MCP Order Management with RBAC
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Order Management with RBACShow me orders for users I manage"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Order Management — RBAC with MCP
Role-Based Access Control enforced inside the MCP server, not the
FastAPI client. FastAPI only authenticates (issues/validates JWTs);
every permission decision is made by permissions.py and applied by
the MCP tools in order_checking.py.
Client -> FastAPI (auth: JWT) -> MCP Server (authz: RBAC) -> MySQLRoles
Action | USER | MANAGER | ADMIN |
View own order | Y | Y | Y |
View managed user's order | N | Y | Y |
View another user's order | N | N | Y |
Refund own order | Y | Y | Y |
Refund managed user's order | N | Y | Y |
Refund anyone | N | N | Y |
Delete order | N | N | Y |
Create manager | N | N | Y |
View users | N | managed users | all |
Related MCP server: MCP Starter
Setup
Create the database and tables:
mysql -u root -p < sql/schema.sqlCopy
.env.exampleto.envand fill in real values (at minimum set a strongJWT_SECRETand your realDATABASE_URL), then export them into your shell / process manager.Install dependencies:
pip install -r requirements.txtSeed example users/orders (akash=ADMIN, raj=MANAGER, aman/vivek=USER managed by raj):
python sql/seed.pyRun the MCP server:
python order_checking.pyRun the FastAPI app (separate process/terminal):
uvicorn main:app --reload
Usage
# Log in, get a JWT
curl -X POST http://127.0.0.1:8000/login \
-H "Content-Type: application/json" \
-d '{"username": "raj", "password": "managerpass123"}'
# Use the token on protected routes
curl http://127.0.0.1:8000/order_status/ORD101 \
-H "Authorization: Bearer <token>"
curl -X POST http://127.0.0.1:8000/refund/ORD101 \
-H "Authorization: Bearer <token>"Files
File | Responsibility |
| Env-driven settings (DB URL, JWT secret, ports) |
| Password hashing, JWT issuing/validation, |
| The RBAC rules -- the only place authorization decisions are made |
| SQL access: users, orders, audit log writes |
| Logs every tool call (allowed or denied) to file + DB |
| The MCP server -- tools call |
| FastAPI app: |
| Pydantic request/response models |
| Table definitions (users, orders, audit_logs) |
| Creates example users/orders matching the permission matrix above |
Security notes
The MCP server trusts the
username/rolepassed in from FastAPI. In this design FastAPI is the only client allowed to reach the MCP server (bind it to localhost / an internal network, not the public internet) -- the JWT check happens once, at the FastAPI edge.Every tool call is written to
audit_logs(andlogs/app.log) with the outcome and reason, whether allowed or denied.Rotate
JWT_SECRETvia environment variable / secret manager -- never commit it.
This server cannot be deployed
Maintenance
Related MCP Connectors
A paid remote MCP for AI SDK data query MCP, built to return verdicts, receipts, usage logs, and aud
A paid remote MCP for AI SDK eval dashboard, built to return verdicts, receipts, usage logs, and aud
A paid remote MCP for hosted MCP server, built to return verdicts, receipts, usage logs, and audit-r
Identity, authorization, audit trails, and revocable permissions for AI agents accessing MCP tools.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables customer support operations such as order lookup, store credit, refunds, and audit log review through an agent using safe, typed MCP tools.-
- FlicenseNot gradedqualityCmaintenanceA production-grade MCP server for order management, featuring tools for looking up and refunding orders with safety measures like confirmation tokens, rate limiting, and error handling.-
- FlicenseNot gradedqualityCmaintenanceA secure MCP server that exposes a SQLite database to AI agents with Role-Based Access Control, supporting authentication, customer/order/user management, and audit logging.-
- FlicenseNot gradedqualityCmaintenanceRemote MCP server for fetching order status and checking refund eligibility, built with FastMCP, FastAPI, and MySQL.-