Skip to content

MCP

MCP server card

GET/mcp/server-card

The server’s card, as application/mcp-server-card+json: its registry name (the public host in reverse DNS), transport, URL, the Authorization header it takes, the protocol versions it speaks, and its tools. It follows the experimental MCP server card extension. /.well-known/mcp/server-card.json and /.well-known/mcp.json answer with the same card for clients that look there.

#Authentication

Agent key

An agent-scoped key (ask_...) bound to exactly one agent, or an OAuth access token (aat_...) issued to an MCP client for that agent, sent as Authorization: Bearer. An agent key may ask, poll and settle. It can never approve, widen a mandate or lift a freeze.