AssureLocker tools for AI agents
One MCP endpoint gives your agents the checks your analysts already trust. Every response is an indicator with a link back to the platform — signals inform, your team decides.
Download the 2-page buyer brief (PDF)Connection details & tool reference
The MCP endpoint configuration and the full tool catalogue are shared with validated partners — the same access control as every API reference on this page.
How it behaves
Indicators in, decisions with you
Tools return evidence-grade facts and signals — never a credit decision, never an allow/deny. Your systems and your people decide; every response links back to the authenticated platform surface where the full evidence trail lives.
Keys your team scopes, per agent
Agent keys carry a subset of the API families your account already holds — they can never exceed your access, and narrowing your account instantly narrows every agent key. Mint, scope and revoke them on the developer portal.
Nothing sensitive lingers in agent context
Document artefacts are served through signed links that expire in 3 minutes; consent-bound personal data never transits MCP unless your organisation explicitly enables Lite disclosure — and even then, only the fields the holder chose to share.
One meter, one invoice
MCP tool calls bill on the same per-family meter as our REST APIs — same quotas, same statement. No separate integration to reconcile.
Get an agent key
Agent keys are minted by validated partners on the developer portal — pick the families your agent may use, copy the key once, revoke any time. Not a partner yet? Request developer access and complete your organisation’s DigiKYB.
Frequently asked
What is MCP, and how does it work with AssureLocker?
Model Context Protocol is an open standard that lets an AI agent call a defined set of tools over one authenticated connection. AssureLocker exposes five evidence families — AssureFirst, Risk Signals, Export Provenance, Business Identity (KYB) and Identity (KYC) — as MCP tools: the same checks your team already uses via the REST API, callable by an agent under a scoped key.
Who controls which tools an agent can use?
Your organisation does, entirely. Every agent key is scoped to a subset of families at mint time, and that scope can only ever narrow your account's existing access — never grant more than your account already holds. Narrowing your account's access instantly narrows every agent key that depends on it. A tool outside a key's scope doesn't exist as far as that agent can tell.
Does personal data cross the MCP connection?
Only if your organisation has explicitly enabled Lite disclosure for consent grants — and even then, only the specific fields the holder already chose to share when they consented, never widened by this setting. By default, an agent sees a grant's lifecycle status and a deep link back to the platform, not the holder's identity fields.
What expires, and why?
Full evidence Packs are never returned inline. Where a Pack exists, the agent receives a signed link that expires after three minutes — long enough to hand off to a person, short enough that it can't be cached, replayed or usefully leaked.
Does the agent make the credit decision?
No. Every tool returns an indicator or evidence fact — never an approval, a decline or a credit score. Each response links back to the authenticated platform surface where your team reviews the full evidence trail and makes the actual decision.
How is MCP usage billed?
On the same per-family meter as the REST API. MCP tool calls and REST calls draw from the same quota and appear on the same statement — there's no separate integration to reconcile.
Which AI clients has this been tested with?
We've published a raw JSON-RPC protocol trace proving the wire contract every MCP-capable client depends on — initialize, scope-filtered discovery, deny-by-default access and correct protocol-vs-tool error handling. We name a specific client as supported only once we've recorded a successful test on that exact surface; ask your account contact for the current list.