Connected Apps & MCP
Gerbtrace exposes a Model Context Protocol (MCP) server so AI assistants and other approved apps can read and change your projects with exactly the permissions you have. Newmatik's assistant Moth uses it; any MCP client that supports OAuth can connect the same way.
How access works
- The app sends you to Gerbtrace, where you sign in (if needed) and see an Authorize access screen naming the app.
- When you allow it, the app receives a token that identifies you. Every request it makes is checked against your team roles, space memberships and project status — it can never see or edit more than you can.
- Tokens expire after an hour and are refreshed silently while the connection stays authorized.
You can review and revoke connected apps at any time under Profile → Connected apps. Revoking immediately invalidates the app's tokens.
What a connected app can do
| Area | Read | Write |
|---|---|---|
| Teams, members, spaces | roles, members, pending invitations, usage | rename team, defaults, invite/change/remove members (admins) |
| Projects | list/search, overview, workflow state, settings | create, rename, reassign, workflow transitions, settings, delete (draft, confirm required) |
| Files & documents | list, download Gerber/drill/PnP text | upload/replace/delete files (draft projects only) |
| BOM | lines with manufacturers and DNP | replace the line list |
| Conversation & inbox | messages, notifications | post comments, mention members, mark read |
| Package library | list and inspect custom SMD/THT packages | — |
Destructive actions require the app to pass an explicit confirmation, and Moth asks you before doing so.
Connecting a generic MCP client
- Server URL:
https://gqrnlnlfidighosujpdb.supabase.co/functions/v1/mcp - Transport: Streamable HTTP (stateless JSON responses)
- Authorization: OAuth 2.1 with PKCE; discovery via
…/mcp/.well-known/oauth-protected-resource
Clients that register themselves dynamically are not enabled by default; ask your Gerbtrace administrator to register the client and share its client ID.
For developers
The server lives in supabase/functions/mcp/ and reuses the same Row Level
Security policies as the web app. See the developer section for the tool
catalog and the deployment checklist.