Security, limits and data
How the DocuTray MCP server authorizes AI clients, how to revoke access, the limits that apply to each tool, and what happens to the documents you send.
Scopes
When a client connects, the consent screen lists the permissions it asks for. DocuTray defines two scopes for the MCP server, plus the standard OpenID Connect ones:
| Scope | Grants |
|---|---|
docutray:read | Read the organization's document types, conversion and identification results, knowledge bases and usage, and validate data. Required for every tool. |
docutray:convert | Start conversions and identifications. These consume pages from the organization's monthly quota. |
openid, profile, email | Identify you to the client. |
offline_access | Let the client renew its access without asking you to sign in again. |
A connection without docutray:convert can still read everything above; when
it tries to convert, the server answers 403 insufficient_scope so the client
can ask you for the extra permission.
One organization per connection
You pick the organization on the consent screen, and it is written into the access token. The server takes the organization only from the token — never from tool arguments — so a client cannot read or process data of another organization, even one you also belong to. Your membership is checked on every request: if you leave the organization or are removed from it, the connection stops working.
To use the assistant with a different organization, connect again and pick it. Each connection appears separately in Connected apps.
Tokens
- Access tokens are signed JWTs bound to the MCP server
(
aud = https://app.docutray.com/api/mcp) and expire after 15 minutes. A token issued for another service is rejected, and DocuTray never forwards your token to third parties. - Clients that requested
offline_accessalso get a refresh token, rotated on every use, to renew access in the background. - API keys are not accepted on the MCP endpoint, and an MCP token does not work on the REST API.
Revoking access
- Sign in to app.docutray.com.
- Go to Settings → Account → Connected apps.
- Find the client and organization, and click Revoke.
Revoking deletes the client's consent and its refresh tokens for that organization, so it can no longer renew its access. An access token already in the client stays valid until it expires — at most 15 minutes. Connections of the same client to other organizations are not affected.
You can also remove the server from the client itself (for example, Settings →
Connectors in Claude or claude mcp remove docutray in Claude Code), but
that alone does not revoke the authorization on DocuTray's side.
Limits
| Limit | Value |
|---|---|
| Rate limit | Your plan's per-minute request limit, shared with the REST API endpoint each tool maps to |
| Monthly quota | convert_document and identify_document consume pages from your plan's monthly quota. Read-only tools keep working when the quota runs out |
| File size | 5 MB per file, sent as a URL or base64 |
| File types | PDF, JPEG, PNG, GIF, BMP, TIFF and WebP |
| File URLs | Public http(s) URLs only. Private, internal and cloud-metadata addresses are rejected, including through redirects |
| Tool duration | About 60 seconds per call. Longer conversions keep running and are checked with get_conversion_status |
| Result size | Field bounding boxes are omitted and very large results are truncated; the full result stays available through the REST API |
For larger files, batch processing or webhooks, use the REST API, the SDKs or the CLI.
Your data
What DocuTray processes
Through the MCP server, DocuTray receives only what the assistant sends in a tool call: the document you ask it to process (or its URL), the document type to use, and the arguments of the call. It does not receive your conversation with the assistant. What the assistant does with the results is governed by the assistant provider's own terms.
Process only documents you are entitled to process. DocuTray is designed for business documents such as invoices, statements, purchase orders and contracts.
Retention
- By default, the uploaded document and the extracted data are stored in your organization's conversion log so you and your team can review them in the DocuTray app.
- With logs disabled for the organization, the document and the extracted data are not stored in the conversion log. They are kept only temporarily, as long as processing needs and for the client to fetch the result, and copies held by DocuTray's processing infrastructure follow its retention policies. Contact support@docutray.com to disable logs for your organization.
Usage metadata (which tool ran, when, for which organization and client, and how many pages it used) is always recorded for billing, security and support.
AI providers
DocuTray uses AI models from third-party providers (such as Google Gemini) under DocuTray's agreements with them, and sends them data only to process the request that needs it:
- Documents:
convert_documentandidentify_documentsend your document to the provider configured for the document type to extract or classify it. - Knowledge-base search queries:
search_knowledge_basesends the text of your query to Google Gemini to compute its embedding, the vector DocuTray compares against your knowledge base. The search itself runs inside DocuTray.
Privacy policy
See the DocuTray Privacy Policy and Terms of Service for the full details, including your rights and how to request deletion of your data.
Reporting a security issue
Write to security@docutray.com. Please do not open a public issue.