Skip to main content

Qoris MCP Server - Technical Reference

Complete technical documentation for integrating with the Qoris MCP server.

Server Information

MCP Server Name: Qoris
MCP Server URL: https://mcp.qoris.ai/mcp
Tagline: Governed AI agents with persistent memory, knowledge, MCP tools, and Knox safety
Description: Qoris provides AI agents with persistent memory and knowledge management capabilities through Model Context Protocol. Store and retrieve information across conversations, search project knowledge bases, and build context-aware applications. Knox adds the governance layer for agents that execute commands, call tools, schedule work, or operate autonomously.

Server URL

Type: Custom MCP URLs (per user) Each user gets their own unique URL with their API key embedded as a query parameter: User URL Format: https://mcp.qoris.ai/mcp?api_key=YOUR_API_KEY Users can also use the Authorization header method with the base URL:
  • Base URL: https://mcp.qoris.ai/mcp
  • Header: Authorization: Bearer YOUR_API_KEY
How users get their URL:
  1. Generate an API key in Qoris project settings
  2. Copy the URL provided: https://mcp.qoris.ai/mcp?api_key=YOUR_API_KEY
  3. Use this URL in their MCP client configuration

Connection Requirements

Setup Requirements:
  • Requires a Qoris account (free tier available)
  • Requires a project in your Qoris workspace
  • Requires an API key generated from project settings
  • No geographic restrictions
  • No admin or developer seat required
Getting Started:
  1. Sign up at qoris.ai
  2. Create a project
  3. Generate an API key from project settings
  4. Configure MCP connection with your API key

Authentication

Authentication Type: API Key or OAuth 2.0 Qoris supports three ways to authenticate MCP connections:

Method 1: OAuth 2.0 (For Cursor, Claude Code)

MCP clients that support OAuth use discovery endpoints (/.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource), register dynamically (DCR), and redirect users to the consent page (https://app.qoris.ai/oauth/consent). Users sign in, select a workspace, approve, and the client receives an access token.
  • Access tokens do not expire — they remain valid until revoked
  • Revocation: Via Connected Apps in the Qoris dashboard, or DELETE /oauth/connections/<token_id>
  • Bearer method: Authorization: Bearer <access_token>
See Authentication for full OAuth flow details.

Method 2: API Key via Query Parameter (Simplest)

Pass the API key as a query parameter in the URL:
Convenient for quick testing and MCP clients that support URL-based auth. Pass the API key in the Authorization header:
More secure than query parameters and recommended for production. Note: The X-Qoris-Project-ID header is not required — the project ID is determined from the API key or OAuth token. API Key Generation:
  1. Navigate to your Qoris project settings
  2. Go to the “MCP” tab
  3. Click “Create API Key” in the API Keys section
  4. Copy and securely store the key (you won’t be able to see it again)
API keys provide full access to your project. Keep them secure and never commit them to version control.

Transport Support

Supported Transport: Streamable HTTP Qoris MCP server supports Streamable HTTP transport. SSE support may be added in the future, but Streamable HTTP is recommended for all integrations.

Read/Write Capabilities

Capability: Read + Write Qoris MCP server provides both read and write operations: Read Operations:
  • get_memories - Retrieve workspace memories
  • search_knowledge - Search project knowledge base
  • list_knowledge_documents - List available knowledge documents
  • get_document_full_content - Retrieve full document content
Write Operations:
  • save_memory - Create new memories
  • update_memory - Update existing memories
  • delete_memory - Delete memories

Knox Governance Layer

MCP controls how agents connect to Qoris memory and knowledge. Knox governs higher-risk actions around that access path. Use Knox when agents can:
  • execute shell commands or scripts
  • write or edit files
  • call MCP tools with untrusted external input
  • create scheduled or background tasks
  • invoke subagents
  • mutate external business systems
  • perform operations that require approval or audit
For developer-agent environments, see the Knox Claude Code Plugin. For the broader Qoris governance model, see the Knox Overview.

MCP App Status

Is this an MCP App? No Qoris MCP server is a standard MCP server without interactive UI elements. All interactions are through MCP tool calls.

Third-party Connections

  • Web Access: No
  • Third-party AI Model Integration: Yes (for knowledge search synthesis)
  • Third-party Data Retrieval: No
  • Third-party Data Modification: No
Qoris uses third-party AI models (via our backend) for knowledge search answer synthesis. The MCP server itself does not directly access external web services or third-party APIs beyond our own infrastructure.

Data Handling

  • Server only accesses data explicitly requested by user: Yes
  • No data is stored beyond session requirements: Yes (data persists per project, not per session)
  • Data transmission is encrypted (HTTPS/TLS): Yes
  • GDPR compliant: Yes (if applicable)
Data Storage:
  • Memories are stored in PostgreSQL databases
  • Knowledge items are stored in project-specific storage
  • All data is encrypted at rest and in transit
  • Data is scoped to projects and users
Data Retention:
  • Memories persist until explicitly deleted by the user
  • Knowledge items persist until removed from the project
  • API keys can be revoked at any time
Personal Health Data: No Qoris does not handle personal health data or medical records.

Categories

Primary Category: Business & Productivity
Secondary Categories: Development tools, Data & Analytics

Use Cases & Examples

Use Case 1: Conversational AI with Memory

Scenario: Building a customer support chatbot that remembers user preferences and previous interactions. Example Prompt:
MCP Tool Call:
Value: Enables personalized experiences across multiple conversations without requiring users to repeat information.

Use Case 2: Documentation Assistant

Scenario: Creating an AI assistant that can answer questions about your project’s documentation and codebase. Example Prompt:
MCP Tool Call:
Value: Provides instant access to project documentation, code examples, and knowledge without manual searching.

Use Case 3: Multi-Agent Workflow Coordination

Scenario: Multiple AI agents working on the same project need to share context and state. Example Prompt:
MCP Tool Call:
Then Agent B retrieves:
Value: Enables coordination between multiple agents working on complex workflows by sharing state and context.

Use Case 4: Code Review Assistant

Scenario: An AI assistant that reviews code and remembers common issues and patterns for your team. Example Prompt:
MCP Tool Call:
Value: Maintains consistent code quality by remembering team-specific standards and preferences.

Use Case 5: Project Knowledge Base Query

Scenario: Quickly finding information from uploaded documentation, meeting notes, or project files. Example Prompt:
MCP Tool Call:
Value: Instantly retrieves relevant information from all project documentation without manual file searching.

API Reference

Base URL

Authentication

Option 1: OAuth 2.0
Access tokens do not expire until revoked. See Authentication for OAuth flow. Option 2: API Key via Query Parameter
Option 3: API Key via Authorization Header

Available Tools

See individual tool documentation:

Error Handling

All tools return consistent error responses:
  • 400 Bad Request: Invalid parameters or validation errors
  • 401 Unauthorized: Invalid or missing API key
  • 403 Forbidden: Permission denied (e.g., trying to update another API key’s memory)
  • 404 Not Found: Resource not found (e.g., memory doesn’t exist)
  • 500 Internal Server Error: Server-side errors
See individual tool documentation for specific error codes and messages.

Rate Limits

Rate limits are applied per API key:
  • Default: 1000 requests per hour
  • Premium: Higher limits available
Rate limit headers are included in responses:

Privacy & Security

Privacy Policy: https://qoris.ai/privacy Data Processing Agreement: Available upon request for enterprise customers Security:
  • All connections use HTTPS/TLS encryption
  • API keys are hashed and stored securely
  • Data is encrypted at rest
  • Regular security audits and updates

Support

Support Channel: [email protected] or GitHub Issues Documentation: https://docs.qoris.ai Status Page: https://status.qoris.ai

Configuration Examples

Cursor / Claude Code (OAuth)

MCP clients that support OAuth discover the server at https://mcp.qoris.ai/mcp and redirect users to the consent page. No manual configuration needed — users sign in and approve. Access tokens do not expire until revoked.

Claude Desktop (API Key)

Option 1: Using Authorization Header (Recommended) Add to claude_desktop_config.json:
Option 2: Using Query Parameter

Custom MCP Client

Versioning

Current Version: 1.0.0 API versioning is handled through the MCP protocol version. Breaking changes will be communicated through our changelog and documentation updates.

Changelog

See https://docs.qoris.ai/changelog for version history and updates.