@transcend-io/mcp-server-consent
v0.6.6
Published
Transcend MCP Server — Consent Management tools.
Maintainers
Keywords
Readme
@transcend-io/mcp-server-consent
Beta — this package is under active development. APIs may change without notice.
Transcend MCP Server for consent management. Provides tools for managing consent preferences, cookie triage, data flow management, and consent regime configuration.
Requires Node.js ≥ 22.12 (see engines in package.json).
For local runs from this repository, copy secret.env.example to secret.env at the repo root (gitignored) and set the OAuth environment variables (see Run from the monorepo).
Install
Install the CLI globally:
npm install -g @transcend-io/mcp-server-consentOr run from a checkout of this repository (see Run from the monorepo below).
Usage
# With OAuth env vars in the environment; from the monorepo use secret.env (see Run from the monorepo)
TRANSCEND_OAUTH_CLIENT_ID=your-client-id \
TRANSCEND_OAUTH_CLIENT_SECRET=your-client-secret \
TRANSCEND_OAUTH_REDIRECT_PORT=your-client-redirect-port \
transcend-mcp-consentThe process speaks MCP over stdio and is meant to be launched by an MCP client (for example Cursor or Claude Desktop), not used as an interactive shell.
OAuth client setup
OAuth stdio is the recommended path for MCP clients (Cursor, Claude Desktop). Requires org admin access to create OAuth clients.
- Navigate to app.transcend.io/admin/oauth-clients and create an OAuth client.
- Copy the client ID and client secret.
- Choose an available localhost port number, then register
http://127.0.0.1:{port}/callbackon the OAuth client ({port}is the number you chose). Use127.0.0.1, notlocalhost, and ensure the path is/callback. SetTRANSCEND_OAUTH_REDIRECT_PORTto the same port number.
At startup the server verifies client ID, secret, and redirect URI. On first tool call it opens a browser for login. Tokens are session-only (in-memory).
OAuth scopes: ViewConsentManager, ViewAssignedConsentManager, ManageConsentManager, ManageAssignedConsentManager, ViewDataFlow, ManageDataFlow. The signed-in user must hold these permissions. See src/scopes.ts.
Full setup, troubleshooting, and multi-server guidance: MCP root README.
API key alternative: set
TRANSCEND_API_KEYinstead of OAuth vars for stdio (OAuth is disabled when both are set).
MCP client configuration
npx runs the package’s transcend-mcp-consent binary (see bin in package.json).
{
"mcpServers": {
"transcend-consent": {
"command": "npx",
"args": ["-y", "@transcend-io/mcp-server-consent"],
"env": {
"TRANSCEND_OAUTH_CLIENT_ID": "your-client-id",
"TRANSCEND_OAUTH_CLIENT_SECRET": "your-client-secret",
"TRANSCEND_OAUTH_REDIRECT_PORT": "your-client-redirect-port"
}
}
}
}When developing in this repository, reuse the same variable names from root secret.env in the env block, or use your client’s env-file support if it has one.
Run from the monorepo
Credentials — From the repository root, copy
secret.env.exampletosecret.envand setTRANSCEND_OAUTH_CLIENT_ID,TRANSCEND_OAUTH_CLIENT_SECRET, andTRANSCEND_OAUTH_REDIRECT_PORT(and optional URL overrides).Build and run —
node ./dist/cli.mjsmatches thetranscend-mcp-consentbin(usenodebecausepnpm exec transcend-mcp-consentmay not resolve this package’s own binary in a pnpm workspace):
# from the repository root — builds this package and its dependencies (e.g. mcp-server-base)
pnpm exec turbo run build --filter="@transcend-io/mcp-server-consent..."
set -a && source ./secret.env && set +a
pnpm -F @transcend-io/mcp-server-consent exec node ./dist/cli.mjsAlternative: ./scripts/mcp-run.sh ./packages/mcp/mcp-server-consent/dist/cli.mjs (sources secret.env when present; run after build).
See CONTRIBUTING.md for workspace layout and pnpm --filter workflows.
Environment variables
| Variable | Required (stdio OAuth) | Default | Description |
| ------------------------------- | ---------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| TRANSCEND_OAUTH_CLIENT_ID | Yes | — | Client ID from app.transcend.io/admin/oauth-clients |
| TRANSCEND_OAUTH_CLIENT_SECRET | Yes | — | Client secret from the same OAuth clients page |
| TRANSCEND_OAUTH_REDIRECT_PORT | Yes | — | Port number you choose for the OAuth callback server (must be available on your machine); must match the port in your registered redirect URI |
| TRANSCEND_OAUTH_REDIRECT_HOST | No | 127.0.0.1 | Loopback host for the OAuth callback (127.0.0.1 or ::1 for http://[::1]:{port}/callback) |
| TRANSCEND_OAUTH_ISSUER | No | auto-detected | OAuth issuer URL; production auto-detects region. Test-only override |
| TRANSCEND_API_KEY | No | — | API key for stdio (alternative to OAuth). Disables OAuth when set alongside client ID |
| TRANSCEND_API_URL | No | https://api.transcend.io | GraphQL backend API URL (matches CLI convention) |
| SOMBRA_URL | No | https://multi-tenant.sombra.transcend.io | Sombra REST API URL (matches CLI / SDK convention) |
Monorepo: keep these in root secret.env (from secret.env.example); see Run from the monorepo.
Tools
consent_get_preferences— Get consent preferences for a userconsent_set_preferences— Set consent preferencesconsent_list_purposes— List tracking purposesconsent_list_data_flows— List data flowsconsent_list_cookies— List cookiesconsent_list_airgap_bundles— List Airgap bundlesconsent_list_regimes— List consent regimesconsent_get_inventory_stats— Cookie/data-flow inventory triage counts (live, needs review, junk)consent_get_aggregate_analytics— Aggregate consent analytics (airgapBundleAggregateAnalytics)consent_get_timeseries_analytics— Timeseries consent analytics (airgapBundleTimeseriesAnalytics)consent_get_analytics_data— Consent metrics viaanalyticsData(opt-in/out, signals, sessions)consent_update_cookies— Update cookies (approve, junk, assign purposes)consent_update_data_flows— Update data flowsconsent_bulk_triage— Bulk approve or junk cookies and data flows
Analytics tools require the ViewConsentManager scope (included in this server's OAuth scopes). See Consent Analytics Using GraphQL API.
Related packages
Also available as part of the unified @transcend-io/mcp, which includes all domains. See the root README for the full list.
