> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP Endpoints

> Publish selected queries and operations to AI agents as an authenticated MCP server

<Warning>MCP endpoints are in beta.</Warning>

An MCP endpoint is a remote, authenticated
[Model Context Protocol](https://modelcontextprotocol.io) server that your
Bijection app defines and serves. It gives an external AI agent a small, explicit
set of tools: the queries it may read and the business
[operations](/operations/overview) it may request. Everything else in your app
stays out of reach.

This is different from the [Bijection MCP server](/ai/bijection-mcp-server),
which the CLI runs on your machine so coding agents can inspect and develop your
deployment. An MCP endpoint is part of your app and serves your app's users.

```ts bijection/mcp.ts theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
import { defineMcpServer, mcpQuery, mcpOperation } from "bijection/mcp";
import { makeFunctionReference, makeOperationReference } from "bijection/server";
import { api } from "./_generated/api";
import { list, complete } from "./tasks";

export const mcpServer = defineMcpServer(async () => ({
  name: "tasks",
  resource: process.env.BIJECTION_SITE_URL!,
  authorization_servers: ["https://auth.example.com"],
  authorize: makeFunctionReference("mcp:authorize"),
  admission: {
    acquire: makeFunctionReference("mcp:acquire"),
    release: makeFunctionReference("mcp:release"),
  },
  dispatch: {
    read: makeFunctionReference("mcp:read"),
    write: makeFunctionReference("mcp:write"),
  },
  tools: {
    list_tasks: mcpQuery(api.tasks.list, list, "List the caller's open tasks."),
    complete_task: mcpOperation(
      await makeOperationReference("tasks:complete", complete),
      "Mark one task as complete.",
    ),
  },
}));
```

`defineMcpServer` takes an async function that returns the definition, because
`makeOperationReference` is asynchronous. The function runs for each request.

Each tool wraps a function you already have. A query tool runs your public query
as the calling agent. An operation tool requests your operation through its
ordinary invocation path, so your validators, [access rules](/access/overview),
transactions, approvals and recovery apply exactly as they do for any other
client. The endpoint adds no second way to read or write your data.

## How it works

An MCP endpoint is built from pieces you write in your `bijection/` folder:

* **Tools.** `mcpQuery`, `mcpOperation` and `mcpOperationStatus` select existing
  functions and derive each tool's input and output schemas from their
  validators.
* **A grant query.** Your `authorize` query decides who the caller is acting for
  and which tools they may use. Publishing a tool grants nothing by itself.
* **Admission.** Two mutations you write enforce rate and concurrency limits in
  your own tables.
* **Dispatch.** An internal query and an internal mutation run each tool call, so
  the publication check, the grant check and the business work share one
  transaction.
* **Routes.** You mount the endpoint and its OAuth metadata as
  [HTTP actions](/functions/http-actions).

Agents connect with a bearer token from the identity provider you already
configured for [authentication](/auth/overview).

## Where it is served

MCP endpoints are served from the same host as your HTTP actions,
`https://<your deployment name>.bijection.site`. Each endpoint URL ends with the
publication revision, a digest of your deployed code and the endpoint's
definition:

```
https://happy-animal-123.bijection.site/mcp/3f9c…e81a
```

When you push new code, the revision changes and the old URL stops answering
with a `409 publication_changed` response, so an agent cannot call tools on code
that changed after it discovered them. See
[Defining MCP endpoints](/mcp/defining-endpoints#serving-the-endpoint) for how to
mount the routes and read the current revision.

## What an endpoint exposes

An MCP endpoint publishes **tools** only. It answers `initialize`, `ping`,
`tools/list` and `tools/call` with fixed JSON responses. It does not offer MCP
resources, prompts, subscriptions, streaming, or arbitrary queries over your
data.

<CardGroup cols={2}>
  <Card title="Defining MCP endpoints" href="/mcp/defining-endpoints">
    Select tools, write the dispatch and admission functions, and mount the
    routes.
  </Card>

  <Card title="Authentication and grants" href="/mcp/authentication">
    Accept tokens from your identity provider and decide what each agent may
    do.
  </Card>

  <Card title="Connecting clients" href="/mcp/connecting-clients">
    Call the endpoint from an MCP client, and make writes recoverable with
    `bijection/mcp/node`.
  </Card>

  <Card title="Limits" href="/mcp/limits">
    Size bounds, supported methods and error codes.
  </Card>
</CardGroup>
