Qoris MCP Server - Technical Reference
Complete technical documentation for integrating with the Qoris MCP server.Server Information
MCP Server Name: QorisMCP Server URL:
https://mcp.qoris.ai/mcpTagline: Governed AI agents with persistent memory, knowledge, MCP tools, and Knox safety Description: Qoris provides AI agents with persistent memory and knowledge management capabilities through Model Context Protocol. Store and retrieve information across conversations, search project knowledge bases, and build context-aware applications. Knox adds the governance layer for agents that execute commands, call tools, schedule work, or operate autonomously.
Server URL
Type: Custom MCP URLs (per user) Each user gets their own unique URL with their API key embedded as a query parameter: User URL Format:https://mcp.qoris.ai/mcp?api_key=YOUR_API_KEY
Users can also use the Authorization header method with the base URL:
- Base URL:
https://mcp.qoris.ai/mcp - Header:
Authorization: Bearer YOUR_API_KEY
- Generate an API key in Qoris project settings
- Copy the URL provided:
https://mcp.qoris.ai/mcp?api_key=YOUR_API_KEY - Use this URL in their MCP client configuration
Connection Requirements
Setup Requirements:- Requires a Qoris account (free tier available)
- Requires a project in your Qoris workspace
- Requires an API key generated from project settings
- No geographic restrictions
- No admin or developer seat required
- Sign up at qoris.ai
- Create a project
- Generate an API key from project settings
- Configure MCP connection with your API key
Authentication
Authentication Type: API Key or OAuth 2.0 Qoris supports three ways to authenticate MCP connections:Method 1: OAuth 2.0 (For Cursor, Claude Code)
MCP clients that support OAuth use discovery endpoints (/.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource), register dynamically (DCR), and redirect users to the consent page (https://app.qoris.ai/oauth/consent). Users sign in, select a workspace, approve, and the client receives an access token.
- Access tokens do not expire — they remain valid until revoked
- Revocation: Via Connected Apps in the Qoris dashboard, or
DELETE /oauth/connections/<token_id> - Bearer method:
Authorization: Bearer <access_token>
Method 2: API Key via Query Parameter (Simplest)
Pass the API key as a query parameter in the URL:Method 3: API Key via Authorization Header (Recommended for API Keys)
Pass the API key in the Authorization header:X-Qoris-Project-ID header is not required — the project ID is determined from the API key or OAuth token.
API Key Generation:
- Navigate to your Qoris project settings
- Go to the “MCP” tab
- Click “Create API Key” in the API Keys section
- Copy and securely store the key (you won’t be able to see it again)
Transport Support
Supported Transport: Streamable HTTP Qoris MCP server supports Streamable HTTP transport. SSE support may be added in the future, but Streamable HTTP is recommended for all integrations.Read/Write Capabilities
Capability: Read + Write Qoris MCP server provides both read and write operations: Read Operations:get_memories- Retrieve workspace memoriessearch_knowledge- Search project knowledge baselist_knowledge_documents- List available knowledge documentsget_document_full_content- Retrieve full document content
save_memory- Create new memoriesupdate_memory- Update existing memoriesdelete_memory- Delete memories
Knox Governance Layer
MCP controls how agents connect to Qoris memory and knowledge. Knox governs higher-risk actions around that access path. Use Knox when agents can:- execute shell commands or scripts
- write or edit files
- call MCP tools with untrusted external input
- create scheduled or background tasks
- invoke subagents
- mutate external business systems
- perform operations that require approval or audit
MCP App Status
Is this an MCP App? No Qoris MCP server is a standard MCP server without interactive UI elements. All interactions are through MCP tool calls.Third-party Connections
- Web Access: No
- Third-party AI Model Integration: Yes (for knowledge search synthesis)
- Third-party Data Retrieval: No
- Third-party Data Modification: No
Data Handling
- Server only accesses data explicitly requested by user: Yes
- No data is stored beyond session requirements: Yes (data persists per project, not per session)
- Data transmission is encrypted (HTTPS/TLS): Yes
- GDPR compliant: Yes (if applicable)
- Memories are stored in PostgreSQL databases
- Knowledge items are stored in project-specific storage
- All data is encrypted at rest and in transit
- Data is scoped to projects and users
- Memories persist until explicitly deleted by the user
- Knowledge items persist until removed from the project
- API keys can be revoked at any time
Categories
Primary Category: Business & ProductivitySecondary Categories: Development tools, Data & Analytics
Use Cases & Examples
Use Case 1: Conversational AI with Memory
Scenario: Building a customer support chatbot that remembers user preferences and previous interactions. Example Prompt:Use Case 2: Documentation Assistant
Scenario: Creating an AI assistant that can answer questions about your project’s documentation and codebase. Example Prompt:Use Case 3: Multi-Agent Workflow Coordination
Scenario: Multiple AI agents working on the same project need to share context and state. Example Prompt:Use Case 4: Code Review Assistant
Scenario: An AI assistant that reviews code and remembers common issues and patterns for your team. Example Prompt:Use Case 5: Project Knowledge Base Query
Scenario: Quickly finding information from uploaded documentation, meeting notes, or project files. Example Prompt:API Reference
Base URL
Authentication
Option 1: OAuth 2.0Available Tools
See individual tool documentation:- save_memory
- get_memories
- update_memory
- delete_memory
- search_knowledge
- list_knowledge_documents
- get_document_full_content
Error Handling
All tools return consistent error responses:- 400 Bad Request: Invalid parameters or validation errors
- 401 Unauthorized: Invalid or missing API key
- 403 Forbidden: Permission denied (e.g., trying to update another API key’s memory)
- 404 Not Found: Resource not found (e.g., memory doesn’t exist)
- 500 Internal Server Error: Server-side errors
Rate Limits
Rate limits are applied per API key:- Default: 1000 requests per hour
- Premium: Higher limits available
Privacy & Security
Privacy Policy: https://qoris.ai/privacy Data Processing Agreement: Available upon request for enterprise customers Security:- All connections use HTTPS/TLS encryption
- API keys are hashed and stored securely
- Data is encrypted at rest
- Regular security audits and updates
Support
Support Channel: [email protected] or GitHub Issues Documentation: https://docs.qoris.ai Status Page: https://status.qoris.aiConfiguration Examples
Cursor / Claude Code (OAuth)
MCP clients that support OAuth discover the server athttps://mcp.qoris.ai/mcp and redirect users to the consent page. No manual configuration needed — users sign in and approve. Access tokens do not expire until revoked.
Claude Desktop (API Key)
Option 1: Using Authorization Header (Recommended) Add toclaude_desktop_config.json:
