Skip to main content

MCP

clepit's MCP surface lets agents read and write workspaces and pages. Bearer only: any request carrying an Origin header is refused.

HostServes
https://api.clepit.com

mcp

POST/mcphttps://api.clepit.com

Invoke an MCP method

JSON-RPC 2.0 over HTTP. Every request needs Mcp-Protocol-Version: 2026-07-28.

Auth bearerAuth

Parameters

NameInTypeDescription
Mcp-Protocol-Version requiredheaderstringMust be 2026-07-28

Body

JSON
{
  "id": "integer",
  "jsonrpc": "2.0",
  "method": "server/discover | ping | tools/list | tools/call",
  "params?": "object"
}

Responses

200 A JSON-RPC 2.0 response object.

Try it

curl -X POST "https://api.clepit.com/mcp" \
  -H "Authorization: Bearer $BEARER_AUTH" \
  -H "Content-Type: application/json" \
  -d '{"id":0,"jsonrpc":"2.0","method":"server/discover","params":{}}'

Protocol revision

Revision 2026-07-28. No session, no initialize handshake. A mismatched Mcp-Protocol-Version is rejected with JSON-RPC error -32020.

Browsers are not a supported client

The allowed-origins list is deliberately empty, so any request carrying an Origin header is refused. This is a machine-to-machine surface; widening it is a security decision, not a configuration tweak.

Discovery

GET /.well-known/oauth-protected-resource/mcp stays reachable with no token at all, it is how an unauthenticated client learns where to authenticate. Its resource is https://api.clepit.com/mcp, the address a client connects to.

Every tool, resource and prompt is listed on pages generated from the server itself: MCP tools, MCP resources and MCP prompts.

Listing the tools

Bash
curl -X POST "https://api.clepit.com/mcp" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Mcp-Protocol-Version: 2026-07-28" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'