citation-mcp
Remote MCP server exposing the CounselStack citation engine as nine legal research tools, enabling read-only citation lookup, statute search, and case text retrieval through Claude.
README
citation-mcp
Remote MCP server exposing the CounselStack citation engine as nine legal research tools. This is a thin consumer of citation-api — it owns no data and no extraction logic; it speaks HTTP to the API and packages the proven citator tool layer (schemas, orchestration, honesty guards) in MCP form so any MCP client — Claude first — can drive the engine.
Claude (web/desktop/mobile) ──MCP (Streamable HTTP)──▶ citation-mcp ──HTTP──▶ citation-api ──▶ mirror-db
The nine tools
| Tool | What it does | citation-api endpoints |
|---|---|---|
citation_lookup |
Resolve one cite or bare case name → canonical authority + precedent footprint | /resolve (+ /mentions) |
find_statutes |
Topic → governing statute/reg sections (multi-phrasing FTS, merged + reranked) | /search-statutes |
citation_mentions |
The opinions citing ONE authority, with treatment snippets; the workhorse | /resolve + /mentions |
find_case_text |
Full-text boolean keyword search over opinion bodies | /search-cases |
find_cases |
Parenthetical proposition search (slim index, fallback) | /search-parentheticals |
grep_opinion |
Search/verify text INSIDE one authority: quotes, pin cites, keywords | /quote |
read_subsection |
One pinpoint provision of a statute/reg + breadcrumb | /subsection |
citation_read |
Full text of one authority (every opinion in a cluster, labeled) | /resolve + /read |
citation_check |
Scan a draft, resolve every distinct authority, report found/not-found | /scan + /resolve |
All nine are read-only over immutable reference data and are annotated as such
(readOnlyHint), with titles, for connector-directory readiness. Research
methodology (tool order, the statutes→mentions front door, treatment honesty
rules) ships in the server's instructions field.
Run it
npm install
cp .env.example .env # point CITATION_API_BASE_URL at a running citation-api
npm run dev # tsx watch, listens on :3300
# in another terminal:
npm run smoke # connect, list tools, verify all nine
SMOKE_LIVE=1 npm run smoke # also exercise citation_lookup against the live API
npm run build && npm start for production (compiles to dist/). The server
is stateless (fresh MCP server + transport per request, no sessions), so it
deploys as a plain web service and scales horizontally with no sticky routing.
GET /healthz for health checks.
Connecting it to Claude
Deploy behind HTTPS, then in Claude: Settings → Connectors → Add custom
connector, URL https://<your-host>/mcp. Authless V1 needs no credentials.
Requests from allowed browser origins (MCP_ALLOWED_ORIGINS, default
claude.ai + claude.com) and server-to-server requests (no Origin header) are
accepted; anything else is rejected 403.
Auth: authless now, OAuth-shaped already (Path C)
V1 runs authless (AUTH_MODE=none): no token required, and — by design —
no user identity, so no per-user metering. The OAuth 2.1 resource-server shape
is already in place so flipping auth on later is additive:
- Every
/mcprequest crossesauthMiddleware(src/auth/auth.ts) — the single boundary. Authless mode threads anullauth context into tool registration. AUTH_MODE=oauthactivates the RFC 9728 discovery handshake:401+WWW-Authenticate: Bearer resource_metadata=...and the/.well-known/oauth-protected-resourcedocument (404 while authless).verifyBearerTokenis a stub that always rejects — real validation (signature/expiry against the issuer, audience = this server per RFC 8707, subject + scopes extraction) lands when an authorization server exists. Do not enable oauth mode in production until then.- Outbound, every citation-api call carries
CITATION_API_TOKENas a Bearer when set — a no-op today, this server's API key when the API's key layer ships.
Layout
src/
index.ts Express app: origin validation, /healthz, well-known, stateless /mcp
config.ts env parsing (AUTH_MODE switch, cache knobs, origins)
http.ts HTTP client: result cache, 60s timeouts, __httpError sentinel
instructions.ts research methodology → MCP instructions field
api/client.ts one function per citation-api endpoint
orchestration/ the composites: lookup, mentions, read, check, grep, subsection, search
tools/index.ts the nine registrations (zod schemas, descriptions, annotations, handlers)
tools/format.ts result → model-facing text, incl. the honesty language
auth/auth.ts Path C skeleton: middleware, RFC 9728 metadata, stubbed verifier
scripts/smoke.ts MCP client: list tools, optional live call
Design notes worth knowing:
- Error honesty is a contract. Upstream failures surface as
__httpErrorsentinels and reach the model as "the engine failed — nothing was learned; treat as unverified, not as not-found." A failed scan chunk is counted and the check report says INCOMPLETE. A mentions filter that misses says "not in the top page", never "no case discusses this." - Result cache (10 min TTL / 500 entries, env-tunable): every endpoint is an idempotent read over immutable law, so identical calls skip the network. Per-instance; correct under horizontal scaling, just less shared.
- CFR mentions works here. The original agent integration had a gap where
CFR cites silently returned no mentions; the mapping in
orchestration/mentions.tsincludes the CFR branch.
Future work (deliberately out of scope for V1)
- CFR topic search tool — the API's
/cfr-searchexists but has no tool yet (an agent can topic-search statutes, not regulations). - OAuth authorization server + real token validation + per-user metering.
- Structured (
structuredContent) outputs alongside the text blocks.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.