IFRC GO MCP Server
Read-only MCP server for IFRC GO data, secured with Microsoft Entra ID OAuth/JWT, exposing datasets as MCP tools with rate limiting and PII filtering.
README
IFRC GO MCP Server
Read-only MCP server for IFRC GO data, secured with Microsoft Entra ID OAuth/JWT.
What this server does
- Exposes some IFRC GO datasets as MCP tools.
- Enforces bearer-token auth with Entra JWT validation.
- Publishes OAuth metadata endpoints for MCP clients.
- Applies request rate limiting.
- Removes selected PII fields from responses before returning data.
- Adds GO frontend URLs to records so callers can open source pages directly.
Main tools
get_agent_instructions- Returns the full data model and querying guidance from
agent-instructions.md.
- Returns the full data model and querying guidance from
get_server_info- Returns runtime configuration and upstream connectivity status.
ifrcgo_meta- Returns live enum/choice metadata for entity fields via OPTIONS.
ifrcgo_read- Main read tool for list/detail access across IFRC GO entities.
ifrcgo_get_country_plan- Finds and summarizes the best available planning document for a country.
ifrcgo_download_document- Downloads authenticated IFRC GO documents and extracts text (including PDFs).
Supported entities (via ifrcgo_read)
- Reference:
region,country,district,disaster_type - Events and reports:
event,field-report,situation_report - Appeals:
appeal,appeal_document - Surge and deployments:
surge_alert,eru,eru_owner,personnel,partner_deployment - Projects:
project,emergency-project - DREF:
active-dref,completed-dref,dref-op-update,dref-final-report - Other:
flash-update,public-per-process-status,public-per-stats,ops-learning,public-local-units - Country detail:
country-plan,country-document,country-supporting-partner,delegation_office
See agent-instructions.md for field-level guidance and workflow examples.
Quick start (local)
1. Create and activate a virtual environment
Windows PowerShell:
python -m venv .venv
.\.venv\Scripts\Activate.ps1
2. Install dependencies
pip install -r requirements.txt
3. Configure environment variables
Set these in your shell, profile, or launch config before starting the server.
Required for auth-gated operation:
ENTRA_TENANT_IDENTRA_AUDIENCEENTRA_CLIENT_IDMCP_SERVER_URLSTATE_SIGNING_SECRET
IFRC GO upstream auth (choose one mode):
- Recommended auto-refresh mode:
IFRCGO_USERNAMEIFRCGO_PASSWORD
- Static token mode:
IFRCGO_API_TOKEN
Optional:
IFRCGO_API_BASE_URL(default:https://goadmin.ifrc.org/api/v2)ENTRA_REQUIRED_SCOPE(default:mcp.access)REQUIRED_GROUP_IDS(comma-separated)REQUIRED_APP_ROLES(comma-separated)MCP_RATE_LIMIT_REQUESTS(default:60)MCP_RATE_LIMIT_WINDOW_SECONDS(default:60)SCOPE_NAME(default:ifrcgo)HOST(default:0.0.0.0)PORT(default:8000)
4. Run the server
python server.py
Health endpoint:
GET /health
OAuth metadata endpoints:
GET /.well-known/oauth-protected-resourceGET /.well-known/oauth-authorization-serverGET /.well-known/oauth-authorization-server/mcp
OAuth helper endpoints:
GET /oauth/authorizeGET /oauth/callbackPOST /oauth/tokenPOST /register
MCP transport:
- Mounted at
/using streamable HTTP from FastMCP.
Testing
Run unit tests:
pytest tests -q -m "not smoke" --ignore=tests/smoke
Run smoke tests (live endpoint + valid token required):
$env:IFRCGO_MCP_URL = "https://<your-host>"
$env:MCP_TEST_TOKEN = "<entra-access-token>"
pytest tests/smoke -q -m smoke
Deployment (Azure Container Apps)
This repo includes an automated deploy script:
- Copy
local.settings.json.templatetolocal.settings.json. - Fill in required values (subscription, RG, ACR, Entra, IFRC GO credentials, etc.).
- Run:
bash infra/deploy.sh
What the script handles:
- Validates local settings.
- Runs non-smoke tests before deploy.
- Builds and pushes Docker image.
- Creates/updates Container App and secrets.
- Applies optional ingress IP allow-list.
- Performs health check and optional smoke tests.
Security and privacy notes
- All data tools are read-only.
- OAuth/JWT validation is enforced unless Entra settings are missing.
- If
REQUIRED_GROUP_IDSorREQUIRED_APP_ROLESare set, caller token must match at least one. - Selected PII fields are stripped from
personnelandprojectresults. - Keep
local.settings.jsonand credentials out of source control.
Repository layout
server.py: MCP server, auth middleware, tool definitions.ifrcgo_client.py: Async IFRC GO client, auth refresh, list/detail/options helpers, document parsing.agent-instructions.md: Data model and usage guidance surfaced to MCP agents.tests/: Unit and smoke tests.infra/deploy.sh: Azure deployment automation.scripts/: One-off data processing utilities and generated outputs.
Notes for MCP clients
- Start sessions by calling
get_agent_instructions. - Use
ifrcgo_metato resolve current enum values before filtering. - Use
ifrcgo_readwithlimitandoffsetfor paging. - Use detail mode with
resource_idwhen you need full single-record payloads.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.