MCP server
Machine translation, not yet reviewed.
Security and limits
Authentication, data protection, usage limits and common errors of the Tax360 MCP server.
Authentication and permissions
- Authorization uses OAuth 2.1 with PKCE. The client discovers the authorization server on its own, through the MCP server's
/.well-known/oauth-protected-resourcedocument. - The token is valid only for the Tax360 MCP server and carries the identity of the user who authorized it.
- Every call respects that user's companies and permissions, as in Tax360. Without permission, the tool returns an access-denied error.
- To revoke access, remove the connector in the client or end the user's session in Tax360.
Data protection
- Responses carry summaries, not full documents.
- Access keys, CPFs and e-mails are masked in responses.
- Files (XML, DANFE, reports) always come as temporary links. The file content does not go through the assistant unless you open and share it.
- The company configuration never includes secrets: CSC, digital certificate and credentials are not returned.
- Every call is logged for audit, with user, company, tool and result. Call arguments are not stored.
- Keep in mind that response text goes through your AI assistant's provider. Use the MCP server according to your company's data policy.
Limits
| Limit | Value |
|---|---|
| Calls per user and per tool | 60 per minute |
| Heavy tools (XML, DANFE, SPED upload, Excel) | 10 per minute |
| Records per search | up to 100 (default 20) |
| Items per page in RocketPVA validation | up to 50 |
| Maximum call time | 60 seconds |
| Request size | about 43 MB |
| Multipart SPED upload | up to 100 parts; links valid for 1 hour |
Common errors
| Error | What it means | What to do |
|---|---|---|
401 / sign-in prompt | Missing or expired token | Authorize again in the client (in Claude Code, /mcp → tax360) |
403 / access denied | The user lacks the permission or the requested company | Ask your company administrator for the product permission |
| Rate limit exceeded | More calls per minute than allowed | Wait the time shown in the message and try again |
413 | Request too large | For large SPED files, use the multipart upload (rpva.create_upload) |
504 / timeout | The service took longer than 60 seconds | Try again or shorten the search period |
If the problem persists, open a ticket through Support → Open a ticket in the footer, with the time of the call and the tool name.