Skip to main content
Glama
munin92

paperless-mcp-oidc

by munin92

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_HOSTNoBind address for the streamable-HTTP transport0.0.0.0
MCP_PORTNoBind port for the streamable-HTTP transport8000
AUTH_MODENo`oidc` or `token`oidc
OIDC_ISSUERNoKeycloak realm issuer URL (inbound token verification)
MCP_BASE_URLNoPublic address of this server (OAuth metadata discovery)
MAX_PAGE_SIZENoUpper bound clamp for any `pageSize` a caller requests100
OIDC_AUDIENCENoExpected `aud` claim on the inbound token, e.g. `paperless`
OIDC_JWKS_URINoKeycloak JWKS endpoint (inbound token verification)
EXCHANGE_CLIENT_IDNoThe Paperless OIDC client in Keycloak (confidential, Standard token exchange enabled)
PAPERLESS_BASE_URLNoPaperless-ngx instance URL
OIDC_TOKEN_ENDPOINTNoKeycloak token endpoint, used for the access_token → id_token exchange
OIDC_USERNAME_CLAIMNoJWT claim used to label the caller for the per-person outbox dir and debug logging (not for Paperless identity — that comes from the exchange)preferred_username
PAPERLESS_API_TOKENNoShared Paperless API token (token mode only)
HTTP_TIMEOUT_SECONDSNoTimeout for calls to Paperless and to Keycloak15
PAPERLESS_OUTBOX_DIRNoDirectory `paperless_documents_export_to_outbox` writes into/home/mcp/outbox
PAPERLESS_HOST_HEADERNoSent as the Host header on every Paperless request — needed when PAPERLESS_BASE_URL is an in-cluster service URL but Paperless' ALLOWED_HOSTS is the public name
EXCHANGE_CLIENT_SECRETNoThat client's secret (`client_secret_basic`)
PAPERLESS_OIDC_PROVIDER_IDNoPaperless allauth provider id for the Keycloak connectionkeycloak
PAPERLESS_TOKEN_CACHE_SECONDSNoHow long an exchanged Paperless DRF token is cached in memory, per person3600

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources