Connect to Daphnis
This is the inbound MCP edge for an organization. Agents reach the organization's tools through it. Every call is policy-checked and recorded in a tamper-evident audit chain.
Connect
Your organization's exact URL comes from the dashboard's Connect page:
https://dashboard.daphnis.app/<org>/connect
An agent connects to:
https://connector.daphnis.app/<org>/mcp
Transport is Streamable HTTP (MCP). The server speaks initialize, tools, and resources.
Authenticate
OAuth 2.0. Discover the authorization server at:
/.well-known/oauth-protected-resource/<org>/mcp
Register a client dynamically at https://dashboard.daphnis.app/oauth/register, use PKCE, and approve in the browser while signed in at the dashboard. Automations with no browser use an agent key instead: a Bearer token minted in the dashboard. A request with no token gets 401 with a WWW-Authenticate header pointing at the metadata.
What you can do
32 tools in three families:
request— 7 tools (GET,POST,PUT,PATCH,DELETE,HEAD,OPTIONS). Call allowlistedhttpsorigins. Redirects are reported, never followed. Each method has its own policy grant.apps— 17 tools. List, read, and publish the pages you own. Publish a page larger than one call can carry in chunks, with per-file hashes and an abort. Inspect retained versions. Set tags. Set a page's MCP tool scope and requirements. Assign a control plane. Set the external asset policy. Read, add, and resolve internal review comments on one exact version.loops— 8 tools. Define and manage automations, and run them.modelslists the model ids an agentic step may name, as the org's policy and catalogue allow;listshows the ones you may see;readgives one's structure — ids, descriptions, tool names, grants — never its prompts or arguments;createdefines one (an administrator only);updatereplaces the parts you send, including the trigger — manual, a cron schedule, or a webhook (which returns its one-time token);deleteremoves one (an administrator only);trigger_asyncasks one to run and returns a run id;runreads that run by id — its status, and once it settles, its outcome and result. Poll with backoff.
Governance
A caller reaches only what the automation's own grants allow, checked on every call. Outbound calls go to allowlisted origins only. Refusals are recorded too.
Find your URL on the dashboard's Connect page. The same facts are machine-discoverable from the metadata paths above.