Optional `mcp` feature. Supports `server/discover`, `tools/list`, and `tools/call` over HTTP POST with JSON-RPC 2.0. The host authenticates with the same Keeper token used by the public API. Tool discovery is permission filtered; calls check permission again. Requests with an `Origin` header are rejected.
Request Body
Required: Yes
application/json object
{
"jsonrpc": "2.0",
"id": "string",
"method": "server/discover",
"params": {
"name": "string",
"arguments": {},
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}
Responses
200 JSON-RPC result, including tool errors and some protocol errors
application/json object | object
{
"jsonrpc": "2.0",
"id": null,
"result": {
"resultType": "complete",
"_meta": {},
"supportedVersions": [
"string"
],
"capabilities": {}
}
}
400 Invalid JSON-RPC request, headers, or protocol version
application/json object
{
"jsonrpc": "2.0",
"id": null,
"error": {
"code": 1,
"message": "string",
"data": {}
}
}
403 Browser origin rejected
application/json object
{
"jsonrpc": "2.0",
"id": null,
"error": {
"code": 1,
"message": "string",
"data": {}
}
}
404 Unknown MCP method
application/json object
{
"jsonrpc": "2.0",
"id": null,
"error": {
"code": 1,
"message": "string",
"data": {}
}
}
default Error response
application/json object
{
"error": "KEEPER_ALREADY_INITIALIZED",
"details": "string",
"imposters": [
"string"
],
"dead": [
"string"
]
}