IDCanopy Developers
Aletheia

MCP server

Drive Aletheia from an AI agent over the Model Context Protocol

Aletheia ships an MCP (Model Context Protocol) server so an AI agent can score applicant documents for fraud, pull back auditable findings, and generate PDF reports through typed tool calls. The server runs locally over stdio and talks to your Aletheia instance over HTTPS using a bearer token.

The verdict itself stays deterministic and rule-based, the agent only orchestrates the calls; it never decides the verdict.

Install

pip install idcanopy-aletheia-mcp

Configure

VariableValue
FORENSIC_API_TOKENYour bearer token (from onboarding). Env only, never commit it.
FORENSIC_API_BASE_URLSee Environments

Point your MCP-capable client's config at the idcanopy-aletheia-mcp command with those two environment variables set.

Tools

ToolWhat it does
analyze_documentsOne-shot, stateless analysis of document files, returns verdict and findings
create_applicantCreate a persistent applicant record
upload_documentsAttach documents to an applicant
get_applicant_resultAnalyze an applicant's stored documents and return the result
get_findingsRe-read a stored result without re-analyzing
analyze_batchSubmit an async batch job over many applicants
get_batch_statusPoll a batch job
get_reportGenerate the branded PDF report to a local file

analyze_documents and get_applicant_result emit progress notifications on long (60s+) multi-document calls when the client supplies a progress token.

Authentication

The bearer token is read from FORENSIC_API_TOKEN only. It is never logged, echoed, or returned by any tool, and is never accepted as a tool argument. Outbound result webhooks are HMAC-signed - see Webhooks before trusting any callback.

Error handling

Every HTTP failure is mapped onto the public error contract and surfaced as a structured error map, never a raw HTTP or HTML body: 4xx/5xx follow the ProblemDetails shape (detail, plus trace_id on stateless /analyze 5xx responses); 429 follows RateLimitError (code: "rate_limit_exceeded" plus retry_after seconds).

On this page