Connect a client
/mcp/account instead. The client runs the OAuth flow on first use.
Raw JSON-RPC
Every call is aPOST to the endpoint with Accept: application/json, text/event-stream. No initialization handshake or session header is required, because the server is stateless.
List tools
structuredContent carries run_id, access_token and upload_url. Give the upload_url to the person, then poll:
Poll the scan
next_action and retry_after_seconds in each response. See scan lifecycle.
Health
admissions_enabled is false, new scans return admissions_paused, while reads, deletion and the catalog tools keep working.