Skip to main content
Use Amber’s MCP server to read the same public business data as the REST API through typed tools. Every tool is read-only. Credentials stay in HTTP headers, never in tool arguments or URLs. This guide covers API key connections for clients that send a Authorization header. Browser OAuth (for example Claude’s remote connector flow) is not available yet. When OAuth ships, this page will document discovery, consent, and independent grant lifecycle separately from API keys.

Endpoint and authentication

Each brand has its own MCP URL:
Replace {brand} with your brand slug. Use the same API key as REST:
Global keys must use a URL for the brand you intend to read. Brand-scoped keys must match that slug. Revoked, expired, or wrong-brand keys return 401 with invalid_token. Missing credentials never fall back to an Amber login session. The transport accepts POST only. There is no long-lived MCP session, SSE subscription, or GET stream on this URL. If you send an Origin header, it must exactly match https://app.amber.ai. Other origins receive 403 before your key is checked. Server-side clients usually omit Origin. Request and per-key rate limits match the Authentication guide, including 429 and Retry-After. Product include on read_parent_products shares the same expansion credit bucket as REST.

Connect with the MCP TypeScript SDK

The examples use @modelcontextprotocol/client against Streamable HTTP. Install the same major versions Amber’s API tests use (2.x as of this writing). Set AMBER_API_KEY and AMBER_BRAND in a server environment. Do not embed keys in browser bundles or paste them into model-visible tool arguments.
After connect, call listTools and callTool. Initialization does not create a persistent session id on Amber’s server.

Tool names and paging

Tools mirror the public REST inventory: REST path products becomes parent_products in tool names. REST rfqs maps to quotes tools. Hyphens in path segments become underscores. List results include items, nextCursor, and totalItems, plus a collection object with the tool name and arguments to call again (without a cursor). When nextCursor is not null, call the same list tool with that cursor value. Default limit is 25; maximum is 100. Detail results use { data, related }. Large child sets (SKUs, order lines, quote revisions, supplier contacts) appear as bounded pages under related, each with its own collection continuation. Follow those tools instead of expecting unbounded arrays on data.

Read a Parent Product and walk SKUs

Optional include on read_parent_products accepts the same comma-separated collection names as REST product detail (for example skus,productOptions). Each distinct include consumes expansion credits described in Product graphs. Each successful tool payload must fit within Amber’s MCP byte budget (256 KiB). Oversized graphs return a structured error with a narrower retrieval hint instead of silent truncation.

Verify a revoked key

Revoke the key in Amber settings, then repeat connect or any tool call. Amber returns 401 with the same body shape as REST key failures. Restore access by creating or rotating a key through your administrator.

Client compatibility

Protocol SDK tests in CI do not substitute for a recorded Claude or Grok Bot session. Amber will update this table when OAuth and external client runs are completed.

OAuth (planned)

A future release will add OAuth protected-resource metadata, dynamic client registration, browser consent at /mcp-connect.html, token exchange, refresh, and per-client revocation without revoking your API keys. OAuth credentials will not call REST endpoints. Until that release ships, rely on API keys only for MCP.