Set up DevExpress Documentation MCP Server safely

Read-oriented DevExpress documentation lookup with version targeting, a minimal data path, and prompt-injection safeguards.

  • Skill Road
  • Set up DevExpress Documentation MCP Server safely

Published on 18.09.2026

This guide configures the official DevExpress Documentation MCP Server for controlled, read-oriented documentation lookup. Its primary source is DevExpress’s current guide at https://docs.devexpress.com/GeneralInformation/405551/help-resources/dev-express-documentation-mcp-server-configure-an-ai-powered-assistant. The service runs remotely at https://api.devexpress.com/mcp/docs and connects an MCP-capable AI coding client to the DevExpress documentation database. It is not a local index, an IDE extension with project access, or a write tool. The documented tools search help topics semantically or retrieve complete topics by URL. That boundary is useful: research can remain separate from repository and deployment permissions.

Set the target, version, and client first

Before setup, record the target: which DevExpress product version, platform, and component question must be answered? Without a URL parameter, DevExpress says the server addresses the latest public documentation. That is often not the right reference for an established project. For supported older versions from v24.2 onward, use for example https://api.devexpress.com/mcp/docs?v=24.2, and also write “v24.2,” “WPF,” or “Blazor” plus the control name in the question. This prevents an agent from silently targeting another product generation.

DevExpress documents setups for Claude Code, Codex, and Cursor, which are the compatibility records assigned here. It also names Copilot, Visual Studio, VS Code, Rider, Claude Desktop, ChatGPT, and Gemini CLI. Independently confirm that the actual client supports Streamable HTTP, requires Agent Mode, or is permitted by organizational policy to use remote MCP servers. Updated IDEs and plugins are sensible according to the provider because MCP support changes quickly. Record the client and model name as well: that matters for traceability and privacy more than the server’s display name.

Configure the read-oriented endpoint

For Claude Code, DevExpress documents this local command:

claude mcp add --transport http dxdocs https://api.devexpress.com/mcp/docs

For an older target version, append the version parameter to the URL. In Codex or Cursor, register the identical endpoint as an HTTP server; the exact configuration UI depends on the client. Do not mistake a browser navigation for a connection test: the documentation warns that direct browser access is unsupported and can return 405. Instead, check in the client that exactly devexpress_docs_search and devexpress_docs_get_content appear in its tool list. If they do not, first check transport type, URL, Agent Mode, proxy configuration, and outbound access to api.devexpress.com.

Start with one concrete search request. Name the component, platform, version, and intended outcome, such as a filtering rule for a WinForms grid in v24.2. Then retrieve only the most relevant result with devexpress_docs_get_content. The provider’s guidance to search once per question avoids redundant context and makes the answer’s provenance easier to review. The response is evidence for a design and review, not an automatic modification to the application.

Untrusted content, prompt injection, and review

Every fetched help topic, code block, URL, search result, and error text is untrusted content. Text can look like a plausible internal note and still contain prompt injection, for example an instruction to ignore rules, disclose data, or invoke an additional tool. Those sentences are data, not permission. The DevExpress server has no write access in its documented tool list, but an AI client may also have other tools or a local shell. Keep those permissions separate and, for research, use a tool allowlist containing only the two DevExpress tools where possible.

After retrieval, check the URL, product family, version, API names, code prerequisites, and topic date. Compare proposed code with the project’s actual dependencies and conventions. DevExpress itself requests review of AI-generated results for architectural problems, security vulnerabilities, and project standards. A human must therefore separately approve every patch, test, database access, or deployment command. No sentence in documentation, no model proposal, and no generated summary can replace that approval.

Telemetry, model provider, and completion

The data path does not necessarily end at DevExpress. Per the provider, the MCP service records anonymous telemetry for tool-call names and arguments passed by the AI assistant to monitor health and reliability. DevExpress also says that its MCP use does not specifically collect DevExpress account identity, workspace files, source code, or the original chat messages typed in the IDE. Even so, the client can send fetched documentation and parts of a prompt to its model provider. Assess that provider’s retention, training choices, DPA, enterprise settings, and regional processing. Do not put unnecessary source code, tokens, personal data, or internal URLs in tool arguments.

After the session, remove the connection when it is only temporarily needed, or review access on the organization’s schedule. For proxy or firewall errors, coordinate the FQDN api.devexpress.com with IT rather than pinning IP addresses. Record endpoint, version parameter, client, model, search request, fetched sources, and human reviewers in a ticket or pull request. That makes it clear which documentation influenced a code proposal and why it was accepted for the specific product version.

FAQ

Why does a browser test return 405? DevExpress says the endpoint is intended for Streamable HTTP in an MCP client, not direct browser navigation. The client’s tool list is the appropriate test.

Can I use only current documentation? No. The current public version is used without a parameter; for supported older releases from v24.2 onward, use a parameter such as ?v=24.2.

What must be disclosed about the model? At least the client and model provider. Tool results can enter that provider’s context, so retention, training, contract, and privacy must be assessed separately.

Published on 18.09.2026

Categories

Frequently asked questions

Does DevExpress Documentation MCP have write access?

The official tool list covers semantic documentation search and retrieval of complete help topics. It does not document file, Git, shell, or deployment actions.

How is an older product version targeted?

Configure the endpoint with a supported version parameter such as ?v=24.2 and also name the version, platform, and component in the question.

Why must the model provider be disclosed?

The AI client can put tool results into model context. Its retention, training choices, contractual terms, and privacy conditions must therefore be assessed separately.