Skip to navigation

Index MCP servers

Talqora exposes two remote Model Context Protocol servers for every index. Both use Streamable HTTP and JSON-RPC, and both are permanently scoped to the index ID in their URL. They do not grant access to another index, even when a caller knows its ID.

ServerConsole locationEndpointRequired API-key scopePurpose
Developer MCPIndex Settingshttps://api.talqora.com/v1/indexes/<INDEX_ID>/mcp/developerTarget index + read and writeInspect the index, write or delete vectors, and retrieve.
Search MCPBelow the index Search workbenchhttps://api.talqora.com/v1/indexes/<INDEX_ID>/mcp/searchTarget index + readPerform retrieval only. It cannot write or delete data.

Use a separate API key for each MCP client. Never give an MCP client an organization-wide key when it only needs one index. API-key scopes apply before a tool executes; metadata filters still define the record-level boundary inside that index.

Create a connection from the console

Open the target index and use the card for the server you need. Talqora creates a new scoped key and renders a copyable client configuration:

{
"mcpServers": {
"talqora-search-my-index": {
"url": "https://api.talqora.com/v1/indexes/<INDEX_ID>/mcp/search",
"headers": {
"Authorization": "Bearer tq_live_<SCOPED_READ_KEY>"
}
}
}
}

The Search MCP key is read-only and is retained in that browser’s sessionStorage, so its configuration can be reopened after changing tabs or reloading during the same browser session. It is never saved by Talqora in recoverable form. Select Forget this browser copy, revoke the key in API keys, or close the browser session to remove the local copy.

The Developer MCP key has read and write access and is shown once only. Store either configuration in the MCP client’s secret store, not in a browser application, source repository, or user-visible prompt.

MCP protocol

Send Authorization: Bearer <SCOPED_API_KEY> on every request. The endpoints implement initialize, ping, tools/list, tools/call, and notification acknowledgement. They use protocol version 2025-03-26 and return JSON-RPC responses over Streamable HTTP.

For example, initialize a Search MCP server:

{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-03-26",
"clientInfo": { "name": "my-agent", "version": "1.0.0" }
}
}

Then call tools/list before invoking a tool. Tool outputs contain an MCP text content item and structuredContent, which carries Talqora’s normal JSON response. Invalid tool inputs and backend validation failures are returned as an MCP tool result with isError: true; clients should show the error and correct the request rather than retrying a malformed payload.

Search MCP tools

Search MCP exposes all retrieval modes available on the public query API. Each tool accepts optional top_k (1–1000), min_score (0–1), filter, include_metadata, and include_distance parameters.

ToolRequired argumentsRetrieval mode
search_densevectorDense semantic search. The vector must have the exact index dimensions.
search_sparsequeryBM25 lexical search over sparse_text.
search_hybridvector, queryConcurrent dense and lexical retrieval followed by fusion.
search_exactqueryLiteral identifier lookup, including punctuation.
search_regexpatternBounded regular-expression matching over indexed sparse text.
search_agenticqueryPlanned parallel retrieval for eligible plans.

For example, retrieve a filtered sparse result:

{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/call",
"params": {
"name": "search_sparse",
"arguments": {
"query": "vendor retention policy",
"top_k": 8,
"filter": { "jurisdiction": "SG" }
}
}
}

search_agentic follows the same plan entitlement and result limit as the API. Read Search and filters and Agentic and regex search for retrieval semantics, filters, regex limits, ranking, and latency behavior.

Developer MCP tools

Developer MCP includes every Search MCP tool plus the index-scoped vector data-plane operations below. It deliberately does not expose organization administration, billing, API-key administration, cross-index actions, or dashboard sessions.

ToolRequired argumentsBehavior
get_indexnoneReturns immutable index configuration and current index usage.
upsert_vectorsidempotency_key, vectorsCreates or replaces up to 500 dense vectors, metadata, and optional sparse_text.
delete_vectorsidempotency_key, idsRemoves up to 500 vector IDs and their sparse records.

upsert_vectors accepts the same vector object contract as POST /v1/indexes/{index_id}/vectors: id, values, optional metadata, and optional sparse_text. The caller must provide a unique idempotency_key with at least eight characters for each logical write. Reuse that key only when retrying the identical operation.

{
"jsonrpc": "2.0",
"id": 3,
"method": "tools/call",
"params": {
"name": "upsert_vectors",
"arguments": {
"idempotency_key": "catalog-import-0001",
"vectors": [
{
"id": "shoe-42",
"values": [0.12, 0.18, 0.44],
"metadata": { "tenant_id": "acme", "sku": "RUN-42" },
"sparse_text": "Trail running shoe SKU RUN-42"
}
]
}
}
}

The example vector is shortened for readability; production vectors must match the index dimensions. Use the public API directly for file-processing jobs, crawls, connectors, branching, and other control-plane workflows.

Security and operations

  1. Scope every MCP key to exactly one index and give Search MCP read-only access.
  2. Keep mandatory tenant, principal, visibility, or document-lifecycle filters in every tool call where an index contains multiple access domains.
  3. Treat tool calls that write or delete as side effects. Use idempotency keys and require user approval in the host where appropriate.
  4. Rotate or revoke the dedicated MCP key when an agent, environment, or employee no longer needs it.
  5. Monitor query and write usage on the index. MCP calls are accounted for exactly like public API calls.

These servers are separate from the narrow Assistant RAG MCP, which exposes only the tools configured for a hosted assistant.