AI assistants (MCP)¶
GxPValidate exposes a Model Context Protocol server, so an AI assistant can read your validation content and edit drafts for you.
Assistants edit drafts; people sign. An assistant can never sign, submit, review or approve anything. Those steps happen only in the web app, by a person who re-authenticates.
Connecting¶
The MCP endpoint is your workspace address followed by /mcp/:
OAuth (recommended)¶
Add the endpoint as a remote MCP server in your assistant (for example Claude's custom connector). The assistant discovers the authorization server from the standard OAuth 2.1 metadata under /.well-known/ (oauth-protected-resource and oauth-authorization-server), opens a browser window where you sign in to GxPValidate and approve access, and receives a token. You never paste a secret.
Bearer token¶
For clients that do not support OAuth, use a per-user bearer token in the Authorization: Bearer <token> header. Ask your platform administrator to issue one for your account. Treat it like a password.
Either way, the assistant acts as you: it sees only your organization, and only the systems you are a member of.
What an assistant can do¶
| Tool | Does |
|---|---|
list_systems |
List the systems you are a member of, with their environments. |
list_documents, get_document |
Read documents, requirements and test cases. |
rtm_gaps |
List open RTM gaps for a system. |
update_document |
Edit a draft document's title or Markdown body. |
update_sra |
Edit the System Risk Assessment answers while the SRA is draft. |
save_requirement, delete_requirement |
Create, edit or delete requirements in a draft specification. |
save_test_case, delete_test_case |
Create, edit or delete test cases in a draft Test Protocol, including the environments they must pass in. |
revise_document |
Return an approved document to draft (version + 1) so it can be changed. |
list_library, get_library_requirement, save_library_requirement, copy_library_requirements |
Search, edit and copy from the requirement library. |
Edits need the Author role on the system and follow the same forms and locks as the web app. Every audit-trail reason written by an assistant starts with MCP:.
What an assistant cannot do¶
A token is not a re-authentication, so during an MCP request the system refuses to create any signature and refuses to move a document to in review or approved. Submitting, reviewing, approving, executing tests and closing deviations happen only in the web app.