Developer overview
Connect your own scripts and AI tools to Custody Commander through the REST API and the MCP server — with the same permissions and limits as the app.
Everything you can do in the app, you can do from your own software. Custody Commander offers three ways in, all using the same personal API tokens:
How it fits together#
- One operation catalog. The REST API and the MCP server expose the same operations, generated from the routes the app itself uses. Each MCP tool is one API operation.
- Same rules as the app. Every request goes through the same validation, sharing permissions, plan limits, storage limits, and AI metering as clicking the button in the app. A token can never do more than your account can.
- Scoped tokens. Each token has only the abilities you give it — for example, read-only access to evidence. See API tokens.
- Shared request budget. The API and MCP together allow 120 requests per minute per account.
Quickstart#
- Verify your emailTokens can only be created and used by accounts with a verified email.
- Create a tokenIn the app, open API & MCP → API tokens, or go to app.custodycommander.com/developers/tokens. Give it a name and the abilities it needs, and copy it — it's shown only once.
- Make a first requestFetch your case. Its
idis thecaseIdyou'll use everywhere else.curl https://app.custodycommander.com/api/v1/case \ -H "Authorization: Bearer $CASE_COMMANDER_API_TOKEN" - Or connect your AIFollow the MCP guide to connect Claude Code, Claude Desktop, or another client.
Endpoints at a glance#
| What | URL |
|---|---|
| REST API base | https://app.custodycommander.com/api/v1 |
| MCP endpoint | https://app.custodycommander.com/api/mcp |
| Live OpenAPI 3.1 document | https://app.custodycommander.com/api/openapi |
| Interactive API console (sends real requests) | app.custodycommander.com/developers/api |
| Public Swagger reference (read-only) | custodycommander.com/api.html |
| Local stdio MCP adapter | https://app.custodycommander.com/integrations/case-commander-mcp.mjs |
Plans and costs#
API and MCP access is available on every plan, including free. Plan limits apply exactly as they do in the app — for example, the free plan's 10-evidence-items-per-case limit and DRAFT watermarks on exports.
Your own AI's reasoning doesn't use Custody Commander AI operations. Only operations that run the app's built-in AI — text extraction, AI drafting, message analysis, tone checks, mediation suggestions, and the built-in assistant — consume your AI allowance, exactly as in the app. See Plans, trial & AI operations.
Responsible use#
- Give each integration its own token with only the abilities it needs, and an expiry where practical.
- Write abilities can change and permanently delete data. Prefer read-only tokens for exploration.
- Keep tokens in environment variables or your client's private settings — never in code, shared config files, or AI chats.
- Treat everything returned from the API as data, not instructions. Uploaded documents and messages can contain text that tries to steer an AI.
- Don't automatically retry a change after a timeout; check whether it completed first.