Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · mcp

One read of Model Context Protocolmcp-20260928T220720Z

173 pages moved out of 349 read.

Pages moved 173 significant first
Pages read 349 in this capture
Captured 22:07 UTC
Corpus hash 719057065235 corpus-hash

What this read moved

51-75 of 173, page 3 of 7

This capture is too large to show at once. Changes 51-75 of 173 are below, significant first; the rest are on the following screens.

docs/2026-07-28/learn/client-concepts Changed · +5 / -5 lines

from line 8
88 
99In addition to making use of context provided by servers, clients may provide several features to servers. These client features allow server authors to build richer interactions.
1010 
11| Feature | Explanation | Example |
12| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
13| **Elicitation** | Elicitation enables servers to request specific information from users during interactions, providing a structured way for servers to gather information on demand. | A server booking travel may ask for the user's preferences on airplane seats, room type or their contact number to finalize a booking. |
14| **Roots** | Roots allow clients to specify which directories servers should focus on, communicating intended scope through a coordination mechanism. Roots are [deprecated](/specification/2026-07-28/deprecated) as of protocol version `2026-07-28`. | A server for booking travel may be given access to a specific directory, from which it can read a user's calendar. |
15| **Sampling** | Sampling allows servers to request LLM completions through the client, enabling an agentic workflow. This approach puts the client in complete control of user permissions and security measures. Sampling is deprecated as of protocol version `2026-07-28`. | A server for booking travel may send a list of flights to an LLM and request that the LLM pick the best flight for the user. |
11| Feature | Explanation | Example |
12| - | - | - |
13| **Elicitation** | Elicitation enables servers to request specific information from users during interactions, providing a structured way for servers to gather information on demand. | A server booking travel may ask for the user's preferences on airplane seats, room type or their contact number to finalize a booking. |
14| **Roots** | Roots allow clients to specify which directories servers should focus on, communicating intended scope through a coordination mechanism. Roots are [deprecated](/specification/2026-07-28/deprecated) as of protocol version `2026-07-28`. | A server for booking travel may be given access to a specific directory, from which it can read a user's calendar. |
15| **Sampling** | Sampling allows servers to request LLM completions through the client, enabling an agentic workflow. This approach puts the client in complete control of user permissions and security measures. Sampling is deprecated as of protocol version `2026-07-28`. | A server for booking travel may send a list of flights to an LLM and request that the LLM pick the best flight for the user. |
1616 
1717### Elicitation
1818 

docs/2026-07-28/learn/server-concepts Changed · +18 / -18 lines

from line 8
88 
99Servers provide functionality through three building blocks:
1010 
11| Feature | Explanation | Examples | Who controls it |
12| ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------ | --------------- |
13| **Tools** | Functions that your LLM can actively call, and decides when to use them based on user requests. Tools can write to databases, call external APIs, modify files, or trigger other logic. | Search flights<br />Send messages<br />Create calendar events | Model |
14| **Resources** | Passive data sources that provide read-only access to information for context, such as file contents, database schemas, or API documentation. | Retrieve documents<br />Access knowledge bases<br />Read calendars | Application |
15| **Prompts** | Pre-built instruction templates that tell the model to work with specific tools and resources. | Plan a vacation<br />Summarize my meetings<br />Draft an email | User |
11| Feature | Explanation | Examples | Who controls it |
12| - | - | - | - |
13| **Tools** | Functions that your LLM can actively call, and decides when to use them based on user requests. Tools can write to databases, call external APIs, modify files, or trigger other logic. | Search flights<br />Send messages<br />Create calendar events | Model |
14| **Resources** | Passive data sources that provide read-only access to information for context, such as file contents, database schemas, or API documentation. | Retrieve documents<br />Access knowledge bases<br />Read calendars | Application |
15| **Prompts** | Pre-built instruction templates that tell the model to work with specific tools and resources. | Plan a vacation<br />Summarize my meetings<br />Draft an email | User |
1616 
1717We will use a hypothetical scenario to demonstrate the role of each of these features, and show how they can work together.
1818 
from line 26
2626 
2727**Protocol operations:**
2828 
29| Method | Purpose | Returns |
30| ------------ | ------------------------ | -------------------------------------- |
29| Method | Purpose | Returns |
30| - | - | - |
3131| `tools/list` | Discover available tools | Array of tool definitions with schemas |
32| `tools/call` | Execute a specific tool | Tool execution result |
32| `tools/call` | Execute a specific tool | Tool execution result |
3333 
3434**Example tool definition:**
3535 
from line 109
109109 
110110**Protocol operations:**
111111 
112| Method | Purpose | Returns |
113| -------------------------- | ------------------------------- | -------------------------------------- |
114| `resources/list` | List available direct resources | Array of resource descriptors |
115| `resources/templates/list` | Discover resource templates | Array of resource template definitions |
116| `resources/read` | Retrieve resource contents | Resource data with metadata |
117| `subscriptions/listen` | Monitor resource changes | Stream of update notifications |
112| Method | Purpose | Returns |
113| - | - | - |
114| `resources/list` | List available direct resources | Array of resource descriptors |
115| `resources/templates/list` | Discover resource templates | Array of resource template definitions |
116| `resources/read` | Retrieve resource contents | Resource data with metadata |
117| `subscriptions/listen` | Monitor resource changes | Stream of update notifications |
118118 
119119To watch specific resources for changes, a client sends a [`subscriptions/listen`](/specification/2026-07-28/basic/patterns/subscriptions) request with the resource URIs listed in the `resourceSubscriptions` filter. The server delivers `notifications/resources/updated` on the resulting stream whenever a watched resource changes.
120120 
from line 182
182182 
183183**Protocol operations:**
184184 
185| Method | Purpose | Returns |
186| -------------- | -------------------------- | ------------------------------------- |
187| `prompts/list` | Discover available prompts | Array of prompt descriptors |
188| `prompts/get` | Retrieve prompt details | Full prompt definition with arguments |
185| Method | Purpose | Returns |
186| - | - | - |
187| `prompts/list` | Discover available prompts | Array of prompt descriptors |
188| `prompts/get` | Retrieve prompt details | Full prompt definition with arguments |
189189 
190190#### Example: Streamlined Workflows
191191 

docs/2026-07-28/sdk Changed · +12 / -12 lines

from line 6
66 
77## Available SDKs
88 
9| SDK | Repository | Tier |
10| :----------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------- | ------------------------------------------------: |
11| <Icon icon="square-js" size={24} />   [TypeScript](https://ts.sdk.modelcontextprotocol.io) | [modelcontextprotocol/typescript-sdk](https://github.com/modelcontextprotocol/typescript-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
12| <Icon icon="python" size={24} />   [Python](https://py.sdk.modelcontextprotocol.io) | [modelcontextprotocol/python-sdk](https://github.com/modelcontextprotocol/python-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
13| <Icon icon="square-c" size={24} />   [C#](https://csharp.sdk.modelcontextprotocol.io) | [modelcontextprotocol/csharp-sdk](https://github.com/modelcontextprotocol/csharp-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
14| <Icon icon="golang" size={24} />   [Go](https://go.sdk.modelcontextprotocol.io) | [modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
15| <Icon icon="rust" size={24} />   [Rust](https://rust.sdk.modelcontextprotocol.io) | [modelcontextprotocol/rust-sdk](https://github.com/modelcontextprotocol/rust-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
16| <Icon icon="java" size={24} />   [Java](https://java.sdk.modelcontextprotocol.io) | [modelcontextprotocol/java-sdk](https://github.com/modelcontextprotocol/java-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
17| <Icon icon="gem" size={24} />   [Ruby](https://ruby.sdk.modelcontextprotocol.io) | [modelcontextprotocol/ruby-sdk](https://github.com/modelcontextprotocol/ruby-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
18| <Icon icon="swift" size={24} />   Swift | [modelcontextprotocol/swift-sdk](https://github.com/modelcontextprotocol/swift-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
19| <Icon icon="php" size={24} />   [PHP](https://php.sdk.modelcontextprotocol.io) | [modelcontextprotocol/php-sdk](https://github.com/modelcontextprotocol/php-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
20| <Icon icon="square-k" size={24} />   [Kotlin](https://kotlin.sdk.modelcontextprotocol.io) | [modelcontextprotocol/kotlin-sdk](https://github.com/modelcontextprotocol/kotlin-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
9| SDK | Repository | Tier |
10| :- | :- | -: |
11| <Icon icon="square-js" size={24} />   [TypeScript](https://ts.sdk.modelcontextprotocol.io) | [modelcontextprotocol/typescript-sdk](https://github.com/modelcontextprotocol/typescript-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
12| <Icon icon="python" size={24} />   [Python](https://py.sdk.modelcontextprotocol.io) | [modelcontextprotocol/python-sdk](https://github.com/modelcontextprotocol/python-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
13| <Icon icon="square-c" size={24} />   [C#](https://csharp.sdk.modelcontextprotocol.io) | [modelcontextprotocol/csharp-sdk](https://github.com/modelcontextprotocol/csharp-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
14| <Icon icon="golang" size={24} />   [Go](https://go.sdk.modelcontextprotocol.io) | [modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
15| <Icon icon="rust" size={24} />   [Rust](https://rust.sdk.modelcontextprotocol.io) | [modelcontextprotocol/rust-sdk](https://github.com/modelcontextprotocol/rust-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
16| <Icon icon="gem" size={24} />   [Ruby](https://ruby.sdk.modelcontextprotocol.io) | [modelcontextprotocol/ruby-sdk](https://github.com/modelcontextprotocol/ruby-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
17| <Icon icon="java" size={24} />   [Java](https://java.sdk.modelcontextprotocol.io) | [modelcontextprotocol/java-sdk](https://github.com/modelcontextprotocol/java-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
18| <Icon icon="swift" size={24} />   Swift | [modelcontextprotocol/swift-sdk](https://github.com/modelcontextprotocol/swift-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
19| <Icon icon="php" size={24} />   [PHP](https://php.sdk.modelcontextprotocol.io) | [modelcontextprotocol/php-sdk](https://github.com/modelcontextprotocol/php-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
20| <Icon icon="square-k" size={24} />   [Kotlin](https://kotlin.sdk.modelcontextprotocol.io) | [modelcontextprotocol/kotlin-sdk](https://github.com/modelcontextprotocol/kotlin-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
2121 
2222See [SDK Tiering System](/community/sdk-tiers) for details on what each tier means.
2323 

docs/2026-07-28/tools/inspector Changed · +4 / -4 lines

from line 4
44 
55The [MCP Inspector](https://github.com/modelcontextprotocol/inspector) is the reference developer tool for testing and debugging [MCP servers](/docs/2026-07-28/learn/server-concepts). It ships as a single package, `@modelcontextprotocol/inspector`, providing **three clients behind one binary**:
66 
7| Client | Invocation | What it's for |
8| ------- | ------------------------------------------- | --------------------------------------------------------------------------------- |
9| **Web** | `npx @modelcontextprotocol/inspector` | A full graphical inspector in the browser. The default, and the richest surface. |
7| Client | Invocation | What it's for |
8| - | - | - |
9| **Web** | `npx @modelcontextprotocol/inspector` | A full graphical inspector in the browser. The default, and the richest surface. |
1010| **CLI** | `npx @modelcontextprotocol/inspector --cli` | A scriptable, machine-readable client for CI, shell pipelines, and coding agents. |
11| **TUI** | `npx @modelcontextprotocol/inspector --tui` | An interactive terminal UI, for when a browser isn't available or wanted. |
11| **TUI** | `npx @modelcontextprotocol/inspector --tui` | An interactive terminal UI, for when a browser isn't available or wanted. |
1212 
1313All three are built on the same shared core, so a connection behaves identically across them: the same transports, the same configuration files, the same OAuth state on disk, and the same [protocol-era](/docs/2026-07-28/tools/inspector/protocol-eras) negotiation (legacy vs. modern 2026-07-28).
1414 

docs/2026-07-28/tools/inspector/authorization Changed · +16 / -16 lines

from line 56
5656 
5757The web app listens for the OAuth callback on its own URL, while the CLI and TUI deliberately share a second one:
5858 
59| Surface | Default callback | Why |
60| ------- | -------------------------------------- | ---------------------------------------------------------------------------------- |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
59| Surface | Default callback | Why |
60| - | - | - |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
6262| **CLI** | `http://127.0.0.1:6276/oauth/callback` | A dedicated loopback listener, so it doesn't collide with a running web Inspector. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
6464 
6565**Register `http://127.0.0.1:6276/oauth/callback`** on any IdP that requires pre-registered redirect URIs before using the CLI or TUI. A predictable default is the point: you register once and reuse it.
6666 
from line 83
8383 
8484## Where credentials live
8585 
86| File | Contents |
87| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/2026-07-28/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
86| File | Contents |
87| - | - |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/2026-07-28/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
9191 
9292The path to `oauth.json` is resolved in order: `MCP_INSPECTOR_OAUTH_STATE_PATH`, then `<MCP_STORAGE_DIR>/oauth.json` (see [Environment variables](/docs/2026-07-28/tools/inspector/configuration#environment-variables)), then the default above. All three clients resolve it the same way. Command-line `--client-id` / `--client-secret` / `--client-metadata-url` override `client.json`.
9393 
from line 122
122122 
123123The common case: a human completed OAuth in the web Inspector on this machine, and now a script wants to use that token.
124124 
125| Flag | Behavior |
126| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
125| Flag | Behavior |
126| - | - |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
132132 
133133A typical remote-VM sequence:
134134 

docs/2026-07-28/tools/inspector/cli Changed · +20 / -20 lines

from line 42
4242 
4343## Methods
4444 
45| `--method` | Required companions | Notes |
46| ------------------------------ | ----------------------------------------------------- | -------------------------------------------------------------------------------- |
47| `initialize` | None | Connect-only probe: `{serverInfo, protocolVersion, capabilities, instructions}`. |
48| `tools/list` | None | |
49| `tools/call` | `--tool-name`, plus `--tool-arg` / `--tool-args-json` | |
50| `resources/list` | None | |
51| `resources/read` | `--uri` | |
52| `resources/templates/list` | None | |
53| `prompts/list` | None | |
54| `prompts/get` | `--prompt-name`, `--prompt-args` | |
55| `logging/setLevel` | `--log-level` | Legacy era only; modern servers opt in per request instead. |
56| `servers/list`, `servers/show` | None | Read the catalog **without connecting** to anything. |
45| `--method` | Required companions | Notes |
46| - | - | - |
47| `initialize` | None | Connect-only probe: `{serverInfo, protocolVersion, capabilities, instructions}`. |
48| `tools/list` | None | |
49| `tools/call` | `--tool-name`, plus `--tool-arg` / `--tool-args-json` | |
50| `resources/list` | None | |
51| `resources/read` | `--uri` | |
52| `resources/templates/list` | None | |
53| `prompts/list` | None | |
54| `prompts/get` | `--prompt-name`, `--prompt-args` | |
55| `logging/setLevel` | `--log-level` | Legacy era only; modern servers opt in per request instead. |
56| `servers/list`, `servers/show` | None | Read the catalog **without connecting** to anything. |
5757 
5858Stream- or session-only methods (`logging/tail`, for example) are rejected, since a process that exits can't hold a stream open.
5959 
from line 106
106106 
107107Every non-zero exit maps to a stable failure class, so a caller can branch on *why* without scraping prose:
108108 
109| Code | Meaning |
110| ---- | ---------------------------------------------------------------------------- |
111| `0` | Success. |
112| `1` | Usage or unexpected error (the catch-all). |
113| `2` | No MCP App found on the tool (`--app-info` probe). |
114| `3` | Server requires authentication (401/403, `WWW-Authenticate`, OAuth). |
115| `4` | Server unreachable (DNS, connection refused, timeout, `fetch failed`). |
116| `5` | Tool error: `tools/call` returned `isError: true`, or the tool wasn't found. |
109| Code | Meaning |
110| - | - |
111| `0` | Success. |
112| `1` | Usage or unexpected error (the catch-all). |
113| `2` | No MCP App found on the tool (`--app-info` probe). |
114| `3` | Server requires authentication (401/403, `WWW-Authenticate`, OAuth). |
115| `4` | Server unreachable (DNS, connection refused, timeout, `fetch failed`). |
116| `5` | Tool error: `tools/call` returned `isError: true`, or the tool wasn't found. |
117117 
118118On any non-zero exit the CLI also writes a **single JSON line to stderr**:
119119 

docs/2026-07-28/tools/inspector/configuration Changed · +56 / -56 lines

from line 6
66 
77## The launcher owns exactly two things
88 
9| Flag | Behavior |
10| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
9| Flag | Behavior |
10| - | - |
1111| `--web` / `--cli` / `--tui` | Selects the client, `--web` by default. Passing more than one fails with `Specify at most one of --web, --cli, or --tui.` Launcher flags must come first: parsing stops at the first argument the launcher does not own, and everything from that point on is forwarded to the client unchanged. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
1313 
1414Everything below belongs to a client.
1515 
from line 19
1919 
2020All three clients resolve `--catalog` and `--config` through the same shared code, so each flag behaves the same in the web app, the CLI, and the TUI. Where the two differ from each other is the table below.
2121 
22| | `--catalog <path>` | `--config <path>` |
23| --------------------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------- |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
22| | `--catalog <path>` | `--config <path>` |
23| - | - | - |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
2929 
3030The two are **mutually exclusive**, and neither combines with an ad-hoc target. Passing both is rejected identically by all three clients.
3131 
from line 73
7373 
7474Defined **separately by each of web, CLI, and TUI**, so they're available in all three, with the divergences noted:
7575 
76| Flag | Meaning | Divergence |
77| ------------------------ | ----------------------------------------------------- | ----------------------------------------------------------------------------------------------- |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
76| Flag | Meaning | Divergence |
77| - | - | - |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
8787 
8888### The `--` separator
8989 
from line 97
9797 
9898## Web-only flags
9999 
100| Flag | Meaning |
101| ------- | ----------------------------------------------------------------------------------------------------- |
100| Flag | Meaning |
101| - | - |
102102| `--dev` | Run the Vite dev server instead of the pre-built bundle. Useful when working on the Inspector itself. |
103103 
104104## CLI and TUI: OAuth client flags
from line 105
105105 
106106These five are defined by the **CLI and TUI** only. The web client obtains the same settings through its Client Settings dialog.
107107 
108| Flag | Environment variable | Meaning |
109| ----------------------------- | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
108| Flag | Environment variable | Meaning |
109| - | - | - |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
115115 
116116## CLI-only flags
117117 
118118The whole scripting surface belongs to the CLI. See [CLI client](/docs/2026-07-28/tools/inspector/cli) for usage.
119119 
120| Group | Flags |
121| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
120| Group | Flags |
121| - | - |
122122| **What to invoke** | `--method`, `--tool-name`, `--tool-arg`, `--tool-args-json`, `--uri`, `--prompt-name`, `--prompt-args`, `--log-level`, `--metadata`, `--tool-metadata` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
125125 
126126## Environment variables
127127 
from line 129
129129 
130130### Read by the launcher
131131 
132| Variable | Effect |
133| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
132| Variable | Effect |
133| - | - |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
136136 
137137### CLI and TUI
138138 
139| Variable | Effect |
140| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
139| Variable | Effect |
140| - | - |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
147147 
148148### Web backend environment variables
149149 
150| Variable | Effect |
151| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/2026-07-28/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
150| Variable | Effect |
151| - | - |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/2026-07-28/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
160160 
161161<Warning>
162162 Never combine `DANGEROUSLY_OMIT_AUTH` and `DANGEROUSLY_BIND_ALL_INTERFACES`.

docs/2026-07-28/tools/inspector/protocol-eras Changed · +19 / -19 lines

from line 8
88 
99Each server carries a `protocolEra` of `legacy`, `auto`, or `modern`. In the web client it lives in **Server Settings**; in a catalog or config file it is the `protocolEra` field; in the CLI and TUI it comes from that same file.
1010 
11| Era | What the Inspector does at connect |
12| -------- | --------------------------------------------------------------------------------------- |
13| `legacy` | **The default.** Plain `initialize`, no probing at all. |
14| `auto` | Probe `server/discover` first, and fall back to `initialize` on any non-modern outcome. |
15| `modern` | Pin exactly `2026-07-28`. No fallback, so a non-modern server fails loudly. |
11| Era | What the Inspector does at connect |
12| - | - |
13| `legacy` | **The default.** Plain `initialize`, no probing at all. |
14| `auto` | Probe `server/discover` first, and fall back to `initialize` on any non-modern outcome. |
15| `modern` | Pin exactly `2026-07-28`. No fallback, so a non-modern server fails loudly. |
1616 
1717<Note>
1818 **Why `legacy` is the default, and not `auto`.** A debugging tool must not
from line 141
141141 
142142`test-servers/configs/mrtr-showcase-http.json` bundles every shape in one modern server:
143143 
144| Tool | What it exercises |
145| --------------- | ----------------------------------------------------------------------------- |
146| `mrtr_confirm` | A single elicitation round. |
147| `mrtr_two_step` | Two elicitation rounds, threaded through `requestState`. |
148| `mrtr_sample` | An embedded sampling request, routed to the Sampling panel. |
149| `mrtr_roots` | An embedded `roots/list`, answered silently from configured roots (no modal). |
150| `mrtr_edge` | An `inputRequests`-only round, then a `requestState`-only round. |
151| `mrtr_loop` | Never completes, so the client stops at its `MRTR_MAX_ROUNDS` limit. |
144| Tool | What it exercises |
145| - | - |
146| `mrtr_confirm` | A single elicitation round. |
147| `mrtr_two_step` | Two elicitation rounds, threaded through `requestState`. |
148| `mrtr_sample` | An embedded sampling request, routed to the Sampling panel. |
149| `mrtr_roots` | An embedded `roots/list`, answered silently from configured roots (no modal). |
150| `mrtr_edge` | An `inputRequests`-only round, then a `requestState`-only round. |
151| `mrtr_loop` | Never completes, so the client stops at its `MRTR_MAX_ROUNDS` limit. |
152152 
153153<Note>
154154 The legacy `collect_elicitation` pattern (a server calling
from line 208
208208 
209209`test-servers/configs/modern-network-http.json` serves four tools that produce a real HTTP status plus a JSON-RPC error body, one per class:
210210 
211| Tool | HTTP | JSON-RPC code | Meaning |
212| ----------------------------- | ----- | ------------- | ------------------------------------------------------------ |
213| `trigger_header_mismatch` | `400` | `-32020` | A required mirrored header was missing or wrong. |
214| `trigger_missing_capability` | `400` | `-32021` | The request omitted a client capability the server requires. |
215| `trigger_unsupported_version` | `400` | `-32022` | Unsupported version; supported versions in `data.supported`. |
216| `trigger_method_not_found` | `404` | `-32601` | Method not found. |
211| Tool | HTTP | JSON-RPC code | Meaning |
212| - | - | - | - |
213| `trigger_header_mismatch` | `400` | `-32020` | A required mirrored header was missing or wrong. |
214| `trigger_missing_capability` | `400` | `-32021` | The request omitted a client capability the server requires. |
215| `trigger_unsupported_version` | `400` | `-32022` | Unsupported version; supported versions in `data.supported`. |
216| `trigger_method_not_found` | `404` | `-32601` | Method not found. |
217217 
218218<Frame caption="The Network tab shows the HTTP layer; here, the 400 Bad Request the strict server answered with.">
219219 <img src="https://mintcdn.com/mcp/gk28X8wi_tbRYzej/images/inspector/network-modern-headers.png?fit=max&auto=format&n=gk28X8wi_tbRYzej&q=85&s=7df4c01f5ab68aa7632ac3b5a5866b42" width="3840" height="2160" data-path="images/inspector/network-modern-headers.png" />

docs/2026-07-28/tools/inspector/recipes Changed · +10 / -10 lines

from line 112
112112 <Step title="Wait on a deterministic signal instead of sleeping">
113113 The Apps screen exposes a stable automation contract. Poll these attributes instead of sleeping:
114114 
115 | Selector | Attribute | Values |
116 | ----------------------------------- | ----------------- | ------------------------------------------------------------------------------------------------------- |
117 | `[data-testid="apps-form"]` | `data-app-status` | `ready` (on failure, `data-app-error` carries the reason) |
118 | `[data-testid="connection-status"]` | `data-status` | `connecting`, then `connected` or `error` (`data-error-message` has the detail) |
119 | `[data-testid="connection-status"]` | `data-deeplink` | `parsed`, `rejected`, or `none` (`none` means no deep link was given, `rejected` means one was refused) |
115 | Selector | Attribute | Values |
116 | - | - | - |
117 | `[data-testid="apps-form"]` | `data-app-status` | `ready` (on failure, `data-app-error` carries the reason) |
118 | `[data-testid="connection-status"]` | `data-status` | `connecting`, then `connected` or `error` (`data-error-message` has the detail) |
119 | `[data-testid="connection-status"]` | `data-deeplink` | `parsed`, `rejected`, or `none` (`none` means no deep link was given, `rejected` means one was refused) |
120120 </Step>
121121</Steps>
122122 
from line 152
152152 
153153The Inspector refuses to bind the **wildcard** all-interfaces addresses (`0.0.0.0`, `::`, and every equivalent spelling) unless you set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Binding a **specific** address is allowed with no opt-in, because that's one deliberate exposure rather than every interface at once, which is the shape DNS-rebinding attacks target.
154154 
155| Goal | What to do |
156| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
157| **Reach it from another machine on the LAN** | `HOST=192.168.1.50`. The default origin allow-list follows the bind host, so `http://192.168.1.50:6274` is accepted with no further config. |
158| **Behind TLS or a reverse proxy** | The browser's `Origin` becomes the public origin, which won't match the bind host. Set `ALLOWED_ORIGINS=https://inspector.example.com`. |
159| **Wildcard bind (containers)** | Set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Loopback access still works out of the box; reaching it at a non-loopback address needs `ALLOWED_ORIGINS`. |
155| Goal | What to do |
156| - | - |
157| **Reach it from another machine on the LAN** | `HOST=192.168.1.50`. The default origin allow-list follows the bind host, so `http://192.168.1.50:6274` is accepted with no further config. |
158| **Behind TLS or a reverse proxy** | The browser's `Origin` becomes the public origin, which won't match the bind host. Set `ALLOWED_ORIGINS=https://inspector.example.com`. |
159| **Wildcard bind (containers)** | Set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Loopback access still works out of the box; reaching it at a non-loopback address needs `ALLOWED_ORIGINS`. |
160160 
161161<Warning>
162162 `ALLOWED_ORIGINS` **replaces** the default list rather than merging with it. List every origin you'll browse from, including the loopback forms you want to keep:

docs/2026-07-28/tools/inspector/tui Changed · +18 / -18 lines

from line 25
2525 
2626## Tabs
2727 
28| Tab | Key | What it shows |
29| ------------- | --- | ------------------------------------------------------------------------------------------- |
30| **Info** | `i` | Server info, capabilities, and negotiated protocol details. |
31| **Auth** | `a` | OAuth state for the selected server, plus a **Clear OAuth state** action. |
32| **Resources** | `r` | Browse and read resources. |
33| **Prompts** | `m` | List prompts and render them with arguments. |
34| **Tools** | `t` | View tools and execute them with form-like inputs. |
35| **Protocol** | `p` | JSON-RPC request/response/notification history. |
36| **Network** | `n` | HTTP traffic for SSE and [Streamable HTTP](/specification/latest/basic/transports) servers. |
37| **Console** | `o` | `stderr` from a connected stdio server process. |
28| Tab | Key | What it shows |
29| - | - | - |
30| **Info** | `i` | Server info, capabilities, and negotiated protocol details. |
31| **Auth** | `a` | OAuth state for the selected server, plus a **Clear OAuth state** action. |
32| **Resources** | `r` | Browse and read resources. |
33| **Prompts** | `m` | List prompts and render them with arguments. |
34| **Tools** | `t` | View tools and execute them with form-like inputs. |
35| **Protocol** | `p` | JSON-RPC request/response/notification history. |
36| **Network** | `n` | HTTP traffic for SSE and [Streamable HTTP](/specification/latest/basic/transports) servers. |
37| **Console** | `o` | `stderr` from a connected stdio server process. |
3838 
3939The accelerators avoid collisions rather than always taking the first letter: **P**rotocol takes `p` so Pro**m**pts takes `m`, and **C**onsole takes `o` because `c` is the global Connect action.
4040 
4141## Navigation
4242 
43| Key | Action |
44| -------------------------------- | --------------------------------------------------- |
45| `Left` / `Right` arrows or `Tab` | Switch tabs |
46| `Up` / `Down` arrows | Move through the current list |
47| `Enter` | Select an item, execute a tool, or fetch a resource |
48| `c` | Connect to the selected server |
49| `d` | Disconnect |
50| `Esc` or `Ctrl+C` | Exit |
43| Key | Action |
44| - | - |
45| `Left` / `Right` arrows or `Tab` | Switch tabs |
46| `Up` / `Down` arrows | Move through the current list |
47| `Enter` | Select an item, execute a tool, or fetch a resource |
48| `c` | Connect to the selected server |
49| `d` | Disconnect |
50| `Esc` or `Ctrl+C` | Exit |
5151 
5252## Authorizing an HTTP server
5353 

docs/2026-07-28/tools/inspector/web Changed · +22 / -22 lines

from line 34
3434 
3535## The tab bar
3636 
37| Tab | Shown when | What it does |
38| ------------- | --------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
39| **Servers** | Always | The server list: add, edit, import, connect, and open per-server settings. |
40| **Apps** | The server exposes MCP App tools | Renders a tool's UI in a sandboxed frame. |
41| **Tools** | `tools` capability | Browse schemas, fill arguments, call, inspect results. |
42| **Prompts** | `prompts` capability | List prompts, supply arguments, preview generated messages. |
43| **Resources** | `resources` capability | Browse, read, and subscribe to resources. |
44| **Tasks** | `capabilities.tasks` (legacy era) or the tasks extension (modern era) | Track long-running tool calls. |
45| **Logs** | `logging` capability | Server `notifications/message` output, plus the era-appropriate level control. |
46| **Protocol** | Always | The JSON-RPC transcript: requests, responses, notifications. |
47| **Network** | HTTP / SSE servers | The raw HTTP view: status, headers, bodies. |
48| **Console** | stdio servers | The server process's `stderr`. |
37| Tab | Shown when | What it does |
38| - | - | - |
39| **Servers** | Always | The server list: add, edit, import, connect, and open per-server settings. |
40| **Apps** | The server exposes MCP App tools | Renders a tool's UI in a sandboxed frame. |
41| **Tools** | `tools` capability | Browse schemas, fill arguments, call, inspect results. |
42| **Prompts** | `prompts` capability | List prompts, supply arguments, preview generated messages. |
43| **Resources** | `resources` capability | Browse, read, and subscribe to resources. |
44| **Tasks** | `capabilities.tasks` (legacy era) or the tasks extension (modern era) | Track long-running tool calls. |
45| **Logs** | `logging` capability | Server `notifications/message` output, plus the era-appropriate level control. |
46| **Protocol** | Always | The JSON-RPC transcript: requests, responses, notifications. |
47| **Network** | HTTP / SSE servers | The raw HTTP view: status, headers, bodies. |
48| **Console** | stdio servers | The server process's `stderr`. |
4949 
5050**Network** and **Console** never appear together. Legacy and modern eras are described in [Protocol eras](/docs/2026-07-28/tools/inspector/protocol-eras).
5151 
from line 67
6767 
6868Where that list comes from, and whether it's editable, depends on how you launched:
6969 
70| Launch | Server list | Editable? |
71| -------------------------------------------- | ----------------------------------------------------------------------- | --------- |
72| `mcp-inspector --web` | The default catalog `~/.mcp-inspector/mcp.json`, seeded on first launch | Yes |
73| `--catalog <path>` | That file, seeded with the sample servers if missing | Yes |
74| `--config <path>` | That file, read-only (never written or seeded) | No |
75| `--server-url <url>` or a positional command | One ad-hoc server, held in memory | No |
70| Launch | Server list | Editable? |
71| - | - | - |
72| `mcp-inspector --web` | The default catalog `~/.mcp-inspector/mcp.json`, seeded on first launch | Yes |
73| `--catalog <path>` | That file, seeded with the sample servers if missing | Yes |
74| `--config <path>` | That file, read-only (never written or seeded) | No |
75| `--server-url <url>` or a positional command | One ad-hoc server, held in memory | No |
7676 
7777On a first launch the web client seeds the catalog with two sample servers: a filesystem server scoped to `/tmp` and the canonical "everything" reference server. See [Configuration and flags](/docs/2026-07-28/tools/inspector/configuration) for the full rules, including why the CLI and TUI seed an empty catalog instead.
7878 
from line 151
151151http://127.0.0.1:6274/?serverUrl=<url>&transport=http|sse&autoConnect=<token>
152152```
153153 
154| Parameter | Meaning |
155| ------------- | -------------------------------------------------------------------------------------------------------------- |
156| `serverUrl` | The MCP server URL. Restricted to `http:` / `https:`; a crafted `javascript:` or `file:` value is rejected. |
157| `transport` | `http` (default) or `sse`. |
154| Parameter | Meaning |
155| - | - |
156| `serverUrl` | The MCP server URL. Restricted to `http:` / `https:`; a crafted `javascript:` or `file:` value is rejected. |
157| `transport` | `http` (default) or `sse`. |
158158| `autoConnect` | **Required CSRF gate.** Must equal the per-launch session token, which only whatever started the server knows. |
159159 
160160Three further parameters land you on a *rendered app*: `openApp=<toolName>` names the tool, `appArgs=<base64url(JSON)>` supplies its arguments (merged over the tool's schema defaults), and `autoOpen=<token>` fires the tool call automatically. Because `autoOpen` fires a call, it carries the same mandatory token gate as `autoConnect`.

docs/draft/develop/build-with-agent-skills Changed · +4 / -4 lines

from line 13
1313[`mcp-server-dev` plugin](https://github.com/anthropics/claude-plugins-official/tree/main/plugins/mcp-server-dev).
1414It provides three composing skills:
1515 
16| Skill | Purpose |
17| ------------------ | ----------------------------------------------------------------------------------------------------------------------- |
16| Skill | Purpose |
17| - | - |
1818| `build-mcp-server` | Entry point. Interrogates the use case, picks a deployment model and tool-design pattern, routes to specialized skills. |
19| `build-mcp-app` | Adds interactive UI widgets (forms, pickers, dashboards) rendered inline in chat. |
20| `build-mcpb` | Packages a local stdio server with its runtime so users can install it without Node or Python. |
19| `build-mcp-app` | Adds interactive UI widgets (forms, pickers, dashboards) rendered inline in chat. |
20| `build-mcpb` | Packages a local stdio server with its runtime so users can install it without Node or Python. |
2121 
2222Each skill ships a `SKILL.md` file plus a `references/` folder of supporting
2323material (auth flows, tool-design patterns, widget templates, manifest schemas)

docs/draft/develop/clients/client-best-practices Changed · +12 / -12 lines

from line 129
129129 
130130When implementing progressive discovery:
131131 
132| Guideline | Rationale |
133| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
134| **Offer multiple detail levels** | Let the model choose between name-only, name-and-description, or full-schema responses. |
135| **Cache tool definitions** | Once fetched from a server, memoize the definition host-side so re-injecting it later doesn't need another `tools/list` round trip. This is separate from what's currently in the model's context. |
136| **Refresh on `list_changed`** | Re-index the search catalog when a server sends `notifications/tools/list_changed`. |
137| **Group tools by server** | Present tools organized by their source server so the model can reason about related capabilities. |
132| Guideline | Rationale |
133| - | - |
134| **Offer multiple detail levels** | Let the model choose between name-only, name-and-description, or full-schema responses. |
135| **Cache tool definitions** | Once fetched from a server, memoize the definition host-side so re-injecting it later doesn't need another `tools/list` round trip. This is separate from what's currently in the model's context. |
136| **Refresh on `list_changed`** | Re-index the search catalog when a server sends `notifications/tools/list_changed`. |
137| **Group tools by server** | Present tools organized by their source server so the model can reason about related capabilities. |
138138 
139139### Caching
140140 
from line 243
243243 
244244The right sandbox depends on the language you want the model to write, your host application's language, and how much isolation you need. The table lists example runtimes rather than endorsements; evaluate maturity for your use case:
245245 
246| Sandboxed language | Runtime / Library | Host language | Approach |
247| ------------------ | ------------------------------------------------------------- | ----------------- | ----------------------------------------------------------------------------------------------- |
248| **JavaScript** | [Deno](https://github.com/denoland/deno), `isolated-vm` | Rust / Node / CLI | V8-based runtimes with fine-grained permissions. Can disable all permissions for full lockdown. |
249| **Python** | [Monty](https://github.com/pydantic/monty) *(experimental)* | Rust | Minimal Python interpreter built for AI use cases. No I/O by default. |
250| **TypeScript** | [pctx](https://github.com/portofcontext/pctx) *(early-stage)* | Python / Rust | Incorporates code mode concepts as a library, with low-level Rust support. |
251| **Any (via Wasm)** | [Wasmtime](https://github.com/bytecodealliance/wasmtime) | Rust / C / Go | Compile any language to Wasm and run it with capability-based security. |
246| Sandboxed language | Runtime / Library | Host language | Approach |
247| - | - | - | - |
248| **JavaScript** | [Deno](https://github.com/denoland/deno), `isolated-vm` | Rust / Node / CLI | V8-based runtimes with fine-grained permissions. Can disable all permissions for full lockdown. |
249| **Python** | [Monty](https://github.com/pydantic/monty) *(experimental)* | Rust | Minimal Python interpreter built for AI use cases. No I/O by default. |
250| **TypeScript** | [pctx](https://github.com/portofcontext/pctx) *(early-stage)* | Python / Rust | Incorporates code mode concepts as a library, with low-level Rust support. |
251| **Any (via Wasm)** | [Wasmtime](https://github.com/bytecodealliance/wasmtime) | Rust / C / Go | Compile any language to Wasm and run it with capability-based security. |
252252 
253253Regardless of sandbox, the integration pattern is the same: the host injects function stubs, intercepts calls over an in-process or stdio channel (so network permissions can stay fully denied), and dispatches them as `tools/call` requests to MCP servers.
254254 

docs/draft/learn/client-concepts Changed · +5 / -5 lines

from line 8
88 
99In addition to making use of context provided by servers, clients may provide several features to servers. These client features allow server authors to build richer interactions.
1010 
11| Feature | Explanation | Example |
12| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
13| **Elicitation** | Elicitation enables servers to request specific information from users during interactions, providing a structured way for servers to gather information on demand. | A server booking travel may ask for the user's preferences on airplane seats, room type or their contact number to finalize a booking. |
14| **Roots** | Roots allow clients to specify which directories servers should focus on, communicating intended scope through a coordination mechanism. Roots are [deprecated](/specification/draft/deprecated) as of protocol version `2026-07-28`. | A server for booking travel may be given access to a specific directory, from which it can read a user's calendar. |
15| **Sampling** | Sampling allows servers to request LLM completions through the client, enabling an agentic workflow. This approach puts the client in complete control of user permissions and security measures. Sampling is deprecated as of protocol version `2026-07-28`. | A server for booking travel may send a list of flights to an LLM and request that the LLM pick the best flight for the user. |
11| Feature | Explanation | Example |
12| - | - | - |
13| **Elicitation** | Elicitation enables servers to request specific information from users during interactions, providing a structured way for servers to gather information on demand. | A server booking travel may ask for the user's preferences on airplane seats, room type or their contact number to finalize a booking. |
14| **Roots** | Roots allow clients to specify which directories servers should focus on, communicating intended scope through a coordination mechanism. Roots are [deprecated](/specification/draft/deprecated) as of protocol version `2026-07-28`. | A server for booking travel may be given access to a specific directory, from which it can read a user's calendar. |
15| **Sampling** | Sampling allows servers to request LLM completions through the client, enabling an agentic workflow. This approach puts the client in complete control of user permissions and security measures. Sampling is deprecated as of protocol version `2026-07-28`. | A server for booking travel may send a list of flights to an LLM and request that the LLM pick the best flight for the user. |
1616 
1717### Elicitation
1818 

docs/draft/learn/server-concepts Changed · +18 / -18 lines

from line 8
88 
99Servers provide functionality through three building blocks:
1010 
11| Feature | Explanation | Examples | Who controls it |
12| ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------ | --------------- |
13| **Tools** | Functions that your LLM can actively call, and decides when to use them based on user requests. Tools can write to databases, call external APIs, modify files, or trigger other logic. | Search flights<br />Send messages<br />Create calendar events | Model |
14| **Resources** | Passive data sources that provide read-only access to information for context, such as file contents, database schemas, or API documentation. | Retrieve documents<br />Access knowledge bases<br />Read calendars | Application |
15| **Prompts** | Pre-built instruction templates that tell the model to work with specific tools and resources. | Plan a vacation<br />Summarize my meetings<br />Draft an email | User |
11| Feature | Explanation | Examples | Who controls it |
12| - | - | - | - |
13| **Tools** | Functions that your LLM can actively call, and decides when to use them based on user requests. Tools can write to databases, call external APIs, modify files, or trigger other logic. | Search flights<br />Send messages<br />Create calendar events | Model |
14| **Resources** | Passive data sources that provide read-only access to information for context, such as file contents, database schemas, or API documentation. | Retrieve documents<br />Access knowledge bases<br />Read calendars | Application |
15| **Prompts** | Pre-built instruction templates that tell the model to work with specific tools and resources. | Plan a vacation<br />Summarize my meetings<br />Draft an email | User |
1616 
1717We will use a hypothetical scenario to demonstrate the role of each of these features, and show how they can work together.
1818 
from line 26
2626 
2727**Protocol operations:**
2828 
29| Method | Purpose | Returns |
30| ------------ | ------------------------ | -------------------------------------- |
29| Method | Purpose | Returns |
30| - | - | - |
3131| `tools/list` | Discover available tools | Array of tool definitions with schemas |
32| `tools/call` | Execute a specific tool | Tool execution result |
32| `tools/call` | Execute a specific tool | Tool execution result |
3333 
3434**Example tool definition:**
3535 
from line 109
109109 
110110**Protocol operations:**
111111 
112| Method | Purpose | Returns |
113| -------------------------- | ------------------------------- | -------------------------------------- |
114| `resources/list` | List available direct resources | Array of resource descriptors |
115| `resources/templates/list` | Discover resource templates | Array of resource template definitions |
116| `resources/read` | Retrieve resource contents | Resource data with metadata |
117| `subscriptions/listen` | Monitor resource changes | Stream of update notifications |
112| Method | Purpose | Returns |
113| - | - | - |
114| `resources/list` | List available direct resources | Array of resource descriptors |
115| `resources/templates/list` | Discover resource templates | Array of resource template definitions |
116| `resources/read` | Retrieve resource contents | Resource data with metadata |
117| `subscriptions/listen` | Monitor resource changes | Stream of update notifications |
118118 
119119To watch specific resources for changes, a client sends a [`subscriptions/listen`](/specification/draft/basic/patterns/subscriptions) request with the resource URIs listed in the `resourceSubscriptions` filter. The server delivers `notifications/resources/updated` on the resulting stream whenever a watched resource changes.
120120 
from line 182
182182 
183183**Protocol operations:**
184184 
185| Method | Purpose | Returns |
186| -------------- | -------------------------- | ------------------------------------- |
187| `prompts/list` | Discover available prompts | Array of prompt descriptors |
188| `prompts/get` | Retrieve prompt details | Full prompt definition with arguments |
185| Method | Purpose | Returns |
186| - | - | - |
187| `prompts/list` | Discover available prompts | Array of prompt descriptors |
188| `prompts/get` | Retrieve prompt details | Full prompt definition with arguments |
189189 
190190#### Example: Streamlined Workflows
191191 

docs/draft/sdk Changed · +12 / -12 lines

from line 6
66 
77## Available SDKs
88 
9| SDK | Repository | Tier |
10| :----------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------- | ------------------------------------------------: |
11| <Icon icon="square-js" size={24} />   [TypeScript](https://ts.sdk.modelcontextprotocol.io) | [modelcontextprotocol/typescript-sdk](https://github.com/modelcontextprotocol/typescript-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
12| <Icon icon="python" size={24} />   [Python](https://py.sdk.modelcontextprotocol.io) | [modelcontextprotocol/python-sdk](https://github.com/modelcontextprotocol/python-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
13| <Icon icon="square-c" size={24} />   [C#](https://csharp.sdk.modelcontextprotocol.io) | [modelcontextprotocol/csharp-sdk](https://github.com/modelcontextprotocol/csharp-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
14| <Icon icon="golang" size={24} />   [Go](https://go.sdk.modelcontextprotocol.io) | [modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
15| <Icon icon="rust" size={24} />   [Rust](https://rust.sdk.modelcontextprotocol.io) | [modelcontextprotocol/rust-sdk](https://github.com/modelcontextprotocol/rust-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
16| <Icon icon="java" size={24} />   [Java](https://java.sdk.modelcontextprotocol.io) | [modelcontextprotocol/java-sdk](https://github.com/modelcontextprotocol/java-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
17| <Icon icon="gem" size={24} />   [Ruby](https://ruby.sdk.modelcontextprotocol.io) | [modelcontextprotocol/ruby-sdk](https://github.com/modelcontextprotocol/ruby-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
18| <Icon icon="swift" size={24} />   Swift | [modelcontextprotocol/swift-sdk](https://github.com/modelcontextprotocol/swift-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
19| <Icon icon="php" size={24} />   [PHP](https://php.sdk.modelcontextprotocol.io) | [modelcontextprotocol/php-sdk](https://github.com/modelcontextprotocol/php-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
20| <Icon icon="square-k" size={24} />   [Kotlin](https://kotlin.sdk.modelcontextprotocol.io) | [modelcontextprotocol/kotlin-sdk](https://github.com/modelcontextprotocol/kotlin-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
9| SDK | Repository | Tier |
10| :- | :- | -: |
11| <Icon icon="square-js" size={24} />   [TypeScript](https://ts.sdk.modelcontextprotocol.io) | [modelcontextprotocol/typescript-sdk](https://github.com/modelcontextprotocol/typescript-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
12| <Icon icon="python" size={24} />   [Python](https://py.sdk.modelcontextprotocol.io) | [modelcontextprotocol/python-sdk](https://github.com/modelcontextprotocol/python-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
13| <Icon icon="square-c" size={24} />   [C#](https://csharp.sdk.modelcontextprotocol.io) | [modelcontextprotocol/csharp-sdk](https://github.com/modelcontextprotocol/csharp-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
14| <Icon icon="golang" size={24} />   [Go](https://go.sdk.modelcontextprotocol.io) | [modelcontextprotocol/go-sdk](https://github.com/modelcontextprotocol/go-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
15| <Icon icon="rust" size={24} />   [Rust](https://rust.sdk.modelcontextprotocol.io) | [modelcontextprotocol/rust-sdk](https://github.com/modelcontextprotocol/rust-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
16| <Icon icon="gem" size={24} />   [Ruby](https://ruby.sdk.modelcontextprotocol.io) | [modelcontextprotocol/ruby-sdk](https://github.com/modelcontextprotocol/ruby-sdk) | <Badge color="blue" shape="pill">Tier 1</Badge> |
17| <Icon icon="java" size={24} />   [Java](https://java.sdk.modelcontextprotocol.io) | [modelcontextprotocol/java-sdk](https://github.com/modelcontextprotocol/java-sdk) | <Badge color="purple" shape="pill">Tier 2</Badge> |
18| <Icon icon="swift" size={24} />   Swift | [modelcontextprotocol/swift-sdk](https://github.com/modelcontextprotocol/swift-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
19| <Icon icon="php" size={24} />   [PHP](https://php.sdk.modelcontextprotocol.io) | [modelcontextprotocol/php-sdk](https://github.com/modelcontextprotocol/php-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
20| <Icon icon="square-k" size={24} />   [Kotlin](https://kotlin.sdk.modelcontextprotocol.io) | [modelcontextprotocol/kotlin-sdk](https://github.com/modelcontextprotocol/kotlin-sdk) | <Badge color="orange" shape="pill">Tier 3</Badge> |
2121 
2222See [SDK Tiering System](/community/sdk-tiers) for details on what each tier means.
2323 

docs/draft/tools/inspector Changed · +4 / -4 lines

from line 4
44 
55The [MCP Inspector](https://github.com/modelcontextprotocol/inspector) is the reference developer tool for testing and debugging [MCP servers](/docs/draft/learn/server-concepts). It ships as a single package, `@modelcontextprotocol/inspector`, providing **three clients behind one binary**:
66 
7| Client | Invocation | What it's for |
8| ------- | ------------------------------------------- | --------------------------------------------------------------------------------- |
9| **Web** | `npx @modelcontextprotocol/inspector` | A full graphical inspector in the browser. The default, and the richest surface. |
7| Client | Invocation | What it's for |
8| - | - | - |
9| **Web** | `npx @modelcontextprotocol/inspector` | A full graphical inspector in the browser. The default, and the richest surface. |
1010| **CLI** | `npx @modelcontextprotocol/inspector --cli` | A scriptable, machine-readable client for CI, shell pipelines, and coding agents. |
11| **TUI** | `npx @modelcontextprotocol/inspector --tui` | An interactive terminal UI, for when a browser isn't available or wanted. |
11| **TUI** | `npx @modelcontextprotocol/inspector --tui` | An interactive terminal UI, for when a browser isn't available or wanted. |
1212 
1313All three are built on the same shared core, so a connection behaves identically across them: the same transports, the same configuration files, the same OAuth state on disk, and the same [protocol-era](/docs/draft/tools/inspector/protocol-eras) negotiation (legacy vs. modern 2026-07-28).
1414 

docs/draft/tools/inspector/authorization Changed · +16 / -16 lines

from line 56
5656 
5757The web app listens for the OAuth callback on its own URL, while the CLI and TUI deliberately share a second one:
5858 
59| Surface | Default callback | Why |
60| ------- | -------------------------------------- | ---------------------------------------------------------------------------------- |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
59| Surface | Default callback | Why |
60| - | - | - |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
6262| **CLI** | `http://127.0.0.1:6276/oauth/callback` | A dedicated loopback listener, so it doesn't collide with a running web Inspector. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
6464 
6565**Register `http://127.0.0.1:6276/oauth/callback`** on any IdP that requires pre-registered redirect URIs before using the CLI or TUI. A predictable default is the point: you register once and reuse it.
6666 
from line 83
8383 
8484## Where credentials live
8585 
86| File | Contents |
87| --------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
86| File | Contents |
87| - | - |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
9191 
9292The path to `oauth.json` is resolved in order: `MCP_INSPECTOR_OAUTH_STATE_PATH`, then `<MCP_STORAGE_DIR>/oauth.json` (see [Environment variables](/docs/draft/tools/inspector/configuration#environment-variables)), then the default above. All three clients resolve it the same way. Command-line `--client-id` / `--client-secret` / `--client-metadata-url` override `client.json`.
9393 
from line 122
122122 
123123The common case: a human completed OAuth in the web Inspector on this machine, and now a script wants to use that token.
124124 
125| Flag | Behavior |
126| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
125| Flag | Behavior |
126| - | - |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
132132 
133133A typical remote-VM sequence:
134134 

docs/draft/tools/inspector/cli Changed · +20 / -20 lines

from line 42
4242 
4343## Methods
4444 
45| `--method` | Required companions | Notes |
46| ------------------------------ | ----------------------------------------------------- | -------------------------------------------------------------------------------- |
47| `initialize` | None | Connect-only probe: `{serverInfo, protocolVersion, capabilities, instructions}`. |
48| `tools/list` | None | |
49| `tools/call` | `--tool-name`, plus `--tool-arg` / `--tool-args-json` | |
50| `resources/list` | None | |
51| `resources/read` | `--uri` | |
52| `resources/templates/list` | None | |
53| `prompts/list` | None | |
54| `prompts/get` | `--prompt-name`, `--prompt-args` | |
55| `logging/setLevel` | `--log-level` | Legacy era only; modern servers opt in per request instead. |
56| `servers/list`, `servers/show` | None | Read the catalog **without connecting** to anything. |
45| `--method` | Required companions | Notes |
46| - | - | - |
47| `initialize` | None | Connect-only probe: `{serverInfo, protocolVersion, capabilities, instructions}`. |
48| `tools/list` | None | |
49| `tools/call` | `--tool-name`, plus `--tool-arg` / `--tool-args-json` | |
50| `resources/list` | None | |
51| `resources/read` | `--uri` | |
52| `resources/templates/list` | None | |
53| `prompts/list` | None | |
54| `prompts/get` | `--prompt-name`, `--prompt-args` | |
55| `logging/setLevel` | `--log-level` | Legacy era only; modern servers opt in per request instead. |
56| `servers/list`, `servers/show` | None | Read the catalog **without connecting** to anything. |
5757 
5858Stream- or session-only methods (`logging/tail`, for example) are rejected, since a process that exits can't hold a stream open.
5959 
from line 106
106106 
107107Every non-zero exit maps to a stable failure class, so a caller can branch on *why* without scraping prose:
108108 
109| Code | Meaning |
110| ---- | ---------------------------------------------------------------------------- |
111| `0` | Success. |
112| `1` | Usage or unexpected error (the catch-all). |
113| `2` | No MCP App found on the tool (`--app-info` probe). |
114| `3` | Server requires authentication (401/403, `WWW-Authenticate`, OAuth). |
115| `4` | Server unreachable (DNS, connection refused, timeout, `fetch failed`). |
116| `5` | Tool error: `tools/call` returned `isError: true`, or the tool wasn't found. |
109| Code | Meaning |
110| - | - |
111| `0` | Success. |
112| `1` | Usage or unexpected error (the catch-all). |
113| `2` | No MCP App found on the tool (`--app-info` probe). |
114| `3` | Server requires authentication (401/403, `WWW-Authenticate`, OAuth). |
115| `4` | Server unreachable (DNS, connection refused, timeout, `fetch failed`). |
116| `5` | Tool error: `tools/call` returned `isError: true`, or the tool wasn't found. |
117117 
118118On any non-zero exit the CLI also writes a **single JSON line to stderr**:
119119 

docs/draft/tools/inspector/configuration Changed · +56 / -56 lines

from line 6
66 
77## The launcher owns exactly two things
88 
9| Flag | Behavior |
10| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
9| Flag | Behavior |
10| - | - |
1111| `--web` / `--cli` / `--tui` | Selects the client, `--web` by default. Passing more than one fails with `Specify at most one of --web, --cli, or --tui.` Launcher flags must come first: parsing stops at the first argument the launcher does not own, and everything from that point on is forwarded to the client unchanged. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
1313 
1414Everything below belongs to a client.
1515 
from line 19
1919 
2020All three clients resolve `--catalog` and `--config` through the same shared code, so each flag behaves the same in the web app, the CLI, and the TUI. Where the two differ from each other is the table below.
2121 
22| | `--catalog <path>` | `--config <path>` |
23| --------------------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------- |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
22| | `--catalog <path>` | `--config <path>` |
23| - | - | - |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
2929 
3030The two are **mutually exclusive**, and neither combines with an ad-hoc target. Passing both is rejected identically by all three clients.
3131 
from line 73
7373 
7474Defined **separately by each of web, CLI, and TUI**, so they're available in all three, with the divergences noted:
7575 
76| Flag | Meaning | Divergence |
77| ------------------------ | ----------------------------------------------------- | ----------------------------------------------------------------------------------------------- |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
76| Flag | Meaning | Divergence |
77| - | - | - |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
8787 
8888### The `--` separator
8989 
from line 97
9797 
9898## Web-only flags
9999 
100| Flag | Meaning |
101| ------- | ----------------------------------------------------------------------------------------------------- |
100| Flag | Meaning |
101| - | - |
102102| `--dev` | Run the Vite dev server instead of the pre-built bundle. Useful when working on the Inspector itself. |
103103 
104104## CLI and TUI: OAuth client flags
from line 105
105105 
106106These five are defined by the **CLI and TUI** only. The web client obtains the same settings through its Client Settings dialog.
107107 
108| Flag | Environment variable | Meaning |
109| ----------------------------- | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
108| Flag | Environment variable | Meaning |
109| - | - | - |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
115115 
116116## CLI-only flags
117117 
118118The whole scripting surface belongs to the CLI. See [CLI client](/docs/draft/tools/inspector/cli) for usage.
119119 
120| Group | Flags |
121| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
120| Group | Flags |
121| - | - |
122122| **What to invoke** | `--method`, `--tool-name`, `--tool-arg`, `--tool-args-json`, `--uri`, `--prompt-name`, `--prompt-args`, `--log-level`, `--metadata`, `--tool-metadata` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
125125 
126126## Environment variables
127127 
from line 129
129129 
130130### Read by the launcher
131131 
132| Variable | Effect |
133| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
132| Variable | Effect |
133| - | - |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
136136 
137137### CLI and TUI
138138 
139| Variable | Effect |
140| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
139| Variable | Effect |
140| - | - |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
147147 
148148### Web backend environment variables
149149 
150| Variable | Effect |
151| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/draft/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
150| Variable | Effect |
151| - | - |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/draft/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
160160 
161161<Warning>
162162 Never combine `DANGEROUSLY_OMIT_AUTH` and `DANGEROUSLY_BIND_ALL_INTERFACES`.

docs/draft/tools/inspector/protocol-eras Changed · +19 / -19 lines

from line 8
88 
99Each server carries a `protocolEra` of `legacy`, `auto`, or `modern`. In the web client it lives in **Server Settings**; in a catalog or config file it is the `protocolEra` field; in the CLI and TUI it comes from that same file.
1010 
11| Era | What the Inspector does at connect |
12| -------- | --------------------------------------------------------------------------------------- |
13| `legacy` | **The default.** Plain `initialize`, no probing at all. |
14| `auto` | Probe `server/discover` first, and fall back to `initialize` on any non-modern outcome. |
15| `modern` | Pin exactly `2026-07-28`. No fallback, so a non-modern server fails loudly. |
11| Era | What the Inspector does at connect |
12| - | - |
13| `legacy` | **The default.** Plain `initialize`, no probing at all. |
14| `auto` | Probe `server/discover` first, and fall back to `initialize` on any non-modern outcome. |
15| `modern` | Pin exactly `2026-07-28`. No fallback, so a non-modern server fails loudly. |
1616 
1717<Note>
1818 **Why `legacy` is the default, and not `auto`.** A debugging tool must not
from line 141
141141 
142142`test-servers/configs/mrtr-showcase-http.json` bundles every shape in one modern server:
143143 
144| Tool | What it exercises |
145| --------------- | ----------------------------------------------------------------------------- |
146| `mrtr_confirm` | A single elicitation round. |
147| `mrtr_two_step` | Two elicitation rounds, threaded through `requestState`. |
148| `mrtr_sample` | An embedded sampling request, routed to the Sampling panel. |
149| `mrtr_roots` | An embedded `roots/list`, answered silently from configured roots (no modal). |
150| `mrtr_edge` | An `inputRequests`-only round, then a `requestState`-only round. |
151| `mrtr_loop` | Never completes, so the client stops at its `MRTR_MAX_ROUNDS` limit. |
144| Tool | What it exercises |
145| - | - |
146| `mrtr_confirm` | A single elicitation round. |
147| `mrtr_two_step` | Two elicitation rounds, threaded through `requestState`. |
148| `mrtr_sample` | An embedded sampling request, routed to the Sampling panel. |
149| `mrtr_roots` | An embedded `roots/list`, answered silently from configured roots (no modal). |
150| `mrtr_edge` | An `inputRequests`-only round, then a `requestState`-only round. |
151| `mrtr_loop` | Never completes, so the client stops at its `MRTR_MAX_ROUNDS` limit. |
152152 
153153<Note>
154154 The legacy `collect_elicitation` pattern (a server calling
from line 208
208208 
209209`test-servers/configs/modern-network-http.json` serves four tools that produce a real HTTP status plus a JSON-RPC error body, one per class:
210210 
211| Tool | HTTP | JSON-RPC code | Meaning |
212| ----------------------------- | ----- | ------------- | ------------------------------------------------------------ |
213| `trigger_header_mismatch` | `400` | `-32020` | A required mirrored header was missing or wrong. |
214| `trigger_missing_capability` | `400` | `-32021` | The request omitted a client capability the server requires. |
215| `trigger_unsupported_version` | `400` | `-32022` | Unsupported version; supported versions in `data.supported`. |
216| `trigger_method_not_found` | `404` | `-32601` | Method not found. |
211| Tool | HTTP | JSON-RPC code | Meaning |
212| - | - | - | - |
213| `trigger_header_mismatch` | `400` | `-32020` | A required mirrored header was missing or wrong. |
214| `trigger_missing_capability` | `400` | `-32021` | The request omitted a client capability the server requires. |
215| `trigger_unsupported_version` | `400` | `-32022` | Unsupported version; supported versions in `data.supported`. |
216| `trigger_method_not_found` | `404` | `-32601` | Method not found. |
217217 
218218<Frame caption="The Network tab shows the HTTP layer; here, the 400 Bad Request the strict server answered with.">
219219 <img src="https://mintcdn.com/mcp/gk28X8wi_tbRYzej/images/inspector/network-modern-headers.png?fit=max&auto=format&n=gk28X8wi_tbRYzej&q=85&s=7df4c01f5ab68aa7632ac3b5a5866b42" width="3840" height="2160" data-path="images/inspector/network-modern-headers.png" />

docs/draft/tools/inspector/recipes Changed · +10 / -10 lines

from line 112
112112 <Step title="Wait on a deterministic signal instead of sleeping">
113113 The Apps screen exposes a stable automation contract. Poll these attributes instead of sleeping:
114114 
115 | Selector | Attribute | Values |
116 | ----------------------------------- | ----------------- | ------------------------------------------------------------------------------------------------------- |
117 | `[data-testid="apps-form"]` | `data-app-status` | `ready` (on failure, `data-app-error` carries the reason) |
118 | `[data-testid="connection-status"]` | `data-status` | `connecting`, then `connected` or `error` (`data-error-message` has the detail) |
119 | `[data-testid="connection-status"]` | `data-deeplink` | `parsed`, `rejected`, or `none` (`none` means no deep link was given, `rejected` means one was refused) |
115 | Selector | Attribute | Values |
116 | - | - | - |
117 | `[data-testid="apps-form"]` | `data-app-status` | `ready` (on failure, `data-app-error` carries the reason) |
118 | `[data-testid="connection-status"]` | `data-status` | `connecting`, then `connected` or `error` (`data-error-message` has the detail) |
119 | `[data-testid="connection-status"]` | `data-deeplink` | `parsed`, `rejected`, or `none` (`none` means no deep link was given, `rejected` means one was refused) |
120120 </Step>
121121</Steps>
122122 
from line 152
152152 
153153The Inspector refuses to bind the **wildcard** all-interfaces addresses (`0.0.0.0`, `::`, and every equivalent spelling) unless you set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Binding a **specific** address is allowed with no opt-in, because that's one deliberate exposure rather than every interface at once, which is the shape DNS-rebinding attacks target.
154154 
155| Goal | What to do |
156| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
157| **Reach it from another machine on the LAN** | `HOST=192.168.1.50`. The default origin allow-list follows the bind host, so `http://192.168.1.50:6274` is accepted with no further config. |
158| **Behind TLS or a reverse proxy** | The browser's `Origin` becomes the public origin, which won't match the bind host. Set `ALLOWED_ORIGINS=https://inspector.example.com`. |
159| **Wildcard bind (containers)** | Set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Loopback access still works out of the box; reaching it at a non-loopback address needs `ALLOWED_ORIGINS`. |
155| Goal | What to do |
156| - | - |
157| **Reach it from another machine on the LAN** | `HOST=192.168.1.50`. The default origin allow-list follows the bind host, so `http://192.168.1.50:6274` is accepted with no further config. |
158| **Behind TLS or a reverse proxy** | The browser's `Origin` becomes the public origin, which won't match the bind host. Set `ALLOWED_ORIGINS=https://inspector.example.com`. |
159| **Wildcard bind (containers)** | Set `DANGEROUSLY_BIND_ALL_INTERFACES=true`. Loopback access still works out of the box; reaching it at a non-loopback address needs `ALLOWED_ORIGINS`. |
160160 
161161<Warning>
162162 `ALLOWED_ORIGINS` **replaces** the default list rather than merging with it. List every origin you'll browse from, including the loopback forms you want to keep:

docs/draft/tools/inspector/tui Changed · +18 / -18 lines

from line 25
2525 
2626## Tabs
2727 
28| Tab | Key | What it shows |
29| ------------- | --- | ------------------------------------------------------------------------------------------- |
30| **Info** | `i` | Server info, capabilities, and negotiated protocol details. |
31| **Auth** | `a` | OAuth state for the selected server, plus a **Clear OAuth state** action. |
32| **Resources** | `r` | Browse and read resources. |
33| **Prompts** | `m` | List prompts and render them with arguments. |
34| **Tools** | `t` | View tools and execute them with form-like inputs. |
35| **Protocol** | `p` | JSON-RPC request/response/notification history. |
36| **Network** | `n` | HTTP traffic for SSE and [Streamable HTTP](/specification/latest/basic/transports) servers. |
37| **Console** | `o` | `stderr` from a connected stdio server process. |
28| Tab | Key | What it shows |
29| - | - | - |
30| **Info** | `i` | Server info, capabilities, and negotiated protocol details. |
31| **Auth** | `a` | OAuth state for the selected server, plus a **Clear OAuth state** action. |
32| **Resources** | `r` | Browse and read resources. |
33| **Prompts** | `m` | List prompts and render them with arguments. |
34| **Tools** | `t` | View tools and execute them with form-like inputs. |
35| **Protocol** | `p` | JSON-RPC request/response/notification history. |
36| **Network** | `n` | HTTP traffic for SSE and [Streamable HTTP](/specification/latest/basic/transports) servers. |
37| **Console** | `o` | `stderr` from a connected stdio server process. |
3838 
3939The accelerators avoid collisions rather than always taking the first letter: **P**rotocol takes `p` so Pro**m**pts takes `m`, and **C**onsole takes `o` because `c` is the global Connect action.
4040 
4141## Navigation
4242 
43| Key | Action |
44| -------------------------------- | --------------------------------------------------- |
45| `Left` / `Right` arrows or `Tab` | Switch tabs |
46| `Up` / `Down` arrows | Move through the current list |
47| `Enter` | Select an item, execute a tool, or fetch a resource |
48| `c` | Connect to the selected server |
49| `d` | Disconnect |
50| `Esc` or `Ctrl+C` | Exit |
43| Key | Action |
44| - | - |
45| `Left` / `Right` arrows or `Tab` | Switch tabs |
46| `Up` / `Down` arrows | Move through the current list |
47| `Enter` | Select an item, execute a tool, or fetch a resource |
48| `c` | Connect to the selected server |
49| `d` | Disconnect |
50| `Esc` or `Ctrl+C` | Exit |
5151 
5252## Authorizing an HTTP server
5353 

docs/draft/tools/inspector/web Changed · +22 / -22 lines

from line 34
3434 
3535## The tab bar
3636 
37| Tab | Shown when | What it does |
38| ------------- | --------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
39| **Servers** | Always | The server list: add, edit, import, connect, and open per-server settings. |
40| **Apps** | The server exposes MCP App tools | Renders a tool's UI in a sandboxed frame. |
41| **Tools** | `tools` capability | Browse schemas, fill arguments, call, inspect results. |
42| **Prompts** | `prompts` capability | List prompts, supply arguments, preview generated messages. |
43| **Resources** | `resources` capability | Browse, read, and subscribe to resources. |
44| **Tasks** | `capabilities.tasks` (legacy era) or the tasks extension (modern era) | Track long-running tool calls. |
45| **Logs** | `logging` capability | Server `notifications/message` output, plus the era-appropriate level control. |
46| **Protocol** | Always | The JSON-RPC transcript: requests, responses, notifications. |
47| **Network** | HTTP / SSE servers | The raw HTTP view: status, headers, bodies. |
48| **Console** | stdio servers | The server process's `stderr`. |
37| Tab | Shown when | What it does |
38| - | - | - |
39| **Servers** | Always | The server list: add, edit, import, connect, and open per-server settings. |
40| **Apps** | The server exposes MCP App tools | Renders a tool's UI in a sandboxed frame. |
41| **Tools** | `tools` capability | Browse schemas, fill arguments, call, inspect results. |
42| **Prompts** | `prompts` capability | List prompts, supply arguments, preview generated messages. |
43| **Resources** | `resources` capability | Browse, read, and subscribe to resources. |
44| **Tasks** | `capabilities.tasks` (legacy era) or the tasks extension (modern era) | Track long-running tool calls. |
45| **Logs** | `logging` capability | Server `notifications/message` output, plus the era-appropriate level control. |
46| **Protocol** | Always | The JSON-RPC transcript: requests, responses, notifications. |
47| **Network** | HTTP / SSE servers | The raw HTTP view: status, headers, bodies. |
48| **Console** | stdio servers | The server process's `stderr`. |
4949 
5050**Network** and **Console** never appear together. Legacy and modern eras are described in [Protocol eras](/docs/draft/tools/inspector/protocol-eras).
5151 
from line 67
6767 
6868Where that list comes from, and whether it's editable, depends on how you launched:
6969 
70| Launch | Server list | Editable? |
71| -------------------------------------------- | ----------------------------------------------------------------------- | --------- |
72| `mcp-inspector --web` | The default catalog `~/.mcp-inspector/mcp.json`, seeded on first launch | Yes |
73| `--catalog <path>` | That file, seeded with the sample servers if missing | Yes |
74| `--config <path>` | That file, read-only (never written or seeded) | No |
75| `--server-url <url>` or a positional command | One ad-hoc server, held in memory | No |
70| Launch | Server list | Editable? |
71| - | - | - |
72| `mcp-inspector --web` | The default catalog `~/.mcp-inspector/mcp.json`, seeded on first launch | Yes |
73| `--catalog <path>` | That file, seeded with the sample servers if missing | Yes |
74| `--config <path>` | That file, read-only (never written or seeded) | No |
75| `--server-url <url>` or a positional command | One ad-hoc server, held in memory | No |
7676 
7777On a first launch the web client seeds the catalog with two sample servers: a filesystem server scoped to `/tmp` and the canonical "everything" reference server. See [Configuration and flags](/docs/draft/tools/inspector/configuration) for the full rules, including why the CLI and TUI seed an empty catalog instead.
7878 
from line 151
151151http://127.0.0.1:6274/?serverUrl=<url>&transport=http|sse&autoConnect=<token>
152152```
153153 
154| Parameter | Meaning |
155| ------------- | -------------------------------------------------------------------------------------------------------------- |
156| `serverUrl` | The MCP server URL. Restricted to `http:` / `https:`; a crafted `javascript:` or `file:` value is rejected. |
157| `transport` | `http` (default) or `sse`. |
154| Parameter | Meaning |
155| - | - |
156| `serverUrl` | The MCP server URL. Restricted to `http:` / `https:`; a crafted `javascript:` or `file:` value is rejected. |
157| `transport` | `http` (default) or `sse`. |
158158| `autoConnect` | **Required CSRF gate.** Must equal the per-launch session token, which only whatever started the server knows. |
159159 
160160Three further parameters land you on a *rendered app*: `openApp=<toolName>` names the tool, `appArgs=<base64url(JSON)>` supplies its arguments (merged over the tool's schema defaults), and `autoOpen=<token>` fires the tool call automatically. Because `autoOpen` fires a call, it carries the same mandatory token gate as `autoConnect`.

extensions/apps/build Changed · +9 / -9 lines

from line 50
5050 
5151 And then copying the skill to the appropriate location for your agent:
5252 
53 | Agent | Skills directory (macOS/Linux) | Skills directory (Windows) |
54 | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ | ------------------------------------- |
55 | [Claude Code](https://docs.anthropic.com/en/docs/claude-code/skills) | `~/.claude/skills/` | `%USERPROFILE%\.claude\skills\` |
56 | [VS Code](https://code.visualstudio.com/docs/copilot/customization/agent-skills) and [GitHub Copilot](https://docs.github.com/en/copilot/concepts/agents/about-agent-skills) | `~/.copilot/skills/` | `%USERPROFILE%\.copilot\skills\` |
57 | [Gemini CLI](https://geminicli.com/docs/cli/skills/) | `~/.gemini/skills/` | `%USERPROFILE%\.gemini\skills\` |
58 | [Cline](https://cline.bot/blog/cline-3-48-0-skills-and-websearch-make-cline-smarter) | `~/.cline/skills/` | `%USERPROFILE%\.cline\skills\` |
59 | [Goose](https://goose-docs.ai/docs/guides/context-engineering/using-skills/) | `~/.config/goose/skills/` | `%USERPROFILE%\.config\goose\skills\` |
60 | [Codex](https://developers.openai.com/codex/skills/) | `~/.codex/skills/` | `%USERPROFILE%\.codex\skills\` |
61 | [Cursor](https://cursor.com/docs/context/skills) | `~/.cursor/skills/` | `%USERPROFILE%\.cursor\skills\` |
53 | Agent | Skills directory (macOS/Linux) | Skills directory (Windows) |
54 | - | - | - |
55 | [Claude Code](https://docs.anthropic.com/en/docs/claude-code/skills) | `~/.claude/skills/` | `%USERPROFILE%\.claude\skills\` |
56 | [VS Code](https://code.visualstudio.com/docs/copilot/customization/agent-skills) and [GitHub Copilot](https://docs.github.com/en/copilot/concepts/agents/about-agent-skills) | `~/.copilot/skills/` | `%USERPROFILE%\.copilot\skills\` |
57 | [Gemini CLI](https://geminicli.com/docs/cli/skills/) | `~/.gemini/skills/` | `%USERPROFILE%\.gemini\skills\` |
58 | [Cline](https://cline.bot/blog/cline-3-48-0-skills-and-websearch-make-cline-smarter) | `~/.cline/skills/` | `%USERPROFILE%\.cline\skills\` |
59 | [Goose](https://goose-docs.ai/docs/guides/context-engineering/using-skills/) | `~/.config/goose/skills/` | `%USERPROFILE%\.config\goose\skills\` |
60 | [Codex](https://developers.openai.com/codex/skills/) | `~/.codex/skills/` | `%USERPROFILE%\.codex\skills\` |
61 | [Cursor](https://cursor.com/docs/context/skills) | `~/.cursor/skills/` | `%USERPROFILE%\.cursor\skills\` |
6262 
6363 <Note>
6464 This list is not comprehensive. Other agents may support skills in different locations; check your agent's documentation.
Feedback