Access control

Tool access is enforced at two levels: by access control role and by development package. Both checks run on every tool call. The MCP server cannot grant a user wider access than the Cockpit would.

Role check

Every tool runs a role check before it dispatches the action. If your user account does not have the role listed for a tool group, the tool fails with an access denied error and no action is performed.

Tool group Required role Operations Reference

Adaptive entities

adaptivedesigner

List, get, save, delete

Adaptive entity tools

AI agents, AI tools, and AI models

ai-agent, ai-model, ai-tool

List, get, save, delete. List vendor settings (models)

AI tools

APIs

apidesigner

List, get, save, delete

API tools

Applications

appdesigner

List, get, save, delete

Applications tools

Artifact locks

locking

List, take, release

Lock tools

Development packages

package

List, get, save, delete

Package tools

npm packages

npmmodules

List, get, save, delete

npm package tools

PDF templates and documents

pdf_templates

List, get, save, delete, and activate templates. Generate, get, and list documents

PDF tools

Process flows

process-flows

List, get, save, delete, run, stop an execution, list and get executions, list, get, and continue assigned user tasks

Process flow tools

Server scripts

scripteditor

List, get, save, delete

Server script tools

System information and configuration

system-info (users with cockpit access)

Get (read-only)

System tools

System logs

syslog

List, get (read-only)

System log tools

Tables

tabledefinition

List, get, save, delete

Table tools

Tiles and tile groups

tile, tile-group

List, get, save, delete (delete requires confirmation)

Tile tools

Users

users

List (read-only)

User tools

Web apps

webapp

List, get, save, delete

Web app tools

To grant or revoke a role, an administrator must update the user account in the Neptune DXP - Open Edition user management interface. See User roles and permissions.

Development package check

For non-administrative users, tools that list or modify artifacts also run under the user’s development package permissions. You see and can change only the artifacts in packages that your roles grant access to.

Save and delete operations additionally run the platform’s standard before-save hooks, edit-lock checks, and package-edit-permission checks. An MCP client has no way to bypass these checks.

Changes made through the MCP server are written to the audit log in the same way as changes made in the Cockpit, under the name of the signed-in user.

When you create an artifact without naming a development package, the artifact is assigned to your default development package. A package that you name explicitly takes precedence. A default package that you cannot edit is skipped instead of blocking the create. See Package tools.

Save and delete operations also respect edit locks held by other users. See Lock tools.

Tool group specifics

Some tool groups apply rules beyond the role and development package checks.

Process flows

The user task tools return the user tasks assigned to you. Administrators see every user task. Running a flow, stopping an execution, and continuing a user task require a signed-in user and also follow the role-based access of process flows.

PDF templates and documents

The template tools require the PDF role. Generating and reading documents check the runtime access to the PDF template instead, as set in the access and roles of the template. Activating a template fails if another user holds its edit lock.

Tiles and tile groups

Deleting a tile always requires confirm set to true. Deleting a tile group requires it only if the tile group still contains tiles or child tile groups. Without confirmation, the call is refused, and the response reports where the tile is used or what the tile group contains.

AI agents, AI tools, and AI models

list_ai_vendor_settings returns the names of the configuration fields of each vendor, not configured values. The model configuration is never included in the result of list_ai_models.

System information and settings

Both tools are read-only. get_system_settings replaces secrets with a placeholder. This applies to every setting marked as sensitive and to the license and key data of the instance.

Artifact locks

delete_lock also removes a lock that another user holds. The removal is written to the audit log.