Developers

Everything your business knows, behind one endpoint.

A knowledge base your systems can talk to. Standard MCP, a small REST API, and a CLI. Every read comes back cited and filtered per requester.

$ zaviro search "when does the Acme MSA renew?"
[doc_412: acme-msa.pdf | Type: contract | Category: legal | Date: 2026-01-15]
12.1 Term. This Agreement renews automatically for successive one-year terms unless either party gives sixty (60) days' written notice.

12.2 Notice. Notice must be in writing and sent to the addresses in Exhibit A.
Sources
[412] acme-msa.pdf — contract · legal · 2026-01-15
Three ways in

Same knowledge base. Pick your surface.

MCP server

/api/mcp

The front door. Streamable HTTP with OAuth (dynamic client registration) or a Bearer key. Read tools for knowledge, entities, facts, documents, and alerts; scoped write tools file work back in. Details below.

REST API

POST /api/v1/query/

Query over plain HTTPS: cited excerpts and structured facts back. Your code does the rest. Idempotent ingest for automations. Read and write are separate credentials. Details below.

CLI

npm i -g @zaviro/cli

The knowledge base from your terminal: search with citations, notes back in, JSON out for scripts. A thin MCP client.

The MCP server

Connected in three steps.

Step 1

Get a key

Sign in and open Deployments. OAuth clients connect with a click-through consent; everything else takes a typed key: zvr_mcp_ to connect and read (MCP or REST), zvr_sk_ to ingest. Shown once, revocable anytime. No separate sandbox: your trial organization is the test environment.

Step 2

Point your client

Add the endpoint to your AI tool. Config snippets for the common clients sit next to the key.

Step 3

Ask

Your AI, your scripts, or your terminal: every read comes back with the sources it stands on.

Claude
ChatGPT
Cursor
VS Code
JetBrains
Zed
Windsurf
OpenClaw
Hermes
Raycast
n8n
+ANY MCP

Read

zaviro_search_knowledge
search the knowledge base, cited
zaviro_get_entity
one entity’s full picture
zaviro_get_structured_facts
aggregated facts, filterable
zaviro_get_document
original file, full text, previews
zaviro_list_alerts
proactive alerts by severity

Write (scoped, rate-limited)

zaviro_ingest_note
file a note from the conversation
zaviro_ingest_document
save a document the AI is holding
zaviro_save_package
save a drafted deliverable, with citations
zaviro_apply_correction
record fixes; future learning respects them
zaviro_update_knowledge
edit entities, relationships, and facts
The API

Retrieval with receipts.

The query endpoint returns cited excerpts and structured facts, extracted and linked at ingest. What your code builds with them is up to you. No SDKs to install: the surface is small enough for curl and any HTTP client. The complete reference is public at zaviro.ai/llms.

The API reference lives inside the product.

POST /api/v1/query/
cited excerpts + structured facts
POST /api/v1/ingest/
files or JSON, 100 MB, idempotent
POST /api/v1/public/query/
own key type zvr_pub_; only docs you mark public are reachable
GET  /api/v1/entity/
one entity’s full picture
GET  /api/v1/facts/
filtered fact aggregation
GET /api/v1/document/{id}/
original file + full text
curl -X POST https://api.zaviro.ai/api/v1/query/ \
    -H "Authorization: Bearer zvr_mcp_..." \
    -H "Content-Type: application/json" \
    -d '{"query": "what are the payment terms in the Acme MSA?"}'
// 200 OK — response shape
{
    "answer_context":   string    // fenced excerpts, most relevant first, with [doc_N] headings
    "source_documents": [{ id, name, url, document_type, category, date, summary }]
    "structured_data":  string    // the aggregation total when there is one, else ""
    "paths_used":       string[]  // e.g. ["aggregation", "simple_lookup"]
}
Idempotent ingest

Re-send the same external_id and the document updates in place. Every REST ingest picks its lane: overnight batch at half the credits, or right now. Built for Zapier, Make, and n8n. Ingest is async: poll GET /api/v1/document/{id}/ for status. No outbound webhooks today.

Honest errors

Paused billing is a clean 402 with a code over REST and a structured status over MCP, never a silent failure. Rate limits return 429 over REST or a retry-after result over MCP, and throttled calls are never charged. Fair-use limits scale with the plan.

One core, two transports

One retrieval core serves both. Same query, same excerpts, same citations, over either transport.

Versioned surface

v1 is in the path. Changes within v1 are additive; a breaking change means a new version, with a migration window.

The CLI

Ask from your terminal.

Install it, point it at your endpoint, and search. Cited results, notes back in, JSON out for scripts.

zaviro configure
endpoint + key, or env vars for CI
zaviro search "..."
cited results, in the terminal
zaviro note add "..."
write back through the full pipeline
zaviro tools
list the MCP tools your AI sees
zaviro completion zsh
bash and zsh tab completion
npm i -g @zaviro/cli
zaviro configure
zaviro search "when does Acme renew?"
zaviro note add "Acme renewal moved to Q3"

--json on every read for scripting. Exit 0 on success, 1 on error, hints on stderr.

What people build

Four shapes, live today.

Agents with real context

Anything that speaks MCP starts from what your business actually knows: search, entities, facts, alerts. Scoped write tools file what it produces back in.

Automations that know your business

Zapier, Make, or n8n: ingest as the step in, query as the step out. Idempotent by external_id, so re-runs update records instead of duplicating them.

A chatbot on your site

POST /api/v1/public/query/ with its own key type. Grounded only in documents you explicitly mark public; internal knowledge is unreachable, and visitor questions are not logged.

Building for clients?

One organization per client, isolated by build. Each organization holds one shared knowledge base. Putting Zaviro inside a product you sell is a conversation: book a demo.

For your security review

Built like you’d build it.

Read-only connections

Read-only OAuth scopes at every source. Zaviro cannot modify what it reads.

Typed, scoped keys

Hashed at rest, shown once. Read scope by default; write is an admin or owner grant. Expiry and instant revocation, every key individually.

Spec-grade OAuth

Audience binding (RFC 8707), dynamic client registration (RFC 7591), a real consent screen.

Isolation in the build

Cross-tenant separation is structural: every tenant query goes through one scoped layer, and code that goes around it fails our build.

Personal stays personal

Keys serve shared knowledge only. Personal scopes are never served to a key, not even its creator’s.

Encrypted everywhere

Hosted on AWS. TLS in transit, encrypted at rest, connector credentials encrypted at the field level, secrets in a managed vault, never in config or code.

Governed writes

Writes only add. Notes, documents, and packages file new records in; corrections and knowledge edits take a signed-in user’s authority, never a bare key. Nothing over MCP can delete a document or an entity. Rate limits on every write tool.

Never trained on

We never use your data to train AI models, and the model providers that process it for us operate under API terms that exclude training on it.

Not yet independently certified: no SOC 2 or ISO today, with controls designed to support SOC 2, GDPR, and PIPEDA. The DPA is public. 2FA ships on every plan, with an organization-wide requirement the owner can enforce; SSO is an Enterprise conversation. Delete your organization and your data goes with it. Security questionnaires, subprocessor list, and data residency: answered in writing.

Pricing

There is no API pricing.

MCP, API, and CLI ship in every plan and draw from the same credit balance as everything else. No gateway tier, no developer add-on, no call-for-pricing for your own organization’s usage. Enterprise adds SSO, security reviews, invoice billing, and custom integrations: that conversation starts at Book a demo.

One endpoint away

Connect a client.
Ask a question.

Connect your business. Watch your AI answer like it’s worked here for years. 14-day trial. Set up in an afternoon. No credit card required.