---
title: "MCP server — React Box documentation"
description: "Connect an AI agent to a React Box organization: OAuth or API key, exposed tools, limits and audit."
url: https://www.react-box.com/en/docs/developers/mcp
lang: en
---

DevelopersMCP server

# MCP server

Plug an agent — Claude, ChatGPT, Cursor — into an organization's data. Only an administrator can give consent, and the agent gets exactly their rights, not one more.

Updated on October 2, 2026

## Connecting a client that speaks OAuth

Claude and ChatGPT negotiate the authorization themselves: all they need is the server address, shown under Settings → MCP. Only an administrator of the organization can give consent.

1. Add the server  
Paste the MCP server address into the client. It discovers where to ask for authorization on its own.
2. Pick the organization  
A consent screen opens in the browser: you sign in, pick the organization, and authorize. The picker only offers the organizations you administer, and the authorization covers that one only.
3. Work  
The agent sees the tools your administrator rights cover. Cut its access whenever you want under Settings → MCP.

## Connecting an agent without a browser

A script, a worker, a self-hosted agent: an organization API key is the direct route, with no consent step to repeat. Only an administrator creates one, which puts it under the same rule.

1. Create a key  
Settings → API keys, with only the scopes the agent needs.
2. Declare the server  
Add the server to the client's configuration, with the key in the x-api-key header.
3. Check what is exposed  
The agent only sees tools its scopes cover: a missing scope makes the tool invisible, not merely refused.

```
{
  "mcpServers": {
    "react-box": {
      "type": "http",
      "url": "https://www.react-box.com/api/mcp",
      "headers": { "x-api-key": "rbx_…" }
    }
  }
}
```

## What an agent can do

The same tool registry as the Atlas assistant, minus the actions that need a human confirmation. The exact list, by domain, with the permission and module each tool requires, is shown in Settings → MCP.

* Context: the organization's profile, what the connection may do, pending items, global search. For an accounting firm, the list of its client files.
* Sales: invoices and credit notes, detail, headline figures, numbering checks, issue blockers, an invoice's history (emails, reminders, credit notes allocated).
* Purchases: supplier invoices, detail, headline figures, payments and credit notes allocated.
* Third parties: customer and supplier directory, full record, bank accounts, a counterpart's position (what it owes, what is owed to it, overdue and not yet due).
* Accounting: chart of accounts, allocation hints, and — for an administrator — the organization's accounting journal, who did what on which record.
* Banking and cash: accounts, statements, searching a line by amount or label, cash receipts and their headline figures.
* Vault: folders, document search, a document's record, tags, history and comments, archives, existing share links.
* File contents: reading the text of a vault PDF or text file, page by page. A scan with no text layer is reported as such.
* Exchanges: document requests, conversations the user takes part in, emails received on the drop-off address.
* Analytics (module required): revenue, expenses, treasury, VAT, receivables and payables ageing.
* Organization: invoicing settings, members, roles and invitations, active modules, storage, notifications, exchange rates and followed currencies.
* Writes: draft invoices, purchases and cash receipts, account allocations, third parties, bank accounts, folders, tags, comments. No issuing, no sending, no deleting.
* Kept to the Atlas chat: the actions that need a human click — changing a third party's identity or bank details, sending a document request, running an AI analysis, searching the web — are not offered to an MCP agent.

## The limits

What bounds an agent, and what no clever phrasing on its part gets around.

* Rights come from the key (its scopes) or from the administrator who consented (their role) — never from the MCP client itself. A token whose person is no longer an administrator stops working in under a minute.
* An accounting firm passes a clientId to work a client file, at an assigned collaborator's level and never a supervisor's.
* 120 calls per minute per connection.
* Lists return 20 items by default, 50 at most, with a skip cursor and — for searches — the matching total, so an agent knows when more remain.
* Every write leaves an entry in the organization's activity log, with the connection that made it. A draft created by an agent also shows up in the record's own history, marked as coming from MCP.

An agent reads your data

An agent connected over OAuth gets an administrator's reach: only connect clients you would trust with that level of access, and prefer an API key with the narrowest scopes when the agent only needs one area. When in doubt, disconnect: it takes effect immediately.
