MCP scopes reference

What each scope on an access token allows.

Scopes narrow what a token can do. They never grant more than the person who created the token already has.

Read scopes

ScopeAllows
mcp:readEverything below.
mcp:read:identityWho the token acts as, and which organisation.
mcp:read:reportsReports, topics, disclosures, data point values, comments and history.
mcp:read:esrsThe standard itself: topics, disclosure requirements and data point definitions.
mcp:read:filesThe organisation file library and data point attachments.
mcp:read:gapGap analysis records.
mcp:read:publicationsPublications and their settings.

Write scopes

ScopeAllows
mcp:writeEverything below.
mcp:write:reportsChanging data point answers, and accepting or skipping items in a version-mapping review. Does not create, delete or publish reports.
mcp:write:create_reportsCreating new reports and report copies. Not available on a token restricted to specific reports.
mcp:write:commentsPosting comments.
mcp:write:gapUpdating gap analysis records.

Choosing scopes

Start from what the client is for.

PurposeSuggested scopes
Asking questions about your reportingmcp:read
Looking up the standard while drafting elsewheremcp:read:esrs, mcp:read:identity
An agent that drafts answers into a specific reportmcp:read, mcp:write:reports, restricted to that report
Automating gap-analysis bookkeepingmcp:read:reports, mcp:read:gap, mcp:write:gap
N

The Cards is a product developed by ICONS OF.

Visit http://www.iconsof.se to read more about us and our vision.

Partner
Microsoft startups
Copyright © 2026 TheCards.eu