id. See
Authentication and grants for how you issue them.
The endpoint URL ends with the current publication revision. Read it after each
push:
https://<your deployment name>.bijection.site/mcp/<revision>.
When you push a change, give clients the new URL.
Trying the endpoint
The endpoint is a stateless JSON-RPC endpoint over HTTPPOST. You can list its
tools with curl:
Read-only clients
Any MCP client that can send a bearer token to a remote HTTP server can discover tools and call query and status tools. Give it the endpoint URL and a token. Operation tools are different. Each operation call needs a request key that stays the same across retries, and a model can’t be trusted to invent one. A client that doesn’t supply the key and grantid can’t call operation tools;
those calls fail with request_scope_mismatch.
Recoverable writes
Thebijection/mcp/node module gives an agent host what it needs to call
operation tools safely. It runs in your agent’s Node.js process, not in your
deployment. Don’t import it from your bijection/ folder.
agent/connection.ts
publicationUrlis the endpoint URL. It must end with the revision and use HTTPS, or HTTP on a loopback address.deploymentUrlis your deployment’s.bijection.cloudURL. It is used for recovery and status, which call your operation’s recovery functions directly and keep working after the endpoint URL changes.getTokenis called for every HTTP request, so tokens can be refreshed freely. Tokens are never written to the store.storepersists each write’s request before it is sent.
The call
id must stay the same when your host replays a step, for example a
persisted workflow step identity. Calling an operation tool again with the same
id returns the same invocation.
Request stores
McpRequestJournal is a small file-based store that syncs each record to disk
before the request is sent. Put its directory on durable storage. For
production hosts, implement the McpRequestStore interface on your own
database:
prepare must atomically keep one immutable record per call ID, return the same
request key when called again with the same input, and reject a call ID reused
with different arguments, grant or endpoint. load must survive a process
restart. Never store credentials in it.
Mastra
Pass the connection’sfetch to Mastra’s MCP client. Create one client per tool
call ID:
agent/mastra.ts
Eve
Eve persists its own session and call identity. UseeveMcpRequest as a
provided argument; Eve hides it from the model and adds it to each call:
agent/connections/tasks.ts
Other clients
If you build your own client, send the request identity in the tool call’s_meta, never in the model’s arguments:
"mode": "recover" to look up an earlier call with the same key and
arguments without invoking the operation. Persist the key before sending the
request.
Errors and deadlines
Each discovery,recover and status attempt, including getting a token, has
a 10-second deadline. Set your MCP client’s own timeout for tool calls, as in
the Mastra example above. Failures are thrown as McpRequestError with a kind
of deadline, cancelled, unavailable, authorization or
request_refused. None of them establishes whether a write committed.
Presenting status
presentMcpOutcome from bijection/mcp/outcome turns a status tool’s result
into a fixed outcome and message for your users, such as pending,
awaiting_review or unknown. Its external_effect_confirmed field is always
false: delivery records alone don’t prove that an external system applied a
change. Show these facts directly rather than a model’s summary of them.