System

Model Context Protocol endpoint

Changed on

Streamable-HTTP MCP endpoint: one JSON-RPC 2.0 object per request, one response per request. There is no server-to-client stream, so a GET returns 405, and a batched array is rejected.

Authenticated with a project access token. The endpoint takes its project from the credential, so a platform token is refused with 403 — it names no project, and letting a tool argument choose one would hand an agent its own blast radius.

Scope carries over from the REST API. A read_only token is not offered mutating tools or credential-returning reads, and is refused if it calls one anyway. Revoking the token ends MCP access on the same path it ends API access.

Methods: initialize, notifications/initialized, ping, tools/list, tools/call. See the MCP guide for the tool surface and client configuration.

post/mcp

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/mcp
  • Auth: HTTP bearer

Request body

jsonrpc'2.0' required
methodstring required

The MCP method to call.

paramsobject

Response

A JSON-RPC response object

jsonrpc'2.0' required
resultobject

Changes