MCP
Reach a brand's catalog from an AI assistant, as the person using it.
The Fabric MCP server exposes a brand's catalog to an AI assistant through the Model Context Protocol. An assistant connected to it can search products, correct values, run enrichment and start exports — as the person who authorized it, with exactly the permissions they have.
Not yet reachable
The server is built but not switched on. This page describes what ships; the endpoint answers once the connection details below are live. Nothing here is speculative — it is what the code does.
How it authenticates
OAuth 2.1, not an API key. An assistant does not hold a credential of its own: it sends the user to Fabric, the user signs in and approves a list of scopes, and the assistant receives a token bound to that user, those scopes, and this server.
That has three consequences worth knowing before you connect one:
- A tool can never do more than the person could. Every call travels as their token and lands on the same API a human uses.
- Approval is per scope. The consent screen names each one in plain terms, and denying is a first-class answer.
- The token is bound to this server. A token issued for another resource is refused, however valid it is elsewhere.
Scopes
| Scope | What an assistant may do |
|---|---|
catalog:read | Read products, categories, attributes, views and lists |
catalog:write | Edit values, images and FAQ answers; move products through review |
enrichment:write | Start enrichment runs, which spend credits |
publishing:read | See destinations, mappings and publishing history |
publishing:write | Publish to connected destinations |
org:read | See the organization and its brands |
org:write | Manage brands, members and keys |
Grant the narrowest set that does the job. An assistant asking for enrichment:write can spend
money; one with catalog:read cannot change anything.
Every tool takes a brand
There is no active brand and no default. A token identifies a person, and a person may belong to
several brands, so each tool takes an explicit brandId.
A brandId the user cannot reach answers not found, not forbidden. Confirming that an id is
real is itself a leak.
Start with list_brands
It is the one tool that takes no brandId, because it is where one comes from. It answers with
every brand you can act on and the organization each belongs to.
Discovering the server
Point a client at the MCP endpoint and it finds the rest on its own, per
RFC 9728. An unauthenticated request answers 401
with the location of the metadata:
WWW-Authenticate: Bearer resource_metadata="https://fabric.inc/.well-known/oauth-protected-resource/api/mcp"That document names the authorization server, the resource identifier your token must be bound to, and the scopes above. A compliant client needs nothing else from you.