Docs / MCP deep dive

MCP servers — Introduction

TokenSaver ships two Model Context Protocol (MCP) servers so agents (Cursor, Claude Code, any MCP client) reach the governed pipeline directly. Both authenticate with your TokenSaver API key (ts_…).

Two MCP servers

Server What it does Endpoint
Tools server — Component A tokensaver_* tools — governed chat, models, usage, cache, RAG inventory, pipeline settings, runs mcp.tokensaver.fr/mcp
Trust Gateway — Component B Transparent proxy in front of any upstream MCP (e.g. filesystem) — adds auth, RBAC/OPA, PII redaction, audit & tracing gateway.tokensaver.fr/mcp

When to use which

  • Use the Tools server when you want the agent to call the TokenSaver pipeline itself — governed chat, model catalogue, usage/quotas, cache and run inspection
  • Use the Trust Gateway when you want to keep an existing MCP server (your filesystem, a DB tool, …) but route every call through TokenSaver governance (policy, PII scan, audit, traces)
  • You can enable both at once in the same client

Authentication

Both hosted servers support two modes. Workspace and quotas always resolve from the effective TokenSaver key (your ts_… or an OAuth pivot key created at consent).

Mode How Typical hosts
Bearer Authorization: Bearer ts_… (HTTP) or TOKENSAVER_API_KEY (stdio / local) Cursor, Codex, Open WebUI, scripts, Debugger smoke tests
OAuth 2.1 (PKCE) Host redirects to TokenSaver consent → pivot API key (e.g. « Mistral MCP », Claude scope). Requires MCP_OAUTH_ENABLED=true Claude.ai Connectors, Mistral Studio / Le Chat
  • Tools server scope: mcp:tools → URL https://mcp.tokensaver.fr/mcp
  • Trust Gateway scope: mcp:gateway → URL https://gateway.tokensaver.fr/mcp
  • Manage sessions: console → Settings → Connexion MCP / OAuth sessions (revoke pivot keys)

Next: Set up the Tools server, browse the tools, or configure the Trust Gateway.