Access control
Tool access is enforced at two levels: by access control role and by development package. Both checks run on every tool call. The MCP server cannot grant a user wider access than the Cockpit would.
Role check
Every tool runs a role check before it dispatches the action. If your user account does not have the role listed for a tool group, the tool fails with an access denied error and no action is performed.
| Tool group | Required role | Operations | Reference |
|---|---|---|---|
Adaptive entities |
|
List, get, save, delete |
|
AI agents, AI tools, and AI models |
|
List, get, save, delete. List vendor settings (models) |
|
APIs |
|
List, get, save, delete |
|
Applications |
|
List, get, save, delete |
|
Artifact locks |
|
List, take, release |
|
Development packages |
|
List, get, save, delete |
|
npm packages |
|
List, get, save, delete |
|
PDF templates and documents |
|
List, get, save, delete, and activate templates. Generate, get, and list documents |
|
Process flows |
|
List, get, save, delete, run, stop an execution, list and get executions, list, get, and continue assigned user tasks |
|
Server scripts |
|
List, get, save, delete |
|
System information and configuration |
|
Get (read-only) |
|
System logs |
|
List, get (read-only) |
|
Tables |
|
List, get, save, delete |
|
Tiles and tile groups |
|
List, get, save, delete (delete requires confirmation) |
|
Users |
|
List (read-only) |
|
Web apps |
|
List, get, save, delete |
To grant or revoke a role, an administrator must update the user account in the Neptune DXP - Open Edition user management interface. See User roles and permissions.
Development package check
For non-administrative users, tools that list or modify artifacts also run under the user’s development package permissions. You see and can change only the artifacts in packages that your roles grant access to.
Save and delete operations additionally run the platform’s standard before-save hooks, edit-lock checks, and package-edit-permission checks. An MCP client has no way to bypass these checks.
Changes made through the MCP server are written to the audit log in the same way as changes made in the Cockpit, under the name of the signed-in user.
When you create an artifact without naming a development package, the artifact is assigned to your default development package. A package that you name explicitly takes precedence. A default package that you cannot edit is skipped instead of blocking the create. See Package tools.
Save and delete operations also respect edit locks held by other users. See Lock tools.
Tool group specifics
Some tool groups apply rules beyond the role and development package checks.
Process flows
The user task tools return the user tasks assigned to you. Administrators see every user task. Running a flow, stopping an execution, and continuing a user task require a signed-in user and also follow the role-based access of process flows.
PDF templates and documents
The template tools require the PDF role. Generating and reading documents check the runtime access to the PDF template instead, as set in the access and roles of the template. Activating a template fails if another user holds its edit lock.
Tiles and tile groups
Deleting a tile always requires confirm set to true. Deleting a tile group requires
it only if the tile group still contains tiles or child tile groups. Without confirmation,
the call is refused, and the response reports where the tile is used or what the
tile group contains.
AI agents, AI tools, and AI models
list_ai_vendor_settings returns the names of the configuration fields of each
vendor, not configured values. The model configuration is never included in the
result of list_ai_models.
System information and settings
Both tools are read-only. get_system_settings replaces secrets with a placeholder.
This applies to every setting marked as sensitive and to the license and key data
of the instance.
Artifact locks
delete_lock also removes a lock that another user holds. The removal is written
to the audit log.
Related topics
-
Tools overview — role summary and artifact type index.
-
Authorization — how the access token that carries the user identity is issued and refreshed.