Skip to main content

Connect a client

For the account tier, use /mcp/account instead. The client runs the OAuth flow on first use.

Raw JSON-RPC

Every call is a POST to the endpoint with Accept: application/json, text/event-stream. No initialization handshake or session header is required, because the server is stateless. List tools
Start a scan with an upload link
The result’s structuredContent carries run_id, access_token and upload_url. Give the upload_url to the person, then poll: Poll the scan
Follow next_action and retry_after_seconds in each response. See scan lifecycle.

Health

If admissions_enabled is false, new scans return admissions_paused, while reads, deletion and the catalog tools keep working.