bijection/mcp.ts
defineMcpServer takes an async function that returns the definition, because
makeOperationReference is asynchronous. The function runs for each request.
Each tool wraps a function you already have. A query tool runs your public query
as the calling agent. An operation tool requests your operation through its
ordinary invocation path, so your validators, access rules,
transactions, approvals and recovery apply exactly as they do for any other
client. The endpoint adds no second way to read or write your data.
How it works
An MCP endpoint is built from pieces you write in yourbijection/ folder:
- Tools.
mcpQuery,mcpOperationandmcpOperationStatusselect existing functions and derive each tool’s input and output schemas from their validators. - A grant query. Your
authorizequery decides who the caller is acting for and which tools they may use. Publishing a tool grants nothing by itself. - Admission. Two mutations you write enforce rate and concurrency limits in your own tables.
- Dispatch. An internal query and an internal mutation run each tool call, so the publication check, the grant check and the business work share one transaction.
- Routes. You mount the endpoint and its OAuth metadata as HTTP actions.
Where it is served
MCP endpoints are served from the same host as your HTTP actions,https://<your deployment name>.bijection.site. Each endpoint URL ends with the
publication revision, a digest of your deployed code and the endpoint’s
definition:
409 publication_changed response, so an agent cannot call tools on code
that changed after it discovered them. See
Defining MCP endpoints for how to
mount the routes and read the current revision.
What an endpoint exposes
An MCP endpoint publishes tools only. It answersinitialize, ping,
tools/list and tools/call with fixed JSON responses. It does not offer MCP
resources, prompts, subscriptions, streaming, or arbitrary queries over your
data.
Defining MCP endpoints
Select tools, write the dispatch and admission functions, and mount the
routes.
Authentication and grants
Accept tokens from your identity provider and decide what each agent may
do.
Connecting clients
Call the endpoint from an MCP client, and make writes recoverable with
bijection/mcp/node.Limits
Size bounds, supported methods and error codes.