Model Context Protocol HTTP endpoint
Verified human Clerk sessions or agent OAuth tokens with exact MCP resource audience. Stateless MCP supports July 2026 per-request envelopes and legacy November 2025 POST compatibility. Authorization is verified before tool discovery; individual tools retain human/agent/scope restrictions.
/mcpAuthorizationOAuth2 access token · headerrequiredOAuth 2.0 authorization-code flow with PKCE S256 over the AgentSub resources; token audience must match the MCP resource.
agentsub:agentAuthorizationBearer token (JWT) · headerrequiredClerk human owner session JWT; iss must equal the configured Clerk issuer and the identity must be a human (not agent) owner with a verified email.
AuthorizationOAuth2 access token · headerrequiredagentsub:ownerMCP protocol response (JSON or SSE stream)
unauthorized problem; live 401s advertise WWW-Authenticate: Bearer resource_metadata=...
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredIdentity, ownership, scope or policy denied (human_required, owner_claim_required, scope_required, FROZEN, CAP_EXCEEDED, SCOPE_FORBIDDEN)
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredRuntime or provider configuration unavailable (runtime_configuration_required, signing_configuration_required, runtime_unavailable, workspace_unavailable, provider_configuration_required)
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequired