Skip to content
For AI agents: the complete documentation index is available at llms.txt; this page is also available as Markdown at index.md.

Work with MCP servers

Cohesivo comes with a built-in MCP server called management, which exposes a set of built-in tools to AI agents.

The server is available under the /mcp/management path, for example:

1
https://example.cohesivo.app/mcp/management

The server uses the Streamable HTTP transport.

Connect to the MCP server

The MCP server accepts the same OAuth 2.0 access tokens as the REST API. Send the token in the Authorization header of every request:

1
Authorization: Bearer <access_token>

For information about how to get a token, see REST API authentication.

Unlike the REST API, the MCP server has no anonymous access. Requests without a valid token respond with 401 Unauthorized:

1
2
3
{
    "error": "MCP endpoints require authentication."
}

Use the built-in tools

Once an agent connects, it discovers the available tools. Based on the prompt you provide to the agent, the agent decides which tools to call.

The built-in tools let an agent work with content types, field definitions, content type groups, translations, and SEO metadata. For example, you can ask the agent to create a content type with a set of fields, to list the content items that have no translation into a given language, or to point out the content items that are missing a meta title.

Because the tools act through the API, everything the agent can do is limited by the permissions of the user that the access token represents. With the client credentials flow, this is the service account.

Test the MCP server with Copilot CLI or Claude Code

You can test your MCP server with Copilot CLI or Claude Code, as illustrated here, or with any other agent or interface.

Add MCP server to agent CLI

You can handle the access token for this test in the following ways:

Hard-coded variant

The configuration with a hard-coded access token in .mcp.json looks as follows:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
{
  "mcpServers": {
    "cohesivo-example": {
      "type": "http",
      "url": "https://example.cohesivo.app/mcp/management",
      "headers": {
        "Authorization": "Bearer <access_token>"
      },
      "tools": ["*"]
    }
  }
}

In this approach, you must edit the .mcp.json file every time the access token expires.

When the agent can't connect to the MCP server:

  1. Update the access token in the .mcp.json file.
  2. Reload the MCP servers in Copilot CLI with one of these methods:
    • Run the /mcp reload command to reload all MCP servers.
    • Run the /mcp disable cohesivo-example and /mcp enable cohesivo-example commands to reload only the cohesivo-example server.

Reloading multiple MCP servers

If you have several MCP servers enabled globally, reloading all of them at the same time can be time-consuming. Consider reloading them one by one.

  1. Update the access token in the .mcp.json file.
  2. Run the /mcp reconnect cohesivo-example command to reconnect the cohesivo-example MCP server.

Fully scripted variant

The configuration with a wrapper script in .mcp.json looks as follows:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
{
  "mcpServers": {
    "cohesivo-example": {
      "type": "stdio",
      "command": "bash",
      "args": ["mcp-cohesivo-example-wrapper.sh"],
      "tools": ["*"]
    }
  }
}

mcp-cohesivo-example-wrapper.sh is a script that requests an access token and connects to the MCP server.

For example, you can use Supergateway, run through npx. The script below requires Node.js, jq, and the TOKEN_ENDPOINT, CLIENT_ID, and CLIENT_SECRET environment variables:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
#!/bin/bash
set -e

mcpServer="https://example.cohesivo.app/mcp/management"
token=$(curl --silent --fail --request POST "$TOKEN_ENDPOINT" \
    --user "$CLIENT_ID:$CLIENT_SECRET" \
    --data 'grant_type=client_credentials' | jq -r .access_token)

if [ -z "$token" ] || [ "$token" = "null" ]; then
    echo "Token request failed" >&2
    exit 1
fi

exec npx -y supergateway \
  --streamableHttp "$mcpServer" \
  --oauth2Bearer "$token" \
  --logLevel none

When the agent can't connect to the MCP server, reload it:

Reload the MCP servers in Copilot CLI with one of these methods:

  • Run the /mcp reload command to reload all MCP servers.
  • Run the /mcp disable cohesivo-example and /mcp enable cohesivo-example commands to reload only the cohesivo-example server.

Run the /mcp reconnect cohesivo-example command to reconnect the cohesivo-example MCP server.

Rate limits

To prevent abuse, MCP server calls are rate limited.

Responses carry the current state of the quota:

Header Description
X-RateLimit-Limit Number of requests permitted in the window.
X-RateLimit-Remaining Number of requests still available.
X-RateLimit-Reset Unix timestamp at which the window resets.

When you exceed the quota, the request responds with 429 Too Many Requests and a Retry-After header that tells you how many seconds to wait.