⚡ OCO AI Signals FastMCP Gateway
Staging Cluster Online

FastMCP Integration Reference

Direct, high-conviction FDI & Corporate Expansion Intelligence for Autonomous AI Agents

🌐 Gateway Endpoints & Connectivity

The OCO FastMCP Gateway exposes our verified 1.77M+ signal Data Lake using the Model Context Protocol (MCP 2024-11-05) over Streamable HTTP and REST fallbacks.

Method Endpoint Path Protocol / Target Authentication
POST /mcp Streamable HTTP / SSE (JSON-RPC 2.0) Bearer JWT
GET /v1/signals/search OpenAPI REST Fallback Bearer JWT
POST /v1/auth/token Automated Self-Service Token Refresh Public Staging
GET /health Liveness & PostgreSQL Status Probe Public

🔑 Authentication & Bearer JWT Token Lifecycle

All tool calls require an Authorization: Bearer <token> header. Tokens enforce tenant isolation and scope boundaries.

1. Pre-generated 30-Day Staging Token (Frankfurt Pilot)

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhZ2VudC1pbm5vbG9mdCIsInRlbmFudCI6Imlubm9sb2Z0IiwiZW50aXRsZW1lbnQiOiJlbnRlcnByaXNlX3RyaWFsIiwic2NvcGUiOiJmcmFua2Z1cnRfcGlsb3QiLCJpYXQiOjE3OTA2ODk0MzgsImV4cCI6MTc5MzI4MTQzOCwiaXNzIjoiaHR0cHM6Ly9zdGFnaW5nLW1jcC5vY29jb25uZWN0LmNvbSIsImF1ZCI6Imh0dHBzOi8vbG9mdG9zLmNvbSJ9.PKLjC2a4Z4TuVDPLhyBAGd3MBtmMm2ifwYRBzb4ZTsw

2. Automated Self-Service Token Refresh Endpoint

When a token expires, subagents can request a fresh 30-day token programmatically without human intervention:

curl -X POST "https://staging-mcp.ococonnect.com/v1/auth/token?tenant=innoloft&scope=frankfurt_pilot"

3. Client-Side JWT Minting (HMAC-SHA256)

If you prefer to mint tokens inside your own backend microservices:

Claim Value Description
algHS256HMAC with SHA-256 (Secret: staging_inno_secret_key_2026_change_in_prod)
subagent-innoloftSubagent identifier
tenantinnoloftTenant isolation partition
scopefrankfurt_pilotAuthorized geographic / project dataset
isshttps://staging-mcp.ococonnect.comIssuer identifier
audhttps://loftos.comTarget audience
expUnix TimestampExpiration time (strictly greater than current time)

🛠️ Canonical Tool: search_signals

Conforms to Anthropic CCAR-F Domain 2 standards with 6 orthogonal parameters. Zero matches return a clean 200 OK with total: 0 and signals: [] to prevent agent crashes.

query *
string • required
Natural language keywords, company names, or investment themes (e.g. data center, semiconductor, logistics hub).
target_market
string • optional
Geographic territory filter (e.g. Germany, Hesse, Frankfurt).
sector
string • optional
Industry taxonomy (e.g. IT & Software, Automotive, Renewable Energy).
lookback_days
integer • optional
Temporal lookback filter (e.g. 30, 90, 180 days).
min_confidence
float • default: 0.65
Confidence score floor between 0.0 and 1.0.
limit
integer • default: 5 (max: 50)
Maximum number of verified signals to return.

💻 Integration Examples

A. Streamable HTTP / SSE Invocations (cURL)

curl -X POST https://staging-mcp.ococonnect.com/mcp \
  -H "Authorization: Bearer <YOUR_JWT_TOKEN>" \
  -H "Accept: application/json, text/event-stream" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "tools/call",
    "params": {
      "name": "search_signals",
      "arguments": {
        "query": "data center",
        "target_market": "Germany",
        "limit": 3
      }
    },
    "id": 1
  }'

B. Claude Desktop Configuration (claude_desktop_config.json)

{
  "mcpServers": {
    "oco-ai-signals": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-streamable-http",
        "https://staging-mcp.ococonnect.com/mcp"
      ],
      "env": {
        "MCP_HEADERS": "{\"Authorization\": \"Bearer <YOUR_JWT_TOKEN>\"}"
      }
    }
  }
}

C. REST API Fallback Query (Direct HTTP GET)

curl "https://staging-mcp.ococonnect.com/v1/signals/search?query=data+center&target_market=Germany&limit=2" \
  -H "Authorization: Bearer <YOUR_JWT_TOKEN>"