A private knowledge base as your own RAG for AI agents, with zero infrastructure
Every serious AI agent eventually hits the same wall: it needs to know things that only exist in your documents. Your procedures, your client specs, your pricing rules, your notes. The usual answer is to build a RAG stack, and that quickly turns into a side project of its own. This guide shows a shorter path: keep your documents in a private knowledge base on Kopik and plug it into your agents over a REST API or MCP. No database to provision, no ingestion pipeline to run, no server to host, and your own questions are free.
Why agents need grounded retrieval
A language model answers from what it learned during training plus whatever sits in its context window. Ask it about your internal refund policy and it will either admit it does not know or, worse, produce something plausible. Retrieval-augmented generation (RAG) fixes this by fetching relevant excerpts from a trusted corpus at question time and handing them to the model. If the idea is new to you, start with what is RAG.
For agents, grounding matters even more than for chat. An agent chains steps: it checks a rule, drafts an email, updates a ticket. One invented fact early in the chain contaminates everything after it. Giving the agent a retrieval tool it can call on its own, with citations it can pass along, is what turns a clever demo into something you can trust with real work.
Build vs buy: what a RAG stack actually involves
Building your own RAG backend is a great learning exercise. Running it in production is another matter. Here is what you would typically have to assemble and keep alive, compared with what a private Kopik base handles for you.
The pieces of a RAG backend
| Component | If you build it | With a private Kopik base |
|---|---|---|
| Document parsing | Extract text from PDF, Word, HTML, CSV… | Upload the file or paste text |
| Chunking | Pick sizes and overlap, handle edge cases | Passages of about 1,200 characters, with overlap |
| Index | Run a vector database or a search engine | Full-text search, managed for you |
| Ingestion pipeline | Jobs to re-process files when they change | Indexed immediately on upload |
| Query layer | Rewrite queries, rank, return passages | Query expansion by a small model, top 8 passages |
| Answer generation | Prompting, citations, refusal when nothing is found | Built-in answer mode with numbered citations |
| Access | Auth, API keys, an MCP server | REST API and MCP with your API key |
| Operations | Hosting, monitoring, backups, upgrades | Nothing to run |
Most tutorials reach for a vector database with embeddings; that is one valid technique among several, and we compare the options in how a RAG pipeline works. Kopik takes a different route, described below. The point here is not that building is wrong, but that for a lot of teams the retrieval layer is plumbing, and plumbing is best when someone else maintains it.
How a private Kopik base works
Kopik is the library of expert knowledge bases for AI, but every base starts out as yours, and you choose its visibility: public, unlisted or private. A private base is visible to its owner only. In practice, it is your own RAG backend.
What you can put in it
- Formats: PDF with a text layer (up to 1,500 pages), Word .docx, TXT, Markdown, CSV, TSV, JSON, HTML and XML, or pasted text.
- Per file: 4 MB maximum and 2 million characters per document.
- Per base: up to 1,000 documents and 20 million characters. An account can hold 20 bases.
- Growth: each upload is split into passages and indexed right away, so the base grows as you add documents.
How retrieval works
Each base has a document language: English, French, German, Spanish, Italian, Portuguese, Dutch, or mixed/other. It tunes the full-text search (stemming, stop words), so pick the language your documents are written in. Changing it later re-indexes the base, which is limited to a few times per hour.
When a question arrives, a small language model first expands it into keywords and synonyms in the language of the documents. That is why a question asked in English can still find passages in a French base. Kopik then runs a PostgreSQL full-text search and keeps the 8 most relevant passages. There is no vector database and no embeddings involved. In answer mode, a language model writes the reply using only those passages, with numbered citations like [1] and [2]. If the base does not contain the answer, it says so instead of guessing.
Your own questions are free
As the owner, you can query your bases from the website, the REST API and MCP at no cost, with a fair-use limit of 200 questions per day. Your own questions do not count in the catalogue ranking either.
Passages mode or answer mode?
The query endpoint returns one of two things. For an agent that already has its own model and prompt, passages mode is usually the better fit: you get the raw excerpts and feed them to your model, which keeps full control over tone, format and reasoning. Answer mode is the shortcut when you simply want a finished, cited answer.
| passages | answer | |
|---|---|---|
| What you get | The most relevant excerpts | A written answer with numbered citations |
| Who writes the final text | Your model | Kopik |
| Best for | Agents that combine sources or follow a strict output format | Scripts, simple bots, quick lookups |
| When nothing matches | Your agent decides what to do | The answer says the base does not cover it |
Query your private base over the REST API
Create an API key in your dashboard. It starts with kpk_ and is sent as a Bearer token. Then send a POST request to the query endpoint of your base, identified by its slug:
Example request
curl -X POST https://kopik.io/api/v1/bases/my-base/query -H "Authorization: Bearer kpk_…" -H "Content-Type: application/json" -d '{"question": "What is our refund window for annual plans?", "mode": "passages"}'
The body takes a question and a mode (answer or passages). The response also includes costCents and balanceCents, which for your own base simply confirm that nothing was charged. Errors come back as {error, code}, with codes such as api_key_invalid, base_not_found, base_empty or rate_limited, so your agent can branch on them. Set the header x-kopik-locale to en or fr to choose the language of error messages. The full reference lives in the developer documentation.
Connect it to your agents over MCP
If your agent runs in an MCP client, you do not even need to write the HTTP call. Kopik exposes a Streamable HTTP MCP server, and each base has its own URL: https://kopik.io/api/mcp?base=my-base. That endpoint provides two tools pre-targeted to the base: search_base, which returns passages, and ask_base, which returns a cited answer. Authentication uses the same header: Authorization: Bearer kpk_…
In Claude Code, one command registers the base. Keep the URL in quotes, otherwise shells such as zsh try to interpret the question mark: claude mcp add --transport http kopik-my-base "https://kopik.io/api/mcp?base=my-base" --header "Authorization: Bearer kpk_…"
Cursor and most other MCP clients read a JSON configuration with the same two pieces of information, the URL and the header: {"mcpServers": {"kopik-my-base": {"url": "https://kopik.io/api/mcp?base=my-base", "headers": {"Authorization": "Bearer kpk_…"}}}}. Claude, Cursor, ChatGPT or an agent you wrote yourself: the base behaves the same way everywhere. For a deeper look at the protocol, read connecting a knowledge base with MCP.
Give your agents a memory in five minutes
Create a private base, upload your documents and query it from your agents over REST or MCP. Free for your own questions.
Security: what stays private
- Owner-only access. A private base can be queried by its owner and nobody else, on every channel.
- Hashed API keys. Keys are stored hashed and shown only once, when you create them. Keep them in environment variables or a secret manager, and revoke any key that leaks.
- Scoped use of your documents. Your documents are only used to answer questions on that base.
- Prompt-injection protection. Over MCP, content from a base is wrapped in <kopik-untrusted> tags with a note telling the agent to treat it as data, never as instructions. That matters as soon as your documents include text written by third parties, such as emails or supplier contracts.
Limits to design around
Kopik limits for agent builders
| Limit | Value |
|---|---|
| Questions per user | 20 per minute, 1,000 per day |
| Free owner questions | 200 per day (fair use) |
| When a limit is hit | HTTP 429, code rate_limited (with Retry-After when the per-IP limit is hit) |
| MCP batches | 10 requests maximum |
| Bases per account | 20 |
| Documents per base | 1,000, and 20 million characters |
| Uploads | 120 per hour |
For an agent that loops, the practical advice is simple: wait before retrying (honour Retry-After when present), cache answers to questions it asks repeatedly, and prefer one precise question over ten vague ones.
Honest limitations
- Retrieval is keyword-based. Query expansion adds synonyms, but the search still matches words. Documents that use clear, explicit vocabulary and headings retrieve better. Our guide on preparing documents for AI shows how.
- The document language matters. A base set to the wrong language gets poorer stemming and stop-word handling. Use mixed/other only when your corpus really mixes languages.
- Scanned PDFs cannot be read. A PDF made of images has no text layer. Run it through OCR first, or export the source document.
- Answers can be wrong. Citations let you or your agent check the source, and nothing Kopik returns is legal, medical or financial advice. Keep a human in the loop for decisions that matter.
Later: open the base to others
Some private bases turn out to be valuable to others: a well-curated regulatory corpus, a methodology, a technical reference. You can switch a base to unlisted (reachable by link only, with a long random identifier) or public (listed in the catalogue) at any time. Subscribers can then chat with it on the website, and other people’s agents can query it over the API and MCP at the per-request price you set. You receive a fixed share of every subscriber question asked to your base and 70% of every paid API or MCP request. Your own questions stay free.
Other people's agents can call your base safely too: the optional maxPriceCents parameter lets them set a price ceiling, and if the base costs more, the call is refused with code price_above_max and nothing is charged. Only document names are shown on the public page, never their full content. How creators are paid is covered in sharing your expertise as a knowledge base, and the building side in building a knowledge base from your documents.
Read the API and MCP reference
Endpoints, error codes, MCP tools and configuration examples for every client.
Frequently asked questions
Can I use a private Kopik base as a RAG backend for my own AI agent?
Yes. A private base is visible to you only, and you can query it from the website, the REST API and MCP with your own API key. Use passages mode to feed the excerpts to your own model, or answer mode to get a finished answer with citations.
Is it really free to query my own base?
Yes. Questions you ask to your own bases are free on every channel, within a fair-use limit of 200 questions per day. The general per-user limits of 20 questions per minute and 1,000 per day still apply.
Does Kopik use a vector database or embeddings?
No. Kopik uses PostgreSQL full-text search tuned to the document language. Before searching, a small language model expands the question into keywords and synonyms, and the 8 most relevant passages are kept.
Which AI clients can connect to my base over MCP?
Any client that supports remote MCP servers over HTTP with a custom header, such as Claude, Cursor, ChatGPT or an agent you build with an MCP SDK. You give it the per-base URL and an Authorization header with your API key.
What happens if my documents are scanned PDFs?
Scanned PDFs are images without a text layer, so Kopik cannot read them. Run them through OCR first, or upload the original Word or text version of the document.
Can I make my private base public later?
Yes. You can switch it to unlisted or public at any time and set a per-request price for API and MCP calls. You then receive a fixed share of every subscriber question asked to it in the website chat and 70% of every paid API or MCP request. Your own questions remain free.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.