DocuTray
MCP Server

Security, limits and data

How the DocuTray MCP server authorizes AI clients, how to revoke access, the limits that apply to each tool, and what happens to the documents you send.

Scopes

When a client connects, the consent screen lists the permissions it asks for. DocuTray defines two scopes for the MCP server, plus the standard OpenID Connect ones:

ScopeGrants
docutray:readRead the organization's document types, conversion and identification results, knowledge bases and usage, and validate data. Required for every tool.
docutray:convertStart conversions and identifications. These consume pages from the organization's monthly quota.
openid, profile, emailIdentify you to the client.
offline_accessLet the client renew its access without asking you to sign in again.

A connection without docutray:convert can still read everything above; when it tries to convert, the server answers 403 insufficient_scope so the client can ask you for the extra permission.

One organization per connection

You pick the organization on the consent screen, and it is written into the access token. The server takes the organization only from the token — never from tool arguments — so a client cannot read or process data of another organization, even one you also belong to. Your membership is checked on every request: if you leave the organization or are removed from it, the connection stops working.

To use the assistant with a different organization, connect again and pick it. Each connection appears separately in Connected apps.

Tokens

  • Access tokens are signed JWTs bound to the MCP server (aud = https://app.docutray.com/api/mcp) and expire after 15 minutes. A token issued for another service is rejected, and DocuTray never forwards your token to third parties.
  • Clients that requested offline_access also get a refresh token, rotated on every use, to renew access in the background.
  • API keys are not accepted on the MCP endpoint, and an MCP token does not work on the REST API.

Revoking access

  1. Sign in to app.docutray.com.
  2. Go to Settings → Account → Connected apps.
  3. Find the client and organization, and click Revoke.

Revoking deletes the client's consent and its refresh tokens for that organization, so it can no longer renew its access. An access token already in the client stays valid until it expires — at most 15 minutes. Connections of the same client to other organizations are not affected.

You can also remove the server from the client itself (for example, Settings → Connectors in Claude or claude mcp remove docutray in Claude Code), but that alone does not revoke the authorization on DocuTray's side.

Limits

LimitValue
Rate limitYour plan's per-minute request limit, shared with the REST API endpoint each tool maps to
Monthly quotaconvert_document and identify_document consume pages from your plan's monthly quota. Read-only tools keep working when the quota runs out
File size5 MB per file, sent as a URL or base64
File typesPDF, JPEG, PNG, GIF, BMP, TIFF and WebP
File URLsPublic http(s) URLs only. Private, internal and cloud-metadata addresses are rejected, including through redirects
Tool durationAbout 60 seconds per call. Longer conversions keep running and are checked with get_conversion_status
Result sizeField bounding boxes are omitted and very large results are truncated; the full result stays available through the REST API

For larger files, batch processing or webhooks, use the REST API, the SDKs or the CLI.

Your data

What DocuTray processes

Through the MCP server, DocuTray receives only what the assistant sends in a tool call: the document you ask it to process (or its URL), the document type to use, and the arguments of the call. It does not receive your conversation with the assistant. What the assistant does with the results is governed by the assistant provider's own terms.

Process only documents you are entitled to process. DocuTray is designed for business documents such as invoices, statements, purchase orders and contracts.

Retention

  • By default, the uploaded document and the extracted data are stored in your organization's conversion log so you and your team can review them in the DocuTray app.
  • With logs disabled for the organization, the document and the extracted data are not stored in the conversion log. They are kept only temporarily, as long as processing needs and for the client to fetch the result, and copies held by DocuTray's processing infrastructure follow its retention policies. Contact support@docutray.com to disable logs for your organization.

Usage metadata (which tool ran, when, for which organization and client, and how many pages it used) is always recorded for billing, security and support.

AI providers

DocuTray uses AI models from third-party providers (such as Google Gemini) under DocuTray's agreements with them, and sends them data only to process the request that needs it:

  • Documents: convert_document and identify_document send your document to the provider configured for the document type to extract or classify it.
  • Knowledge-base search queries: search_knowledge_base sends the text of your query to Google Gemini to compute its embedding, the vector DocuTray compares against your knowledge base. The search itself runs inside DocuTray.

Privacy policy

See the DocuTray Privacy Policy and Terms of Service for the full details, including your rights and how to request deletion of your data.

Reporting a security issue

Write to security@docutray.com. Please do not open a public issue.

On this page