MCP

MCP-Kolumne

AI-Agenten sicher anbinden: User-MCP für Betrieb, Developer-MCP für Integrationen — mit Profilen, Confirm, Dry-Run und Freigaben.

MCP track_package(tracking_number) Tool
RPC tools/list JSON-RPC 2.0
RPC tools/call JSON-RPC 2.0
Documentation

MCP-Kolumne Überblick

Dieser Leitfaden ist die Superroute-MCP-Kolumne im Developer Center: beide Server, Agentensicherheit und der Live-Tool-Katalog.

Was ist MCP?

Das Model Context Protocol (MCP) ist ein offener Standard, der KI-Assistenten wie Claude, Cursor und ChatGPT ermöglicht, mit externen Tools und Diensten zu interagieren. Es ermöglicht Ihrer KI, echte Aktionen durchzuführen — wie z.B. ein Paket zu verfolgen — direkt im Gespräch.

Durch die Konfiguration des Superroute MCP-Servers erhält Ihr KI-Assistent Zugang zu Logistik-Tools, ohne Ihren Workflow zu verlassen.

Zwei MCP-Server

Wählen Sie den passenden Server. Geben Sie unbeaufsichtigten Agenten nicht den Developer-Server mit Vollzugriff.

Servername Endpunkt Zielgruppe Auth
superroute https://api.superlabel.ca/mcp Ops-/Support-/Business-Agenten Bearer + optionales Profil/Scopes (sonst Vollzugriff)
superroute-developer https://api.superlabel.ca/mcp/developer Integrationsentwickler & Coding-Agenten Connection-Bearer bevorzugt; Tool-api_token wird abgeschaltet

Schnellstart

Öffentliche Tools wie Paketverfolgung funktionieren ohne Authentifizierung. Fügen Sie diese Konfiguration zu Ihrem MCP-Client hinzu:

JSON
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp"
    }
  }
}
Probieren Sie es aus! Fragen Sie nach der Einrichtung Ihren KI-Assistenten: „Paket SR100012345 verfolgen"

Authentifizierter Zugang

Um Tools zu verwenden, die Benutzerberechtigungen erfordern, fügen Sie Ihr API-Bearer-Token zur Konfiguration hinzu:

Token immer in MCP-Connection-Headern setzen — nie in Tool-Argumenten oder Prompts.

JSON
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp",
      "headers": {
        "Authorization": "Bearer <your-api-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

So erhalten Sie ein API-Token

Rufen Sie den Login-Endpunkt mit Ihren Anmeldedaten auf:

Bash
curl -X POST https://api.superlabel.ca/api/v1/user/login \
  -H "Content-Type: application/json" \
  -d '{"email": "you@example.com", "password": "your-password"}'

Die Antwort enthält Ihr Zugriffstoken:

JSON Response
{
  "access_token": "eyJ0eXAiOiJKV1Qi...",
  "token_type": "Bearer",
  "expires_at": "2026-02-20 00:00:00"
}

Verwenden Sie den access_token-Wert im Authorization-Header Ihrer MCP-Konfiguration.

Agenten-Sicherheitsmodell

User-MCP ist für Least-Privilege-Agenten gebaut. Token mit MCP-Profil (Standard: Ops nur lesen) oder Header setzen.

Profile (X-MCP-Profile)

Benannte Scope-Bündel. Für unbeaufsichtigte Agenten ops-readonly oder support.

Profil Bezeichnung Scopes
ops-readonly Ops nur lesen orders:read, labels:read, routes:read, drivers:read, analytics:read, address:read, approvals:read
support Support (Kundenservice) orders:read, analytics:read, address:read, approvals:read
ops-write Ops schreiben (Aufträge + Labels + Routen) orders:read, orders:write, labels:read, labels:write, routes:read, routes:write, drivers:read, analytics:read, address:read, approvals:read, approvals:write
wms-readonly WMS nur lesen wms:read, orders:read
datasets-readonly Datensätze nur lesen datasets:read
alliance-readonly Alliance nur lesen alliance:read
full Vollzugriff (alle MCP-Tools) — nicht für unbeaufsichtigte Agenten *
.mcp.json — empfohlene Agentenkonfiguration
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp",
      "headers": {
        "Authorization": "Bearer <ops-readonly-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

Optionale Header

Header Zweck
Authorization: Bearer …API-Bearer-Token (Connection-Ebene).
X-MCP-ProfileBenanntes Profil: ops-readonly, support, ops-write, wms-readonly, datasets-readonly, alliance-readonly, full.
X-MCP-ScopesExplizite kommagetrennte Scopes (überschreibt Profil).
X-MCP-Dry-Run: 1Schreibtools ohne Mutation vorschauen.
X-MCP-Require-Approval: 1Riskante Schreibvorgänge zur Freigabe einreihen statt ausführen.

Hochrisiko-Confirm

Diese Tools erfordern confirm=true bei tools/call (oder Freigabewarteschlange):

Menschliche Freigabewarteschlange

Unbeaufsichtigte Agenten sollen Schreibvorgänge vorschlagen; Menschen freigeben.

  1. Agent: propose_write oder X-MCP-Require-Approval: 1
  2. Mensch: MCP-Freigaben in der App oder list_pending_approvals
  3. Mensch: approve_pending_write mit confirm=true oder reject_pending_write

Web-UI-Pfad (Login erforderlich): /mcp-approvals

Developer-MCP-Authentifizierung

Bevorzugen Sie Authorization: Bearer auf der Verbindung. Per-Tool-api_token ist veraltet und endet nach 2026-12-31.

Verfügbare Tools

Die folgenden Tools sind derzeit auf dem MCP-Server verfügbar: 47 Live-Tools aus dem Serverkatalog

Diese Tabelle wird zur Laufzeit aus UserMcpToolCatalog erzeugt und bleibt mit tools/list synchron.

Werkzeug Authentifizierung Risiko Scopes Beschreibung
track_package Öffentlich low Track a package by its tracking number. Returns delivery status, tracking events timeline, and proof of delivery if available.
otep_tracking Öffentlich low Get the unified OTEP (Open Tracking Event Protocol) timeline for a tracking number — self-delivery, third-party and carrier events normalize...
get_capabilities Öffentlich low List MCP tools available to the current connection, with risk level, required scopes, and whether confirm=true is needed. Call this first wh...
get_orders Erforderlich low orders:read List orders with filtering and pagination. Returns order details including status, tracking, and delivery info.
get_order_detail Erforderlich low orders:read Get full details of a specific order by ID, including address, status, packages, and tracking info.
find_order Erforderlich low orders:read Fuzzy-find orders across tracking number, external tracking, ref, recipient name, and phone in a single query. Use this instead of get_order...
get_operation_events Erforderlich low orders:read Get the full audit trail for orders — every status change, who performed it, GPS coordinates, and photos.
create_order Erforderlich medium orders:write Create a delivery/pickup order. D=delivery (warehouse→customer), P=pickup (customer→warehouse), P2P=peer-to-peer. Returns order ID and track...
cancel_order confirm Erforderlich high orders:write Cancel an existing order by order ID. Only works for orders not yet delivered.
bulk_create_orders confirm Erforderlich high orders:write Create up to 100 delivery orders in one call. Returns a per-order success/failure summary; partial failures do not abort the batch unless st...
reroute_to_address confirm Erforderlich high orders:write Change the delivery address of an order that has not been picked up yet: cancels the original order and recreates it with the new address. R...
update_delivery_instruction Erforderlich medium orders:write Update only the delivery_instruction field on an existing order (PATCH). Safer than full order rewrite.
update_order_note Erforderlich medium orders:write Update only the internal note field on an existing order (PATCH).
update_time_window_by_refs Erforderlich medium orders:write Bulk-update delivery time windows (and optional schedule_date) for orders identified by external refs.
hold_order confirm Erforderlich high orders:write Put an order on HOLD so it is not dispatched until release_order. HIGH-RISK: requires confirm=true.
release_order confirm Erforderlich high orders:write Release an order from HOLD back to NEW_ORDER. HIGH-RISK: requires confirm=true.
propose_write Erforderlich low approvals:read Queue a write/high-risk tool for human approval instead of executing it. Reviewers use list_pending_approvals + approve_pending_write.
list_pending_approvals Erforderlich low approvals:read List pending MCP write approvals for this business (or mine_only).
approve_pending_write confirm Erforderlich high approvals:write Approve and execute a pending write proposal. HIGH-RISK: requires confirm=true. Reviewer must have scopes for the underlying tool.
reject_pending_write Erforderlich medium approvals:write Reject a pending write proposal without executing it.
get_routes Erforderlich low routes:read List delivery routes with their status, assigned driver, and order count.
get_route_detail Erforderlich low routes:read Get one route with its stop/order list. Prefer this over get_routes when you already know route_id.
get_drivers Erforderlich low drivers:read List drivers for the authenticated business (ids, names, capacity defaults). Use driver id with get_driver_routes_today or route tools.
get_driver_routes_today Erforderlich low routes:read, drivers:read Orders assigned to a driver on a given date (defaults to today). Useful for "what is driver X running today?"
get_build_route_options Erforderlich low routes:read List routing engines, balance modes, capacity types, and defaults before calling build_route.
build_route confirm Erforderlich high routes:write Build/optimize a delivery route (POST /api/v3/client/build-route). HIGH-RISK: assigns orders to drivers. Call get_build_route_options first....
order_snapshot Erforderlich low orders:read One-call order context for support: order detail + operation events + public tracking (when tracking number is known). Pass order_id or trac...
list_exceptions Erforderlich low orders:read List failed/returned/exception-like orders for a schedule date (default today). Read-only ops triage helper.
get_shipping_methods Erforderlich low labels:read List available shipping carriers/methods. Returns IDs and names — use the ID for rate/label tools.
get_shipping_rate Erforderlich low labels:read Get a shipping cost quote. Dry-run — no label created. Returns rate options with pricing and transit time.
create_shipping_label Erforderlich medium labels:write Book a shipment with a carrier and generate a shipping label with tracking numbers.
quote_and_ship Erforderlich medium labels:write One-shot: rate across all enabled carriers, pick the best one by strategy, create the shipping label, return tracking number. Saves 3+ tool...
compare_all_carriers Erforderlich low labels:read Get rate quotes from every enabled carrier for the same shipment, in one call. Returns a sorted comparison (cheapest first) with price + tra...
search_address Erforderlich low address:read Search and resolve addresses by postal code or free-text query. Returns structured address suggestions.
daily_digest Erforderlich low analytics:read One-call summary of today's logistics activity: total orders, by status, exceptions (failed/returned), pending pickups. Designed as the firs...
get_orders_summary Erforderlich low analytics:read Aggregate order metrics over a time window: counts by status, top carriers, on-time rate, exception count. Use period=today|week|month or pa...
get_account_credits Erforderlich low analytics:read Get the authenticated customer's wallet balance, currency, and recent topup history. Customer (B2C) accounts only — returns an error for cli...
get_warehouses Erforderlich low wms:read List WMS warehouses available to the authenticated business.
get_inventory Erforderlich low wms:read Query WMS inventory (POST /api/v1/wms/inventory). Pass filters supported by the inventory API (sku, warehouse_id, etc.).
list_datasets Erforderlich low datasets:read List custom datasets available to the business.
get_dataset Erforderlich low datasets:read Get one dataset by id (metadata/columns).
list_dataset_groups Erforderlich low datasets:read List groups inside a dataset.
search_dataset_records Erforderlich low datasets:read Search records across groups in a dataset (POST .../search).
list_alliances Erforderlich low alliance:read List alliances the authenticated business belongs to.
get_alliance Erforderlich low alliance:read Get one alliance by id.
list_alliance_members Erforderlich low alliance:read List members of an alliance.
list_accessible_clients Erforderlich low alliance:read List clients accessible via alliance partnerships.

Client-spezifische Einrichtung

Wählen Sie Ihren KI-Client unten für maßgeschneiderte Einrichtungsanweisungen:

Claude Code

Claude Code liest die MCP-Konfiguration aus einer .mcp.json-Datei im Projektstammverzeichnis oder Home-Verzeichnis.

  1. Erstellen Sie eine .mcp.json-Datei im Projektstammverzeichnis (oder ~/.claude/.mcp.json für globalen Zugriff).
  2. Fügen Sie die folgende Konfiguration hinzu:
.mcp.json
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp"
    }
  }
}

Um authentifizierte Tools zu verwenden, fügen Sie das headers-Feld hinzu:

.mcp.json (mit Authentifizierung)
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp",
      "headers": {
        "Authorization": "Bearer <your-api-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

Cursor

Cursor unterstützt MCP-Server über seine integrierte Konfiguration.

  1. Erstellen Sie eine .cursor/mcp.json-Datei im Projektstammverzeichnis.
  2. Fügen Sie die folgende Konfiguration hinzu:
  3. Starten Sie Cursor neu, um den neuen MCP-Server zu laden.
.cursor/mcp.json
{
  "mcpServers": {
    "super-label": {
      "type": "url",
      "url": "https://api.superlabel.ca/mcp"
    }
  }
}

Windsurf

Windsurf verwendet eine globale MCP-Konfigurationsdatei.

  1. Bearbeiten Sie ~/.codeium/windsurf/mcp_config.json (erstellen Sie die Datei, falls sie nicht existiert).
  2. Fügen Sie die folgende Konfiguration hinzu:
~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "super-label": {
      "serverUrl": "https://api.superlabel.ca/mcp"
    }
  }
}

ChatGPT

ChatGPT unterstützt MCP-Verbindungen für Plus-, Pro- und Team-Benutzer.

  1. Öffnen Sie ChatGPT und gehen Sie zu den Einstellungen.
  2. Navigieren Sie zum Abschnitt „Verbundene Apps" oder „Tools".
  3. Fügen Sie einen neuen MCP-Server mit der oben angezeigten Endpunkt-URL hinzu.
Die MCP-Unterstützung von ChatGPT kann je nach Ihrem Plan und Ihrer Region variieren. Aktuelle Anweisungen finden Sie in der OpenAI-Dokumentation.

Technische Details