Skip to content

MCP

MCP server

POST/mcp

The MCP server agents connect to as tools: Streamable HTTP, JSON-RPC 2.0, protocols 2025-06-18, 2025-03-26 and 2024-11-05, stateless. Authenticate with an agent key or an OAuth access token; authentication comes before anything else, including initialize.

Tools: authorize_action, request_payment, request_personal_data, check_action_status, explain_decision and settle_action. Batches are not supported.

#Authentication

Agent key

An agent-scoped key (ask_...) bound to exactly one agent, or an OAuth access token (aat_...) issued to an MCP client for that agent, sent as Authorization: Bearer. An agent key may ask, poll and settle. It can never approve, widen a mandate or lift a freeze.