Model Context Protocol
Model Context Protocol
Connect MCP clients to Lattix's tenant-bound, metadata-only Platform API tools.
The Lattix MCP server gives agents access to the same metadata-only control
plane exposed by the public Platform API. It supports MCP
2026-07-28 as the primary protocol and a stateless compatibility path for MCP
2025-11-25 clients.
Ask your Lattix administrator for the MCP endpoint assigned to your deployment.
The endpoint path is /mcp; its origin and OAuth registration are
deployment-specific. Do not infer an endpoint from the Platform API URL.
Security properties
- Every request uses a tenant-bound OAuth access token minted for the MCP audience.
- Production access uses mTLS sender-constrained tokens.
- The MCP server exchanges the inbound token for a separate Platform API audience token. It never forwards the MCP token to another service.
- The exchanged token and every Platform API response must retain the same tenant as the inbound MCP identity.
- Tool inputs contain bounded metadata only. Never send plaintext content, credentials, private keys, bearer tokens, or raw artifact bytes.
- Artifact registration and evidence recording require explicit user confirmation.
Start a connection
- Obtain the MCP endpoint, OAuth client registration, tenant assignment, and client certificate from your administrator.
- Discover OAuth resource metadata at
/.well-known/oauth-protected-resource/mcpon the MCP origin. - Request a token for the configured MCP audience and required
mcp.accessscope. - Connect to
/mcpwith the bearer token and matching client certificate. - Use
server/discover, thentools/list, with MCP2026-07-28.
Read authentication before configuring a client.