Best practices
Apply security, token management, and integration practices when connecting AI clients to Mindtickle MCP.
Use these practices when administering a Mindtickle MCP connector or building a custom client. For setup instructions, see Set up the connector or Build a custom client.
Security
Section titled “Security”Apply these practices to both managed connectors and custom clients.
- Connect only to official endpoints: Only point a client at Mindtickle MCP server URLs obtained directly from Mindtickle (your own instance’s
https://{mindtickle-instance-url}/mcp). Never configure a client to use an MCP server URL, token endpoint, or credential from an untrusted or unverified source. - Use HTTPS exclusively: Never configure a connector URL over unencrypted HTTP.
- Treat tool output as untrusted: Content returned by a tool call (for example, search results or Copilot responses) reflects data stored in Mindtickle, which can include text entered by other users. Don’t let an agent treat that content as instructions to follow. Validate or sandbox how tool output is used downstream, the same way you would for any untrusted input, to avoid prompt-injection risks.
Connector administrators
Section titled “Connector administrators”- Apply least privilege: Grant only the scopes an AI client actually needs. Use admin-controlled scope mode when you need to enforce a fixed policy across the organization. See Set up the connector for scope-control modes.
- Rotate credentials regularly: If you use admin-controlled scopes, rotate the
client_idandclient_secreton a schedule by requesting new credentials from your Mindtickle Customer Success Manager (CSM). - Restrict redirect URIs: The Mindtickle MCP server requires an exact HTTPS match for redirect URIs, with no fragments. Register only the URIs you use, up to the limit of 10 per client.
- Audit access: Periodically review which users have connected to the connector in the AI client’s connector settings.
- Monitor activity: Use your Mindtickle audit logs and the AI client’s logs to review tool calls and access patterns.
Custom client developers
Section titled “Custom client developers”- Store credentials securely: Keep
client_secretin a secure vault or secret manager, and store access and refresh tokens in environment variables or a secret manager. Never hardcode either in your client configuration, code, or logs. - Request least-privilege scopes: When requesting a token, include only the specific scopes your integration needs.
- Use the supported PKCE method: For the authorization code grant with Proof Key for Code Exchange (PKCE) and dynamic client registration, only
S256is accepted. Theplainmethod is rejected.
Reliability
Section titled “Reliability”- Cache and reuse tokens: Cache and reuse the access token, and obtain a replacement before it expires, rather than requesting a new one on every call. The token endpoint is rate-limited to 20 requests per minute per client, and returns a
429error once that limit is exceeded. - Expect automatic session recovery: If an MCP session expires mid-conversation, the server recovers automatically on the next tool call. You don’t need to detect this or reconnect yourself.
Integration design
Section titled “Integration design”When building an AI client, map user requests to tools and preserve the conversation context needed by Seller Copilot. See Build a custom client for examples.
- Route intent automatically: Configure your agent or copilot to map user intent (for example, training or content queries) to the appropriate MCP tool. Don’t require users to reference Mindtickle or name a tool explicitly. Reserve explicit tool references for manual or developer testing.
- Send full conversation history to Copilot: For the
mindtickle_seller_copilot_asktool, maintain the complete conversation history, including all follow-up questions, and send the updated history with each request to maintain context, accuracy, and continuity.