MCP for AI assistants
POST /api/mcp on the same API keys. Read documentation and the knowledge base; never a secret, never a reveal tool.
Trove KB speaks the Model Context Protocol at POST /api/mcp, Streamable HTTP with JSON responses, authenticated by the same API keys as the REST API with the read scope. Access is granted and revoked in one place, and a key’s companies apply to every tool.
claude mcp add --transport http trove-kb https://docs.example.com/api/mcp \
--header "Authorization: Bearer $TROVE_KEY"
Tools
| Tool | What it returns |
|---|---|
search_documents, get_document | Documentation, secrets redacted |
list_companies, get_company, list_doc_types | The hierarchy and the templates |
list_kb_collections | Knowledge base collections; with collection_id, its categories |
search_kb | One result per article: the passage that matched, and source_url |
get_kb_article | An article in chunks; follow next_chunk for a long one. A runbook also carries steps |
list_kb_articles | A collection’s articles with their external_id and kind; kind filters |
upsert_kb_article | Writes an article, replacing the one with the same external_id; kind: "runbook" makes a procedure |
archive_kb_article | Takes an article out of the collection; nothing is deleted |
The last two are offered only to a key granted write on a collection, under Admin → Knowledge base → the collection → API key access, and work only there. An assistant working in a code repository can keep that product’s own documentation current this way.
A knowledge base collection kept to named companies is seen only by a key with access to one of them, and no key sees a collection with MCP turned off.
No assistant can read a credential
Secret fields are stripped from every MCP response, and there is deliberately no reveal tool. Revealing a credential stays a decision a person makes in Trove KB, where it is audited. Nothing exposed over MCP can change client documentation.
Behind Cloudflare Access
An Access login page is HTML, and an MCP client presenting a bearer token has nowhere to put it. If Access sits in front of the hostname, leave /api/* out of the policy or scope it to a service token.