MCP Server: Connecting AI Assistants to Your Library
The Model Context Protocol, usually shortened to MCP, is an open standard that lets an AI assistant call tools in another system instead of guessing at what that system contains. The platform runs an MCP server, so a client such as Claude or Cursor can search your library, read an asset's details and assemble a portal - acting as you, with your permissions, against the same API the interface itself uses. This article covers what an MCP connection is, how to set one up, what an assistant can and cannot do once connected, and how it differs from the Virtual Assistant built into the platform.
Why Connect an Assistant to the Library at All
An assistant with no access to your library can only work from whatever someone pasted into the conversation. Ask it which logo is current and it will either decline or invent an answer, because the question is not about the world, it is about your content.
The questions that waste the most time are exactly the ones a connected assistant can answer: which version of the product shot is approved, whether a video is cleared for external use, what was sent to a particular client in March, which assets are missing a campaign tag. None of those are hard questions. They are just questions whose answers live in a system the assistant cannot see.
The distinction that matters is not whether AI can reach your files but whether it reaches them under the same rules as everyone else. A connection that bypasses your permissions to be helpful has not saved anyone time; it has created a problem that surfaces later.
Connecting a Client
The server is reached at /mcp on your workspace address, and any MCP-capable client can be pointed at it. There is no key to copy, no application to register in advance, and nothing to configure on the platform side first.
Adding the connection in the client opens an approval screen in your browser, where you sign in as you normally would and confirm the connection. Approving it creates an ordinary API token, named for the connection and dated, which appears alongside your other tokens in settings. Revoking the token there ends the connection immediately.
Two details are worth knowing. The connection is per person rather than per workspace, so two colleagues connecting the same client each get their own view of the library. And a local process is available for editors and desktop tools that expect to launch a command rather than call a URL, which connects through the same approval step in the browser.
An Assistant Cannot Reach What You Cannot
Every request the assistant makes goes through the same API as the interface, authenticated as the person who approved the connection. There is no service account, no elevated access and no separate copy of the library for AI to read.
The practical consequence is that all the access control you have already configured applies without being restated:
- Folder permissions: folders you cannot open do not appear in results, and neither do the assets filed in them.
- Visibility levels: assets above your tier stay hidden inside folders you can otherwise see.
- Metadata field permissions: restricted fields are withheld from asset detail the same way they are withheld in the interface.
- Lifecycle state: embargoed and archived assets are filtered before ranking, not after, so an assistant never sees a title it cannot retrieve.
- Roles: an action you lack permission for fails for the assistant exactly as it would fail for you.
This is worth being precise about, because it is the first question any security review asks. Granting a contractor an AI client does not widen what they can see. It changes how they ask.
What It Can Find
Reading is where most of the value is, and the assistant has several ways in rather than one:
- Folders: browse the structure a level at a time, or fetch the whole hierarchy in one call to work out where something sits without walking the tree.
- Assets: list what is filed in a folder, or search across asset names, assigned metadata, tags and text extracted from documents.
- Everything else: a single search across accounts, contacts, portals, copyrights, leads and projects, for when a name could refer to a company, a person or a shared portal.
- Asset detail: metadata, the file versions behind an asset, and the technical capture data the file carries - camera, lens, exposure and GPS coordinates.
- People: who has access to the workspace, which is how a name in a request becomes the right user.
Search results arrive with aggregations describing the matches, so an assistant asked a broad question can report the shape of what it found rather than reciting the first twenty hits.
What It Can Change
A connection is not limited to reading. The assistant can also create folders and move them, edit an asset's name and description, manage the shared tag vocabulary, and create a portal, fill it with assets and attach the contacts it is meant for. Adding files to the library is possible too, though uploads stay switched off unless your workspace has deliberately enabled them.
Anything destructive describes itself as destructive and instructs the assistant to check what it is about to affect and confirm with you first - deleting a folder takes its subfolders and their assets with it, and deleting a portal breaks a link recipients may still be holding. That instruction is a useful habit rather than a hard stop, which is the honest way to describe it: the guarantee is your permissions, not the wording of a tool description.
The sensible reading of this is to treat write access as something to grant deliberately. Someone who cannot restructure the library in the interface cannot restructure it through an assistant either, and that is the control worth relying on.
Images an Assistant Can Actually Display
A search that returns forty filenames is a poor answer to a question about which photograph to use. Asset lookups therefore return image URLs that need no credentials and work directly in a browser or chat window, so the client can show you the picture rather than describe it. The links expire after thirty minutes, which keeps a pasted URL from becoming permanent public access.
Each asset also reports whether a displayable image exists yet, distinguishing one that is ready from one still being generated and from a file type that never gets a preview. That small piece of honesty prevents the familiar failure where an assistant confidently offers a broken image.
MCP, the Virtual Assistant and AI Search
The platform has three capabilities that all sound like AI and do entirely different jobs:
- An MCP connection brings your own AI client to the library. It searches, reads and, where permitted, changes things. Use it when you want to work on your content in a conversation.
- The Virtual Assistant is built into the platform and answers questions about using it, drawn from this documentation. It does not search your library.
- AI Search is not an assistant at all. It is how the ordinary search box understands what an asset depicts, so describing a photograph finds it.
They compose rather than compete. An assistant connected over MCP searching for "the wide shot of the harbour at dusk" is relying on AI Search to answer it.
Where to Start
Begin read-only, with one person, on the questions your team already repeats. Asset discovery for approved brand and campaign content is the usual first case, because the value is immediate and nothing can go wrong that a permission was not already going to prevent.
Expect the exercise to be an unusually frank audit of your metadata. An assistant can only answer from what has been recorded, and unlike a colleague it does not fill the gaps with charitable guessing. Fields nobody completes produce vague answers, and that shows up within an afternoon of real use.
Add write access once reading has proved useful, and add it to the people who already hold the equivalent permission in the interface. Starting narrow is not caution for its own sake - it is how you find out which tasks were actually worth automating before granting the access to automate them.
Availability
MCP connections rely on API tokens being enabled for your workspace and on your having permission to create one. If the approval screen refuses the connection, contact your administrator or Data Dwell support.