mcp
Agent-facing MCP JSON-RPC gateway. Generic `tools/list` / `tools/call`
Authorization rules (docs/MCP_GATEWAY_AGENT_AUTH.md §2.4), all failing closed:
- bearer token missing/unknown/revoked → 401
tools/list(and initialize/ping) → allowed with agent-only identitytools/callwith no/unknown/dead-flow traceparent → 403tools/callwhere the agent is not a recorded flow participant → 403- identity store unreachable → 403
POST
Agent-facing MCP JSON-RPC gateway. Generic `tools/list` / `tools/call`
Headers
Bearer <MCP_GATEWAY_TOKEN> — the per-agent gateway credential injected into the container env at deploy time
W3C trace context naming the flow this call belongs to — required for tools/call; the user identity is resolved from the flow record
Body
application/json
JSON-RPC 2.0 request: tools/list or tools/call
The body is of type object.
Response
JSON-RPC 2.0 response (result or error object)
The response is of type object.
