DMS MCP Server
This server exposes the Mock DMS over the Model Context Protocol. It is a third-party MCP server as far as any consumer is concerned: reachable from outside the cluster, used by more than one party, and it makes no assumption about what sits in front of it. Every call must present a signed token; unauthenticated calls get a 401.
It describes itself the standard way, unauthenticated, so a client can discover what may be asked for before holding any token:
GET /.well-known/oauth-protected-resource # RFC 9728The governed route in is Stater's MCP Gateway, which authenticates the caller (Entra), derives the tenant from its roles claim, resolves the per-tool grant and mints the short-lived token this server verifies:
POST https://mcp.<env>.onprem.aiplatform.triplebeta.nl/servers/dms-mcp/mcp
Authorization: Bearer <Entra access token> # client-credentials, scope api://<mcp-gateway>/.default
X-Use-Case-Slug: <your-use-case-slug>
# The token this server receives names the granted tools (capabilities) and the
# opaque resource selectors (resources). This server enforces both on its own
# authority — it does not take "the gateway let it through" as an answer.Tools: list_dossiers, get_dossier, get_document.