IFRC GO MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@IFRC GO MCP Serverfind active drefs for Kenya"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
IFRC GO MCP Server
Read-only MCP server for IFRC GO data, secured with Microsoft Entra ID OAuth/JWT.
What this server does
Exposes some IFRC GO datasets as MCP tools.
Enforces bearer-token auth with Entra JWT validation.
Publishes OAuth metadata endpoints for MCP clients.
Applies request rate limiting.
Removes selected PII fields from responses before returning data.
Adds GO frontend URLs to records so callers can open source pages directly.
Related MCP server: MSSQL MCP Python Server
Main tools
get_agent_instructionsReturns the full data model and querying guidance from
agent-instructions.md.
get_server_infoReturns runtime configuration and upstream connectivity status.
ifrcgo_metaReturns live enum/choice metadata for entity fields via OPTIONS.
ifrcgo_readMain read tool for list/detail access across IFRC GO entities.
ifrcgo_get_country_planFinds and summarizes the best available planning document for a country.
ifrcgo_download_documentDownloads authenticated IFRC GO documents and extracts text (including PDFs).
Supported entities (via ifrcgo_read)
Reference:
region,country,district,disaster_typeEvents and reports:
event,field-report,situation_reportAppeals:
appeal,appeal_documentSurge and deployments:
surge_alert,eru,eru_owner,personnel,partner_deploymentProjects:
project,emergency-projectOther:
public-per-process-status,public-per-stats,ops-learning,public-local-unitsCountry detail:
country-plan,country-document,country-supporting-partner,delegation_office
See agent-instructions.md for field-level guidance and workflow examples.
Quick start (local)
1. Create and activate a virtual environment
Windows PowerShell:
python -m venv .venv
.\.venv\Scripts\Activate.ps12. Install dependencies
pip install -r requirements.txt3. Configure environment variables
Set these in your shell, profile, or launch config before starting the server.
Required for auth-gated operation:
ENTRA_TENANT_IDENTRA_AUDIENCEENTRA_CLIENT_IDMCP_SERVER_URLSTATE_SIGNING_SECRET
IFRC GO upstream auth:
Static token mode (supported by current
server.py):IFRCGO_API_TOKEN
Note: local.settings.json.template and deployment scripts include IFRCGO_USERNAME and IFRCGO_PASSWORD, but the current server process initializes IFRCGOClient with IFRCGO_API_TOKEN only.
Optional:
IFRCGO_API_BASE_URL(default:https://goadmin.ifrc.org/api/v2)ENTRA_REQUIRED_SCOPE(default:mcp.access)REQUIRED_GROUP_IDS(comma-separated)REQUIRED_APP_ROLES(comma-separated)MCP_RATE_LIMIT_REQUESTS(default:60)MCP_RATE_LIMIT_WINDOW_SECONDS(default:60)SCOPE_NAME(default:ifrcgo)HOST(default:0.0.0.0)PORT(default:8000)
4. Run the server
python server.pyHealth endpoint:
GET /health
OAuth metadata endpoints:
GET /.well-known/oauth-protected-resourceGET /.well-known/oauth-authorization-serverGET /.well-known/oauth-authorization-server/mcp
OAuth helper endpoints:
GET /oauth/authorizeGET /oauth/callbackPOST /oauth/tokenPOST /register
MCP transport:
Mounted at
/using streamable HTTP from FastMCP.MCP JSON-RPC calls are available at
/mcp.
Testing
Run unit tests:
pytest tests -q -m "not smoke" --ignore=tests/smokeRun smoke tests (live endpoint + valid token required):
$env:IFRCGO_MCP_URL = "https://<your-host>"
pytest tests/smoke -q -m smokeNotes:
Smoke tests require a valid Entra access token. The test fixture in
tests/conftest.pydefines how this is sourced (az_token).The smoke suite calls MCP methods on
${IFRCGO_MCP_URL}/mcp.
Deployment (Azure Container Apps)
This repo includes an automated deploy script:
Copy
local.settings.json.templatetolocal.settings.json.Fill in required values (subscription, RG, ACR, Entra, IFRC GO credentials, etc.).
Run:
bash infra/deploy.shOn Windows, run the deploy script from a Bash-compatible shell (for example WSL or Git Bash).
What the script handles:
Validates local settings.
Runs non-smoke tests before deploy.
Builds and pushes Docker image.
Creates/updates Container App and secrets.
Applies optional ingress IP allow-list.
Performs health check and optional smoke tests.
Security and privacy notes
All data tools are read-only.
OAuth/JWT validation is enforced unless Entra settings are missing.
If
REQUIRED_GROUP_IDSorREQUIRED_APP_ROLESare set, caller token must match at least one.Selected PII fields are stripped from
personnelandprojectresults.Keep
local.settings.jsonand credentials out of source control.
Repository layout
server.py: MCP server, auth middleware, tool definitions.ifrcgo_client.py: Async IFRC GO client, auth refresh, list/detail/options helpers, document parsing.agent-instructions.md: Data model and usage guidance surfaced to MCP agents.tests/: Unit and smoke tests.infra/deploy.sh: Azure deployment automation.scripts/: One-off data processing utilities and generated outputs.
Notes for MCP clients
Start sessions by calling
get_agent_instructions.Use
ifrcgo_metato resolve current enum values before filtering.Use
ifrcgo_readwithlimitandoffsetfor paging.Use detail mode with
resource_idwhen you need full single-record payloads.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only MCP server for AIStatusDashboard status, incidents, metrics, and fallback recommendations.
Read-only MCP server for public WeJob jobs, formations, and companies.
MCP server that lets AI assistants use all OneSchema features exposed via the public API.
Official Microsoft MCP Server to query Microsoft Entra data using natural language
Related MCP Servers
- AlicenseAqualityAmaintenanceMCP server for Microsoft Dataverse API with safe-by-default configuration. Works with any Dataverse / Dynamics 365 environment.2324 npm7MIT
- AlicenseNot gradedqualityAmaintenanceMCP server for safely exposing SQL Server database capabilities to LLM clients, with read-only mode, security features, and observability.28MIT
- FlicenseNot gradedqualityBmaintenanceA governed MCP server with OAuth 2.1 + PKCE, declarative tool scoping, row-level data filters, per-identity rate limits, and a tamper-evident audit trail.-
- AlicenseAqualityCmaintenanceA reference MCP server that enforces identity-aware tool access using role-based permissions (Reader, Analyst, Auditor) and supports multiple identity routes like Entra RBAC, Copilot Studio, and Okta XAA. It provides read-only access to test evidence with explicit denial paths for unauthorized tools.7MIT