---
title: "MCP Server in a SaaS – Secure AI Access in Practice — Blackbook"
description: "How we built an MCP server into Valiyou: OAuth 2.1, 17 consolidated tools and server-side permission enforcement. A technical walkthrough."
canonical_url: https://www.blackbook.dk/en/journal/mcp-server-in-valiyou/
md_url: https://www.blackbook.dk/en/journal/mcp-server-in-valiyou/index.md
language: en
last_updated: 2026-10-05
---

# MCP Server in a SaaS – Secure AI Access in Practice — Blackbook

How we built an MCP server into Valiyou: OAuth 2.1, 17 consolidated tools and server-side permission enforcement. A technical walkthrough.

> Alternate (Danish): https://www.blackbook.dk/journal/mcp-server-i-valiyou/index.md
> Author: Jeppe Sloth Carlsen — Senior Product Designer & Creative Technologist (https://www.blackbook.dk/en/about/)
> Author ID: https://www.blackbook.dk/#person-jeppe
> Publisher ID: https://www.blackbook.dk/#organization
> Topics: MCP server, Model Context Protocol, AI integration, SaaS security
> Part of: Blackbook — digital design agency, Copenhagen (https://www.blackbook.dk/en/)
> Published: 2026-10-05
> LLM reference: https://www.blackbook.dk/llms.txt
> Full reference: https://www.blackbook.dk/llms-full.txt
> Markdown sitemap: https://www.blackbook.dk/sitemap.md
> Preferred citation URL: https://www.blackbook.dk/en/journal/mcp-server-in-valiyou/

## Journal — How We Built an MCP Server into Valiyou

- Valiyou dashboard with sponsorship valuation, media breakdown and brand metrics – the system the AI can now work in

Model Context Protocol (MCP) is the open standard that lets AI assistants like Claude and ChatGPT work directly inside third-party systems. We built it into Valiyou – the sponsorship and valuation platform we designed and developed. The result: a user can say “import this sponsor report and create a draft valuation” – and the AI does it, in the user's own system, with the user's own permissions.

The challenge is never making it work. The challenge is making it work without the AI being able to do more than the user can in the web app – and without losing a single byte of traceability along the way.

## One endpoint, OAuth 2.1, stateless

The entire MCP server is exposed on a single endpoint. Authentication uses OAuth 2.1 – the MCP profile from the 2025 spec – built on the platform's existing auth layer: no separate API keys, no new user database. The client (Claude, ChatGPT, Cursor) completes a standard OAuth flow, and every request carries a token the server verifies. The server is stateless – no session state between calls – which suits serverless hosting.

## 17 tools – not 130

The platform's REST API has 130 endpoints. Mirroring them 1:1 as MCP tools would be a mistake: every tool definition costs space in the AI's context, and 130 options make the model worse, not better. We consolidated down to 17 high-signal tools – for example one package tool with actions like create, update and send proposal, instead of four separate ones. Every input and output field carries its own description, so the AI understands the domain without external documentation.

- Valuation trends over time with sales, media value and quality multiplier – data the AI can pull through analytics tools

## The security model: assume the AI is jailbroken

The most important design principle: guidance is UX – enforcement is server-side. We send instructions to the AI client (“confirm before deleting”), but we never trust them. A manipulated client can ignore any instruction. So every boundary lives on the server:

Transport-level scopes: tokens are issued with granular scopes for valuations, partnerships, documents and analytics. A read-only token physically cannot call write tools.

Per-call permission checks: every tool call looks up the user's membership and role in the database and runs them through the exact same permission engine as the web UI – 23 granular permissions. If the user can't see the Organization page on the web, the AI doesn't get address and tax data through MCP either. Fields are removed server-side, not in the prompt.

Opt-in for destructive actions: deletion and sending proposals require the organisation to explicitly enable it for MCP. Without the toggle: hard error, regardless of what the AI “decides”. Demo organisations are entirely invisible to MCP, and settings are read-only by design – the AI can read label aliases, locale and currency, but no tool can write to configuration, API keys or billing.

- Valuation details with a sankey visualisation of sponsorship components – the kind of draft the AI can create from a report

## The audit trail: every mutation leaves evidence – human or AI

This is where most AI integrations cut corners. All MCP mutations go through the same service functions as the web app – there is no “MCP shortcut” into the database, so the audit layer was inherited, not duplicated. Every row in the log records who, what, which fields changed – and how: a source field distinguishes web, mcp and api_key. An administrator can always answer the question “did a human click this, or did an AI do it?”

We log field-level diffs rather than full row copies – only what actually changed, with old and new values. That also powers restore: an admin can revert a change directly from the audit page, and the revert itself is logged too. Secrets never reach the log – a sanitizer redacts fields like password, token and secret, by construction rather than by convention.

We also audited our own auditing: all ~181 mutation handlers were cross-referenced against the audit call sites, and the six configuration and billing mutations that left no trace now do. One deliberate trade-off, stated honestly: if the audit write fails, the customer action still succeeds – a documented choice, not an accident.

## The underrated problem: the guidance budget

MCP servers can send instructions to the client at connect – but Claude Code, for instance, truncates them around 2 KB, and the most important part has to fit in the first ~512 characters. The server's instructions are therefore maintained under a hard byte budget, with workflow, rules and examples compressed to their essence: always fetch context first, use the organisation's own terminology, never approve a valuation without explicit confirmation. For clients that ignore server instructions, we maintain a parallel, verbose version for copy-paste – both generated from the same source file, so they never drift apart.

## The result

A user can now connect Claude or ChatGPT to Valiyou and import a report that becomes a draft valuation with extracted metrics and CPM rates. Register a sponsorship contract with sponsor, package, price and period. Manage inventory, documents and folders. Pull analytics: revenue trend, pipeline and top sponsors. All with the user's login, the user's permissions, the organisation's opt-ins and a full audit trail.

The AI is a new client on top of the platform. Not a backdoor into it.

Want to see the platform behind it? See the [Valiyou case](https://www.blackbook.dk/en/portfolio/valiyou-io/) in the portfolio.

Want to try the integration? The guide lives at [docs.valiyou.com/platform/mcp](https://docs.valiyou.com/platform/mcp).

## More

- [Journal](https://www.blackbook.dk/en/journal/)

## About Blackbook

Blackbook is a Copenhagen digital agency blending creativity and technology across UX, branding, websites and eCommerce.

Areas of expertise:

- [Apps & Products](https://www.blackbook.dk/en/area/apps-products/index.md)
- [Brand & Campaigns](https://www.blackbook.dk/en/area/brand-campaigns/index.md)
- [Websites & eCommerce](https://www.blackbook.dk/en/area/websites-ecommerce/index.md)

Key figures:

- 250+ Digital projects
- 150+ Clients
- 15+ Fortune 500
- 5+ Top 100 Brands
- 25+ Years experience

## Site

[Home](https://www.blackbook.dk/en/index.md)
[Portfolio](https://www.blackbook.dk/en/portfolio/index.md)
[About](https://www.blackbook.dk/en/about/index.md)
[Services](https://www.blackbook.dk/en/services/index.md)
[Experience](https://www.blackbook.dk/en/experience/index.md)
[Recognition](https://www.blackbook.dk/en/awards/index.md)
[Contact](https://www.blackbook.dk/en/contact/index.md)
[CV](https://www.blackbook.dk/en/cv/index.md)
[Journal](https://www.blackbook.dk/en/journal/index.md)

Blackbook · Jerichausgade 7 · 1777 Copenhagen · (+45) 31 10 79 13 · [jeppe@blackbook.dk](mailto:jeppe@blackbook.dk)
