# MCP server

How Covo speaks the Model Context Protocol: transport, sign-in, tools, resources, prompts and how errors come back.

|  |  |
| --- | --- |
| Address | `https://covo.lanaai.io/mcp` |
| Transport | Streamable HTTP, stateless: send JSON-RPC with `POST`; answers are JSON (no SSE). `GET` and `DELETE` answer 405. |
| Protocol versions | `2025-11-25`, `2025-06-18`, `2025-03-26` and `2024-11-05` |
| Sign in | OAuth 2.1 (discovered from the 401) or `Authorization: Bearer cc_pat_...` |
| Server | `covo` (title Covo), with tools, resources and prompts |
| Cross-origin | Allowed (any origin), for browser-based clients and inspectors |

## Tools

One tool per operation (37), named like the operation, with the same JSON Schema inputs. Each carries annotations:

| Annotation | Meaning |
| --- | --- |
| `readOnlyHint: true` | Changes nothing (Read). |
| `destructiveHint: true` | Changes what visitors see or removes something (Sensitive write); needs `confirm: true`. |
| `idempotentHint: true` | Safe to retry with the same arguments. |
| `openWorldHint: false` | Acts only on Covo. |

Tools that create something and are not idempotent take an optional `idempotency_key` argument (8 to 200 characters of letters, digits, `_ . : -`). Retrying with the same key returns the first result.

## Resources

| URI | What |
| --- | --- |
| `concierge://docs/guide` | The working guide for agents (concepts, safe workflow, errors). |
| `concierge://docs/scopes` | Scopes and presets. |
| `concierge://schema/configuration` | The configuration schema. |
| `concierge://agents` | Agents this token can reach. |
| `concierge://agents/{agent_id}` | One agent; add `/configuration`, `/versions`, `/deployment` or `/diagnostics`. |

## Prompts

- `improve_agent(agent_id, goal)`: a guided session to improve a Concierge toward a goal, using the safe workflow.
- `diagnose_agent(agent_id)`: find out why a Concierge is not answering well.

## Errors

A failed tool call returns `isError: true` with the same error object as the REST API (`code`, `message`, `field`, `resolution`, `details`, `request_id`) as JSON text and `structuredContent`. Follow `resolution`.

## Try it

```bash
curl -X POST https://covo.lanaai.io/mcp \
  -H "Authorization: Bearer $COVO_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
```
