MCP
MCP Overview
What the Panoptes MCP server is, and how an AI agent uses it.
Panoptes serves a Model Context Protocol server so an AI agent — Claude, ChatGPT, Cursor or your own — can answer questions about a restaurant from real numbers and, when you allow it, take actions.
| URL | https://api.panoptesos.com/api/v1/mcp (staging: https://staging-api.panoptesos.com/api/v1/mcp) |
| Transport | Streamable HTTP, stateless JSON-RPC |
| Auth | X-Api-Key header, or an OAuth bearer from the Panoptes OAuth issuer |
| Admission | cap:view_reports (or the legacy read:reports) |
In the dashboard, Settings → Developers → MCP / AI shows the URL for your install, ready-to-paste client configs and the tool list.
How an agent works with it
get_business_contextfirst. It names the branch the credential is bound to, the currency every amount is in, today's business date and the grounding rules.- Facts answer the common questions (sales, prime cost, COGS, loss, shrinkage, reorder, payroll…) with numbers computed by the server — the agent never does the arithmetic.
- Tables let it look further: list, read, count and aggregate the readable tables.
- Actions let it change data:
list_actionsfinds what the credential may call,call_actionperforms it through the REST pipeline.
Guarantees
- Same permissions as the REST API. Effective access is the owner's role AND the credential's scopes. Each fact tool keeps its own capability.
- Reads cannot write. Fact and table tools run in a
READ ONLYtransaction;call_actionis the only write path. - Writes are the real thing.
call_actionruns in-process through the console pipeline: validation, separation of duties, period locks, idempotency and the audit chain all apply. - The model is told to ask. The server instructs the agent to confirm any money or stock movement
with the user, and to pass an
idempotencyKeyon every write.
Next: Connect a client · Tool reference · Actions