Sewa Setu — Old Age Pension Portal

Department of Social Welfare · Government of Purvanchal

← All documentation

MCP install and connect

Connect Claude Code, Cursor, or any MCP client to the Seva Setu citizen and officer servers.

Live endpoints

RoleURL
Citizenhttps://seva-setu.ruchir.dev/mcp/citizen
Officerhttps://seva-setu.ruchir.dev/mcp/officer

Transport is streamable HTTP. Both advertise RFC 9728 protected-resource metadata.

OAuth 2.1

Every MCP call needs a Bearer access token from this portal's authorization server.

  1. Discover the AS at https://seva-setu.ruchir.dev/.well-known/oauth-authorization-server.
  2. Authorize with PKCE S256.
  3. Request scope=citizen for the citizen server, or scope=officer for the officer server.
  4. Set resource to the MCP URL you will call. The token audience must match.

Citizen login is 10-digit mobile plus OTP. Read the OTP at /__gateway/. Citizen sessions last 2 hours from consent. Officer login uses the departmental admin account. Officer sessions last 8 hours.

Admin credentials for officer flows:

Claude Code / Cursor config

{
  "mcpServers": {
    "seva-setu-citizen": {
      "type": "http",
      "url": "https://seva-setu.ruchir.dev/mcp/citizen"
    },
    "seva-setu-officer": {
      "type": "http",
      "url": "https://seva-setu.ruchir.dev/mcp/officer"
    }
  }
}

Claude Code CLI:

claude mcp add --transport http seva-setu-citizen \
  https://seva-setu.ruchir.dev/mcp/citizen
claude mcp add --transport http seva-setu-officer \
  https://seva-setu.ruchir.dev/mcp/officer

Cursor: save the JSON in ~/.cursor/mcp.json or project .cursor/mcp.json. The client discovers OAuth from the MCP URL. Do not hard-code a Bearer token unless you minted a program token at /admin/tokens for officer use.

Why a browser GET shows 401

Paste an MCP URL into a browser and you get HTTP 401. That is correct. The resource server requires a Bearer token. A browser GET is not an authenticated MCP session. Use an MCP client over streamable HTTP after OAuth completes.

Unauthenticated POST responses include WWW-Authenticate pointing at /.well-known/oauth-protected-resource/mcp/citizen or /.well-known/oauth-protected-resource/mcp/officer.

Local compose URLs

RoleURL
Citizenhttp://localhost:8001/mcp/citizen
Officerhttp://localhost:8002/mcp/officer
Through gatewayhttp://localhost:8080/mcp/citizen and /mcp/officer

Swap the live URLs in the JSON snippet for these when developing locally. Keep PUBLIC_BASE_URL, CITIZEN_MCP_URL, and OFFICER_MCP_URL aligned with what the client calls so issuer and audience match.

Citizen tools

get_scheme_info, check_eligibility, apply_for_pension, get_my_application, withdraw_application

Agent apply is limited to Sonari, Rajapara, and Namti.

Officer tools

list_pending_queue, get_application_details, approve_application, reject_application