is on the MCP page. In Claude Code it is one command:

claude mcp add --transport http fleetai \
  https://ai.theassettrack.com/mcp \
  --header "Authorization: Bearer <your token>"

Ask your own fleet instead

FleetAI reads your Wialon account and answers in plain words. Your own token, read-only, nothing to install.

Open the app