MCP
Model Context Protocol サーフェスにより、エージェントはツール呼び出しでフラグ、分析、ワークフロー、メッセージを読み書きできます。これはマシン間のサーフェスであり、ブラウザからのリクエストは拒否されます。
| Host | Serves |
|---|---|
| https://eu.mcp.prodantix.com |
mcp
Invoke an MCP method
JSON-RPC 2.0 over HTTP. Every request needs Mcp-Protocol-Version: 2026-07-28.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
| Mcp-Protocol-Version required | header | string | Must be 2026-07-28 |
Body
{
"id": "integer",
"jsonrpc": "2.0",
"method": "server/discover | ping | tools/list | tools/call | resources/list | resources/templates/list | resources/read | prompts/list | prompts/get",
"params?": "object"
}Responses
200 A JSON-RPC 2.0 response object.
Try it
curl -X POST "https://eu.mcp.prodantix.com/mcp" \
-H "Authorization: Bearer $BEARER_AUTH" \
-H "Content-Type: application/json" \
-d '{"id":0,"jsonrpc":"2.0","method":"server/discover","params":{}}'const response = await fetch('https://eu.mcp.prodantix.com/mcp', {
method: 'POST',
headers: {
Authorization: `Bearer ${bearerAuth}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"id": 0,
"jsonrpc": "2.0",
"method": "server/discover",
"params": {}
}),
});
const data = await response.json();final response = await http.post(
Uri.parse('https://eu.mcp.prodantix.com/mcp'),
headers: {
'Authorization': 'Bearer $bearerAuth',
'Content-Type': 'application/json',
},
body: jsonEncode({"id":0,"jsonrpc":"2.0","method":"server/discover","params":{}}),
);response = requests.post(
"https://eu.mcp.prodantix.com/mcp",
headers={"Authorization": f"Bearer {bearer_auth}"},
json={"id":0,"jsonrpc":"2.0","method":"server/discover","params":{}},
)Connect an agent
An agent reaches prodantix at https://eu.mcp.prodantix.com/mcp. Agents have to be on for your company first: someone who can manage agents turns them on with the switch on the console's Agents page, which also shows this address with a copy button and the steps below.
Claude
- In Claude, open Customize, then Connectors, choose + and then Add custom connector.
- Paste the server address, add it, then choose Connect.
- Sign in with Bomdisoft, then choose the company, the projects and what the agent may do.
On a Team or Enterprise plan an owner adds the connector once, under Organization settings, Connectors, and each member connects it from Customize, Connectors. See Claude's guide to custom connectors.
ChatGPT
- In ChatGPT on the web, turn on Developer mode under Settings, Security and login. It is available on Plus, Pro, Business, Enterprise and Education.
- On the Plugins page choose +, name the app, paste the server address as its MCP server URL, then create it.
- Sign in with Bomdisoft, then choose the company, the projects and what the agent may do.
See OpenAI's guide to developer mode.
Any other MCP client
A client that supports remote servers with OAuth connects the same way: add the address, and the client learns where to sign in from /.well-known/oauth-protected-resource, which answers without a token.
What the agent may do
Signing in opens the Bomdisoft permissions screen. You choose the companies, asked only when you belong to more than one; all projects or only some; and how much the agent may do: Read allows every action prodantix marks as read-only that you hold, Write allows everything you can do, and Customize lets you pick actions one by one.
One connection can cover several companies. When it does, each call names the company it acts in with company_id, as prodantix.me lists them, and a resource takes it on its address as ?company_id=. A connection that covers one company needs nothing more.
The agent acts as you, and every call is checked twice: against what you granted and against what your own role allows at that moment, so an agent never does more than you could. The check covers every step inside a tool, not only the tool itself. An agent lists only the tools, resources and prompts its connection allows.
When a call is refused
A refusal before the call runs is an HTTP error with a JSON body naming its code, such as {"error":{"code":"AGENTS_DISABLED","message":"agents are switched off for this company"}}.
| Response | What it means | What to do |
|---|---|---|
| 401, with WWW-Authenticate | No valid token, or the connection was disconnected | Sign in again from the agent. A disconnected agent has to be connected again. |
| 403 INSUFFICIENT_SCOPE, with WWW-Authenticate: Bearer error="insufficient_scope" | The connection does not cover this permission, this project or this company | Connect the agent again and grant what it needs. |
| A tool result, or error -32602, asking for company_id | The connection covers more than one company and the call did not say which, or named one it does not cover | Name the company in company_id, as prodantix.me lists them. To add a company, connect again and add it on the permissions screen. |
| 403 AGENTS_DISABLED | Agents are off for the company. No connection was removed | Someone who can manage agents turns them back on from the Agents page. Calls work again within a minute. |
| A tool result reading forbidden: <action> | A step inside the tool needs a permission the connection, or your own role, does not have | Connect again granting that permission, or ask for it in your company. |
| A tool result reading this company is paused until its bill is paid | A payment failed and the bill is still open past its deadline, so the company is paused. prodantix.billing.standing still answers | Someone who manages billing pays the bill in the console. Tools answer again once it is paid. |
| 503 | The accounts service that holds connections could not be reached | Try again. |
Disconnecting
The console's Agents page lists your own connections, and every connection in the company for someone who can manage agents. Disconnect is in each row's menu and at the foot of its panel. Bomdisoft ID, at https://accounts.bomdisoft.com, lists every agent you connected across Bomdisoft products under Agents, with the same Disconnect.
Either way the agent loses access within a minute, and connecting it again goes through the permissions screen afresh. Turning agents off is different: it pauses every connection in the company without removing any.
Protocol revision
This server targets revision 2026-07-28. There is no session and no initialize handshake. A request carrying an Mcp-Protocol-Version the server does not support is rejected with JSON-RPC error -32020.
Methods
| Method | Purpose |
|---|---|
| server/discover | Server identity, supported protocol revisions and capabilities |
| ping | Liveness |
| tools/list | The tools this connection may call |
| tools/call | Invoke one tool |
| resources/list | The resources this connection may read |
| resources/templates/list | The resource templates this connection may read |
| resources/read | Read one resource by its address |
| prompts/list | The prompts this connection may use |
| prompts/get | One prompt, filled in with its arguments |
Authentication
Bearer only. An unauthenticated client learns where to authenticate from GET /.well-known/oauth-protected-resource, which stays reachable with no token at all. An agent never handles a token by hand: its client runs the sign-in described above.
Reference
Every tool, resource and prompt is listed on pages generated from the server itself: MCP tools, MCP resources and MCP prompts.
Listing the tools
curl -X POST "https://eu.mcp.prodantix.com/mcp" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-H "Mcp-Protocol-Version: 2026-07-28" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'