Skip to content
Tenzro
Documentation menu
Agents

MCP server

Connect any MCP client to Tenzro over Streamable HTTP. Read tools are open; write tools need an OAuth 2.1 token bound to your key with DPoP.

Tenzro exposes the network to AI agents as a Model Context Protocol server. Any MCP client, whether a desktop assistant, an IDE agent or your own framework, can connect and use the network's tools: wallet and identity, inference in every modality, agent memory, payments, storage and files, skills and tools, tasks and templates, verification and events.

Endpoint

TransportURL
Streamable HTTP (JSON-RPC 2.0)https://mcp.tenzro.xyz/mcp

Every node can serve MCP; the default local address is http://localhost:3001/mcp.

Connect a client

Most clients accept a URL. For a desktop or IDE client, add:

json
{
  "mcpServers": {
    "tenzro": {
      "url": "https://mcp.tenzro.xyz/mcp"
    }
  }
}

List the tools from the command line:

bash
curl -s -X POST https://mcp.tenzro.xyz/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Call a read tool:

bash
curl -s -X POST https://mcp.tenzro.xyz/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call",
       "params":{"name":"get_node_status","arguments":{}}}'

Authentication

Tools are tiered.

  • Read tools need no credentials: node status, balances, models, DID resolution, registry listings and similar.
  • Write tools need an OAuth 2.1 access token: anything that moves money, signs, stakes, registers or changes state.

The server publishes standard OAuth discovery documents, so a compliant client finds everything it needs from the MCP URL:

PathPurpose
/.well-known/oauth-protected-resourceProtected resource metadata
/.well-known/oauth-authorization-serverAuthorisation server metadata
/registerClient registration
/authorizeAuthorisation. You sign in and approve the client with your passkey.
/tokenToken and refresh exchange
/revokeToken revocation

Tokens are:

  • Bound to the MCP resource. A token issued for another service is rejected.
  • Bound to your key with DPoP (RFC 9449). Each request sends Authorization: DPoP <token> and a fresh DPoP proof signed by the client's key, so a leaked token cannot be replayed from elsewhere.
  • Scoped with rich authorisation details (RFC 9396): which tools, which operations and how much value per call and per day.

Agents get their tokens when they are created; see Agents. A delegated agent's MCP token carries the same delegation scope its controller set, and revoking the controller revokes the agent's tokens.

Every write tool goes through the same access check as its JSON-RPC equivalent, so MCP never reaches more than the RPC does. The acting account comes from the authenticated token, never from a tool argument, and tools never take private keys. Signing happens on the device that holds the key. See RPC access for the open, owner and admin classes.

Revoke a token with tenzro_revokeJwt, or a whole identity and everything it authorised with tenzro_revokeDid.

Reaching the whole RPC surface

Named tools cover the common tasks. Two gateway tools cover the rest:

  • list_rpc_methods lists every JSON-RPC method the node serves and its access class, filterable by namespace or substring.
  • call_rpc invokes any listed method. It passes the same gates as a direct call, so it reaches only what your credentials allow.

Tools that consume paid resources, such as inference, storage or a priced skill, charge the authenticated account. Operators can also require an API key (X-Tenzro-Api-Key) for their paid surfaces, and some requests can be paid per call over x402 or MPP.

Run it yourself

Every tenzro-node serves MCP on its own listener. There is also a standalone Python server that exposes the network's tools over stdio or Streamable HTTP and talks to any node's JSON-RPC:

bash
pip install tenzro-mcp-server

# stdio, for a local client
tenzro-mcp-server

# Streamable HTTP
tenzro-mcp-server --transport http --port 3001

A local stdio entry for a desktop client:

json
{
  "mcpServers": {
    "tenzro": { "command": "tenzro-mcp-server" }
  }
}