TemplateMaster has deployed a Model Context Protocol (MCP) server at https://mcp.templatemaster.fr/mcp, enabling any MCP-compatible agent to execute document generation and email sending tasks. This move bridges the gap between AI assistants and business-critical document workflows, allowing prompts like "Generate invoice INV-10023 for John Doe" to trigger complex, multi-step operations under the same security rules as the existing REST API. The server supports Streamable HTTP transport and requires authentication via the X-API-KEY header, strictly rejecting Bearer tokens for API key authentication to prevent configuration errors.

Permission Architecture and Least Privilege

The platform enforces a granular permission model where each API key must explicitly enable MCP capabilities, which are disabled by default. Agents can be granted specific scopes such as mcp.templates.read, mcp.documents.generate, and the sensitive mcp.emails.send, but they are strictly prohibited from performing deletions. This design ensures that an agent cannot accidentally wipe data, and developers are advised to create dedicated keys for each agent instance, granting email sending permissions only when absolutely necessary to mitigate the risk of unauthorized external communications.

Asynchronous Tool Execution and Data Isolation

Document generation and email sending are asynchronous operations that return identifiers immediately, requiring agents to poll endpoints like get_document or get_email_status for completion. The system maintains strict per-organization data isolation, ensuring that an agent acting on one organization's key cannot access or leak resources from another, even through error message analysis. Download links for generated PDFs are short-lived, lasting approximately 60 seconds, which forces agents to retrieve fresh URLs if delays occur during the generation process.

Key Takeaways

  • MCP access is disabled by default and must be explicitly enabled per API key in settings.
  • Authentication requires the X-API-KEY header; using Authorization: Bearer for API keys results in a 401 error.
  • Agents cannot delete resources, limiting potential damage from hallucinations or malicious prompts.
  • The send_email tool is flagged as sensitive and counts toward separate email quotas.
  • Error handling uses stable codes like TEMPLATE_NOT_FOUND or QUOTA_EXCEEDED for reliable agent logic.

The Bottom Line

This is a pragmatic step toward making AI agents production-ready for business ops. By locking down deletions and enforcing strict quotas, TemplateMaster avoids the classic 'agent goes rogue' scenario while still delivering the automation payoff developers want.