MCP server

Machine translation, not yet reviewed.

Security and limits

Authentication, data protection, usage limits and common errors of the Tax360 MCP server.

Authentication and permissions

  • Authorization uses OAuth 2.1 with PKCE. The client discovers the authorization server on its own, through the MCP server's /.well-known/oauth-protected-resource document.
  • The token is valid only for the Tax360 MCP server and carries the identity of the user who authorized it.
  • Every call respects that user's companies and permissions, as in Tax360. Without permission, the tool returns an access-denied error.
  • To revoke access, remove the connector in the client or end the user's session in Tax360.

Data protection

  • Responses carry summaries, not full documents.
  • Access keys, CPFs and e-mails are masked in responses.
  • Files (XML, DANFE, reports) always come as temporary links. The file content does not go through the assistant unless you open and share it.
  • The company configuration never includes secrets: CSC, digital certificate and credentials are not returned.
  • Every call is logged for audit, with user, company, tool and result. Call arguments are not stored.
  • Keep in mind that response text goes through your AI assistant's provider. Use the MCP server according to your company's data policy.

Limits

LimitValue
Calls per user and per tool60 per minute
Heavy tools (XML, DANFE, SPED upload, Excel)10 per minute
Records per searchup to 100 (default 20)
Items per page in RocketPVA validationup to 50
Maximum call time60 seconds
Request sizeabout 43 MB
Multipart SPED uploadup to 100 parts; links valid for 1 hour

Common errors

ErrorWhat it meansWhat to do
401 / sign-in promptMissing or expired tokenAuthorize again in the client (in Claude Code, /mcp → tax360)
403 / access deniedThe user lacks the permission or the requested companyAsk your company administrator for the product permission
Rate limit exceededMore calls per minute than allowedWait the time shown in the message and try again
413Request too largeFor large SPED files, use the multipart upload (rpva.create_upload)
504 / timeoutThe service took longer than 60 secondsTry again or shorten the search period

If the problem persists, open a ticket through Support → Open a ticket in the footer, with the time of the call and the tool name.

On this page