MCP server
Vehiso runs a Model Context Protocol server, so an AI assistant can look up stock, enquiries, customers, appointments and deals, and make a small set of changes, on a dealer's behalf.
| URL | https://api.vehiso.com/v1/mcp |
| Transport | Streamable HTTP, JSON responses |
| Protocol version | 2025-06-18 (2025-03-26 and 2024-11-05 are also accepted) |
| Authentication | Authorization: Bearer <key>: a secret key or an OAuth access token. Publishable keys cannot use it. |
The server uses the same services as the REST endpoints, so it follows the same rules: the key's scopes, its owner's permissions, branch restrictions and rate limits all apply.
Choose a key
Create a secret key in the DMS under Administration > Developers just for the assistant (a partner app can use its OAuth access token instead), so you can see its usage separately and revoke it on its own. Give it only the scopes the assistant needs. Every tool is filtered by scope: a tool whose scope the key lacks is simply not offered. A read-only key (only :read scopes) gives a read-only assistant.
Use a test key (vh_test_sk_...) first to try it against the sandbox dealer.
Available tools
| Tool | Scope | What it does |
|---|---|---|
search_vehicles | vehicles:read | Lists vehicles, filtered by status, make, model or registration. |
get_vehicle | vehicles:read | One vehicle with its full details and photos. |
update_vehicle_price | vehicles:write | Sets the asking price in minor units, or marks it price on application. |
stock_summary | vehicles:read | How many vehicles are in each status, and the asking value of stock on sale. |
list_enquiries | enquiries:read | Lists enquiries, filtered by status. |
get_enquiry | enquiries:read | One enquiry with its notes. |
create_enquiry | enquiries:write | Records a lead; takes the POST /v1/enquiries body. |
search_customers | customers:read | Finds customers by email or phone. |
list_appointments | appointments:read | Appointments, optionally between two dates. |
list_deals | sales:read | Sales deals. |
request_website_theme | website_themes:write | Starts a website theme build from a brief, or a revision of the last one. It does not go live by itself. |
get_theme_generation | website_themes:read | A theme build's status, with a preview link once it has succeeded. |
A tool is listed only when the key has its scope. Each tool describes its own inputs to the client, so the assistant knows how to call it. When a tool refuses (a validation failure, a record that does not exist), it answers with a result whose isError is true, so the model can read the reason and correct itself.
Claude Code
claude mcp add --transport http vehiso https://api.vehiso.com/v1/mcp \
--header "Authorization: Bearer vh_live_sk_..."
Then ask, for example, "Which vehicles have been in stock the longest?". Run /mcp inside Claude Code to check the connection.
Claude Desktop
Claude Desktop connects to remote servers that need a custom header through the mcp-remote bridge, which needs Node.js installed. Open Settings > Developer > Edit Config and add:
{
"mcpServers": {
"vehiso": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://api.vehiso.com/v1/mcp",
"--header",
"Authorization:${VEHISO_AUTH}"
],
"env": {
"VEHISO_AUTH": "Bearer vh_live_sk_..."
}
}
}
}
Restart Claude Desktop. The Vehiso tools appear in the tools menu. (Writing the header as Authorization:${VEHISO_AUTH}, with the value in env, avoids a quoting problem with spaces in arguments on some platforms.)
Other MCP clients
Any client that supports the streamable HTTP transport and custom headers can connect: point it at https://api.vehiso.com/v1/mcp and send Authorization: Bearer <key> on every request. For clients that only launch local (stdio) servers, use mcp-remote as above.
The server supports the initialize, ping, tools/list and tools/call methods. Each request body is one JSON-RPC 2.0 message; batches are not supported. A notification (a message with no id) is acknowledged with 202 and no body. The server sends nothing unprompted, so GET /v1/mcp, which would open a server-sent event stream, answers 405 as the MCP specification provides.
To check a key by hand, send an initialize request:
curl https://api.vehiso.com/v1/mcp \
-H "Authorization: Bearer $VEHISO_API_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"1.0"}}}'
Then list the tools the key can use:
curl https://api.vehiso.com/v1/mcp \
-H "Authorization: Bearer $VEHISO_API_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2025-06-18" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}'
Protocol errors use JSON-RPC error codes inside a 200 response: -32700 parse error, -32600 invalid request, -32601 unknown method and -32602 unknown tool.
Keeping it safe
- The assistant can do anything the key's scopes allow. Leave out write scopes unless you want it to change data, and leave out personal-data scopes (enquiries, customers, sales, appointments) unless it needs them.
- The key sits in the client's configuration file on that computer. Treat that file like a password, and revoke the key in the DMS if the computer is lost.
- Every call appears in the dealer's request log in the DMS, like any other API request.