Secure Reports MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| BACKEND | No | `mock` for synthetic data, `playwright` for a real system | mock |
| DATA_DIR | No | Audit log, vault file and exports | ./data |
| MCP_ROLE | No | Role served by this process | reporting_staff |
| MCP_USER | No | User id written to the audit log | demo_user |
| CONFIG_PATH | No | Role and tool definitions | config/roles.json |
| VAULT_MASTER_KEY | Yes | Fernet key for the credential vault | |
| MOCK_DELAY_SECONDS | No | How long a mock export takes | 2 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_available_reportsA | List the report types this role may download. domain is 'management' or 'billing'. |
| download_reportB | Start exporting a report. date_range is {"from": "YYYY-MM-DD", "to": "YYYY-MM-DD"}. Returns a job_id. |
| get_report_job_statusB | Check whether an export job has finished and where the file is. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: listing available reports, initiating an export job, and polling job status. There is no overlap in resource or action, so an agent can easily choose the right tool.
All three tools use consistent snake_case with verb-led names (list_..., download_..., get_...). The pattern is predictable and readable across the set.
Three tools are well-scoped for a focused report-export server. Each earns its place in the core workflow without being excessive.
The set covers listing, starting an export, and checking job status, which forms a complete minimal lifecycle. Minor gaps exist (no cancel job or list jobs operation), but agents can work around them for the stated purpose.