MCP
What is MCP?
MCP (Model Context Protocol) is an open, standardized protocol that lets AI assistants and other agent-based clients call tools and read data from external services — in the same way REST APIs make it possible for ordinary programs to talk to a service. Communication happens via JSON-RPC over HTTP.
By connecting an MCP-compatible AI client to Brick's MCP server, you can ask your AI assistant to search for files, read and edit documents, organize folders, manage shares and more — directly in natural language, without having to click your way through Brick HQ.
What the client is allowed to do is governed by which so called scopes it has been granted: brick gives read access and brick:manage also gives the right to create, change and delete.
Available tools
Brick offers the following tools to your MCP-compatible AI client:
Files and folders
| Tool | Description |
|---|---|
list_folder | Lists the direct contents of a folder. Omit both path and node id to list the account root. |
get_metadata | Fetches metadata for a file or folder: size, MIME type, timestamps, version etag and path. |
read_file | Reads a line-numbered excerpt of a text file's contents (in the style of cat -n). |
write_file | Makes an exact search-and-replace edit to a text file's contents. |
replace_file | Overwrites an entire file's contents. Lands as a new version — the previous contents can still be restored via list_file_revisions / restore_file_revision. |
create_file | Creates a new text file with the given contents. |
create_folder | Creates a new folder. |
delete | Moves a file or folder to the trash (soft delete). |
copy | Copies a file or folder to the same or another folder; the original is left untouched. |
move | Renames and/or moves a file or folder. |
get_download_link | Creates a short-lived link for downloading a file's current contents without further authentication. |
Search
| Tool | Description |
|---|---|
search | Searches for files and folders by name across the whole account. |
list_recent | Lists recently updated files across the whole account. |
list_largest | Lists the largest files in the account, largest first — handy for finding what can be cleaned out. |
Trash
| Tool | Description |
|---|---|
list_trash | Lists items currently in the trash, most recently deleted first. |
restore_from_trash | Restores a deleted file or folder (and, for a folder, everything beneath it) to an active location again. |
empty_trash | Permanently deletes every item in the trash that the caller is allowed to modify. Cannot be undone. |
Version history
| Tool | Description |
|---|---|
list_file_revisions | Lists a file's version history, most recent first. |
restore_file_revision | Makes an older version of a file the active one again. |
Sharing
| Tool | Description |
|---|---|
create_shared_link | Creates a public link to a file or folder. Anyone with the link can access it (read-only by default) without an account of their own. |
share_with_user | Shares a file or folder directly with another member of the account. |
list_shared_links | Lists public shared links created by the caller, optionally limited to a particular file or folder. |
get_shared_link_metadata | Fetches details about a shared link: recipients, expiry date and which file/folder it points to. |
list_incoming_share_senders | Lists the account members who have shared something with the caller, one entry per person with a count of shared items. |
list_incoming_shares | Lists what a specific account member has shared with the caller. |
Account
| Tool | Description |
|---|---|
who_am_i | Reports the caller's own identity and access: account id, user id, email and granted scopes. |
get_usage_and_quota | Fetches storage usage and quota for the account, plus a breakdown of the caller's own usage per media type. |
get_activity_log | Fetches the account's audit log of file and account events. |
Connecting to Brick's MCP server
Brick's MCP server is reached at https://api.brick.wbite.net/v1/mcp and is authenticated with OAuth2/OIDC. For your MCP client to be able to log in and get an access token, you first need to register it as an OIDC client on the account in Account HQ.
Here's how you create an OIDC client for your MCP client:
- Log in to Account HQ.
- Click the profile icon in the top right to open the profile menu.
- Under the heading Account in the menu, click OIDC Clients.
- Click the button to add a new client.
- Fill in the form:
- Give the client a name, e.g. the name of your AI client.
- Under Client type, choose Public — MCP clients use the Code flow with PKCE and need no client secret.
- Under Account mode, choose Single-mode.
This matters: an access token from Brick's MCP server is always tied to a single account, so the client must force an account choice at login instead of giving access to all your accounts at once. - Under Redirect URIs, enter the redirect URI that your MCP client shows you during its own connection process. It has to match exactly, otherwise the login is denied.
- Under Scopes, tick
accounts,brickandbrick:manage. These three cover everything the MCP server offers above —accountsfor account information,brickfor read access andbrick:manageto also be able to create, change and delete.
- Click the Create client button.
- Copy the Client ID that is shown and paste it into your MCP client's settings together with the server address
https://api.brick.wbite.net/v1/mcp. Since the client is of the Public type, no client secret is shown — nor is one needed.
When you then connect in your MCP client, you are sent to Account HQ to log in and approve the access, just like with a regular OAuth2 login.