Expand description
MCP over Streamable HTTP, hand-rolled JSON-RPC 2.0.
Stateless: no Mcp-Session-Id, and tools/call works without a prior
initialize, so the CLI can make one call per connection. Every answer is
plain application/json; the server never streams and never initiates, so
GET /mcp (the server-to-client SSE stream) is 405.
Structs§
- Audited
- What the audit hook hears: a tool call, admitted or refused, or a
terminal opening (
terminal.open) and closing (terminal.close). - Hooks
- What the embedder plugs into every listener.
- Registry
- Every tool the server offers, before any listener’s policy.
- Tool
- One MCP tool.
handlergets the call’sarguments(an object,{}when omitted). AnErris reported to the client as a tool result withisError: true, as MCP specifies, not as a protocol error. - Tool
Policy - Which tools a listener exposes: the allow list (empty = all), then the deny
list, which always wins. Entries are exact names or shell-style globs
(
*,?,[a-z],[!x]).
Enums§
- Authenticated
- Caller
- Who made a call. Handlers use it for audit logs and to hold remote callers to a stricter policy than the local CLI.
Constants§
- PROTOCOL_
VERSIONS - The MCP protocol versions
isb servespeaks, newest first; an unknown client version is answered with the first.
Functions§
- ambient_
ok - Defences for a caller whose credential the browser sends by itself (a tailnet identity, like a cookie), so a page open on a tailnet machine cannot drive the API:
- glob_
match - Shell-style glob over the whole name. Linear backtracking over the last
*, so a hostile pattern cannot blow up. - origin
- Where a request came from, for the audit log: the surface (
cliover the unix socket,mcp,webfor a browser session, elserest), the client’s address and agent, and a request id (X-Request-Idwhen it is sane, elseCf-Ray, else a fresh one). - origin_
is_ local Originof a page on this machine. Without Access, a page on any other origin is a DNS-rebinding attempt to reach the loopback port.
Type Aliases§
- Audit
- Records what happened; it must not fail the call.
- Authn
- Who is calling, from an API token or session (
Authorization: Bearer, or the session cookie) or from a verified Access identity. - Authorize
- May
callerruntoolwith these arguments? Returns the arguments to use (an org-scoped endpoint pinsorg), or the refusal, reported as a tool error.scopeis the org of an/orgs/<org>/...endpoint. - Events
- The body of
GET /api/v1/events: a stream of server-sent events for this caller, starting aftersince(from?since=orLast-Event-ID). - Listed
- Is
toollisted tocallerhere? Fortools/listonly;Authorizejudges calls. - Route
- Runs an admitted call elsewhere (a control plane forwarding it to the
server that holds the org):
Someis its outcome,Noneruns the tool here. Called after authorization and before the audit record. - Tool
Handler