mcp

package
v0.91.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

README

MCP runner

mcp/runner calls an external MCP server over stateless Streamable HTTP with the 2026-07-28 protocol. It opens a fresh connection for each Endly action. Tool calls are sent once; transport failures are returned without replaying a call.

The listTools action returns Tools and NextCursor. The call action takes name and structured arguments, and returns Result (the full MCP result), StructuredContent, Content, and IsError. A tool result with isError: true fails the Endly action while retaining the result in the service response. Set allowToolError: true on a call action when a workflow needs to inspect and publish an expected tool error; transport and protocol errors still fail.

pipeline:
  mcp-tool:
    action: mcp/runner:call
    init:
      url: https://example.com/mcp
      bearerTokenSecret: example-mcp-token
      timeoutMs: 30000
      name: describe
      arguments:
        entity: sample

bearerTokenSecret is a Scy resource reference or a root workflow credentialMap alias. The secret value is loaded at runtime and never included in the workflow response. Authenticated HTTP requires HTTPS, except for loopback HTTP. HTTP redirects are rejected when calling MCP endpoints.

For Scy OOB OAuth, set oauth instead of bearerTokenSecret:

oauth:
  configURL: /path/to/oauth-config.json|blowfish://default
  secretsURL: /path/to/basic-secret.json|blowfish://default
  authFlow: OOB
  scopes: [read]
  usePKCE: true

The OAuth config and Basic credentials must be stored as Scy resources. The runner passes these references to scy/auth/authorizer, receives an access token, and uses it only for the current MCP operation. OOB authorization may require interactive input. timeoutMs bounds authorization and the MCP call together. OAuth and bearer token references are mutually exclusive. No OAuth provider is contacted by the unit tests; they inject a local authorizer and mock HTTP server.

Documentation

Index

Constants

View Source
const ServiceID = "mcp/runner"

Variables

This section is empty.

Functions

func New

func New() endly.Service

Types

type CallRequest

type CallRequest struct {
	Request
	Name      string                 `json:"name" yaml:"name"`
	Arguments map[string]interface{} `json:"arguments,omitempty" yaml:"arguments,omitempty"`
	// AllowToolError returns an MCP isError result as a successful Endly action
	// so a workflow can inspect the complete diagnostic content.
	AllowToolError bool `json:"allowToolError,omitempty" yaml:"allowToolError,omitempty"`
}

func (*CallRequest) Validate

func (r *CallRequest) Validate() error

type CallResponse

type CallResponse struct {
	Result            *schema.CallToolResult
	StructuredContent interface{}
	Content           []schema.CallToolResultContentElem
	IsError           bool
}

CallResponse preserves the full MCP result, including content and isError. StructuredContent is the decoded JSON object returned by tools that provide it.

type ListToolsRequest

type ListToolsRequest struct {
	Request
	Cursor *string `json:"cursor,omitempty" yaml:"cursor,omitempty"`
}

func (*ListToolsRequest) Validate

func (r *ListToolsRequest) Validate() error

type ListToolsResponse

type ListToolsResponse struct {
	Tools      []schema.Tool
	NextCursor *string
}

type OAuthRequest

type OAuthRequest struct {
	ConfigURL  string   `json:"configURL" yaml:"configURL"`
	SecretsURL string   `json:"secretsURL" yaml:"secretsURL"`
	AuthFlow   string   `json:"authFlow,omitempty" yaml:"authFlow,omitempty"`
	Scopes     []string `json:"scopes,omitempty" yaml:"scopes,omitempty"`
	UsePKCE    bool     `json:"usePKCE,omitempty" yaml:"usePKCE,omitempty"`
}

OAuthRequest identifies Scy encrypted resources. No credential literals are accepted in the workflow request.

type Request

type Request struct {
	URL               string        `json:"url" yaml:"url"`
	BearerTokenSecret string        `json:"bearerTokenSecret,omitempty" yaml:"bearerTokenSecret,omitempty"`
	OAuth             *OAuthRequest `json:"oauth,omitempty" yaml:"oauth,omitempty"`
	TimeoutMs         int           `json:"timeoutMs,omitempty" yaml:"timeoutMs,omitempty"`
	ProtocolVersion   string        `json:"protocolVersion,omitempty" yaml:"protocolVersion,omitempty"`
}

Request configures one outbound MCP operation. BearerTokenSecret is a Scy resource reference (or a workflow credentialMap alias), never a token value.

func (*Request) Validate

func (r *Request) Validate() error

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL