idnow-mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@idnow-mcp-serverlist my verification flows"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
IDnow Trust Platform MCP Server (Assignment)
Introduction
An MCP server that lets an LLM agents operate the IDnow Trust Platform sandbox - list the
verification flows on the account, kick off a new identity-verification session, check on
existing sessions, and pull full detail on one specific session. IDnow's customers are banks
and fintechs that need to verify their own customers remotely: a "flow" is a verification strategy
(video KYC, document scan, etc.), a "session" is one verification attempt for one person, and
the playerUrl a session returns is the link that person opens to actually go through verification.
This server is a small version of how those customers' own agents would eventually orchestrate that flow.
Everything here runs against the real IDnow sandbox (staging environment) - nothing is mocked.
Related MCP server: OpenAPI MCP Server
Setup & Run
git clone https://github.com/DevMohith/idnow-mcp-server.git
npm install
That's it - no
.env, no config step. Credentials are hardcoded insrc/config.js, which is exactly what the assignment asked for ("fine to put it directly in the code to keep things simple").In a real production integration these would live in a secrets manager and get injected at *runtime, never committed - that's a scope choice for this assignment, not an oversight.
for running it, and pointing an LLM client at it
There are three ways i designed to actually talk to this server, depending on what you're trying to check.
Before jumping I want to let you know - This server uses #stdio transport pipes, so it only works when the client and server are on the same machine :
the client spawn the server for you using the path in its config,
no manual "run the server" step needed.
A cloud-based client would need the server hosted separately over HTTP (Cloudflare Tunnel or VPS server)
Option A - Claude Desktop (the real end-to-end demo) with prettier print
Edit your Claude Desktop config:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"idnow": {
"command": "node",
"args": ["/ABSOLUTE/PATH/TO/idnow-mcp-server/src/server.js"]
}
}
}For e.g. - Absolute Path looks like below ("C:\Users\mohithtummala\Desktop\idnow-mcp-server\src\server.js")
Restart Claude Desktop fully (not just the window - check it's not still running in the
background tasks or tray), and the 4 tools show up under [+ icon -> connectors -> manage connectors -> idnow] .
This is the setup transcript.md was captured against.
Option B - Claude Code (CLI)
If you've got the claude CLI installed, this is the fastest way to try it:
cd idnow-mcp-server
claude mcp add idnow -- node src/server.js
claudeThen just talk to it naturally - "which verification flows can I use?" and so on.
Option C - MCP Inspector (protocol-level, no LLM involved, Developer tool)
Useful for checking the raw tool schemas and responses without an LLM in the loop at all:
npm run mcp-inspectoropens a browser UI automatically, or for scripting/CI-style checks, the CLI mode works well:
This is how the tool schemas and error responses in this project were actually verified during development, independent of any particular chat client.
Other Options (e.g. Cursor, Cline)
Use mcp config provided in option A, to connect to the local mcp clients uses STDIN, STDOUT pipelines.
Architecture
Four files, each with one job:
src/config.js - The sandbox credentials and URLs, in one place
src/auth.js - OAuth2 client-credentials token manager — in-memory cache, 60s early-refresh buffer, in-flight request de-duplication, forceRefresh for 401 recovery
src/api.js - 4 endpoint functions, a shared request() helper with one-time 401 retry, and toCleanError() centralizing all error message formatting
src/server.js - FastMCP tool registration - 4 tools with Zod schemas and descriptions written for chaining, UserError wrapping so failures surface as clean tool errors
Transport is stdio, schemas are Zod, HTTP is axios - this is the stack I followed, and there's no database or Docker involved; state lives in-memory only, which is explicitly stated fine in Assignment.
The 4 tools in server.js
| Tool | Purpose | Endpoint |
list_flows - List available verification flows (GET /api/v1/flows/staging)
create_session - Start a new session for a flow (POST /api/v1/flows/{flowId}/staging/sessions)
list_sessions - List sessions for a flow (defaults to the first flow if none given) (GET /api/v1/flows/{flowId}/staging/sessions)
get_session - Full detail on one session (GET /api/v1/staging/sessions/{sessionId})
Results / Verification
See transcript.md for verification of the three prompts working against the sandbox
all four tools working end-to-end, including tool chaining and error handling tests.
Testing
npm test # tests/auth.test.js - proves getToken() fetches and caches it rather than re-authenticatrin on every call.
npm run smoke # scripts/smoke.js - This is where i started testing, walks all 4 endpoints against the live sandbox, prints resultsThe two are kept separate on purpose: npm test should be fast, deterministic, and side-effect
free, while the smoke script deliberately creates a real session every time it runs, which isn't
something you want happening on every npm test.
Design choices & trade-offs
Stack: Node.js + official MCP SDK + FastMCP SDK + Zod Input Validation + axios + Node test + assert runtime-checks
Transport: stdio, MCP's default - kept simple; an HTTP/SSE transport would remove the local-config step for a real deployment, I would extend in production.
MCP SDK: used FastMCP abstraction of official MCP SDK, which the brief explicitly allows either, mainly for the Zod-schema-to-tool-schema generation.
Client secret: hardcoded in
config.js, per the assignment's own instruction ("fine to put it directly in the code to keep things simple") - not an oversight, i would use secret manager and .env in prod.Real sandbox only: every response shape documented above, and everything in
transcript.md, came from actually hittingidnow.sx- nothing here is mocked or guessed.list_sessionsstatus filter runs client-side, not server-side: Verified directly against the live sandbox — and cross-checked IDnow's own docs - that the sessions-listing endpoint has no working status filter parameter; So added filter expression onlistSessions()fetches the full list first and filters bysessionStatusin JavaScript instead.
A note on AI usage
This was built by contesting on AI-generated code rather than completely accepting everything it given - for example, the initial auth module re-authenticated on every call; I added expiry tracking and in-flight deduplication.
Available Tools
4 toolscreate_sessionA
Create a new identity-verification session for a given flow. Requires the flowId (from list_flows) and a subjectId (your internal reference for the person being verified - never a real name or other PII). Returns the sessionId and a playerUrl and the initial sessionStatus, which is the link the end-user opens to complete verification. Session starts in CREATED and moves to RUNNING once the user begins.
| Name | Required | Description | Default |
|---|---|---|---|
| flowId | Yes | Flow id obtained from list_flows | |
| locale | No | Language for the verification player UI | en |
| subjectId | Yes | Internal reference id for the person being verified; must not contain PII such as a real name |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses the expected output (sessionId, playerUrl, sessionStatus), the initial state (CREATED) and transition to RUNNING, and the PII constraint on subjectId. It does not cover error cases or authorization requirements, but the key behavioral traits are clearly described.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is relatively concise at three sentences, but the third sentence has awkward grammar ('which is the link' could ambiguously refer to playerUrl or sessionStatus). It front-loads the core action and prerequisites, making it easy to scan. Minor redundancy exists but overall it is well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite no output schema, the description explains the return values and the session lifecycle, which is essential for an AI agent to understand the tool's behavior. It also gives context about how to obtain the flowId. While it omits error handling and edge cases, the tool is relatively simple and the description is sufficient for correct use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and the description repeats the schema's parameter explanations (e.g., flowId from list_flows, subjectId as non-PII reference) without adding significant new detail. The locale parameter is not mentioned in the description, so the description does not augment the schema meaningfully. Baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb and resource: 'Create a new identity-verification session.' It also specifies the context (for a given flow) and differentiates from sibling tools (list_flows, list_sessions, get_session) by focusing on creation rather than listing or retrieval.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context by indicating that flowId comes from list_flows and that subjectId is your internal reference, implying the prerequisite steps. However, it does not explicitly mention when not to use this tool or alternative options, so it earns a 4 rather than a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_sessionA
Retrieve full detail and current status for ONE verification session by its sessionId. Use this after create_session (or after finding a sessionId via list_sessions) to check the progress or outcome of a specific session.
| Name | Required | Description | Default |
|---|---|---|---|
| sessionId | Yes | Session id from create_session or list_sessions |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses that the tool returns 'full detail and current status', which implies read-only behavior, but does not specify side effects, error cases, or permissions. This is typical for a get operation but lacks deeper behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with action, then usage context. Every word earns its place, with no redundancy or unnecessary detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is simple (one parameter, no output schema, no annotations). The description sufficiently explains what it retrieves, when to use, and how the session ID is obtained. It does not detail return format, but the phrase 'full detail and current status' covers this adequately for a simple retrieval.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%: the parameter sessionId is described as 'Session id from create_session or list_sessions' in the schema. The description adds no extra parameter semantics beyond reinforcing the source of the ID, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Retrieve') and clearly defines the resource ('full detail and current status for ONE verification session'). It distinguishes from siblings by emphasizing 'ONE' session versus list_sessions, and references create_session/list_sessions for context.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when to use: after create_session or after finding a sessionId via list_sessions, and the purpose: check progress/outcome. However, it does not explicitly mention when not to use or name alternatives, though the sibling tool names imply this.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_flowsA
List the identity-verification flows available to this IDnow account. Returns each flow's id, name, and description. Call this first to discover a flowId before creating or listing sessions.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It states the return values and its role as a prerequisite, but it does not explicitly disclose read-only behavior, authentication requirements, or potential edge cases like no flows returned. This is adequate for a simple list but lacks richer behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three concise sentences with no filler: the action, the return fields, and the usage guidance. It is front-loaded with the core purpose and every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple list tool with no parameters and no output schema, the description is complete. It specifies exactly what is returned (id, name, description) and provides the key usage context (discover flowId first), covering all necessary aspects.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters (empty input schema), so there are no parameter details to clarify. Per the rubric, a baseline of 4 applies when there are no parameters, and the description correctly does not attempt to fabricate parameter semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action 'List' and the resource 'identity-verification flows' scoped to 'this IDnow account'. It specifies the return fields (id, name, description) and distinguishes it from session-related siblings by framing it as the discovery step for flowId.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly says 'Call this first to discover a flowId before creating or listing sessions', giving clear when-to-use guidance. It references the sibling session tools implicitly but does not name them explicitly or state when not to use it, so it lacks full alternatives specification.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_sessionsA
List verification sessions for a flow, newest first. If flowId is omitted, the account's first available flow is used automatically. Returns each session's sessionId, sessionStatus (CREATED/RUNNING/COMPLETED/EXPIRED/ABORTED/ERROR), outcome, and createdAt. Use this to find the sessionId of a session you just created, then pass it to get_session for full detail.
| Name | Required | Description | Default |
|---|---|---|---|
| flowId | No | Flow id to list sessions for; if omitted, the first flow from list_flows is used | |
| status | No | Status filter, e.g. RUNNING, COMPLETED, EXPIRED |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations available, the description carries the full burden. It discloses several behaviors: newest-first ordering, automatic flow selection when flowId is omitted, and the specific return fields (sessionId, sessionStatus, outcome, createdAt) including all possible status values. This is far beyond a generic 'list sessions' statement.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, each serving a distinct purpose: what it does, how it behaves, and when to use it. No redundant or extraneous information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description effectively documents the return shape and statuses. It also covers ordering, fallback logic, and the next-step usage with get_session, making it complete for a simple list tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% for both parameters. The description adds only a reiteration of the flowId fallback (already in the schema) and does not provide additional parameter-level insights. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'List verification sessions for a flow, newest first' – a specific verb and resource. It also explains the primary use case (finding a sessionId to pass to get_session), distinguishing it from sibling tools like list_flows and create_session.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly instructs when to use this tool: 'Use this to find the sessionId of a session you just created, then pass it to get_session for full detail.' It also notes the automatic fallback to the account's first flow when flowId is omitted, providing clear context for usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v1.0.0- First observed
create_session - First observed
get_session - First observed
list_flows - First observed
list_sessions
TDQS
Each tool targets a distinct resource and action: listing flows, listing sessions, creating a session, and retrieving a single session. There is no overlap or ambiguity between them.
All tools follow a consistent verb_noun pattern (list_flows, list_sessions, create_session, get_session) with no mixed conventions or deviations.
Four tools is well-scoped for an identity verification server, covering discovery, creation, and status retrieval without unnecessary bloat.
The core workflow is fully covered: discover flows, create sessions, list and retrieve session details. However, an explicit cancel or abort session operation is missing, which might be a minor gap given the session statuses include ABORTED.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
MCP server for verifying EUDI/Talao wallet data via OIDC4VP (pull) for AI agents.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Related MCP Servers
- FlicenseAqualityDmaintenanceAn MCP server that enables LLMs to interact with Agent-to-Agent (A2A) protocol compatible agents, allowing for sending messages, tracking tasks, and receiving streaming responses.528-
- AlicenseAqualityDmaintenanceA generic MCP server that dynamically exposes any OpenAPI-documented REST API to LLMs by auto-discovering endpoints. It provides tools for exploring API capabilities and making authenticated requests directly through natural language interfaces.214MIT
- AlicenseAqualityCmaintenanceMCP server for AgentFolio — the identity and reputation layer for AI agents. Query agent profiles, trust scores, verification status, and marketplace listings through 8 MCP tools.91341MIT
- AlicenseNot gradedqualityDmaintenanceMCP Server for AI agent identity and authorization. Create, verify, and manage agent identities with trust scores and scoped authorization tokens.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DevMohith/idnow-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server