MCP
FabHub MCP (@fabhub/mcp) exposes a fixed, public-safe set of tools for API-backed agent workflows. Each tool maps to exactly one public API scope; there is no generic HTTP proxy.
Install
npx -y @fabhub/mcp
Local configuration
{
"mcpServers": {
"fabhub": {
"command": "npx",
"args": ["-y", "@fabhub/mcp"],
"env": {
"FABHUB_API_KEY": "pk_test_example"
}
}
}
}
The server advertises only the tools your key has scopes for, so an agent can never call beyond the credential's permissions.
Tool safety
- Read-only tools are available when the credential has the matching read scope.
- Write tools require the matching write scope and an explicit confirmation input.
- Destructive tools require the delete scope and explicit delete confirmation.
- Hosted HTTP mode validates credentials per request and does not store tenant keys.
Tools
| Tool | Scopes | Safety |
|---|---|---|
list_items | items:read | read_only |
get_item | items:read | read_only |
list_item_ingredients | items:read | read_only |
list_item_suppliers | items:read | read_only |
create_item | items:write | write, requires confirmation |
update_item | items:write | write, requires confirmation |
delete_item | items:write | destructive, requires confirmation |
get_organization | organization:read | read_only |
list_orders | orders:read | read_only |
get_order | orders:read | read_only |
list_order_lines | orders:read | read_only |
create_order | orders:write | write, requires confirmation |
update_order | orders:write | write, requires confirmation |
list_contacts | contacts:read | read_only |
get_contact | contacts:read | read_only |
create_contact | contacts:write | write, requires confirmation |
update_contact | contacts:write | write, requires confirmation |
delete_contact | contacts:write | destructive, requires confirmation |
get_usage_summary | usage:read | read_only |
list_webhooks | webhooks:read | read_only |
get_webhook | webhooks:read | read_only |
create_webhook | webhooks:write | write, requires confirmation |
update_webhook | webhooks:write | write, requires confirmation |
delete_webhook | webhooks:delete | destructive, requires confirmation |
list_webhook_deliveries | webhooks:deliveries:read | read_only |
list_audit_events | audit:read | read_only |
list_stock_levels | inventory:read | read_only |
list_stock_documents | inventory:read | read_only |
get_stock_document | inventory:read | read_only |
list_stock_document_lines | inventory:read | read_only |
create_stock_document | inventory:write | write, requires confirmation |
update_stock_document | inventory:write | write, requires confirmation |
create_stock_document_line | inventory:write | write, requires confirmation |
update_stock_document_line | inventory:write | write, requires confirmation |
delete_stock_document | inventory:write | destructive, requires confirmation |
delete_stock_document_line | inventory:write | destructive, requires confirmation |
submit_stock_document | inventory:write | write, requires confirmation |
cancel_stock_document | inventory:write | write, requires confirmation |
approve_stock_document | inventory:write | destructive, requires confirmation |
create_item_ingredient | items:write | write, requires confirmation |
update_item_ingredient | items:write | write, requires confirmation |
delete_item_ingredient | items:write | destructive, requires confirmation |
create_item_supplier | items:write | write, requires confirmation |
update_item_supplier | items:write | write, requires confirmation |
delete_item_supplier | items:write | destructive, requires confirmation |