Connect an AI agent to DLBR MCP
On desktop, opening MCP slides the dashboard to the left while preserving its width. The panel stays fixed on the right and the viewport hides horizontal overflow. On smaller screens, the panel opens as a modal. Full screen expands the workspace. Exit full screen returns to the side panel; closing MCP restores the original dashboard position.
DLBR Gateway provides a tenant-scoped Model Context Protocol (MCP) endpoint for starting wallet verification and checking privacy-preserving results. The endpoint uses Streamable HTTP:
https://api.dlbr.app/v1/mcpIn the tenant dashboard, select MCP in the top bar to open Connect an AI agent. An Owner or Admin can connect with a scoped, console-only credential that expires after one hour. The key stays in memory and is revoked when the panel closes. Stay live retains it while the panel is closed; closing the dashboard or explicitly disconnecting ends the console connection. If immediate revocation cannot finish, the credential still expires within one hour.
The welcome screen offers three fast actions: Start verification, Check verification, and Credential types. Their order follows successful manual tool calls within the current connection. Automatic catalog loading and status polling do not change this order.
The verification form uses the server's discovered input schema and credential catalog. Select the credential and claim names, then supply the issuer registered in your tenant policy. Starting a verification returns a wallet QR code, handoff links and session ID. The wallet sends its presentation directly to the Gateway.
Follow status automatically checks the session every three seconds while the panel and browser tab are visible. Following stops on verified, failed or expired results, or on a request error. The response card shows the verdict, proven claim names and a safe failure category when available. Safe response displays the same permitted fields as JSON; claim values and wallet tokens are omitted. If session creation is interrupted, check your existing sessions before creating another request.
Connect your MCP client
The current endpoint authenticates with a tenant API key. Create a scoped key in Settings → API keys with session:create and session:read, then add the endpoint and key to your MCP client. Keep the key in the client's secret store or environment configuration; do not paste it into a prompt or commit it to source control. Use a separate key for each external client; the console's temporary credential is restricted to its browser origin.
The endpoint applies the selected key's tenant, environment, origin and scope restrictions. MCP OAuth/device authorization is not available yet.
Agent discovery
The Gateway publishes machine-readable discovery documents at the API origin:
- MCP Server Card
- ARD capability catalog
- Agent Skills index
- Protected Resource Metadata
- Agent connection instructions
The ARD catalog is also available at its canonical /.well-known/ard.json path. Protected Resource Metadata describes the API key scopes and points clients to this API resource; it does not identify an OAuth authorization server. DLBR does not currently issue OAuth access tokens for tenant MCP connections.
Tools
| Tool | What it does | What the agent receives |
|---|---|---|
list_supported_credential_types | Lists supported credential profiles and claim names | Credential types and claim names |
verify_credential | Starts a normal Gateway verification session | Session ID, expiry and wallet presentation links |
check_verification | Checks a session's result | Verdict, credential type and proven claim names |
The wallet sends its presentation directly to the existing OID4VP callback. The MCP endpoint does not accept presentation tokens. check_verification omits claim values and verification details. Session creation follows the same relying-party issuer policy and validation as POST /v1/sessions.
Use session:create for verify_credential and session:read for check_verification. Listing supported types is available to any authenticated key.
For the full request schemas and credential identifiers, see the Gateway MCP reference.