Skip to main content
IronClaw supports the Model Context Protocol (MCP), allowing you to connect to external tool servers that provide additional capabilities through a standardized JSON-RPC interface. Location: src/tools/mcp/

What is MCP?

MCP (Model Context Protocol) is a standardized protocol for connecting AI agents to external tool servers. It provides:
  • JSON-RPC communication: Standard request/response protocol
  • Tool discovery: Dynamic tool listing via tools/list
  • Tool execution: Invoke tools via tools/call
  • Authentication: Support for OAuth and custom auth
  • Ecosystem: Pre-built servers for GitHub, Notion, Postgres, etc.
Protocol version: 2024-11-05 Location: src/tools/mcp/protocol.rs:6

Architecture

MCP Protocol Types

Tool Definition

Location: src/tools/mcp/protocol.rs:8-28
Example tool from MCP server:

Requests

Location: src/tools/mcp/protocol.rs:78-148

Responses

Location: src/tools/mcp/protocol.rs:150-176

Content Blocks

Location: src/tools/mcp/protocol.rs:268-292

MCP Client

Location: src/tools/mcp/client.rs

Configuration

Location: src/tools/mcp/config.rs

Server Config

Config File

mcp_servers.json:

Authentication

OAuth Flow

Location: src/tools/mcp/auth.rs
OAuth flow steps:
  1. Check if access token exists and is valid
  2. If expired, use refresh token to get new access token
  3. If no refresh token, initiate new OAuth flow
  4. Store new tokens securely

Session Management

Location: src/tools/mcp/session.rs

Usage Examples

Connect to Unauthenticated Server

Connect to OAuth Server

Register MCP Tools

Tool Annotations

MCP tools can provide hints about their behavior:
Location: src/tools/mcp/protocol.rs:68-76 Annotation types:
  • destructive_hint: Tool performs destructive operations (requires approval)
  • side_effects_hint: Tool has side effects beyond return value
  • read_only_hint: Tool only reads data
  • execution_time_hint: Expected execution time (fast/medium/slow)

MCP vs WASM Tools

Both are first-class in the extension system (ironclaw tool install handles both), but they have different strengths. WASM Tools (IronClaw native):
  • ✅ Sandboxed: fuel metering, memory limits, no access except allowlist
  • ✅ Credentials injected by host, tool code never sees actual token
  • ✅ Output scanned for secret leakage before returning to LLM
  • ✅ Auth (OAuth/manual) declared in capabilities, agent handles flow
  • ✅ Single binary, no process management, works offline
  • ❌ Must build yourself in Rust, no ecosystem, synchronous only
MCP Servers (Model Context Protocol):
  • ✅ Growing ecosystem of pre-built servers (GitHub, Notion, Postgres, etc.)
  • ✅ Any language (TypeScript/Python most common)
  • ✅ Can do websockets, streaming, background polling
  • ❌ External process with full system access (no sandbox)
  • ❌ Manages own credentials, IronClaw can’t prevent leaks
Decision guide: Source: src/tools/README.md:105-136

MCP Server Examples

Popular MCP servers:
  • @modelcontextprotocol/server-github - GitHub API access
  • @modelcontextprotocol/server-postgres - PostgreSQL queries
  • @modelcontextprotocol/server-filesystem - File operations
  • @modelcontextprotocol/server-slack - Slack integration
  • notion-mcp-server - Notion workspace access
  • mcp-server-sqlite - SQLite database access
Find more at: https://github.com/modelcontextprotocol

Running MCP Servers

Node.js Server

Python Server

Docker Server

Protocol Details

Initialize Handshake

List Tools

Call Tool

Next Steps

Building Tools

Create custom tools using the builder

WASM Tools

Build sandboxed WASM tools