MCP Server: Connecting AI Assistants to Your Library

The Model Context Protocol, usually shortened to MCP, is an open standard that lets an AI assistant call tools in another system instead of guessing at what that system contains. The platform runs an MCP server, so a client such as Claude or Cursor can search your library, read an asset's details and assemble a portal — acting as you, with your permissions, against the same API the interface itself uses. This article covers what an MCP connection is, how to set one up, what an assistant can and cannot do once connected, and how it differs from the Virtual Assistant built into the platform.

Why Connect an Assistant to the Library at All

An assistant with no access to your library can only work from whatever someone pasted into the conversation. Ask it which logo is current and it will either decline or invent an answer, because the question is not about the world, it is about your content.

The questions that waste the most time are exactly the ones a connected assistant can answer: which version of the product shot is approved, whether a video is cleared for external use, what was sent to a particular client in March, which assets are missing a campaign tag. None of those are hard questions. They are just questions whose answers live in a system the assistant cannot see.

The distinction that matters is not whether AI can reach your files but whether it reaches them under the same rules as everyone else. A connection that bypasses your permissions to be helpful has not saved anyone time; it has created a problem that surfaces later.

Connecting a Client

The server is reached at /mcp on your workspace address, and any MCP-capable client can be pointed at it. There is no key to copy, no application to register in advance, and nothing to configure on the platform side first.

Adding the connection in the client opens an approval screen in your browser, where you sign in as you normally would and confirm the connection. Approving it creates an ordinary API token, named for the connection and dated, which appears alongside your other tokens in settings. Revoking the token there ends the connection immediately.

Two details are worth knowing. The connection is per person rather than per workspace, so two colleagues connecting the same client each get their own view of the library. And a local process is available for editors and desktop tools that expect to launch a command rather than call a URL, which connects through the same approval step in the browser.

An Assistant Cannot Reach What You Cannot

Every request the assistant makes goes through the same API as the interface, authenticated as the person who approved the connection. There is no service account, no elevated access and no separate copy of the library for AI to read.

The practical consequence is that all the access control you have already configured applies without being restated:

This is worth being precise about, because it is the first question any security review asks. Granting a contractor an AI client does not widen what they can see. It changes how they ask.

What It Can Find

Reading is where most of the value is, and the assistant has several ways in rather than one:

Search results arrive with aggregations describing the matches, so an assistant asked a broad question can report the shape of what it found rather than reciting the first twenty hits.

What It Can Change

A connection is not limited to reading. The assistant can also create folders and move them, edit an asset's name and description, manage the shared tag vocabulary, and create a portal, fill it with assets and attach the contacts it is meant for. Adding files to the library is possible too, though uploads stay switched off unless your workspace has deliberately enabled them.

Anything destructive describes itself as destructive and instructs the assistant to check what it is about to affect and confirm with you first — deleting a folder takes its subfolders and their assets with it, and deleting a portal breaks a link recipients may still be holding. That instruction is a useful habit rather than a hard stop, which is the honest way to describe it: the guarantee is your permissions, not the wording of a tool description.

The sensible reading of this is to treat write access as something to grant deliberately. Someone who cannot restructure the library in the interface cannot restructure it through an assistant either, and that is the control worth relying on.

Images an Assistant Can Actually Display

A search that returns forty filenames is a poor answer to a question about which photograph to use. Asset lookups therefore return image URLs that need no credentials and work directly in a browser or chat window, so the client can show you the picture rather than describe it. The links expire after thirty minutes, which keeps a pasted URL from becoming permanent public access.

Each asset also reports whether a displayable image exists yet, distinguishing one that is ready from one still being generated and from a file type that never gets a preview. That small piece of honesty prevents the familiar failure where an assistant confidently offers a broken image.

MCP, the Virtual Assistant and AI Search

The platform has three capabilities that all sound like AI and do entirely different jobs:

They compose rather than compete. An assistant connected over MCP searching for "the wide shot of the harbour at dusk" is relying on AI Search to answer it.

Where to Start

Begin read-only, with one person, on the questions your team already repeats. Asset discovery for approved brand and campaign content is the usual first case, because the value is immediate and nothing can go wrong that a permission was not already going to prevent.

Expect the exercise to be an unusually frank audit of your metadata. An assistant can only answer from what has been recorded, and unlike a colleague it does not fill the gaps with charitable guessing. Fields nobody completes produce vague answers, and that shows up within an afternoon of real use.

Add write access once reading has proved useful, and add it to the people who already hold the equivalent permission in the interface. Starting narrow is not caution for its own sake — it is how you find out which tasks were actually worth automating before granting the access to automate them.

Availability

MCP connections rely on API tokens being enabled for your workspace and on your having permission to create one. If the approval screen refuses the connection, contact your administrator or Data Dwell support.

Related Articles

Start Free Today


Get free DAM

Information

+354 525 3535Bjargargata 1102 Reykjavikdatadwell@datadwell.com