Remote MCP / read-only customer plane

Bring attributable source access into AI workflows.

Zenith exposes one JSON-RPC MCP endpoint for supported remote clients that can present an organization-scoped bearer token. Every call is authorized against eight generic read-only tool categories.

CLIENT-NEUTRAL DOCK08

Eight generic tool categories share one call-time authorization boundary.

01

Connection sequence

Authenticate the client. Recheck every call.

A display-once MCP token does not bypass customer entitlement, source policy, call balance, rate limit, or operation authorization.

  • Hash-only token verification
  • Explicit revocation
  • Read-only operation boundary
02

Client-neutral contract

Supported remote MCP clients share one boundary.

Clients connect to the same endpoint with a bearer token. No client receives a policy exception, and no OAuth metadata or client-specific redirect flow is claimed.

  • Stable JSON-RPC endpoint
  • Eight generic tools
  • No client-specific policy bypass

MCP Dock / client-neutral

A connection is a route, not a bypass.

Supported bearer-token MCP clients follow the same authorization and policy decisions.

  1. 01

    Create a display-once MCP token

  2. 02

    Connect a supported client to the JSON-RPC endpoint

  3. 03

    Resolve customer entitlement at call time

  4. 04

    Invoke one read-only tool category

  5. 05

    Return attribution and weighted-call context

  6. 06

    Revoke the token when required

Eight read-only categories

Describe, discover, and interpret.

Generic categories communicate public breadth without exposing private tool names, client IDs, or security internals.

T1

Catalog discovery

Call-time customer authorization · read-only

T2

Capability discovery

Call-time customer authorization · read-only

T3

Source metadata

Call-time customer authorization · read-only

T4

Operation schemas

Call-time customer authorization · read-only

T5

Illustrative request planning

Call-time customer authorization · read-only

T6

Provenance review

Call-time customer authorization · read-only

T7

Usage interpretation

Call-time customer authorization · read-only

T8

Policy explanation

Call-time customer authorization · read-only

Resilient state contract

Calm in every condition.

Bring attributable source access into AI workflows. retains truthful context, navigation, and a safe next action when live records are empty or unavailable.

EMPTY

No published records

Heading, explanation, and recovery path remain.

LOADING

Reserved layout

Text status and stable geometry prevent surprise.

DEGRADED

Verified context first

Unavailable data is labeled with an alternate path.

ERROR

No false success

Plain language, stable navigation, and safe recovery.