Saphan

MCP — ask the record where you already chat.

Saphan Studio serves the record over MCP — the open protocol your chat clients already speak. Fleet state, gates awaiting you, spend by any axis: answered in plain language, from the client you have open anyway.

What it is

01

Read-only, by construction

The MCP surface is a client of the engine like every other — named projections of the same record, never a second writer. Nothing you can type into a chat can change fleet state, approve a gate, or dispatch work. Asking is free; acting still goes through the engine’s own doors.

02

The questions it answers

What is running right now. Which gates await you, with what evidence. What this stream cost against its quote. Spend by person, by model, by project, by billing class — the axes compose, so a question nobody pre-built a report for still gets an answer, because every answer is a projection of the same record.

03

Behind standard OAuth

The front door is standard OAuth 2.1 / OIDC. Team authenticates through the Saphan-operated saphan-oauth SaaS. Enterprise uses customer-run saphan-oauth or any customer-local identity provider behind a human-gated issuer trust list. Fail-closed: an identity without an explicit grant reads zero rows, and a token cannot widen its own slice of the data.

04

Every access logged

Reads leave a trail too: an audit-grade access log on every request, with refusals logged as what they are. The log carries who asked and what surface answered — never the values that were served. Access to the record is itself part of the record’s story.

Runs against your own self-hosted engine — the MCP surface adds no new place your data goes; it is a window, not a channel out.

More of Saphan Studio

Design partner inquiries

Contact us — hello@saphan.ai