paperless-mcp-oidc
by munin92
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_HOST | No | Bind address for the streamable-HTTP transport | 0.0.0.0 |
| MCP_PORT | No | Bind port for the streamable-HTTP transport | 8000 |
| AUTH_MODE | No | `oidc` or `token` | oidc |
| OIDC_ISSUER | No | Keycloak realm issuer URL (inbound token verification) | |
| MCP_BASE_URL | No | Public address of this server (OAuth metadata discovery) | |
| MAX_PAGE_SIZE | No | Upper bound clamp for any `pageSize` a caller requests | 100 |
| OIDC_AUDIENCE | No | Expected `aud` claim on the inbound token, e.g. `paperless` | |
| OIDC_JWKS_URI | No | Keycloak JWKS endpoint (inbound token verification) | |
| EXCHANGE_CLIENT_ID | No | The Paperless OIDC client in Keycloak (confidential, Standard token exchange enabled) | |
| PAPERLESS_BASE_URL | No | Paperless-ngx instance URL | |
| OIDC_TOKEN_ENDPOINT | No | Keycloak token endpoint, used for the access_token → id_token exchange | |
| OIDC_USERNAME_CLAIM | No | JWT claim used to label the caller for the per-person outbox dir and debug logging (not for Paperless identity — that comes from the exchange) | preferred_username |
| PAPERLESS_API_TOKEN | No | Shared Paperless API token (token mode only) | |
| HTTP_TIMEOUT_SECONDS | No | Timeout for calls to Paperless and to Keycloak | 15 |
| PAPERLESS_OUTBOX_DIR | No | Directory `paperless_documents_export_to_outbox` writes into | /home/mcp/outbox |
| PAPERLESS_HOST_HEADER | No | Sent as the Host header on every Paperless request — needed when PAPERLESS_BASE_URL is an in-cluster service URL but Paperless' ALLOWED_HOSTS is the public name | |
| EXCHANGE_CLIENT_SECRET | No | That client's secret (`client_secret_basic`) | |
| PAPERLESS_OIDC_PROVIDER_ID | No | Paperless allauth provider id for the Keycloak connection | keycloak |
| PAPERLESS_TOKEN_CACHE_SECONDS | No | How long an exchanged Paperless DRF token is cached in memory, per person | 3600 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues