DMS MCP Server

This server exposes the Mock DMS over the Model Context Protocol. It is a third-party MCP server as far as any consumer is concerned: reachable from outside the cluster, used by more than one party, and it makes no assumption about what sits in front of it. Every call must present a signed token; unauthenticated calls get a 401.

It describes itself the standard way, unauthenticated, so a client can discover what may be asked for before holding any token:

GET /.well-known/oauth-protected-resource # RFC 9728

The governed route in is Stater's MCP Gateway, which authenticates the caller (Entra), derives the tenant from its roles claim, resolves the per-tool grant and mints the short-lived token this server verifies:

POST https://mcp.<env>.onprem.aiplatform.triplebeta.nl/servers/dms-mcp/mcp Authorization: Bearer <Entra access token> # client-credentials, scope api://<mcp-gateway>/.default X-Use-Case-Slug: <your-use-case-slug> # The token this server receives names the granted tools (capabilities) and the # opaque resource selectors (resources). This server enforces both on its own # authority — it does not take "the gateway let it through" as an answer.

Tools: list_dossiers, get_dossier, get_document.