For developers
Through the MCP server, an AI app or your own program uses miphu with a person's account, to read and, if allowed, to write.
https://api.miphu.com/mcp
Connect
- Address
https:/, Streamable HTTP,/ api. miphu. com/ mcp POSTonly, stateless- Sign-in
- OAuth 2.1 authorization code with PKCE (
S256). Clients register through dynamic client registration or with a client ID metadata document. - Metadata
/and. well- known/ oauth- protected- resource/ mcp /. well- known/ oauth- authorization- server - Tokens
- Access token 1 hour, refresh token rotating. A connection that is not used for 30 days ends.
- Scope of a connection
- one person in one company
When connecting, the person signs in with their miphu account, chooses the company, the areas and the access "Read only" or "Read and write", and confirms. The connection sees only what the person may see in miphu, and tools/ names only the tools they can run.
The owner switches AI connections on for the company and sets the AI access of each person: none, read, or read and write. Administrators do this for employees. Writing is possible only once the owner has accepted the current terms of use.
Your own application connects the same way: through OAuth, with a person's account and their rights.
Scopes and write mode
Scopes are areas, writing is a mode: every connection carries only read scopes (*.), and whether it may also create and change records is its mode (mode in miphu_).
A scope is a ceiling. The person's rights in miphu apply on top.
| Scope | Area |
|---|---|
miphu.tasks.read | Tasks |
miphu.crm.read | Leads, customers & contacts, quotes and orders |
miphu.finance.read | Invoices and expenses |
miphu.inventory.read | Items, stock and purchasing |
miphu.documents.read | Documents: titles, details and recognised text |
miphu.insights.read | Insights |
miphu.team.read | Team |
The person selects documents on purpose when connecting, and only if the company has switched on "AI connections may read documents". miphu never hands out the files themselves.
Tools
Once connected, miphu shows the AI app every tool its scope and the person's rights allow, each with a short description in tools/. Which area it reaches is decided entirely by the authorization above; write tools appear only in the mode "Read and write".
Limits
Never through the interface: deleting or archiving, issuing or sending quotes and invoices, confirming orders, recording payments, placing purchase orders, posting goods receipts and stock movements, sending delivery notes, changing accounts, rights, bank and tax details, and exporting data. That stays in the app.
Orders are created only as drafts. An order is confirmed in the app, and only then does miphu reserve the goods. For shortages, the answer names the quantity available today for each item line (available).
Over a limit, miphu answers HTTP 429 with Retry- and error. mcp_.
Examples
Typical tasks an AI app solves through the interface.
- 01
Net revenue per customer in the second quarter, the ten largest
One call with the date range, grouped by customer. The total over all customers is the revenue the insights show for the same period.
- 02
Create an order from a web shop order
First check whether the customer exists, then create customer and contact, and the order as a draft with the shop's item numbers, delivery date and delivery address. It is confirmed in the app.
- 03
Compare items with price and stock against the shop's list
Read both lists page by page and compare by item number. A kit has no stock of its own.
- 04
A task for bookkeeping for every overdue invoice
The receivables carry the customer. Before creating, check whether the customer already has an open task.
- 05
Items at or below the reorder point, with a suggested order
The suggestions name quantity and supplier. If you want, they become purchase order drafts; ordering happens in the app.