MCP Server
Overview
Expose selected application tools to external MCP clients.
The MCP Server is a standalone service in apps/mcp. It lets external MCP clients sign in through your app, ask the user for consent, and call selected application tools with that user's permissions.
It is independent of the in-app AI Agent. The external client supplies the model; the server only executes authorized application calls and returns results.
What is included
- OAuth authorization through Better Auth, with PKCE and a localized consent page
- A stateless HTTP endpoint at
/mcp - The
codetool for combining application calls in one JavaScript program - The
read_skilltool for reading packaged Agent Skills - Packaged skills served through the MCP Skills extension
- Sandboxed JavaScript execution with strict time, memory, and transfer limits
- Notification tools as a reference implementation
- A separate Node deployment that does not require model credentials
How it works
- The client discovers your OAuth endpoints.
- The user signs in and approves the requested scopes.
- The client receives an access token.
- The client calls the
codetool with an async JavaScript program. - The server executes the program and invokes the authorized application procedures in-process.
See setup to configure OAuth and start the server, or Code Mode to learn how clients use the code tool.