Servidor MCP

Conecte sua IA favorita

Servidor MCP pronto para Claude, ChatGPT, Cursor, VS Code e qualquer cliente compatível — login por OAuth, sem chave de API.

Copiar link do MCP

MCP
https://vault.diagnos.health/mcp

Connect in a minute

Seven ways to reach the same server — pick yours. Each one was checked against the client's own official docs on 2026-09-15; where a client's UI churns often, that's flagged.

Claude.ai (web, desktop and mobile)

Custom connector with OAuth handled for you — including Claude's own published identity, so there's no client to register.

  1. Open Customize → Connectors.
  2. Click "Add custom connector" and paste https://vault.diagnos.health/mcp.
  3. Under Authentication, choose "Sign in now".
  4. Under OAuth client, choose "Use Claude's published identity (recommended)".
  5. Click "Add", then "Connect", and approve the sign-in.

Team and Enterprise workspaces: an admin adds it once under Organization Settings → Connectors, and everyone else just clicks Connect. On mobile, add it from web or desktop first — it syncs automatically to the app.

Usage suggestions

None of these is an API call — it's the plain sentence you'd type into Claude, ChatGPT, or any connected client.

  • “Search diagnos's help center for how exam versioning works, and summarize it in three lines.”

  • “List my active AI agents in diagnos.”

  • “Send this summary to agent Red 1 in diagnos: [paste text here].”

  • “Create a new AI agent in my diagnos workspace and send it this audio file.”

  • “What's the status of agent Blue 3 in diagnos? When was it last active?”

Available tools

One implementation, three doors in: the MCP server, the equivalent REST API, and diagnos's own in-app AI agent orchestrator all call these exact same eight functions. This table is the complete list — there's no more permissive ninth tool hiding behind a different door.

Tool Required permission What it does
search
alias: help_search
Read-only
none · public Lists every article in diagnos's public help center for the requested locale — id, title, summary and URL for each. No relevance ranking: this tool and its alias always return the full catalog.
fetch
alias: help_fetch
Read-only
none · public Fetches one help-center article by id, as Markdown, with links to related articles. Its alias, help_fetch, accepts several ids at once and returns every article merged into a single response.
whoami Read-only any valid token Returns the connected workspace, client, granted scopes and remaining usage — nothing about a patient or an exam.
agents_list Read-only agents.list Lists your AI agents by name, color and status (e.g. "Red 1", running). No exam, patient or message content.
agent_create Write agents.create Creates a new AI agent in a workspace and returns a link to open it. Cannot attach it to an exam or a patient — that only happens inside the app.
agent_send_message Write agents.write Sends a text message (up to 32 KB) to one of your agents. The reply is an acknowledgment only — never the agent's content.
agent_send_inline_file Write agents.write Attaches a small file (up to 1 MB) directly in the request — text, CSV, JSON or a common image. No executables, no DICOM.
agent_request_upload_url Write files.upload Requests short-lived signed URLs to upload up to 6 larger files (30 MB each) directly, without the bytes passing through the model.

The same logic serves POST /mcp (JSON-RPC), the /api/agents/v1/* REST facade and the app's own orchestrator — none of the three can reach a function the others can't.

This is the entire read/write surface. There is no tool, in any client, that reads a message, a patient or an exam.

What a connected AI agent can do

  • Send a text message, or a small file, to one of your AI agents.
  • Request a signed URL to upload a larger file — up to 6 files, 30 MB each.
  • Search and read diagnos's public help center.

What it can never do

  • Read a conversation — not yours, and not even the agent's own reply to what it just sent.
  • See a patient, an exam, or any clinical document, in any form.
  • See anything about an agent beyond its name, color, number and status.

Every write is audited

Every message, file and upload that comes in through this integration lands in your workspace's audit trail — the same log that already records everything else that touches your data.

Revoke it whenever you want

Every connected client and every AI agent is listed in Workspace Settings → AI Agents. Revoking takes the client's access away immediately — no grace period, no lingering token.

Open workspace settings

This chat is not the vault

Unlike your reports, which live in an end-to-end encrypted vault diagnos itself cannot open, whatever you send through this integration is processed in a separate zone the AI model needs to be able to read. Never share a patient's name, phone number, email or other identifying detail here — even briefly. This is an AI agent, and it can make mistakes.

Limits and quotas

Every call is rate-limited per connection (or per IP, on the anonymous path) and size-capped. None of this is hidden — it's what keeps one connection stuck in a loop from eating everyone else's quota.

Tools Call limit
search, fetch (anonymous, per IP) 300 / min
whoami, agents_list 120 / min
agent_send_message 60 / min
agent_send_inline_file 20 / min
agent_request_upload_url 10 / min

Size caps

  • Message text: up to 32 KB. Above that, send it as a file instead.
  • Inline file: up to 1 MB decoded, allowlisted types only (Markdown, plain text, CSV, JSON, common images) — no executables, no DICOM.
  • Signed upload: up to 6 files per call, 30 MB each — the signed URL locks the declared size, which has to match exactly.

These are opening numbers, tuned as real usage comes in. Call whoami any time to see the exact limits and remaining usage for your connection.

Perguntas frequentes

O agente de IA conectado consegue ler meus pacientes ou exames?

Não. A integração é só de entrada: ela manda mensagem, arquivo ou pedido de upload, e lê o help center público. Não existe uma tool — em nenhum cliente — que devolva conteúdo de paciente, exame ou conversa.

Para onde vai o que eu mando para o agente de IA?

Vira uma mensagem dentro do agente de IA correspondente, do mesmo jeito que se você tivesse mandado pelo app. Ela aparece lá — no editor de exame, se o agente estiver ligado a um, ou no chat do workspace — para você conferir e agir.

Preciso criar ou guardar uma chave de API?

Não. A conexão usa OAuth 2.1: você faz login como faria em qualquer outro app, aprova o que o cliente pode fazer, e pronto. Não existe uma chave secreta para copiar, colar ou vazar.

Dá para desconectar depois?

A qualquer momento, em Configurações do workspace → Agentes de IA. A conexão pode ser revogada quando quiser, sem precisar avisar ninguém.

Qual padrão de autenticação vocês usam?

OAuth 2.1 com PKCE obrigatório, metadados de recurso protegido (RFC 9728), indicador de audiência (RFC 8707) e registro de cliente por CIMD ou DCR — sem chave estática de longa duração, e o servidor nunca repassa para frente um token que não foi emitido para ele.

Toda ação fica registrada?

Sim. Toda escrita entra no audit trail do workspace, cada chamada passa por rate limit por conexão, e o consumo de cota é reservado antes de acontecer e confirmado depois — sem exceção silenciosa.

Qual versão do protocolo MCP vocês suportam?

As duas em uso hoje: a revisão stateless atual (2026-07-28) e a anterior (2025-11-25), que ainda é a que a maioria dos clientes fala. A exceção conhecida é a ponte mcp-remote (usada por clientes que só falam stdio): até a data desta página, ela ainda trava na revisão antiga — se você usa essa ponte e recebe um erro de versão de protocolo, é uma lacuna de compatibilidade dela, não um sinal de que sua conexão está errada.

O modelo de IA treina com os meus dados, ou guarda para sempre?

O Vertex AI (Gemini), que processa o conteúdo, não treina com dado de cliente por padrão. O armazenamento desta zona fica na região UE, é privado, sem acesso público, e tem ciclo de vida curto — mas ela não é o cofre cifrado do produto.