How to connect an AI assistant to DockAccess with MCP
DockAccess runs an MCP (Model Context Protocol) server. It lets an AI assistant, such as Claude Code, OpenAI Codex CLI or Gemini CLI, work with your DockAccess account on your behalf. The assistant can check your plan limits, list your sites and their services, start an automatic audit, and show audit results, subscriptions and invoices.
The assistant sees only your company and only the tools you select when you create the key.
At a glance
Step 1. Create an MCP key
When a key is created, its owner receives a notification e-mail. The e-mail never contains the secret. If you did not create the key, revoke it immediately.
Step 2. Add the server to your MCP client
In every example, replace YOUR_MCP_KEY with the secret you copied.
Claude Code
OpenAI Codex CLI
Codex reads the secret from an environment variable, so it never ends up in the configuration file:
Gemini CLI
Other clients (JSON configuration file)
Clients that support remote HTTP servers with custom headers are usually configured like this:
The details depend on the client, such as the file name and whether the field is called type, transport or url. Look for “remote MCP server” or “Streamable HTTP” in its documentation.
What cannot be connected
The DockAccess server authenticates only with a key in the Authorization header. There is no OAuth. Clients that support only OAuth for remote servers and do not let you add your own header cannot connect directly. Some connectors in web-based AI chat apps work this way. In that case use a command-line client (Claude Code, Codex CLI, Gemini CLI) or a code editor that lets you set the header.
Step 3. Check the connection
Ask the assistant, for example: “Show my DockAccess plan limits”. The assistant should call the limits_get tool and return, among other things, this month's widget views and the audits used today.
If the assistant does not see any DockAccess tools, go to the “Troubleshooting” section.
Available tools
The assistant sees the tools that are both selected in the key and allowed by your permissions in the company. If one of your permissions is removed, the tool disappears from the key at once, without creating a new key.
Account and limits
Sites (widget tokens)
Automatic audits
Subscriptions and invoices
Who sees which tools
The tools depend on your role in the company:
Write tools and safe retries
Every write tool (sites_create, sites_set_service, audits_scan) needs an operation_id argument: a unique UUID generated by the client. It makes the operation run exactly once:
AI assistants generate this id themselves, because the tool schema describes it.
Limits
Security
A key also stops working when:
Treat an MCP key like a password: do not paste it into a repository, a chat or a support ticket. If it leaks, revoke it and create a new one.
Example prompts
The assistant acts only on your explicit request. Most clients ask for confirmation before running a write tool.
How it works (for developers)
The server accepts POST https://dockaccess.org/mcp requests with a JSON-RPC 2.0 body. The client sends the protocol version in initialize or in the MCP-Protocol-Version header. Notifications (notifications/* methods without an id) are answered with 202.
Initialization:
The tools available to the key:
Calling a write tool (operation_id is a new UUID):
A successful call returns the result twice:
When a tool refuses to run, for example when a limit is used up or a service is not subscribed, the response has result.isError: true and a text in the form code: sentence, e.g. limit_exceeded: …. Any other error returns one generic sentence, with no technical details.
Troubleshooting
Frequently asked questions
Does MCP cost extra?
No, there is no separate fee. Your plan limits apply, just as in the panel.
Can the assistant change payments, delete a site or add someone to the team?
No. Only three tools write data: adding a site, switching a site's service on or off, and starting an audit. Payments, deleting data and team management are available only in the panel.
Can DockAccess see my conversations with the assistant?
No. DockAccess receives only the tool calls. The company activity log stores the tool name and time, without arguments or results.
How many keys can I have?
You can have a separate key for each tool and device, for example “Claude Code – laptop” and “Codex – CI server”. Each one can be revoked independently.
Related posts
- Automatic Audit and Accessibility Monitoring
- AI-powered alt text generator for images
- Counting requests - how it works
- Domain for site
- WCAG-conformance accessibility statement
Still looking for answers?
Ask our experts using online chat