Authorization
header. Browser OAuth (for example Claude’s remote connector flow) is not
available yet. When OAuth ships, this page will document discovery, consent, and
independent grant lifecycle separately from API keys.
Endpoint and authentication
Each brand has its own MCP URL:{brand} with your brand slug. Use the same API key as REST:
401 with
invalid_token. Missing credentials never fall back to an Amber login session.
The transport accepts POST only. There is no long-lived MCP session, SSE
subscription, or GET stream on this URL.
If you send an Origin header, it must exactly match https://app.amber.ai.
Other origins receive 403 before your key is checked. Server-side clients
usually omit Origin.
Request and per-key rate limits match the Authentication
guide, including 429 and Retry-After. Product include on
read_parent_products shares the same expansion credit bucket as REST.
Connect with the MCP TypeScript SDK
The examples use@modelcontextprotocol/client against Streamable HTTP. Install
the same major versions Amber’s API tests use (2.x as of this writing).
Set AMBER_API_KEY and AMBER_BRAND in a server environment. Do not embed
keys in browser bundles or paste them into model-visible tool arguments.
connect, call listTools and callTool. Initialization does not
create a persistent session id on Amber’s server.
Tool names and paging
Tools mirror the public REST inventory:
REST path
products becomes parent_products in tool names. REST rfqs maps
to quotes tools. Hyphens in path segments become underscores.
List results include items, nextCursor, and totalItems, plus a
collection object with the tool name and arguments to call again (without a
cursor). When nextCursor is not null, call the same list tool with that
cursor value. Default limit is 25; maximum is 100.
Detail results use { data, related }. Large child sets (SKUs, order lines,
quote revisions, supplier contacts) appear as bounded pages under related, each
with its own collection continuation. Follow those tools instead of expecting
unbounded arrays on data.
Read a Parent Product and walk SKUs
include on read_parent_products accepts the same comma-separated
collection names as REST product detail (for example skus,productOptions).
Each distinct include consumes expansion credits described in
Product graphs.
Each successful tool payload must fit within Amber’s MCP byte budget (256 KiB).
Oversized graphs return a structured error with a narrower retrieval hint instead
of silent truncation.
Verify a revoked key
Revoke the key in Amber settings, then repeatconnect or any tool call. Amber
returns 401 with the same body shape as REST key failures. Restore access by
creating or rotating a key through your administrator.
Client compatibility
Protocol SDK tests in CI do not substitute for a recorded Claude or Grok Bot
session. Amber will update this table when OAuth and external client runs are
completed.
OAuth (planned)
A future release will add OAuth protected-resource metadata, dynamic client registration, browser consent at/mcp-connect.html, token exchange, refresh,
and per-client revocation without revoking your API keys. OAuth credentials will
not call REST endpoints. Until that release ships, rely on API keys only for MCP.