Overview
The Ironfang MCP server is a remote Model Context Protocol server. One endpoint serves Ironfang Render, Ironfang Audit, Ironfang Finance and Ironfang Rig:
https://mcp.ironfang.com/mcp| Product | MCP support | Tools | What is covered |
|---|---|---|---|
| Ironfang Render | Available | 17, named render.* | Screenshots, PDFs, QR codes, template renders, clips, batches, signed render URLs, webhook delivery destinations, jobs and usage. Storage destinations carry credentials and stay in the portal. |
| Ironfang Audit | Available | 9, named audit.* | Read sites, audits, findings, rules and usage, and start a bounded audit of a site. Changing a rule, a site, a monitor or a finding stays in the portal and the REST API. |
| Ironfang Finance | Reference tools only | 3, named finance.* | Reference only: what a validation rule means and how to fix it, and which rulesets the validator runs. Validating and generating documents, results and jobs are REST-only; the Ironfang Finance API takes a platform API key and has no OAuth delegation yet. |
| Ironfang Rig | Available | 19, named rig.* | Projects and suites, runs and their resources, the timeline and waits, replay, deterministic faults, the local connector bootstrap, evidence manifests and signed receipts. |
| Ironfang Analytics | Not available | None | Not yet available over MCP. Sites, recordings, playback and deletion are in the portal and the REST API. |
| Property | Value |
|---|---|
| Transport | Streamable HTTP. POST /mcp only; there is no standalone event stream and no session id, so any replica can answer any request. |
| Protocol revision | 2026-07-28 is current. 2025-11-25, 2025-06-18, 2025-03-26 are accepted and echoed back on initialize for the compatibility window. |
| Capabilities | Tools, resource templates, and the io.modelcontextprotocol/tasks extension for long-running work. No prompts, sampling, roots or apps. |
| Authorization | OAuth 2.1 through id.ironfang.com. Resource metadata at /.well-known/oauth-protected-resource/mcp. |
| Status | Beta, listed in the MCP Registry as com.ironfang/ironfang. Tool names are a compatibility contract; anything that changes semantics gets a new name. |
MCP is not a separate product and has no separate price. It is another safe way to use the products you already have: rendering and audits spend the organisation's ordinary credits, reads are free, and each connection has its own spending budget (see credits and budgets).
Client compatibility
The server speaks standard OAuth. Claude Code and claude.ai are tested by us; other MCP clients connect through the same standards.
Claude Code
claude mcp add --transport http ironfang https://mcp.ironfang.com/mcpThen inside Claude Code run /mcp, pick ironfang and choose Authenticate. A browser tab opens at id.ironfang.com: sign in, pick the organisation this connection acts for, review the scopes and allow. The tab closes and the tools appear.
Claude Desktop and claude.ai
Settings → Connectors → Add custom connector, name it Ironfang and enter https://mcp.ironfang.com/mcp. The same sign-in follows.
Never paste an API key into a chat. The MCP server does not accept Ironfang API keys as a credential; keys stay with the REST API where they belong.
Authentication
The server is an OAuth 2.1 protected resource. An unauthenticated request answers 401 with a WWW-Authenticate challenge that points at the resource metadata document; from there a client discovers the authorization server and completes the code flow with PKCE (S256). The flow, from the client's side:
- Read
https://mcp.ironfang.com/.well-known/oauth-protected-resource/mcp. - Read
https://id.ironfang.com/.well-known/oauth-authorization-server. - Identify itself: by a Client ID Metadata Document (an HTTPS URL as the client id, preferred), or by registering as a public client at
/oauth/register. - Send the person to
/oauth/authorizewithresource=https://mcp.ironfang.com/mcp, the scopes it wants and a PKCE challenge. - The person signs in, chooses one organisation and consents. A connection is one person, one organisation, one client.
- Exchange the code at
/oauth/token. The access token is short-lived and addressed only to the MCP resource; a rotating refresh token keeps the connection alive without asking again.
Scopes
Scopes are the product's own. A scope is granted only if the person holds the matching permission in the organisation they chose, and it is checked again live on every call - losing a permission ends the access the same minute.
| Scope | Needs permission | Lets the assistant |
|---|---|---|
ironfang:mcp | membership | Connect, list tools and inspect this connection and its budgets |
render:render | render | Create screenshots, PDFs, QR codes, clips and template renders, and read or cancel its own jobs |
render:usage:read | usage.read | Read the period's credit usage |
render:templates:read | templates.read | List templates and their variable names (never the markup) |
render:sign | render | Create signed render URLs that expire within 24 hours |
render:destinations | destinations.manage | Register and test where finished renders are delivered, and name a destination on a job or a batch |
audit:read | audit.read | Read sites, audits, findings and rules |
audit:run | audit.run | Start a manual audit of a site, within its page bound and the connection budget |
audit:evidence | audit.evidence | See where an audit's signed evidence bundle is and how to verify it; the bytes are never served through the connection |
rig:read | rig.read | Read Ironfang Rig projects, suites, runs, resources, faults and connectors; read and wait on a run's timeline; read the evidence manifest |
rig:write | rig.write | Create projects and create or revise suites |
rig:run | rig.run | Start, finish and cancel runs, allocate resources, arm and disarm faults, replay a callback |
rig:connector | rig.connector | Mint a bootstrap token for a local connector; the token is returned once and lives ten minutes |
A tool whose scope was not granted is still listed, so a client can ask for it: the call answers 403 with the complete scope set in the challenge and the client runs the flow again for the extra scope.
What the server does with the token
Nothing leaves the MCP server carrying your MCP token. To call a product it asks id.ironfang.com for a separate two-minute token addressed to that product, limited to the scopes you granted and to the organisation you chose, and marked as acting on your behalf. Products refuse an MCP token outright, and the MCP server refuses portal or product tokens.
Revoking
Disconnect a client from the portal's AI clients page or from your account settings at id.ironfang.com. Revocation ends the refresh token family and the connection; a live access token stops working within thirty seconds, not at its expiry.
Ironfang Render tools
Tool inputs are strict JSON Schema objects: unknown fields are rejected rather than ignored, and every string, size and duration is bounded. Rendering tools take a public URL or bounded raw HTML. They do not accept cookies, authorization headers, custom request headers, proxy settings, scripts to execute, or private network targets.
| Tool | Scope | Credits | Effect | Does |
|---|---|---|---|---|
ironfang.connection.get | ironfang:mcp | Free | Read-only. Answers in the request. | The current MCP connection: the organisation it acts for, the scopes it holds, the products available and its credit budgets. |
render.batch.create | render:render | 1 per screenshot, 2 per PDF, up to 200 | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Submit up to 100 screenshot or PDF jobs together, with a shared default and optional delivery. Credits are reserved for every item up front - one per screenshot, two per PDF - and the reservation settles at that total; poll render.batch.get for progress and each job's result. |
render.batch.get | render:render | Free | Read-only. Answers in the request. | A batch's progress: counts by status, whether it is done, and every job with its state, cost and result link once succeeded. |
render.clip.create | render:render | up to 1 credit per second | Changes data; a repeat acts again; reaches the public Internet. Long-running: always a durable job; ask for a task or poll the matching get tool. | Render a short captioned video clip (1-60 seconds) over a public image, video or solid colour. Always a durable job; ask for a task or poll render.job.get. Costs up to one Ironfang Render credit per second depending on size. |
render.destination.create | render:destinations | Free | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Register an https endpoint to receive signed webhook deliveries when jobs finish. The signing secret is returned once, here, and never again; hand it to whoever runs the endpoint. Storage (S3) destinations carry credentials and are registered in the portal, not through an assistant. |
render.destination.delete | render:destinations | Free | Destructive: removes or abandons something; safe to repeat. Answers in the request. | Stop deliveries to a destination and forget it. Jobs already naming it keep their delivery records; nothing new is sent. |
render.destination.list | render:destinations | Free | Read-only. Answers in the request. | Where this account's finished renders can be delivered: webhook endpoints and storage buckets registered in the portal or through render.destination.create. Ids from here go in a create tool's delivery block. |
render.destination.test | render:destinations | Free | Changes data; safe to repeat; reaches the public Internet. Answers in the request. | Send a test delivery now and report what happened. A destination that does not answer is a successful call with ok=false and the reason; nothing is wrong with the request. |
render.job.cancel | render:render | Free | Destructive: removes or abandons something; safe to repeat. Answers in the request. | Cooperatively cancel a queued or running render job. Queued work is refunded in full; running work is charged only if it produced a usable output. |
render.job.get | render:render | Free | Read-only. Answers in the request. | The state of a render job created through this connection, with its cost and, once succeeded, the result metadata and a short-lived download link. |
render.pdf.create | render:render | 2 credits | Changes data; a repeat acts again; reaches the public Internet. Long-running: a durable job; a task when the client asks for one, otherwise poll the matching get tool. | Render a public web page or raw HTML to PDF. Queued as a durable job. Costs two Ironfang Render credits. |
render.qr.create | render:render | Free | Changes data; safe to repeat. Answers in the request. | Generate a QR code image for text or a URL. Free on every plan; returned inline as a data URL. |
render.screenshot.create | render:render | 1 credit | Changes data; a repeat acts again; reaches the public Internet. Long-running: a durable job; a task when the client asks for one, otherwise poll the matching get tool. | Capture a public web page or raw HTML as an image. Queued as a durable job: poll render.job.get for the result. Costs one Ironfang Render credit; cached repeats are free. |
render.signed_url.create | render:sign | charged when fetched | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Create a signed URL that renders a screenshot or template when fetched. Nothing is charged until the link is used. Lifetime is at most 24 hours through MCP. |
render.template.get | render:templates:read | Free | Read-only. Answers in the request. | One template's id, name, size and variable names. |
render.template.list | render:templates:read | Free | Read-only. Answers in the request. | The organisation's Ironfang Render templates: id, name, size and the variable names each expects. Never the template markup. |
render.template.render | render:render + render:templates:read | 1 credit | Changes data; a repeat acts again. Long-running: a durable job; a task when the client asks for one, otherwise poll the matching get tool. | Render one of the organisation's templates with variables into an image. Queued as a durable job. Costs one Ironfang Render credit. |
render.usage.get | render:usage:read | Free | Read-only. Answers in the request. | Ironfang Render usage for the current period: credits used, the plan limit and when the period resets. |
Cached repeats are free, exactly as on the REST API, and free-plan output branding is the same whichever way you render. Every tool carries hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) and namespaced metadata naming its scope, product, credit behaviour and risk, so a client can show a person what a call will do before it does it.
Jobs, tasks and results
Every creation tool queues a durable Ironfang Render job and answers at once with the same envelope, so a retry or a dropped connection never loses or duplicates work:
{
"request_id": "01a0...",
"job_id": "01a0...",
"status": "queued",
"product": "render",
"kind": "screenshot",
"cached": false,
"credits": { "reserved": 1, "charged": 0 },
"result": null,
"created_at": "2026-08-27T23:09:45Z",
"connection_id": "01a0..."
}Poll render.job.get (or read the job resource). Once status is succeeded, result holds the media type, byte size, SHA-256, the moment the hosted result expires, and a download link:
- Hosted results are kept for 24 hours after success.
- Download links are signed and valid for 15 minutes; every read of the job or its result resource issues a fresh one.
- Links are the default even for screenshots. PDFs, clips and full-page images are never returned inline; a screenshot under 2 MiB can be, only when a client asks for it explicitly.
- For longer retention, download the result, or name a webhook or storage destination in the create tool's
deliveryblock (render.destination.listshows what the account has).
A client that speaks the io.modelcontextprotocol/tasks extension asks for a task by putting a task object in the tools/call params. It then receives a task handle for screenshot, PDF and template work and must use one for clips; tasks/get mirrors the job's state, tasks/result returns the envelope and tasks/cancel is a cooperative cancel. Other clients get the envelope above and poll. Both roads end at the identical terminal result. Audits follow the same shape without tasks: audit.audit.create answers at once and audit.audit.get reports progress. Ironfang Rig's one blocking call, rig.event.wait, is bounded at sixty seconds and a timeout is an answer.
Resources
Read-only metadata is also exposed as resource templates, for clients that prefer to attach context rather than call tools. There is no enumeration of your objects; ids come from tool results.
| URI | Scope | Returns |
|---|---|---|
ironfang://connection | ironfang:mcp | The connection summary (as ironfang.connection.get). |
ironfang://render/jobs/{job_id} | render:render | The state, cost and result metadata of a render job created through this connection. |
ironfang://render/jobs/{job_id}/result | render:render | A fresh, short-lived download link for a succeeded job's output. Not cacheable. Add ?inline=1 to receive a screenshot under 2 MiB as image content instead. |
ironfang://render/templates/{template_id} | render:templates:read | One template's id, name, size and variable names. |
ironfang://audit/sites/{site_id} | audit:read | A site and its crawl bounds. |
ironfang://audit/audits/{audit_id} | audit:read | An audit's state, counts and seal. |
ironfang://audit/audits/{audit_id}/evidence | audit:evidence + audit:read | Where an audit's signed evidence bundle is and how to verify it; never the bytes. |
ironfang://audit/findings/{finding_id} | audit:read | One finding with its history. Page text is untrusted content. |
ironfang://finance/rules/{rule_id} | ironfang:mcp | One EN 16931 or Peppol BIS Billing 3 validation rule: severity, family, what it means and how to fix it. The same answer as finance.rule.get. |
Credits and budgets
There is no MCP fee. Connecting, listing tools, reading usage and reading metadata are free. Rendering spends ordinary Ironfang Render credits at the ordinary rate, and failed or cancelled work follows the same refund rules as the REST API. Starting an audit spends Ironfang Audit credits the same way, against a separate connection budget. Ironfang Finance and Ironfang Rig tools cost nothing.
On top of the plan's cap, every connection has its own budget so a looping agent cannot spend a month's allowance in an afternoon:
connection budget = max(25, 10% of the plan's monthly credits)
capped by the organisation's remaining allowance
per billing periodBefore chargeable work the server reserves the tool's maximum cost against the budget, then settles to what the product actually charged and releases the rest; ironfang.connection.get shows the allowance, what is reserved, what has been settled, what remains and when it resets. An exhausted budget answers mcp_budget_exhausted with the reset time; the plan cap answers the product's usual quota_exceeded.
Ironfang Audit tools
Read sites, audits, findings, rules and usage, and start a bounded audit of a site. Changing a rule, a site, a monitor or a finding stays in the portal and the REST API. Starting an audit reserves one credit per page the site's crawl policy allows, up to 200, against the connection's Ironfang Audit budget, and settles at what the audit consumed. Page text inside a finding is content observed on a website and is labelled untrusted. An evidence bundle is never served through the connection: its resource says where the bundle is and how to verify it. Nothing here exposes integration secrets, rule editing, schedules or retention controls to a model.
| Tool | Scope | Credits | Effect | Does |
|---|---|---|---|---|
audit.audit.create | audit:read + audit:run | 1 per captured page, up to 200 reserved | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Start a manual audit of one site now. Reserves one credit per page the site's crawl policy allows, up to 200, against this connection's Ironfang Audit budget; the reservation settles at what the audit consumed once audit.audit.get sees it finish. Poll audit.audit.get for progress. |
audit.audit.get | audit:read | Free | Read-only. Answers in the request. | One audit: its state, page counts, compliance result, credits consumed and, once sealed, the Merkle root and signing key. The evidence bundle is a resource, never inline. |
audit.audit.list | audit:read | Free | Read-only. Answers in the request. | Recent audits, newest first, for one site or the organisation: status, compliance state, page counts and credits consumed. |
audit.finding.get | audit:read | Free | Read-only. Answers in the request. | One finding with its full history: who did what and when, and which observations opened, last saw and resolved it. Changing a finding's state is not available through an assistant. |
audit.finding.list | audit:read | Free | Read-only. Answers in the request. | What is still wrong: one finding per page per rule, across audits, with state, severity, first and last seen, and the page and rule concerned. Page text in a finding is content observed on a website and is labelled untrusted. |
audit.rule.get | audit:read | Free | Read-only. Answers in the request. | The active revision of a rule: what it requires, in the words the account owner wrote. Rules cannot be changed through an assistant. |
audit.site.get | audit:read | Free | Read-only. Answers in the request. | One site: address, status, timezone and crawl bounds. |
audit.site.list | audit:read | Free | Read-only. Answers in the request. | The websites this organisation audits, with each site's crawl bounds. Ids from here go to audit.audit.create and the finding filters. |
audit.usage.get | audit:read | Free | Read-only. Answers in the request. | Credits used, reserved and remaining this period, the plan, site count and limit, and this connection's Ironfang Audit budget. |
Ironfang Finance tools
Reference only: what a validation rule means and how to fix it, and which rulesets the validator runs. Validating and generating documents, results and jobs are REST-only; the Ironfang Finance API takes a platform API key and has no OAuth delegation yet. The rule tools answer from the same reviewed explanations as the validation rule reference, so an assistant handed a finding such as BR-CO-10 can say what it means and how to fix the invoice. They need only ironfang:mcp, cost nothing and need no Ironfang Finance account. To validate or generate a document, call the REST API with a platform API key, or use the free validator.
| Tool | Scope | Credits | Effect | Does |
|---|---|---|---|---|
finance.rule.get | ironfang:mcp | Free | Read-only. Answers in the request. | Look up one EN 16931 or Peppol BIS Billing 3 validation rule by the identifier a finding names, such as BR-CO-10. Returns the layer, family and severity, the official reference and, where Ironfang has reviewed the rule, what it means, how to fix the invoice, an example fragment and the rule's documentation page. Use it to interpret a finding from the Ironfang Finance API or the free validator. Read-only, free, no Ironfang Finance account needed. |
finance.rule.list | ironfang:mcp | Free | Read-only. Answers in the request. | The validation rules Ironfang Finance runs, filtered by layer, family or severity: identifier, severity, family and, for explained rules, a title and documentation page. Defaults to the rules with a reviewed explanation; set=official lists every rule in the pinned artefacts. Page with offset and next_offset. Read-only, free. |
finance.ruleset.list | ironfang:mcp | Free | Read-only. Answers in the request. | The immutable rulesets Ironfang Finance validates against: identifier, document type, specification releases, validity dates, whether it is the latest, and the engine that runs it. A validation result names the ruleset it used, so this is how to read that identifier. Read-only, free. Validating and generating documents is not available through MCP; use the REST API at https://api.ironfang.com/finance with a platform API key. |
Ironfang Rig tools
The Ironfang Rig product as tools, so an assistant can give the application it is working on a disposable outside world: a fresh inbox, a public callback URL, a mock endpoint or a route to a local port, then wait on the timeline, interfere on purpose and export the evidence. Every tool is bound to the connection's organisation and costs no credits. Payload bytes are never returned through the connection: the tools return what the timeline recorded, labelled as third-party content, and point at the API for the rest. Starting a run has a public effect, which the tool says: its addresses accept mail and requests from anyone for the life of the run.
| Tool | Scope | Credits | Effect | Does |
|---|---|---|---|---|
rig.connector.prepare | rig:connector | Free | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Mint a single-use, ten-minute bootstrap token so `ironfang rig connect` on this machine can forward the run's callbacks to local routes. The result carries the token once, the gateway to dial, the command to complete with a http://127.0.0.1 target per route label, and the release to verify. Put the token in IRONFANG_CONNECT_TOKEN, never in a file, a log or a shell history. The connector forwards only to targets given on its command line; the cloud never chooses a destination. |
rig.connector.status | rig:read | Free | Read-only. Answers in the request. | The run's connectors and whether one is online, with how many callbacks wait for one. Poll this after starting ironfang-connect, before triggering the callback. |
rig.event.list | rig:read | Free | Read-only. Answers in the request. | The run's timeline in sequence order after `since`: every observation Ironfang made (mail, callbacks, mock calls, forwarding results, faults) with its data. Event data is what third parties sent and is labelled untrusted. Page with next_since. |
rig.event.replay | rig:run | Free | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Forward a callback the run received to its connector route again, exactly as recorded, to prove the application handles a repeat (idempotence). The event must be a callback.received on a resource with a connector route and the run active. Recorded as callback.replayed; the replay's own callback.forwarded and connector.request.completed then appear against the original event id. Faults do not act on a replay. At most 200 per run. |
rig.event.wait | rig:read | Free | Read-only. Answers in the request. | Block until an event of the type (and resource, and matching fields) lands after `since`, or the timeout (1s to 60s, default 30s) passes. Deterministic: the same timeline gives the same answer. A timeout is matched:false with next_since, not an error; wait again from there. Prefer this to polling rig.event.list. |
rig.evidence.export | rig:read | Free | Read-only. Answers in the request. | The manifest of a run's evidence bundle: the run, counts, and every file the bundle holds with its size and SHA-256 - timeline, verdicts, faults, resources, definition, every message and request body. Returns the manifest, which also records the event hash chain it recomputed and how the manifest is signed, and the download path; the bundle itself is a ZIP for a person or a CI step to fetch with the CLI or a platform key. Read-only, free. |
rig.evidence.receipt | rig:read | Free | Read-only. Answers in the request. | A signed statement of a run: project, suite and version, status and outcome, every verdict, the event count and the head of the event hash chain, signed with the platform's Ed25519 key when it has one. The signature carries the key; rig.evidence.export's manifest and GET /rig/v1/evidence/keys name it. Give this to whoever needs proof of what the run did. |
rig.fault.add | rig:run | Free | Changes data; a repeat acts again. Answers in the request. | Arm deterministic interference on one resource of an active run: delay, duplicate, drop, reorder or change the body of a callback forwarded to a connector route, or make a mock answer a chosen status, reset the connection, throttle its body or cut it short. Fires on the next matching observation, `count` times or until removed; every firing is a fault.injected event on the timeline. Use to prove the application survives duplicates, delays, reordering, corrupted payloads and dependency failures. |
rig.fault.remove | rig:run | Free | Changes data; safe to repeat. Answers in the request. | Disarm a fault so it fires no more. Its history stays on the timeline. |
rig.project.create | rig:write | Free | Changes data; a repeat acts again. Answers in the request. | Create a project for one application. Use when rig.project.list has none that fits; a project is permanent and costs nothing. |
rig.project.list | rig:read | Free | Read-only. Answers in the request. | Ironfang Rig projects: the persistent containers suites live in. Ids from here go to rig.suite.upsert. Free; nothing changes. |
rig.resource.create | rig:run | Free | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Allocate one more resource on an active run beyond what the suite declared: an inbox, a callback URL (optionally forwarded to a connector route), a mock with rules, or a route label. Public Internet effect as for rig.run.create; lives until the run ends. |
rig.run.cancel | rig:run | Free | Destructive: removes or abandons something; safe to repeat. Answers in the request. | End a run without an outcome, for a test that was abandoned. Same effect as finishing on the run's addresses. |
rig.run.create | rig:run | Free | Changes data; a repeat acts again; reaches the public Internet. Answers in the request. | Start a run of a suite's current version and allocate its resources: fresh inbox addresses, public callback and mock URLs, route labels. Public Internet effect: those addresses accept mail and requests from anyone who knows them until the run ends (its ttl, default 30m, at most 24h). Idempotent per call. Free; runs count toward the organisation's limits. Finish the run when done rather than letting it expire. |
rig.run.finish | rig:run | Free | Changes data; safe to repeat. Answers in the request. | End a run with an outcome (pass, fail or none). Its addresses stop accepting at once; the timeline stays readable. Use when the test is over. |
rig.run.get | rig:read | Free | Read-only. Answers in the request. | One run: status, outcome, expiry, and its resources with the address or URL each answers at. Read this for the addresses to configure in the application under test. |
rig.suite.get | rig:read | Free | Read-only. Answers in the request. | One suite with its current definition, exactly as stored. |
rig.suite.list | rig:read | Free | Read-only. Answers in the request. | Suites in a project or the organisation: id, slug, current version. A suite is a persistent, versioned definition of the resources a run receives and the expectations it is judged by. |
rig.suite.upsert | rig:write | Free | Changes data; safe to repeat. Answers in the request. | Create a suite (project_id and slug) or revise one (suite_id) with a definition. Revising stores a new immutable version only when the definition changed; runs already started keep theirs. Free. Use before rig.run.create; do not use to change what a running test observes - add resources or faults to the run instead. |
Discovery
Everything a registry, a scanner or a coding agent needs to understand the server can be read without a token. Calling a tool always needs one.
| Document | Says |
|---|---|
/.well-known/ironfang-mcp.json | The capability catalogue: every product, tool, input schema, scope, hint, credit cost and task support, plus resources and how to authenticate. Generated from the server's own tool definitions. An Ironfang document, not a standard. |
/docs/mcp.md | This reference as Markdown, generated from the same data. |
https://mcp.ironfang.com/.well-known/oauth-protected-resource/mcp | OAuth protected resource metadata (RFC 9728): the authorization server and the scopes a first connection asks for. |
https://id.ironfang.com/.well-known/oauth-authorization-server | Authorization server metadata (RFC 8414): endpoints, PKCE, Client ID Metadata Documents and dynamic registration. |
/llms.txt | The map of every Ironfang product, contract and document for a model. |
| MCP Registry | Listed as com.ironfang/ironfang. |
After connecting, initialize returns short instructions naming each tool prefix and where to start, tools/list returns every tool with its schema, hints and metadata, and ironfang.connection.get returns the organisation, scopes, products and budgets of this connection.
Names and compatibility
Renderwolf, Auditwolf and Financewolf are the names Ironfang Render, Ironfang Audit and Ironfang Finance launched under. They are not separate products. An alias is the name a product launched under. It is callable so that saved configurations keep working, it is never listed by tools/list, and it is not a separate product. Resource URIs under the alias names resolve the same way. Use the current names.
| Launch-era prefix | Current prefix | Status |
|---|---|---|
renderwolf.* | render.* | Alias. Callable, never listed. |
auditwolf.* | audit.* | Alias. Callable, never listed. |
Scopes follow the same rule: a token or key minted with a launch-era scope such as renderwolf:render is read as render:render. New connections are only ever offered the current names.
Security
- The MCP access token is addressed to
https://mcp.ironfang.com/mcpand nowhere else; products reject it, and the MCP server rejects tokens meant for the portal or a product. - Product calls use a separate two-minute token minted per call, limited to your granted scopes and your chosen organisation, and never a stored key.
- Scopes are re-checked against your live organisation permissions on every call, and the connection's grant status with a fail-closed cache of at most thirty seconds.
- Client identity is a Client ID Metadata Document fetched over HTTPS with private-network, redirect and size protections, or a rate-limited public-client registration that is retired after thirty days unused. Registrations cannot choose their own scopes.
- Rendering tools refuse cookies, authorization and custom headers, proxies, script execution and private-network targets. Raw HTML is bounded and never logged.
- Signed download links expire in fifteen minutes and are bound to the job's organisation.
- There is no tool that mints keys, manages members or clients, changes plans, deletes evidence or calls an arbitrary API.
- Per-connection and per-organisation concurrency limits, per-call cost ceilings and a per-tool kill switch bound the damage a misbehaving client can do.
Troubleshooting
Every response carries X-Ironfang-Request-ID; a request id or the connection id from ironfang.connection.get is all support needs to find a call. Quote those, never a token.
| What you see | What it means | What to do |
|---|---|---|
redirect_uri not registered for client | The client's registered callback does not match the one it used. Loopback callbacks may change port, but not host or path. | Update the client, or if you pre-registered it by hand, register the exact callback it sends. |
the client's registration changed; start again | The client's metadata document changed between the consent page opening and you pressing Allow. | Start the connection again. |
| "requires re-authorization (token expired)" | The connection had no refresh token, or its refresh token was revoked. | Authenticate again; a new connection carries a refresh token. If it keeps happening, the connection was revoked from the portal. |
| "protocol version is not supported" | The client speaks a revision the server does not accept. | Update the client. Revisions from 2025-03-26 onward are accepted. |
403 with insufficient_scope | The tool needs a scope this connection was not granted. | Let the client re-authorize with the scope in the challenge; you must hold the matching permission in the organisation. |
tenant_access_lost | Your membership or permission in the chosen organisation was removed. | Reconnect and choose an organisation you are still part of. |
connection_revoked | The connection was disconnected in the portal. | Connect again if that was not intended. |
product_not_enabled | The product the tool belongs to is not available to this connection. | Check the organisation has an account for that product and you hold its permission; the beta may also not be enabled for the organisation yet. |
budget_store_unavailable | The server cannot record spending, so it refuses chargeable work rather than run unmetered. | Retry shortly; reads still work. Persisting: contact support. |
mcp_budget_exhausted | This connection's budget for the period is spent. | Wait for the reset in the message, or ask an organisation administrator to raise the connection's budget (never above the plan's remaining allowance). |
quota_exceeded | The organisation's plan credits are spent. | Upgrade or wait for the period to reset. |
not_available_in_beta | A capability that exists in the REST API is deliberately withheld from MCP for now. | Use the REST API for it. |
target_failed | The page could not be rendered (timeout, error status, blocked target). | Check the URL is public and answers; the message is sanitised and never includes internal detail. |
result_not_ready / result_too_large / inline_not_allowed | The job has not succeeded yet, or the output must be fetched by link. | Poll again; use the download link. |
Privacy
For each MCP call Ironfang records the connection id, organisation, tool name, method, outcome, latency, request size and request id. It does not record tool arguments, prompts, tool results or model output. Rendered outputs are stored as Ironfang Render jobs under the organisation's ordinary retention (24 hours for hosted results) and are visible to that organisation in the portal. Consent screens and registrations are recorded as security events on the account. Disconnecting a client revokes its tokens; it does not delete the jobs the organisation already paid for.

