MCP
O MCP da FabHub (@fabhub/mcp) expõe um conjunto fixo e seguro para o público de ferramentas para fluxos de trabalho de agentes apoiados na API. Cada ferramenta mapeia para exatamente um scope da API pública; não existe nenhum proxy HTTP genérico.
Instalar
npx -y @fabhub/mcp
Configuração local
{
"mcpServers": {
"fabhub": {
"command": "npx",
"args": ["-y", "@fabhub/mcp"],
"env": {
"FABHUB_API_KEY": "pk_test_example"
}
}
}
}
O servidor anuncia apenas as ferramentas para as quais a sua chave tem scopes, pelo que um agente nunca pode chamar para além das permissões da credencial.
Segurança das ferramentas
- As ferramentas só de leitura estão disponíveis quando a credencial tem o scope de leitura correspondente.
- As ferramentas de escrita exigem o scope de escrita correspondente e um input de confirmação explícito.
- As ferramentas destrutivas exigem o scope de eliminação e uma confirmação de eliminação explícita.
- O modo HTTP alojado valida credenciais a cada pedido e não armazena chaves de tenant.
Ferramentas
| Ferramenta | Scopes | Segurança |
|---|---|---|
list_items | items:read | read_only |
get_item | items:read | read_only |
list_item_ingredients | items:read | read_only |
list_item_suppliers | items:read | read_only |
create_item | items:write | write, requires confirmation |
update_item | items:write | write, requires confirmation |
delete_item | items:write | destructive, requires confirmation |
get_organization | organization:read | read_only |
list_orders | orders:read | read_only |
get_order | orders:read | read_only |
list_order_lines | orders:read | read_only |
create_order | orders:write | write, requires confirmation |
update_order | orders:write | write, requires confirmation |
list_contacts | contacts:read | read_only |
get_contact | contacts:read | read_only |
create_contact | contacts:write | write, requires confirmation |
update_contact | contacts:write | write, requires confirmation |
delete_contact | contacts:write | destructive, requires confirmation |
get_usage_summary | usage:read | read_only |
list_webhooks | webhooks:read | read_only |
get_webhook | webhooks:read | read_only |
create_webhook | webhooks:write | write, requires confirmation |
update_webhook | webhooks:write | write, requires confirmation |
delete_webhook | webhooks:delete | destructive, requires confirmation |
list_webhook_deliveries | webhooks:deliveries:read | read_only |
list_audit_events | audit:read | read_only |
list_stock_levels | inventory:read | read_only |
list_stock_documents | inventory:read | read_only |
get_stock_document | inventory:read | read_only |
list_stock_document_lines | inventory:read | read_only |
create_stock_document | inventory:write | write, requires confirmation |
update_stock_document | inventory:write | write, requires confirmation |
create_stock_document_line | inventory:write | write, requires confirmation |
update_stock_document_line | inventory:write | write, requires confirmation |
delete_stock_document | inventory:write | destructive, requires confirmation |
delete_stock_document_line | inventory:write | destructive, requires confirmation |
submit_stock_document | inventory:write | write, requires confirmation |
cancel_stock_document | inventory:write | write, requires confirmation |
approve_stock_document | inventory:write | destructive, requires confirmation |
create_item_ingredient | items:write | write, requires confirmation |
update_item_ingredient | items:write | write, requires confirmation |
delete_item_ingredient | items:write | destructive, requires confirmation |
create_item_supplier | items:write | write, requires confirmation |
update_item_supplier | items:write | write, requires confirmation |
delete_item_supplier | items:write | destructive, requires confirmation |