All documentation
MCP server
Configure the authenticated hosted MCP endpoint.
Hosted MCP server
Docpipe can expose parsing and RAG query tools over authenticated, stateless Streamable HTTP. The endpoint is opt-in and uses operator-managed bearer tokens; it is separate from the legacy JSON tool routes and HTTP Basic authentication.
Install the optional `profile-mcp` extra or `mcp-server` alongside the server. Keep tokens in a secret manager or Kubernetes Secret, terminate HTTPS at a trusted ingress, and never put bearer values in committed files or logs.
Enable the endpoint
pip install 'docpipe-sdk[server,mcp-server]'
DOCPIPE_MCP_SERVER_ENABLED=true
DOCPIPE_MCP_OPERATOR_TOKENS=["<random-token-at-least-32-characters>"]
DOCPIPE_MCP_ALLOWED_HOSTS=["docpipe.example.com"]
DOCPIPE_MCP_ALLOWED_ORIGINS=[]
DOCPIPE_MCP_TOOL_TIMEOUT_SECONDS=300
DOCPIPE_MCP_RATE_LIMIT_PER_MINUTE=60
# Serve the MCP endpoint over HTTPS at:
# https://docpipe.example.com/mcp- Connect an MCP client to `/mcp` and send `Authorization: Bearer <operator-token>`. Set exact allowed host values; keep allowed origins empty for server-to-server clients unless browser CORS is needed.
- The `docpipe_parse` and `docpipe_rag_query` tools use operator-configured source policy, vector index, and model settings. Clients cannot supply a database connection string or model API key.
- All configured MCP tokens share the configured tenant scope; per-token tenant assignment is not currently supported. Enable and configure tenant mapping explicitly when using tenant policies.
- `GET /mcp/health` is a liveness-only endpoint. Legacy `/mcp/tools` and `/mcp/call` remain for compatibility; new MCP clients should use `/mcp`.
- MCP POST requests are rate-limited before authentication and body processing. Parsing and RAG can be expensive, so scope tokens to trusted integrations and set timeouts for deployment capacity.
- Some hosted clients require OAuth instead of a static bearer token. Use an OAuth-capable gateway for those clients; do not disable authentication to work around this limitation.
Full environment reference and client compatibility notes: `docs/MCP_SERVER.md` in the Docpipe repository.