Skip to main content
The Navis Ops MCP server lets AI assistants read and write your workspace data using the Model Context Protocol. It implements the MCP specification version 2025-06-18 over Streamable HTTP transport, and supports both API key and OAuth 2.1 authentication. Everything the server exposes — tools, resources, and prompts — is scoped to the authenticated user via row-level security. No cross-user data access is possible.

Base URL

Replace <your-supabase-project> with your Supabase project reference. You can find the full URL in Settings → Connected Apps when you create an API key or connect an OAuth client.

Authentication

Pass your API key or OAuth access token as a bearer credential in the Authorization header on every request:
For OAuth access tokens, the format is the same — replace the value with your OAuth token. If authentication fails, the server returns 401 Unauthorized with a WWW-Authenticate header pointing at the discovery document. See the authentication overview for details on both methods.

What the server exposes

Request format

The MCP server uses JSON-RPC 2.0. Every request is an HTTP POST with a Content-Type: application/json body:
The server also accepts Accept: text/event-stream to receive responses as Server-Sent Events (SSE). Most MCP clients handle this negotiation automatically.

Supported JSON-RPC methods

Session management

The server maintains DB-backed sessions. After a successful initialize call, the server returns a Mcp-Session-Id header. Include this header in subsequent requests. Sessions idle out after one hour.
Most MCP client libraries handle session initialization automatically.

Data scoping and security

All tools and resources are scoped to the authenticated user. The server enforces row-level security on every database query — there is no way for an AI assistant to read or modify another user’s data, even if it tries. The only access control knob available is scope: mcp:read grants every read tool, and mcp:write grants reads plus all write tools. There is no per-tool ACL.

Next steps

Tools

All 52 tools organized by domain with scope requirements.

Resources

5 read-only resources for workspace overview, projects, tasks, and calendar.

Prompts

4 named prompt templates for planning, standups, and retrospectives.