Docs
Integrate

Connect to MCP

Discover and call the app's authenticated Model Context Protocol endpoint.

Connect to MCP

The app exposes an authenticated HTTP MCP endpoint at /mcp. A bearer access token is required. Production deployments never allow unauthenticated MCP requests; local development should use a test credential as well.

Discover the server

Use the server card and protected-resource metadata:

GET /.well-known/mcp/server-card.json
GET /.well-known/oauth-protected-resource

The server advertises tools and the versioned MCP Apps content resource; it does not advertise prompts. Tool names, input schemas, and widget metadata are registered by the application and the @repo/mcp-server package.

Call the endpoint

Send Streamable HTTP JSON-RPC requests to the endpoint from the server card with:

POST /mcp
Authorization: Bearer <access_token>
Content-Type: application/json
Accept: application/json, text/event-stream
MCP-Protocol-Version: 2025-11-25

{"jsonrpc":"2.0","id":"1","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"client","version":"1"}}}

After initialization, use POST requests with tools/list and tools/call JSON-RPC messages, for example:

{"jsonrpc":"2.0","id":"2","method":"tools/list","params":{}}
{"jsonrpc":"2.0","id":"3","method":"tools/call","params":{"name":"show_content","arguments":{"name":"Ada"}}}

The exact tenant origin and current protocol version come from discovery/runtime negotiation; the version above is the current SDK default and clients should fall back to a version they advertise as supported.

Authenticate with one of:

  • an operator token (Authorization: Bearer opt_...) for account-owned automation and tools;
  • Agent authentication for external agents registered through the auth.md contract;
  • an OAuth MCP access token for connector flows.

Treat 401 responses and the WWW-Authenticate challenge as a signal to restart discovery and authentication. Retired personal account tokens (cet_...) return an actionable 401 pointing at /account/settings/operators.

On this page