src/tools/mcp/
What is MCP?
MCP (Model Context Protocol) is a standardized protocol for connecting AI agents to external tool servers. It provides:- JSON-RPC communication: Standard request/response protocol
- Tool discovery: Dynamic tool listing via
tools/list - Tool execution: Invoke tools via
tools/call - Authentication: Support for OAuth and custom auth
- Ecosystem: Pre-built servers for GitHub, Notion, Postgres, etc.
2024-11-05
Location: src/tools/mcp/protocol.rs:6
Architecture
MCP Protocol Types
Tool Definition
Location:src/tools/mcp/protocol.rs:8-28
Requests
Location:src/tools/mcp/protocol.rs:78-148
Responses
Location:src/tools/mcp/protocol.rs:150-176
Content Blocks
Location:src/tools/mcp/protocol.rs:268-292
MCP Client
Location:src/tools/mcp/client.rs
Configuration
Location:src/tools/mcp/config.rs
Server Config
Config File
mcp_servers.json:
Authentication
OAuth Flow
Location:src/tools/mcp/auth.rs
- Check if access token exists and is valid
- If expired, use refresh token to get new access token
- If no refresh token, initiate new OAuth flow
- Store new tokens securely
Session Management
Location:src/tools/mcp/session.rs
Usage Examples
Connect to Unauthenticated Server
Connect to OAuth Server
Register MCP Tools
Tool Annotations
MCP tools can provide hints about their behavior:src/tools/mcp/protocol.rs:68-76
Annotation types:
destructive_hint: Tool performs destructive operations (requires approval)side_effects_hint: Tool has side effects beyond return valueread_only_hint: Tool only reads dataexecution_time_hint: Expected execution time (fast/medium/slow)
MCP vs WASM Tools
Both are first-class in the extension system (ironclaw tool install handles both), but they have different strengths.
WASM Tools (IronClaw native):
- ✅ Sandboxed: fuel metering, memory limits, no access except allowlist
- ✅ Credentials injected by host, tool code never sees actual token
- ✅ Output scanned for secret leakage before returning to LLM
- ✅ Auth (OAuth/manual) declared in capabilities, agent handles flow
- ✅ Single binary, no process management, works offline
- ❌ Must build yourself in Rust, no ecosystem, synchronous only
- ✅ Growing ecosystem of pre-built servers (GitHub, Notion, Postgres, etc.)
- ✅ Any language (TypeScript/Python most common)
- ✅ Can do websockets, streaming, background polling
- ❌ External process with full system access (no sandbox)
- ❌ Manages own credentials, IronClaw can’t prevent leaks
Source:
src/tools/README.md:105-136
MCP Server Examples
Popular MCP servers:- @modelcontextprotocol/server-github - GitHub API access
- @modelcontextprotocol/server-postgres - PostgreSQL queries
- @modelcontextprotocol/server-filesystem - File operations
- @modelcontextprotocol/server-slack - Slack integration
- notion-mcp-server - Notion workspace access
- mcp-server-sqlite - SQLite database access
Running MCP Servers
Node.js Server
Python Server
Docker Server
Protocol Details
Initialize Handshake
List Tools
Call Tool
Next Steps
Building Tools
Create custom tools using the builder
WASM Tools
Build sandboxed WASM tools