MCP Services
The tool servers that let AI clients operate the lab, how they are grouped, and how a remote client signs in.
The Model Context Protocol (MCP) lets an AI client call tools and read resources on a server. In the lab, MCP is how an assistant is given hands: it can read a phone's SMS, check a host, query data or run an agent, always through a narrow, typed interface.
Pools
Small tool servers are grouped into pools by the kind of power they carry, so each pool can be started, restricted and watched on its own.
| Pool | Purpose |
|---|---|
| Communications | Messaging and calendar tools |
| Data, API and agents | Data access, API calls and agent tools |
| Host and admin | Tools that operate the server itself |
| OAuth gateway | Sign-in and token handling for remote clients |
| SSH bridge | A remote shell over a Server-Sent Events bridge |
Two applications also ship their own MCP endpoint, because their tools belong next to their data:
- PhoneGate exposes the phone: status, SMS, calls, audio and transcripts.
- JobHunter exposes read and control tools for the job agent. MCP is a control surface only: the scheduler and workers keep running with no client connected.
Transport
Endpoints use Streamable HTTP, not the older SSE transport and not a local stdio command. That lets a hosted AI client reach them over the internet with one URL.
Authentication
Every public MCP host has two kinds of path:
- Discovery and OAuth paths are open, so a client can learn how to sign in and complete the flow. A single OAuth gateway serves them for every host.
- Tool paths need a bearer token. A request without it gets
401and a pointer to the OAuth metadata.
Servers that hold their own keys store only hashes of them. A raw token exists only in the secret store of the client that uses it.
Tools are powerful
A host-admin or SSH tool is effectively root on the server. Those pools are kept apart from the rest, sit behind the same authentication as everything else, and are what the audit and rate-limit rules protect hardest.
Safety conventions
- Tools that act on the outside world are labelled as having external effects, so a client can ask a person to confirm.
- Secrets, OAuth tokens and full documents are never returned in a tool result.
- Each write operation leaves an audit event with who did it.
- A pool is a normal service. A failure in one does not take down the others, and the status page lists each pool separately.