Kiteworks MCP

Kiteworks MCP Server Overview

The Kiteworks MCP Server is a Model Context Protocol (MCP) server that gives AI assistants governed access to Kiteworks files, folders, forms, and user data. Every AI-initiated operation is authenticated with OAuth 2.1, encrypted with TLS 1.3, and logged to a tamper-evident audit trail — keeping your enterprise security and compliance requirements intact.

Innovators in AI
Join the Innovators in AI program — Full MCP access included for all members

Unlimited agent workflows, policy controls, and audit telemetry at no additional cost for the first 6 months. Kiteworks admins can activate it through the admin console.

MCP Tool Taxonomy

What each MCP tool is actually for — sorted by what an agent does with data, not by tool family. Three planes: one moves data, one moves pointers and permissions, one only reads the record of what happened.

These planes are a lens for writing policy, not a full inventory. For every tool the server exposes, grouped by tool family with a description of each, see Available Tools.

Compliant AI

The agent reads, writes, and sends data.

Data plane
Data in
read_file_contents download_file_to_path Text reads inline; Office and PDF go through a local parser.
Data out
create_file_from_content
Retrieval and routing
search search_files search_folders get_folder_children get_top_folders get_file_metadata
Governed send and intake
compose_email send_email request_file_to_folder create_form list_mail get_mail

Kiteworks Operations

Pointers, permissions, and accounts. No data moves at all.

Control plane
File and folder lifecycle
rename_file move_file copy_file delete_file create_folder rename_folder move_folder delete_folder
Access and identity
manage_members find_user_by_email search_users_ldap
Account admin
create_user update_user reset_user_totp search_users get_user_metadata Plus mailbox and profile administration.
Policy config
create_tag Risk-policy writes are gated behind an admin grant.

Kiteworks Insights

Read-only visibility. Proves what happened, including what the agent did.

Audit plane
Audit trail
get_user_activity get_admin_activity
Policy visibility
get_risk_policies
Diagnostics
get_profile_eligibility get_mail_counters

The thinnest of the three. Two activity-log tools carry the whole agent audit story, and get_risk_policies doubles as a pre-flight check on the data plane.

Before you map tools to policy

Three things the categories above don't tell you on their own.

Runtime dependent
File reads and writes are built in for Claude Code and Cowork. Claude Chat needs the Filesystem connector enabled first.
Flips by intent
search_files move_file list_members Land in a different plane depending on why the agent calls them — policy follows intent, not tool name.
Two steps for binaries
PDF, Word, Excel, and PowerPoint can't be read inline — download them locally first, then parse.

Capabilities

The MCP Server exposes these groups of tools to connected LLM applications. Every tool is capped by the API scopes granted to the fixed MCP application and by the signed-in user's own Kiteworks permissions — see the API scopes for what to enable.

File Management
  • Upload and download files
  • Read file text into context, or create a file from it
  • Retrieve file metadata
  • Rename, move, copy, and delete files
  • Operate on single files or batches
Folder Operations
  • Navigate folder hierarchies
  • Create, rename, move, and delete folders
  • Search by name or content with filtering
  • Request files by email invitation to a folder
  • Operate on single folders or batches
Forms & Search
  • Generate Kiteworks Forms from templates
  • Return preview links for generated forms
  • Search files and folders by name or content
Sharing & Permissions
  • List folder and file members with their roles
  • See how each member's access was granted
  • Add, update, and remove members — every change confirmation-gated
Secure Email
  • List and read messages with filtering
  • Read mailbox counters and scan status
  • Draft server-side and validate against policy
  • Send exactly what was validated, on confirmation
Administration
  • Search, create, and update users; reset TOTP enrollment
  • Manage user profiles, test mapping rules, bulk-assign
  • Manage shared mailboxes and their members
  • Query user and admin activity logs
  • Create security tags for DLP policy conditions
  • Retrieve risk policies (read-only)
Administration tools require an administrator account, and the move and delete tools are not registered at all unless the server is started with --enable-destructive-tools. Deletions, member changes, and sending mail each require explicit confirmation. The full catalogue with parameters is in Available MCP Tools ↗.

Deployment Modes

The MCP Server ships in three deployment configurations to match different integration scenarios and user scales. Choose the mode that fits your environment:

Local STDIO Server

Single-user deployment running locally via standard input/output. Supports direct file upload and download from the local machine. Native binaries available for Windows, Linux, and macOS.

Best for: Individual developers and personal workflows.

Remote HTTPS Server

Centralized multi-user server with OAuth 2.1 authentication, deployable as a Docker container or systemd service. Supports concurrent users with per-user and per-session rate limiting. Browser-based AI platforms connect over this endpoint — see Microsoft Copilot Studio and ServiceNow AI Agent Studio.

Best for: Teams and enterprise deployments where multiple users share a single server.

Claude Desktop Connector

Available directly in the Claude Desktop connector marketplace — install it in a few clicks, no binary download or upload required. Provides a zero-configuration path to connecting Kiteworks with Claude.

Best for: Claude Desktop users who want a guided, one-click setup experience. See Claude Desktop Connector for setup steps.

Security Model

The Kiteworks MCP Server is built for regulated environments where data governance is non-negotiable. Its security model operates across three layers:

Authentication

The Remote HTTPS Server uses OAuth 2.1 with Dynamic Client Registration, Authorization Code flow with PKCE, and JWT access and refresh tokens. Tokens are automatically refreshed, so long-running sessions stay authenticated without user intervention.

Encryption & FIPS Compliance

When FIPS 140-3 mode is enabled, all cryptographic operations use approved algorithms:

RequirementImplementation
Data encryptionAES-256-GCM
SignaturesRSA with SHA-256
Transport securityTLS 1.3 with NIST-approved curves
Key exchangeHybrid X25519 + ML-KEM-768 (FIPS 203) for quantum-resistant forward secrecy

Rate Limiting

Configurable rate limits can be applied at three levels independently: globally across all traffic, per authenticated user, and per active session. This allows fine-grained control over how AI applications consume Kiteworks resources.

Scopes & Least Privilege

Kiteworks MCP is governed by a single fixed OAuth application whose API scope grant sets the ceiling for every connected AI client. Within that ceiling, each call is still bounded by the signed-in user's own roles, profiles, and folder permissions, so an agent never reaches further than the person it acts for. Nine scope entities cover the entire released tool set — granting more widens the blast radius of a mistake without adding capability.

API scopes → the exact toggles to set, in the order the Admin Portal displays them.

Governed AI Use Cases

The Kiteworks Agent Marketplace offers a catalog of ready-to-use, policy-governed agents built on the MCP Server. Each one automates a complex workflow while keeping every interaction with sensitive data compliant and governed. Browse the catalog and add the agents that fit your environment.

Kiteworks Agent Marketplace

Explore the catalog to see each agent's purpose, governance controls, and requirements, then add the ones you need. Agents run against the files already in your Kiteworks, under your own account and audit trail. Claude is supported today; ChatGPT, Gemini, and Microsoft Copilot are not supported yet.

Browse the Agent Marketplace →

Frequently Asked Questions

What is the Kiteworks MCP Server?

The Kiteworks MCP Server is a Model Context Protocol server that exposes Kiteworks file management, folder operations, forms, and search capabilities as tools to AI clients such as Claude. It acts as a secure bridge between AI workflows and your Kiteworks instance, enforcing all access policies and generating audit trails for every operation.

How does the Kiteworks MCP Server differ from the REST API?

The REST API is a standard HTTP interface for programmatic integration. The MCP Server wraps a subset of that API as structured tools that AI models can discover and call in natural-language workflows. MCP is designed for human-in-the-loop AI use cases, while the REST API suits fully automated code integrations.

Is it safe to connect an AI model to Kiteworks through MCP?

Yes. The Kiteworks MCP Server enforces OAuth 2.1 authentication, respects all existing Kiteworks access control policies, encrypts data in transit with TLS 1.3, and generates tamper-evident audit trails for every AI-initiated operation. No action can bypass the governance layer.

What deployment modes does the Kiteworks MCP Server support?

The Kiteworks MCP Server supports three deployment modes: Local STDIO (for Claude Code and VS Code), the Claude Desktop Connector (installed from the marketplace), and Remote HTTPS (for shared or production environments). Choose the mode that matches how your team uses AI tools.

How is AI agent access governed?

Agent access can be governed with both ABAC and RBAC — using the Kiteworks Data Policy engine together with the user permission model. Every AI-initiated action is subject to the same attribute- and role-based controls that apply to your users, so agents never gain access beyond what their identity is permitted.

What use cases does the Kiteworks Marketplace offer?

The Kiteworks Marketplace offers a catalog of ready-to-use, policy-governed use cases that run through the Kiteworks MCP Server. They cover workflows such as governed folder operations, file management, and forms creation — all with identity verification, access enforcement, encrypted handling, and tamper-evident audit trails. They are built for regulated industries including financial services, healthcare, legal, and federal government.

Next Steps

Ready to connect Kiteworks to your LLM application?