Skip to content

AI assistants (MCP)

GxPValidate exposes a Model Context Protocol server, so an AI assistant can read your validation content and edit drafts for you.

Assistants edit drafts; people sign. An assistant can never sign, submit, review or approve anything. Those steps happen only in the web app, by a person who re-authenticates.

Connecting

The MCP endpoint is your workspace address followed by /mcp/:

https://<org>.gxpvalidate.app/mcp/

OAuth (recommended)

Add the endpoint as a remote MCP server in your assistant (for example Claude's custom connector). The assistant discovers the authorization server from the standard OAuth 2.1 metadata under /.well-known/ (oauth-protected-resource and oauth-authorization-server), opens a browser window where you sign in to GxPValidate and approve access, and receives a token. You never paste a secret.

Bearer token

For clients that do not support OAuth, use a per-user bearer token in the Authorization: Bearer <token> header. Ask your platform administrator to issue one for your account. Treat it like a password.

Either way, the assistant acts as you: it sees only your organization, and only the systems you are a member of.

What an assistant can do

Tool Does
list_systems List the systems you are a member of, with their environments.
list_documents, get_document Read documents, requirements and test cases.
rtm_gaps List open RTM gaps for a system.
update_document Edit a draft document's title or Markdown body.
update_sra Edit the System Risk Assessment answers while the SRA is draft.
save_requirement, delete_requirement Create, edit or delete requirements in a draft specification.
save_test_case, delete_test_case Create, edit or delete test cases in a draft Test Protocol, including the environments they must pass in.
revise_document Return an approved document to draft (version + 1) so it can be changed.
list_library, get_library_requirement, save_library_requirement, copy_library_requirements Search, edit and copy from the requirement library.

Edits need the Author role on the system and follow the same forms and locks as the web app. Every audit-trail reason written by an assistant starts with MCP:.

What an assistant cannot do

A token is not a re-authentication, so during an MCP request the system refuses to create any signature and refuses to move a document to in review or approved. Submitting, reviewing, approving, executing tests and closing deviations happen only in the web app.