AI and integrations

MCP server

Connect AI clients to your organization's knowledge, agents and connectors over the Model Context Protocol.

Endpoint

https://mcp.cactive.com.au/mcp

The server speaks the Streamable HTTP transport, statelessly: each request is handled on its own, with no session, and answered with a JSON response rather than an event stream. It's the programmatic interface for organizations.

Authenticate

Send an MCP key as a bearer token, or sign in with OAuth:

Authorization: Bearer si_mcp_…

Owners and admins create MCP keys at https://id.cactive.com.au → organization → Keys, type MCP client (Keys). The key's scopes decide which tools the server offers. Without a valid key (missing, unknown, revoked, expired or not an MCP key) the server answers 401 with a JSON-RPC error and WWW-Authenticate: Bearer realm="mcp", resource_metadata="…" (see below; with error="invalid_token" when a key or token was sent but isn't accepted).

Sign in with OAuth

Clients that support MCP authorization can sign in with your account instead of a key. Add the server URL without a header; the client finds out where to sign in from the 401:

  • WWW-Authenticate: Bearer resource_metadata="https://mcp.cactive.com.au/.well-known/oauth-protected-resource/mcp" points to this server's metadata (RFC 9728), which names https://id.cactive.com.au as its authorization server.
  • The client registers itself at https://id.cactive.com.au/oauth/register (dynamic client registration, public clients with PKCE) and opens the sign-in page.
  • You choose the organization (one where your role can connect MCP clients: developer and above) and the permissions the client gets, from the scopes you hold there. Read scopes are preselected.

The client then sends access tokens issued for this server (1 hour, renewed with a refresh token). Role changes apply at the next renewal; remove the client on your account page under Connected apps to end its access. Tools act as you: changes they make are recorded in the audit log with you as the actor.

Caity uses this server too, with your sign-in to it and one organization per request: it gets the tools your role allows there, and its changes are recorded as you via Caity.

Connect a client

claude mcp add --transport http si https://mcp.cactive.com.au/mcp --header "Authorization: Bearer $SI_MCP_KEY"

For clients configured with an mcpServers file, such as .mcp.json:

.mcp.json
{
  "mcpServers": {
    "si": {
      "type": "http",
      "url": "https://mcp.cactive.com.au/mcp",
      "headers": { "Authorization": "Bearer ${SI_MCP_KEY}" }
    }
  }
}
curl -s https://mcp.cactive.com.au/mcp \
  -H "Authorization: Bearer $SI_MCP_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Tools

Every key gets whoami; the others need the scope shown. Arguments and details are on MCP tools.

ToolScopeDescription
whoaminoneIdentity and scopes of the current key, and the language of the person behind it (locale: en-AU writes Australian spelling and day/month/year dates, en-US US spelling and month/day/year).
weather_forecastweather:readWeather for a place: current conditions, today's high and low, sunrise and sunset, hourly (from now) and daily forecasts, and air quality where there is some.
weather_places_searchweather:readPlaces by name or postcode, best first, with coordinates and time zone (to ask weather_forecast for).
food_recipes_searchfood:readThe person's recipes (and ones their household shares) as short summaries: title, minutes, servings, rating, calories per serving, cuisines, courses, diets met, allergens.
food_recipe_getfood:readOne recipe in full: ingredients (scaled to servings when given), numbered steps, notes and its source.
food_suggestionsfood:readRecipe ideas from the person's own recipes, best first, each with why: what they cook and rate, what's in season in Australia, what's in their pantry (and about to go off), how long since they made it.
food_what_can_i_cookfood:readRecipes the person can make with what's in their pantry, fridge and freezer, best covered first, with what's missing and what's about to go off.
food_plan_getfood:readThe household's meal plan between two days (at most 92): each meal's day, meal (breakfast, lunch, dinner, snack), title and recipe.
food_substitutefood:readSubstitutes for an ingredient (e.g.
food_use_soonfood:readWhat in the household's pantry needs using soon (within days, 3 by default; leftovers included) and the person's recipes that use the most of it ("what should I cook with what's expiring?").
food_spendingfood:readThe household's grocery spending by month, from the receipts it added to Food (Coles and Woolworths e-receipts), and what it last paid for things when asked about one (item).
food_plan_mealsfood:readPlans meals for the days ahead from the person's recipes (e.g.
food_plan_addfood:readPuts a meal on the household's plan: a recipe (by id) or a note such as "Leftovers" or "Eating out".
food_shopping_listfood:readMakes a shopping list ("turn this into a shopping list"): from the plan between two days, or from recipes at given servings.
food_list_addfood:readAdds things to a shopping list (the most recent one unless listId says), one item per string ("2 L milk", "dishwashing liquid").
food_pantry_addfood:readRecords what the household has in: one item per string ("2 L milk", "spinach"), placed where it keeps and given an estimated use-by unless useBy (YYYY-MM-DD) says, added to the same thing when it's there already.
food_recipe_savefood:readSaves a recipe to the person's Food: from a web page (url, read from its recipe data), or written out (title, ingredients one per line, steps one per line or paragraph).
drive_searchnone
drive_listnone
drive_getnoneDetails of a file or folder: where it is, size, type, versions, who it's shared with (for editors) and its link setting.
drive_readnoneRead a text file (plain text, Markdown, CSV, JSON, code…), up to 1 MB.
drive_download_urlnoneA link to download a file, valid for an hour.
drive_folder_createnoneCreate a folder.
drive_file_writenoneSave a small text file (up to 1 MB).
drive_sharenoneShare a file or folder with a member (by email) or a team (by name), as viewer, commenter or editor.
document_createnoneCreate a document (Documents), optionally with content in Markdown (headings, lists, tables, links).
document_readnoneRead a document: as Markdown (format: "markdown", the default) or its outline of headings ("outline").
document_editnoneChange a document.
document_commentnoneComment on a document: on the text quoted (quote, a short passage as it appears) or on the whole document.
sheet_createnoneCreate a spreadsheet (Sheets), optionally with sheets of rows: strings starting with "=" are formulas (A1 references), numbers and dates as typed.
sheet_readnoneRead cells of a spreadsheet: range in A1 form with an optional sheet ("Budget!A1:D20"; the first sheet without one).
sheet_writenoneWrite cells from the top-left of range ("Sheet1!B2"): values as rows; strings starting with "=" are formulas.
sheet_add_chartnoneAdd a chart over a range (headers in its first row, categories in its first column): column, bar, line, area, pie, donut or scatter.
slides_createnoneCreate a presentation (Slides) from an outline: a title slide, then one slide per entry (bullets make a title-and-body slide, none a section slide), with speaker notes.
slides_readnoneRead a presentation: each slide's title, text and speaker notes, in order.
slides_addnoneAdd slides to a presentation after the slide after (a slide id from slides_read; the end without it).
office_searchnoneFind documents, spreadsheets and presentations by what's in them (every word must appear), with a snippet each.
office_exportnoneA download link (an hour) for a document, spreadsheet or presentation in another format: md or txt for documents, csv or tsv for spreadsheets, txt for presentations; docx, xlsx, pptx and pdf where the platform has them on.
video_readnoneRead a video project (Video): its sequences with size, rate and length; tracks with their clips (media names, start and end as timecode, where each starts in its media); markers; caption tracks with their text and times; and the media.
video_createnoneMake a video project (Video) from Drive files in order: a rough cut on one sequence, each clip optionally trimmed (in and out in seconds of its file).
video_transcribenoneTranscribe one media item of a video project into a new caption track (Amazon Transcribe; speakers labelled).
photos_albumsnoneList the albums in your photo library (title, number of photos, id).
photos_albumnoneThe photos in one album, in the album's order (up to 200).
photos_searchnoneFind photos and videos by when they were taken (from/to: 2024-06-12 or ISO date-times), where (near a latitude/longitude within km, or a box), words in names and descriptions, type, favourites.
photos_getnoneA photo's details: when and where it was taken, camera, size, description, albums, and a link to see it (an hour).
mirage_serversnoneThe person's Mirage servers (Discord-style communities), in their order, with unread and mention counts and the channels they can see (ids for the other Mirage tools).
mirage_inboxnoneWhat needs the person's attention in Mirage: recent messages that mention them (by name, their roles or @everyone), newest first, and the channels they haven't read, by server, with mention counts.
mirage_messagesnoneA Mirage channel's or thread's recent messages, oldest first (before: a message id, for the ones before it).
mirage_searchnoneSearch a Mirage server's messages the person can read: words, and optionally who sent them (from, a user id), where (in, a channel id) or what they have (link, file, image, video).
mirage_sendnoneSend a message in a Mirage channel or thread as the person (Markdown; mention someone as <@userId>).
health_summarynoneThe person's Health summary for today and this week: each metric they let you read (steps, sleep, heart rate and so on) with today's value, the week's daily average, the trend against the week before and the latest reading.
health_metricnoneOne Health metric's daily values between two days (at most a year), with the average and best day.
context_getknowledge:readRead a context entry by namespace and key.
context_listknowledge:readList context entries in a namespace, optionally filtered by key prefix.
pages_listknowledge:readList Notes pages (the organization's pages and databases) under a parent (default: top level).
page_getknowledge:readRead a Notes page as Markdown with front matter (title, version, ...).
page_searchknowledge:readSearch Notes pages by title and text.
context_putknowledge:writeCreate or replace a context entry.
context_deleteknowledge:writeDelete a context entry.
page_upsertknowledge:writeCreate a Notes page from Markdown, or replace an existing page's content.
agent_job_createagents:runQueue work for one of the organization's self-hosted agents.
agent_job_cancelagents:runCancel an agent job: a queued job is canceled at once; a running job stops at its device's next check (status canceling, then canceled).
agent_job_getagents:readStatus of an agent job, with a temporary results URL once done.
issues_metaissues:readIssue tracking catalogs: spaces (keys), issue types, statuses, priorities, resolutions, link types, custom fields and people.
issues_searchissues:readSearch issues with the query language (JQL-compatible), e.g.
issues_reportissues:readReport over the issues a query matches.
issues_agendaissues:readYour Tasks dates between from and to (YYYY-MM-DD, at most 100 days): issues assigned to you by due and start date, and sprint starts, sprint ends and releases of the spaces you work in.
issue_getissues:readOne issue by key (e.g.
boards_listissues:readBoards with their type (scrum or kanban), spaces and columns, plus the open sprints of scrum boards.
board_getissues:readA board's cards by column: the active sprint for scrum boards, the flow for kanban boards.
filters_listissues:readSaved filters shared with the organization or with this key's teams: name and query (run one with issues_search).
sprint_createissues:writeCreate a future sprint on a scrum board (see boards_list for board ids).
sprint_planissues:writePut issues (keys) into a sprint, or back into the backlog with sprintId null.
sprint_startissues:writeStart a future sprint.
sprint_completeissues:writeComplete an active sprint.
issue_createissues:writeCreate an issue.
issue_updateissues:writeChange an issue's fields (not its status: use issue_transition).
issue_transitionissues:writeMove an issue through its workflow by transition or target status name (see issue_get for the available ones).
issue_commentissues:writeAdd a Markdown comment to an issue.
issue_linkissues:writeLink two issues, e.g.
issue_worklogissues:writeLog work on an issue, e.g.
issues_rankissues:writeReorder issues in the backlog: put issues (keys, in order) right before or right after another issue.
issue_moveissues:writeMove an issue (and its subtasks) to another space.
issue_deleteissues:writeDelete an issue with its comments, attachments, work logs and subtasks.
space_createissues:writeCreate a space (project) from a template: scrum, kanban, bugs, service or basic.
crm_objectscrm:readThe objects in Customers (accounts, contacts, leads, opportunities, activities and custom ones) with their fields: ids, types, picklist values and lookups' targets, and the pipelines with their stages.
crm_searchcrm:readFind records in Customers by words of their name, company, email, phone or website (prefixes match), or by id.
crm_records_listcrm:read
crm_record_getcrm:readRead a record in Customers by id: its fields (lookups and owners by name), what the caller may do with it, its related records and its latest activities.
crm_record_createcrm:writeCreate a record in Customers: the object id and field values by field id (crm_objects lists them; picklists take a value or its label, lookups a record id, dates YYYY-MM-DD).
crm_record_updatecrm:writeChange a record's fields in Customers (by field id; null clears one) or owner.
crm_activity_logcrm:writeLog an activity on records in Customers: a task (open, with a due date), call, meeting, note or email, related to one or more records (contacts, accounts, opportunities, leads).
crm_pipeline_summarycrm:readThe sales pipeline at a glance: open opportunities by stage (count, amount, weighted), won and lost this month and the last six months, per pipeline, and how many records each object has.
marketing_segments_listmarketing:readThe organization's Marketing segments (saved audiences over contacts and leads): ids, names, their groups' filters and the last size estimate.
marketing_segment_getmarketing:readOne segment: its groups (Customers filters, engagement and list conditions) and the last size estimate.
marketing_segment_estimatemarketing:readCounts a segment's people (each address once) in the background and returns the segment: counting while it runs, then estimate.
marketing_lists_listmarketing:readMarketing lists: static lists and suppression lists (never sent to), by channel, with member counts.
marketing_campaigns_listmarketing:readMarketing campaigns, newest first: status (draft, waiting for approval, scheduled, sending, sent, paused, cancelled), topic, schedule and, once sending started, their numbers.
marketing_campaign_getmarketing:readOne campaign and its results: audience, topic, approval, schedule, send progress and numbers (sent, delivered, opened, clicked, bounced, complained, unsubscribed, skipped, conversions, revenue).
marketing_journeys_listmarketing:readMarketing journeys: status (draft, running, paused, stopped), the live version and how many people entered, are in them, completed and reached the goal.
marketing_journey_getmarketing:readOne journey: its draft (entry, re-entry, goal and steps), versions, approval, and its numbers: totals, each step's (entered, completed, exited, goal) and each email and text step's sends.
marketing_consent_getmarketing:readAn email address's or mobile number's Marketing consent: status (subscribed, pending, unsubscribed, bounced, complained), each topic's choice, and the history of changes with their evidence.
marketing_stats_dailymarketing:readThe organization's Marketing numbers per UTC day and their totals: emails sent, delivered, opened, clicked, bounced, unsubscribed, conversions and revenue, texts, form submissions, journey entries and page views.
marketing_forms_listmarketing:readMarketing forms (web-to-lead): what they create, whether they're open, and their submissions and the spam they turned away.
marketing_campaign_createmarketing:writeDrafts a campaign: a name, a topic id (from the settings' topics), an audience (segments and lists to include and exclude) and content (a block document, or a template id).
marketing_campaign_request_approvalmarketing:writeAsks the organization's approvers to approve a draft campaign as it stands (when the organization requires approvals).
marketing_journey_createmarketing:writeDrafts a journey with a name and description (and optionally a definition: entry, re-entry, goal and steps).
aircraft_findmaps:readWhere is an aircraft now: by ICAO hex (7C6B2D), registration (VH-ABC) or callsign (QFA1).
aircraft_trackmaps:readRecorded track of a watched aircraft over the last hours (positions every ~10 s while a watch covers it): start, end, distance and sampled points.
flight_watches_listmaps:readFlight watches you can see, with targets, areas, which events notify, and when each last fired.
flight_logs_listmaps:readFlights a watch logged (each airframe by ICAO hex): when, start and end, distance, highest altitude, roads followed and events.
flight_log_getmaps:readOne logged flight: its events and road spans with a sampled track, or the whole track as a GPX, KML or CSV file (format).
flight_watch_eventsmaps:readRecent events of a flight watch (takeoffs, landings, signal lost or back, areas, orbits, roads followed, thresholds), newest first.
maps_locations_listmaps:readThe org's alert locations (bases, hospitals, airfields): name, position and on-site radius.
my_location_statusmaps:readWhether your phone shares its location with Maps for near-me alerts (from the Maps app): phones, background or not, and until when the current fix counts.
flight_watch_createmaps:write
circling_alert_createmaps:writeAlert when aircraft circle or hold somewhere (searching, orbiting, holding), below 5,000 ft and ignoring airfield circuits within 3 km.
maps_location_createmaps:writeAdd an org alert location (a base, a hospital, an airfield): name, lat, lon and the on-site radius in metres (50–5,000; default 300).
maps_location_updatemaps:writeChange an org alert location (its owner or an org admin).
maps_location_deletemaps:writeDelete an org alert location (its owner or an org admin).
my_location_deletemaps:writeDelete your location from Maps: every phone's current fix, the phones sharing and their keys.
flight_watch_pausemaps:writePause a flight watch (nothing is evaluated or sent) or resume it with paused: false.
flight_watch_restartmaps:writeStart an ended flight watch again (after its end time, notification or flight limit) with its counters at zero.
incidents_listmaps:readCurrent emergency incidents and warnings in Australia from the state agencies' public feeds (VicEmergency, NSW RFS, Queensland Fire Department, ACT ESA): Australian Warning System level, hazard, status, what to do and the agency's page.
incident_getmaps:readOne incident or warning by id (from incidents_list): everything the agency says, and its history of level and status changes.
watch_zones_listmaps:readWatch zones in Maps: areas where emergency incidents and warnings alert people (by push, email or text), with their hazards, minimum level and status.
watch_zone_eventsmaps:readRecent alerts of a watch zone, newest first, with what was sent.
watch_zone_createmaps:writeMake a watch zone that alerts on emergency incidents and warnings in Australia: areas (a circle around a point, an org location, your phone's location with near_me, a drawn polygon or a whole state), hazards, minimum warning level and which changes alert (new, escalated, downgraded, closed, updated).
watch_zone_updatemaps:writeChange a watch zone (its owner, or an org admin for org zones): fields given replace the current ones.
watch_zone_pausemaps:writePause a watch zone (no alerts) or resume it with paused: false.
watch_zone_deletemaps:writeDelete a watch zone (its owner, or an org admin for org zones).
tenant_overviewtenant:readThe organization's tenant overview: properties, member counts, the sign-in policy and security recommendations (members without a passkey or two-step sign-in, old invites, expiring keys and secrets).
tenant_users_listtenant:readList the organization's members with role, title, department, status (active or blocked), guest access, groups, passkeys and last sign-in; and pending invites.
tenant_user_gettenant:readOne member in detail: groups, browser sessions, keys they created, app assignments and recent sign-ins.
tenant_groups_listtenant:readList the organization's groups with their size, owners and the roles they grant.
tenant_group_gettenant:readOne group: members and owners, granted roles, Serverless App Service and repository access, and app assignments.
tenant_roles_listtenant:readBuilt-in and custom roles with their scopes, and the members and groups holding each.
tenant_sign_instenant:readMembers' sign-ins and failed sign-ins, newest first: method, address, approximate place and device.
tenant_policy_gettenant:readThe organization's sign-in policy and the members it would leave without access.
tenant_invitetenant:writeInvite someone to the organization by email.
tenant_user_updatetenant:writeChange a member's role, title or department.
tenant_user_blocktenant:writeBlock a member's sign-in to this organization: no new tokens, and current ones stop within 30 seconds.
tenant_user_unblocktenant:writeUnblock a member's sign-in; they sign in again to reach the organization.
tenant_user_revoke_sessionstenant:writeEnd a member's sessions for this organization (they sign in again) and disconnect their MCP clients here; keys also revokes keys they created here.
tenant_group_member_settenant:writeAdd a member to a group, make them a group owner, or take them out (role null).
databases_listresources:readThe organization's databases (DynamoDB tables): id, name, region and linked Serverless App Service.
database_describeresources:readKey schema, indexes, status and approximate item count of a database.
database_queryresources:readQuery a database (or one of its indexes) by partition key, with an optional sort key condition and filters.
database_scanresources:readScan a database page by page, optionally with filters.
database_item_getresources:readRead one item by its key (strongly consistent).
buckets_listresources:readThe organization's buckets (S3): id, name, region and linked Serverless App Service.
bucket_listresources:readList one folder of a bucket: subfolders and files (key, size, last modified).
bucket_download_urlresources:readA link that downloads one file for the next 5 minutes.
database_item_putresources:writeCreate an item (an existing key is an error), or with replace replace the existing item with the same key (a missing one is an error).
database_item_deleteresources:writeDelete one item by its key.
bucket_upload_urlresources:writeA link (15 minutes) to upload one file with an HTTP PUT, up to 5 GB.
bucket_deleteresources:writeDelete files (keys) and folders (prefixes ending in /, with everything in them).
project_trafficanalytics:readTraffic of the organization's deployments (or one Serverless App Service's): requests, bandwidth, status classes, cache hits, p50/p95 latency, a series over the range and top paths, countries and deployments.
keys_listnoneKeys that protect the organization's data (with keys:read: Drive, secrets, connectors and integrations too) and its own keys for encrypting and signing: id, name, what it protects, algorithm, current version, uses in the last 30 days.
key_getnoneOne key by id (ck_…) or name: versions still in use, created, last rotated, last used, uses in the last 30 days, rotation schedule and recent re-encryption jobs.
keys_encryptkeys:useEncrypts up to 64 KB with one of the organization's aes-256-gcm keys.
keys_decryptkeys:useDecrypts a ciphertext (k1.…) made with one of the organization's keys, with the context it was encrypted with.
keys_signkeys:useSigns up to 64 KB with one of the organization's ed25519 or ecdsa-p256 keys.
keys_verifykeys:useChecks a signature (k1s.…) from keys_sign against a message.
secrets_listenv:readSecrets (sensitive environment variables) of a Serverless App Service, or the organization's shared ones: name, environments, version, rotation reminder and when it's due.
secret_getenv:readA secret's value, only if its access rule lets the caller read it (owners and admins, plus the roles and groups it names).
secret_setenv:writeSets a secret (a sensitive environment variable) to a new value: a new version, for the given environments (default all three).
connectors_listconnectors:readRemote MCP servers connected to this organization and the tool names they add here.

Keys with connectors:read also get the tools of the organization's enabled connectors, named <slug>__<tool>.

Database and bucket tools (resources:read to read, resources:write to change) work on the organization's own databases and buckets by resource id, with typed DynamoDB JSON for items and short-lived links for file downloads and uploads. project_traffic (analytics:read) returns the same numbers as Analytics.

Activity

Tools that change data (context_put, context_delete, page_upsert, agent_job_create, database_item_put, database_item_delete, bucket_delete) are recorded in the audit log with the key as the actor. Requests time out after 60 seconds.