Skip to content

Connect an AI agent to DLBR MCP ​

On desktop, opening MCP slides the dashboard to the left while preserving its width. The panel stays fixed on the right and the viewport hides horizontal overflow. On smaller screens, the panel opens as a modal. Full screen expands the workspace. Exit full screen returns to the side panel; closing MCP restores the original dashboard position.

DLBR Gateway provides a tenant-scoped Model Context Protocol (MCP) endpoint for starting wallet verification and checking privacy-preserving results. The endpoint uses Streamable HTTP:

text
https://api.dlbr.app/v1/mcp

In the tenant dashboard, select MCP in the top bar to open Connect an AI agent. An Owner or Admin can connect with a scoped, console-only credential that expires after one hour. The key stays in memory and is revoked when the panel closes. Stay live retains it while the panel is closed; closing the dashboard or explicitly disconnecting ends the console connection. If immediate revocation cannot finish, the credential still expires within one hour.

The welcome screen offers three fast actions: Start verification, Check verification, and Credential types. Their order follows successful manual tool calls within the current connection. Automatic catalog loading and status polling do not change this order.

The verification form uses the server's discovered input schema and credential catalog. Select the credential and claim names, then supply the issuer registered in your tenant policy. Starting a verification returns a wallet QR code, handoff links and session ID. The wallet sends its presentation directly to the Gateway.

Follow status automatically checks the session every three seconds while the panel and browser tab are visible. Following stops on verified, failed or expired results, or on a request error. The response card shows the verdict, proven claim names and a safe failure category when available. Safe response displays the same permitted fields as JSON; claim values and wallet tokens are omitted. If session creation is interrupted, check your existing sessions before creating another request.

Connect your MCP client ​

The current endpoint authenticates with a tenant API key. Create a scoped key in Settings → API keys with session:create and session:read, then add the endpoint and key to your MCP client. Keep the key in the client's secret store or environment configuration; do not paste it into a prompt or commit it to source control. Use a separate key for each external client; the console's temporary credential is restricted to its browser origin.

The endpoint applies the selected key's tenant, environment, origin and scope restrictions. MCP OAuth/device authorization is not available yet.

Agent discovery ​

The Gateway publishes machine-readable discovery documents at the API origin:

The ARD catalog is also available at its canonical /.well-known/ard.json path. Protected Resource Metadata describes the API key scopes and points clients to this API resource; it does not identify an OAuth authorization server. DLBR does not currently issue OAuth access tokens for tenant MCP connections.

Tools ​

ToolWhat it doesWhat the agent receives
list_supported_credential_typesLists supported credential profiles and claim namesCredential types and claim names
verify_credentialStarts a normal Gateway verification sessionSession ID, expiry and wallet presentation links
check_verificationChecks a session's resultVerdict, credential type and proven claim names

The wallet sends its presentation directly to the existing OID4VP callback. The MCP endpoint does not accept presentation tokens. check_verification omits claim values and verification details. Session creation follows the same relying-party issuer policy and validation as POST /v1/sessions.

Use session:create for verify_credential and session:read for check_verification. Listing supported types is available to any authenticated key.

For the full request schemas and credential identifiers, see the Gateway MCP reference.

Built for developers integrating privacy-preserving identity verification. • v0.1.0 • 286a32d6