the platform MCP server
Enter the MCP platform server, which covers connection authentication, the 293 available tools, read-only testing, and the MCP Inspector.
Platform serverMCP enables AI assistants and development tools to work with your platform data through Model Context ProtocolA connected client can discover the platform tools, inspect input schemes, and, with your permission, read or modify records within your organization.
Use it when you want:
- Ask questions that require live context from the platform.
- Review risks, controls, evidence, audits and other compliance records.
- Create or update records from an AI assistant.
- Build an agent workflow without implementing every platform operationAPI.
How a connection works
Section entitled “How a connection works”- Your client connects to the regional or self-hosted platform terminal point.
- the platform authenticates the connection with an interactive OAuth or scalable OAuth token.
- During initialization, the client discovers the tools available on the server and their JSON schemes.
- The customer selects a tool based on your request and asks for approval when its policy requires it.
- The platform checks both the token domains and the underlying user permissions before running the operation.
A token can access an organization and can only perform an operation when both its scope and user permissions allow it.
Connect to the platform.
Section entitled “Connect to the platform”Select the implementation endpoint that contains your data:
| Deployment | MCP endpoint |
|---|---|
| the platform US | https://us.probo.com/api/mcp/v1 |
| the platform EU | https://eu.probo.com/api/mcp/v1 |
| Self-hosted | https://<your-host>/api/mcp/v1 |
It requires the /api/mcp/v1 path. the platform servesMCPover HTTP Streamable; it does not expose REST-style routes for individual tools.
Most interactive clients discover the platform’s OAuth configuration and open a browser authorization stream.For a client that requires a static configuration, create a comprehensive OAuth token in the platform and send it as a carrier credential.
Start with a Request for Reading Only
“Start with a read-only request”After connecting a client, confirm the identity and organization limit before asking them to change the data:
Use Probo to list the organizations I can access. Do not change anything.Then include an organization in a narrow application:
For organization org_xxx, summarize open high-priority risks and cite therecord names and IDs. Do not change anything.Explicit organization IDs eliminate ambiguity when an account can access more than one organization.
When you are ready to test a writing, specify the desired result and ask the client to submit the proposed arguments before invoking the tool:
Prepare a new third party named Acme Corp for cloud hosting in organizationorg_xxx. Show me the tool and arguments first; do not create it until I approve.The exact approval experience depends on the client.
Instruments and Schemes
Section “Tools and Schemas”the platform currently exposes 293 tools These include organizations, risks, controls, frameworks, evidence, documents, audits, findings, privacy, third-party access reviews, webhooks, consent to cookies and other compliance workflows.
Each tool advertises:
- A name and description used by the customer to select it.
- JSON input and output schemas.
- Behavioral advice, such as just reading, destructive and idempotent.
Behavioral suggestions help customers submit more secure approvals, but do not replace reviewing tool arguments.
Explore with MCP Inspector
“Explore withMCPInspector”Use the MCP Inspector pentru a explora interactiv platformaMCPServer:
export PROBO_OAUTH_TOKEN="your_oauth_token"npx @modelcontextprotocol/inspector --cli \ https://us.probo.com/api/mcp/v1 \ --transport http \ --header "Authorization: Bearer $PROBO_OAUTH_TOKEN" \ --method tools/listThe command lists the tools available through the server. It replaces the endpoint for the EU region or a self-hosted implementation. The inspector can also navigate through schemes, call tools and expose protocol errors during troubleshooting.
Operational guidance
Section entitled “Operational guidance”- Give each client or medium its own token so that access can be revoked independently.
- Assign only the fields required by the workflow.
- Keep credentials out of source control, logs, shared configuration, and prompts.
- Requires explicit approval of writing and destruction tools.
- Page list operations until
next_cursoris absent when a full set of results is required. - Revoke exposed or unused credentials promptly.