Endpoint
POST /mcp with JSON-RPC requests. GET /mcp returns a method notice so crawlers and humans understand that the endpoint requires POST.
Tools
- map_permissions
- flag_sensitive_fields
- summarize_boundary
- export_remediation_plan
Authentication
Paid Bearer token access is expected in production. The endpoint is independent for this site and does not depend on a shared MCP core package.