Model Context Protocol

Connect your AI assistant to Crane Connect

Crane Connect exposes a Model Context Protocol (MCP) server over Streamable HTTP. Assistants sign in with a Crane Connect account and only ever see that account's own jobs, bookings and timesheets.

Endpoints

Authentication

Every request needs an Authorization: Bearer <access token> header. Tokens are issued by the Crane Connect account service advertised in the OAuth metadata document above; assistants that support OAuth discovery pick this up automatically after a 401 response.

Requests without a token are refused with 401 and a WWW-Authenticate pointer to the metadata URL.

Allowlist (approved assistants only)

On top of OAuth, the endpoint can be restricted to approved callers. When an allowlist is active, a request must come from an approved IP address or carry an approved client key:

x-mcp-key: <client key provided by V.S.C. Cranes>

Blocked callers receive 403 with a short explanation. The health probe stays open so uptime monitoring keeps working. Ask V.S.C. Cranes (info@infovsccranes.net) for a client key or to add your assistant's outbound IP addresses.

Quick check

Confirm the server is up before configuring anything:

curl -s https://www.infovsccranes.net/api/public/mcp-health

Then a real call, with headers exactly as below:

POST https://www.infovsccranes.net/api/public/mcp
Content-Type: application/json
Accept: application/json, text/event-stream
Authorization: Bearer <access token>
x-mcp-key: <client key, when an allowlist is active>

Omitting the Accept header returns 406 Not Acceptable.

Available tools

ToolTypeDescription
get_my_profilereadProfile and role of the signed-in user.
list_jobsreadLift jobs visible to the user (status, limit).
list_bookingsreadBookings as client or operator (status, limit).
list_timesheetsreadTimesheet entries (booking_id, limit).
log_timesheetwriteLog worked hours on a booking.

The live tool list is always available from the health probe, so an assistant can verify it before connecting.