MCP server
Connect AI assistants to HILLS over the Model Context Protocol: server URL, OAuth sign-in, who can connect and the tools.
The HILLS Music MCP server lets AI assistants that support the Model Context Protocol read your workspace: catalog, release status, streams and revenue, statements and requests. Every call runs as the HILLS account that connected it and sees what that account sees in the workspace.
Connect
| Server URL | https://app.hillsmusic.com/mcp |
| Transport | Streamable HTTP, stateless: POST JSON-RPC messages, JSON responses (no server-sent stream, no session). GET and DELETE answer 405. |
| Sign-in | OAuth 2.1 with your HILLS account (scope read) |
| Rate limit | 120 calls a minute per connected app |
Add the server URL as a remote MCP server (custom connector) in your assistant. It opens a HILLS sign-in, you approve the connection, and the tools appear. Disconnect it any time under Settings, Connected apps in the HILLS web app.
Authorization
HILLS is the OAuth 2.1 authorization server and the MCP endpoint the protected resource. A request without a valid token gets 401 with WWW-Authenticate naming the resource metadata, which is how MCP clients find where to sign in. Clients register themselves (dynamic client registration), the user approves the connection in the HILLS web app, and every tool call runs as that account.
| Resource metadata | https://app.hillsmusic.com/.well-known/oauth-protected-resource/mcp |
| Authorization server metadata | https://app.hillsmusic.com/.well-known/oauth-authorization-server |
Scope read |
Read-only access to your catalog, streams and statements |
| PKCE | S256 only |
| Access tokens | Valid 1 hour |
| Refresh tokens | Valid 30 days, rotated on every use (a reused one ends the connection) |
Who can connect
- Clients (partner accounts) and their team members, the owner and admins: on by default.
- Artists and labels with their own HILLS account, and other staff: when HILLS staff switch it on.
- Artists and labels under a client: never; MCP is the client’s.
- Some tools are for client accounts only; an account that can’t use a tool doesn’t see it.
- A client’s team member needs the role permission each tool lists; staff see what their role permissions open.
Tools
| Tool | What it does | Who gets it |
|---|---|---|
list_members |
List artists and labels | Client accounts and their team only |
payouts |
Balance and withdrawals | Client accounts and their team only |
smartlinks |
Smartlinks | Client accounts and their team only |
list_deliveries |
DDEX deliveries | Client accounts and their team only |
delivery_status |
Delivery status | Client accounts and their team only |
search_catalog |
Search catalog | Every account with MCP access |
release_status |
Release status | Every account with MCP access |
streams_and_revenue |
Streams and revenue | Every account with MCP access |
statements |
Statements | Every account with MCP access |
requests |
Requests | Every account with MCP access |
What assistants are told
The server gives every assistant these instructions when it connects:
HILLS Music distribution data for the signed-in account, read-only. Find releases with search_catalog, then use their ids with release_status and streams_and_revenue. Streams and revenue come from monthly store statements (USD, net of the store’s share), usually 1–3 months behind, so there are no daily or weekly figures — say so when asked for days or weeks and use the latest months instead. Everything is limited to what this account can see in the HILLS workspace.