[{"data":1,"prerenderedAt":32},["ShallowReactive",2],{"$f2yxxldimghl64":3},{"href":4,"title":5,"description":6,"kind":7,"mark":7,"planned":8,"contributors":9,"provenance":7,"html":10,"headings":11},"\u002Fdocs\u002Fmcp","The MCP server","Your enterprise's own MCP server, for agents you run: what it is, what it can do, and what a token lets it reach.",null,false,[],"\u003Ch2 id=\"what-it-is\">What it is\u003C\u002Fh2>\n\u003Cp>Zero Human OS runs an MCP server that any MCP client can connect to. Point an agent you run at it, with an API\ntoken, and the agent can see what your enterprise is doing: its runs, what is blocked, and which decisions are\nwaiting on you.\u003C\u002Fp>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>What\u003C\u002Fth>\n\u003Cth>Detail\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Endpoint\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>https:\u002F\u002Fmcp.zerohuman.com\u002Fv1\u002Fmcp\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Transport\u003C\u002Ftd>\n\u003Ctd>Streamable HTTP, stateless: every request is a \u003Ccode>POST\u003C\u002Fcode>, answered in JSON. There is no session.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Authentication\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>Authorization: Bearer zhos_…\u003C\u002Fcode>, an API token from \u003Cstrong>Settings → API tokens\u003C\u002Fstrong> in the portal\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>What a token reaches\u003C\u002Ftd>\n\u003Ctd>What its scopes allow, exactly as on the API (\u003Ca href=\"\u002Fdocs\u002Fapi\u002Fauthentication\">Authentication\u003C\u002Fa>), in the enterprise it was created in\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Tools\u003C\u002Ftd>\n\u003Ctd>Reads over runs, blockers, waiting gates and KPIs; writes of KPI readings and targets; and chat with a member. The complete list, generated from the server's own definitions, is \u003Ca href=\"\u002Fdocs\u002Fmcp\u002Ftools\">Tools\u003C\u002Fa>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Health\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>https:\u002F\u002Fmcp.zerohuman.com\u002Fv1\u002Fhealth\u003C\u002Fcode>, with no token\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>To connect Claude Code, Claude Desktop or another client, see \u003Ca href=\"\u002Fdocs\u002Fmcp\u002Fconnect\">Connect a client\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2 id=\"what-it-can-do\">What it can do\u003C\u002Fh2>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Family\u003C\u002Fth>\n\u003Cth>Tools\u003C\u002Fth>\n\u003Cth>Scope\u003C\u002Fth>\n\u003Cth>What they read\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Runs\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>os.list_runs\u003C\u002Fcode>, \u003Ccode>os.get_run\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>runs:read\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>Runs, newest first, by status, by task, or only those in progress; one run's status, input and last eight events.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Blockers\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>os.list_blockers\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>blockers:read\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>What is stopping work now, as the \u003Cstrong>Blockers\u003C\u002Fstrong> page shows it.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Gates\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>os.list_open_gates\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>gates:read\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>Every gate waiting on a decision: the run, the tool call it holds, and who decides.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>KPIs\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>kpi.list_readings\u003C\u002Fcode>, \u003Ccode>kpi.record_reading\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>kpis:read\u003C\u002Fcode>, \u003Ccode>kpis:write\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>A KPI's reading history; and a write: append a new reading to a signed-off KPI.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Chat\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>os.chat_list\u003C\u002Fcode>, \u003Ccode>os.chat_read\u003C\u002Fcode>, \u003Ccode>os.chat_open\u003C\u002Fcode>, \u003Ccode>os.chat_write\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>chats:read\u003C\u002Fcode>, \u003Ccode>chats:write\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>Your chats with members and what was said in one; and two writes: open a chat with a member, and write to them. The member replies in the same call.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>Every tool is listed to every token. Each tool's description ends with the scope it needs, so an agent knows\nbefore it calls. \u003Ca href=\"\u002Fdocs\u002Fmcp\u002Ftools\">Tools\u003C\u002Fa> is the complete list, with each tool's arguments; it is generated from\nthe definitions the server serves, so it cannot drift from them.\u003C\u002Fp>\n\u003Ch2 id=\"what-it-cannot-do\">What it cannot do\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Run your enterprise.\u003C\u002Fstrong> Its writes record KPI readings and targets, and write to a member in\n\u003Ca href=\"\u002Fdocs\u002Fwork\u002Fchat\">chat\u003C\u002Fa>. No tool starts a task, decides a gate, or cancels or retries a run: that is done in the\nportal or over the \u003Ca href=\"\u002Fdocs\u002Fapi\">API\u003C\u002Fa>. A member you write to in chat can start a task it holds, as it can for\nanyone it talks to.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manage API tokens.\u003C\u002Fstrong> No tool does, and the API refuses any token that tries.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reach another enterprise.\u003C\u002Fstrong> A token acts for the enterprise it was created in. Another enterprise's run is\n&quot;not found&quot;.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Offer resources or prompts.\u003C\u002Fstrong> It offers tools only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tell your agent when something changes.\u003C\u002Fstrong> It never sends a message unasked. The agent asks again.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"how-it-relates-to-the-api\">How it relates to the API\u003C\u002Fh2>\n\u003Cp>The MCP server is a thin layer over the \u003Ca href=\"\u002Fdocs\u002Fapi\">API\u003C\u002Fa>. Each tool is one API route. Calling a tool makes that one\nrequest with your token, and the API's answer comes back as the tool's result. So:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>the token's scopes decide what a tool can do, exactly as they would for a script calling the API;\u003C\u002Fli>\n\u003Cli>a refusal is the API's own, in its own words (\u003Ca href=\"\u002Fdocs\u002Fmcp\u002Ferrors\">Errors\u003C\u002Fa>);\u003C\u002Fli>\n\u003Cli>the token's \u003Cstrong>Last used\u003C\u002Fstrong> in the portal moves when a tool call reaches the API.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Connecting and listing tools do not reach the API. They only need a bearer token to be present, so a client\nconnects even with a revoked or mistyped token, and fails on its first tool call. To know a token works, call a\ntool.\u003C\u002Fp>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"sign-in-instead-of-a-token\">Sign in instead of a token\u003C\u002Fh2>\n\u003Cp>An MCP client that supports sign-in, such as a custom connector in Claude, will connect by signing in with\nZero Human instead of holding a token: you choose the enterprise, the member it acts as and what it may do, and\nrevoke it later under \u003Cstrong>Settings → Connected apps\u003C\u002Fstrong>. See \u003Ca href=\"\u002Fdocs\u002Fmcp\u002Fconnected-apps\">Connected apps\u003C\u002Fa>. Today the\nMCP server accepts API tokens only.\u003C\u002Fp>\n\u003Ch2 id=\"tools-that-change-things\">Tools that change things\u003C\u002Fh2>\n\u003Cp>The MCP server will offer more of the OS's own tools, including ones that change things. Each will be one API route\nbehind the scope that route needs, so a token's scopes will govern them as they govern the API.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Starting a task, the OS's own tasks included.\u003C\u002Fstrong> An agent will list the tasks a member holds and start one.\nThe OS's own tasks are among them, the same in every enterprise: ask for a new team, role, member or task, or a\nchange to one, and the OS designs it and puts it to you to sign off, as it does from \u003Ca href=\"\u002Fdocs\u002Fwork\u002Fchat\">chat\u003C\u002Fa>.\nThe agent will read the run and the decision it waits on, and decide it when it acts for a person who may.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Changing roles, teams and members directly.\u003C\u002Fstrong> The same writes the portal's pages make, under the scopes that\nalready govern them on the API, with no plan and no sign-off.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fdiv>\n",[12,16,19,22,25,29],{"id":13,"text":14,"level":15,"planned":8},"what-it-is","What it is",2,{"id":17,"text":18,"level":15,"planned":8},"what-it-can-do","What it can do",{"id":20,"text":21,"level":15,"planned":8},"what-it-cannot-do","What it cannot do",{"id":23,"text":24,"level":15,"planned":8},"how-it-relates-to-the-api","How it relates to the API",{"id":26,"text":27,"level":15,"planned":28},"sign-in-instead-of-a-token","Sign in instead of a token",true,{"id":30,"text":31,"level":15,"planned":28},"tools-that-change-things","Tools that change things",1791124519647]