Strac MCP DLP
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| STRAC_API_KEY | Yes | Your Strac API key. Required for all requests. Request one at https://www.strac.io/mcp-integrations | |
| STRAC_API_BASE | No | Optional base URL for the Strac API. Defaults to https://api.live.tokenidvault.com for sk_live_ keys and https://api.test.tokenidvault.com for sk_test_ keys. | |
| STRAC_API_TIMEOUT | No | Optional timeout in seconds for API calls. Defaults to 60. | 60 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| redact_textA | Redact PII, PHI, PCI and secrets out of a block of text using Strac DLP. Returns the redacted text plus the data element types that were found. Call this before putting untrusted or user-supplied text into a prompt, a log line, a ticket or any downstream system. |
| detect_sensitive_dataA | Detect sensitive data in text without changing it — personal data (PII), health data (PHI), payment and card data (PCI), and credentials such as API keys, cloud access keys, tokens and connection strings. Returns the data element types Strac found. Use this to decide whether text is safe to send onward; use redact_text when you need the sanitised text itself. |
| detect_fileA | Detect PII, PHI, PCI and secrets in a local file — image, PDF, scan or text. Strac runs OCR on images and scanned documents. Returns the data element types found, without modifying the file. |
| redact_fileA | Redact PII, PHI, PCI and secrets out of a local file — image, PDF, scan or text — and write the redacted copy to disk. The original is never modified. Returns the path to the redacted file. |
| detokenizeA | Resolve Strac vault tokens (tkn_…) back to their original values. Use this only when the caller is authorised to see the raw sensitive data. Accepts up to 10 tokens per call and requires an IP-allowlisted server-to-server key in live mode. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool has a clearly distinct purpose: detect vs. redact, text vs. file, and detokenize for vault resolution. The detect/redact pair on text and file is well-differentiated by descriptions and output behavior.
Most tools follow a readable verb_noun pattern like redact_text, detect_file, and redact_file. detect_sensitive_data fits the pattern too, though it names the data type rather than the input kind, and detokenize is a single verb rather than verb_noun.
With five tools, the server is tightly scoped without being thin. Each tool covers a distinct operation that earns its place in the DLP workflow.
The set covers detect and redact for both text and files, plus detokenization for authorized recovery. A minor gap is that token creation is not explicitly surfaced as its own tool, but redaction likely handles that internally, so core workflows are covered.