MCP Integration
SupportBot ships with a Model Context Protocol (MCP) server: Claude and any other MCP-capable AI client can operate your support platform directly through 44 tools — inspect conversations, upload knowledge-base documents, run test scenarios, trigger weekly reports, and more.
Endpoint
| Field | Value |
|---|---|
| URL | https://showcase.<your-domain>/api/mcp |
| Transport | Streamable HTTP (MCP standard; POST/GET/DELETE) |
| Authentication | Authorization: Bearer <API key> |
| Rate limit | 60 requests per minute per key |
| Sessions | Stateful; idle sessions close after 30 minutes |
Creating an API key
- Open Settings → API Keys in the admin panel.
- Give the key a name (e.g. "Claude Desktop") and create it.
- The key, starting with
sk_showcase_, is shown only once — store it somewhere safe. The server keeps a SHA-256 digest, never the key itself. - Revoke unused keys from the same screen. Every MCP call is attributed to the calling key and user (audit trail).
Connecting Claude
Claude Code (CLI):
claude mcp add supportbot \
--transport http https://showcase.<your-domain>/api/mcp \
--header "Authorization: Bearer sk_showcase_..."
Claude Desktop / other clients: add the same URL as a Streamable HTTP MCP server and set your key in the Authorization header.
To try the connection from a browser, use the /mcp-test page in the showcase app.
Tool catalog
Tools carry MCP behavior annotations (read-only / mutating / reaching external systems), so your client can present confirmation flows accordingly.
Monitoring & conversations (read-only)
| Tool | Purpose |
|---|---|
get_overview |
Overview metrics (conversation counts, resolution rate) |
get_recent_conversations |
Recent conversations; topic/sentiment/time filters |
get_conversation |
Single conversation detail |
get_quality_report |
Bot quality report |
get_system_health |
Service health (Chatwoot, Dify, DB, Redis) |
Knowledge base
| Tool | Purpose |
|---|---|
list_datasets / list_documents |
List datasets and documents |
upload_document |
Upload a document to the knowledge base |
get_document_status |
Track indexing status |
delete_document |
Delete a document |
query_knowledge |
Search the knowledge base (RAG query) |
get_knowledge_stats |
KB statistics |
Configuration & appearance
| Tool | Purpose |
|---|---|
get_config / update_config |
Bot configuration (name, welcome message, LLM model…) |
get_appearance / set_appearance |
Widget colors and appearance |
get_widget_config / update_widget_config |
Widget configuration |
get_widget_snippet |
Embed code for your site |
list_topics / create_topic / update_topic / delete_topic |
Topic taxonomy (delete = archive) |
Personas & testing
| Tool | Purpose |
|---|---|
list_personas / list_customer_personas |
Bot and customer personas |
create_bot_persona / update_bot_persona / delete_bot_persona |
Persona management |
set_default_persona |
Change the default persona |
list_scenarios / run_scenario |
List/run test scenarios |
run_acceptance_suite |
Run the acceptance test suite |
run_rag_eval |
End-to-end RAG validation test |
run_rag_metrics |
Ragas-style RAG metrics (faithfulness, context precision/recall…) |
send_test_message / test_model / classify_message |
One-off test calls |
Reports & operations
| Tool | Purpose |
|---|---|
list_reports / get_report |
List/read weekly reports |
trigger_weekly_report |
Trigger report generation manually |
submit_conversation_feedback |
Attach operator feedback to a conversation |
list_webhook_events / retry_webhook_event |
Inspect/retry the webhook queue |
list_api_keys |
List API keys |
Security notes
- The endpoint validates the
Originheader on browser-originated requests (DNS-rebinding protection). Non-browser clients such as Claude Desktop/CLI are unaffected; extra trusted browser origins go in theMCP_ALLOWED_ORIGINSenvironment variable. - Keys are stored as irreversible digests; if you suspect a leak, revoke the key in the panel and mint a new one.
- Mutating tools (configuration, documents, topics) are written to the audit log.