jump to content

the platform MCP server

Enter the MCP platform server, which covers connection authentication, the 293 available tools, read-only testing, and the MCP Inspector.

Show as Markdown

Platform serverMCP enables AI assistants and development tools to work with your platform data through Model Context ProtocolA connected client can discover the platform tools, inspect input schemes, and, with your permission, read or modify records within your organization.

Use it when you want:

  • Ask questions that require live context from the platform.
  • Review risks, controls, evidence, audits and other compliance records.
  • Create or update records from an AI assistant.
  • Build an agent workflow without implementing every platform operationAPI.
  1. Your client connects to the regional or self-hosted platform terminal point.
  2. the platform authenticates the connection with an interactive OAuth or scalable OAuth token.
  3. During initialization, the client discovers the tools available on the server and their JSON schemes.
  4. The customer selects a tool based on your request and asks for approval when its policy requires it.
  5. The platform checks both the token domains and the underlying user permissions before running the operation.

A token can access an organization and can only perform an operation when both its scope and user permissions allow it.

Select the implementation endpoint that contains your data:

Deployment MCP endpoint
the platform US https://us.probo.com/api/mcp/v1
the platform EU https://eu.probo.com/api/mcp/v1
Self-hosted https://<your-host>/api/mcp/v1

It requires the /api/mcp/v1 path. the platform servesMCPover HTTP Streamable; it does not expose REST-style routes for individual tools.

Most interactive clients discover the platform’s OAuth configuration and open a browser authorization stream.For a client that requires a static configuration, create a comprehensive OAuth token in the platform and send it as a carrier credential.

Start with a Request for Reading Only

“Start with a read-only request”

After connecting a client, confirm the identity and organization limit before asking them to change the data:

Use Probo to list the organizations I can access. Do not change anything.

Then include an organization in a narrow application:

For organization org_xxx, summarize open high-priority risks and cite the
record names and IDs. Do not change anything.

Explicit organization IDs eliminate ambiguity when an account can access more than one organization.

When you are ready to test a writing, specify the desired result and ask the client to submit the proposed arguments before invoking the tool:

Prepare a new third party named Acme Corp for cloud hosting in organization
org_xxx. Show me the tool and arguments first; do not create it until I approve.

The exact approval experience depends on the client.

Instruments and Schemes

Section “Tools and Schemas”

the platform currently exposes 293 tools These include organizations, risks, controls, frameworks, evidence, documents, audits, findings, privacy, third-party access reviews, webhooks, consent to cookies and other compliance workflows.

Each tool advertises:

  • A name and description used by the customer to select it.
  • JSON input and output schemas.
  • Behavioral advice, such as just reading, destructive and idempotent.

Behavioral suggestions help customers submit more secure approvals, but do not replace reviewing tool arguments.

Explore with MCP Inspector

“Explore withMCPInspector”

Use the MCP Inspector pentru a explora interactiv platformaMCPServer:

Terminal window
export PROBO_OAUTH_TOKEN="your_oauth_token"
npx @modelcontextprotocol/inspector --cli \
https://us.probo.com/api/mcp/v1 \
--transport http \
--header "Authorization: Bearer $PROBO_OAUTH_TOKEN" \
--method tools/list

The command lists the tools available through the server. It replaces the endpoint for the EU region or a self-hosted implementation. The inspector can also navigate through schemes, call tools and expose protocol errors during troubleshooting.

  • Give each client or medium its own token so that access can be revoked independently.
  • Assign only the fields required by the workflow.
  • Keep credentials out of source control, logs, shared configuration, and prompts.
  • Requires explicit approval of writing and destruction tools.
  • Page list operations until next_cursor is absent when a full set of results is required.
  • Revoke exposed or unused credentials promptly.

Ultima actualizare: