Docs / MCP deep dive
MCP servers — Introduction
TokenSaver ships two Model Context Protocol (MCP) servers so agents (Cursor, Claude Code, any MCP client) reach the governed pipeline directly. Both authenticate with your TokenSaver API key (ts_…).
Two MCP servers
| Server | What it does | Endpoint |
|---|---|---|
| Tools server — Component A | tokensaver_* tools — governed chat, models, usage, cache, RAG inventory, pipeline settings, runs |
mcp.tokensaver.fr/mcp |
| Trust Gateway — Component B | Transparent proxy in front of any upstream MCP (e.g. filesystem) — adds auth, RBAC/OPA, PII redaction, audit & tracing | gateway.tokensaver.fr/mcp |
When to use which
- Use the Tools server when you want the agent to call the TokenSaver pipeline itself — governed chat, model catalogue, usage/quotas, cache and run inspection
- Use the Trust Gateway when you want to keep an existing MCP server (your filesystem, a DB tool, …) but route every call through TokenSaver governance (policy, PII scan, audit, traces)
- You can enable both at once in the same client
Authentication
Both hosted servers support two modes. Workspace and quotas always resolve from the effective TokenSaver key (your ts_… or an OAuth pivot key created at consent).
| Mode | How | Typical hosts |
|---|---|---|
| Bearer | Authorization: Bearer ts_… (HTTP) or TOKENSAVER_API_KEY (stdio / local) |
Cursor, Codex, Open WebUI, scripts, Debugger smoke tests |
| OAuth 2.1 (PKCE) | Host redirects to TokenSaver consent → pivot API key (e.g. « Mistral MCP », Claude scope). Requires MCP_OAUTH_ENABLED=true |
Claude.ai Connectors, Mistral Studio / Le Chat |
- Tools server scope:
mcp:tools→ URLhttps://mcp.tokensaver.fr/mcp - Trust Gateway scope:
mcp:gateway→ URLhttps://gateway.tokensaver.fr/mcp - Manage sessions: console → Settings → Connexion MCP / OAuth sessions (revoke pivot keys)
Next: Set up the Tools server, browse the tools, or configure the Trust Gateway.