Skip to main content

Module mcp

Module mcp 

Source
Expand description

MCP over Streamable HTTP, hand-rolled JSON-RPC 2.0.

Stateless: no Mcp-Session-Id, and tools/call works without a prior initialize, so the CLI can make one call per connection. Every answer is plain application/json; the server never streams and never initiates, so GET /mcp (the server-to-client SSE stream) is 405.

Structs§

Audited
What the audit hook hears: a tool call, admitted or refused, or a terminal opening (terminal.open) and closing (terminal.close).
Hooks
What the embedder plugs into every listener.
Registry
Every tool the server offers, before any listener’s policy.
Tool
One MCP tool. handler gets the call’s arguments (an object, {} when omitted). An Err is reported to the client as a tool result with isError: true, as MCP specifies, not as a protocol error.
ToolPolicy
Which tools a listener exposes: the allow list (empty = all), then the deny list, which always wins. Entries are exact names or shell-style globs (*, ?, [a-z], [!x]).

Enums§

Authenticated
Caller
Who made a call. Handlers use it for audit logs and to hold remote callers to a stricter policy than the local CLI.

Constants§

PROTOCOL_VERSIONS
The MCP protocol versions isb serve speaks, newest first; an unknown client version is answered with the first.

Functions§

ambient_ok
Defences for a caller whose credential the browser sends by itself (a tailnet identity, like a cookie), so a page open on a tailnet machine cannot drive the API:
glob_match
Shell-style glob over the whole name. Linear backtracking over the last *, so a hostile pattern cannot blow up.
origin
Where a request came from, for the audit log: the surface (cli over the unix socket, mcp, web for a browser session, else rest), the client’s address and agent, and a request id (X-Request-Id when it is sane, else Cf-Ray, else a fresh one).
origin_is_local
Origin of a page on this machine. Without Access, a page on any other origin is a DNS-rebinding attempt to reach the loopback port.

Type Aliases§

Audit
Records what happened; it must not fail the call.
Authn
Who is calling, from an API token or session (Authorization: Bearer, or the session cookie) or from a verified Access identity.
Authorize
May caller run tool with these arguments? Returns the arguments to use (an org-scoped endpoint pins org), or the refusal, reported as a tool error. scope is the org of an /orgs/<org>/... endpoint.
Events
The body of GET /api/v1/events: a stream of server-sent events for this caller, starting after since (from ?since= or Last-Event-ID).
Listed
Is tool listed to caller here? For tools/list only; Authorize judges calls.
Route
Runs an admitted call elsewhere (a control plane forwarding it to the server that holds the org): Some is its outcome, None runs the tool here. Called after authorization and before the audit record.
ToolHandler