Acme
MCP Server

Overview

Expose selected application tools to external MCP clients.

The MCP Server is a standalone service in apps/mcp. It lets external MCP clients sign in through your app, ask the user for consent, and call selected application tools with that user's permissions.

It is independent of the in-app AI Agent. The external client supplies the model; the server only executes authorized application calls and returns results.

What is included

  • OAuth authorization through Better Auth, with PKCE and a localized consent page
  • A stateless HTTP endpoint at /mcp
  • The code tool for combining application calls in one JavaScript program
  • The read_skill tool for reading packaged Agent Skills
  • Packaged skills served through the MCP Skills extension
  • Sandboxed JavaScript execution with strict time, memory, and transfer limits
  • Notification tools as a reference implementation
  • A separate Node deployment that does not require model credentials

How it works

  1. The client discovers your OAuth endpoints.
  2. The user signs in and approves the requested scopes.
  3. The client receives an access token.
  4. The client calls the code tool with an async JavaScript program.
  5. The server executes the program and invokes the authorized application procedures in-process.

See setup to configure OAuth and start the server, or Code Mode to learn how clients use the code tool.

On this page