MCP
MCP server card
GET
/mcp/server-cardThe server’s card, as application/mcp-server-card+json: its registry name (the public host in reverse DNS), transport, URL, the Authorization header it takes, the protocol versions it speaks, and its tools. It follows the experimental MCP server card extension. /.well-known/mcp/server-card.json and /.well-known/mcp.json answer with the same card for clients that look there.
#Authentication
Agent key
An agent-scoped key (ask_...) bound to exactly one agent, or an OAuth access token (aat_...) issued to an MCP client for that agent, sent as Authorization: Bearer. An agent key may ask, poll and settle. It can never approve, widen a mandate or lift a freeze.