跳到主要内容

MCP

clepit 的 MCP 接口让代理读写工作区与页面。仅支持 Bearer;任何带 Origin 头的请求都会被拒绝。

HostServes
https://api.clepit.com

mcp

POST/mcphttps://api.clepit.com

Invoke an MCP method

JSON-RPC 2.0 over HTTP. Every request needs Mcp-Protocol-Version: 2026-07-28.

Auth bearerAuth

Parameters

NameInTypeDescription
Mcp-Protocol-Version requiredheaderstringMust be 2026-07-28

Body

JSON
{
  "id": "integer",
  "jsonrpc": "2.0",
  "method": "server/discover | ping | tools/list | tools/call",
  "params?": "object"
}

Responses

200 A JSON-RPC 2.0 response object.

Try it

curl -X POST "https://api.clepit.com/mcp" \
  -H "Authorization: Bearer $BEARER_AUTH" \
  -H "Content-Type: application/json" \
  -d '{"id":0,"jsonrpc":"2.0","method":"server/discover","params":{}}'

Protocol revision

Revision 2026-07-28. No session, no initialize handshake. A mismatched Mcp-Protocol-Version is rejected with JSON-RPC error -32020.

Browsers are not a supported client

The allowed-origins list is deliberately empty, so any request carrying an Origin header is refused. This is a machine-to-machine surface; widening it is a security decision, not a configuration tweak.

Discovery

GET /.well-known/oauth-protected-resource/mcp stays reachable with no token at all, it is how an unauthenticated client learns where to authenticate. Its resource is https://api.clepit.com/mcp, the address a client connects to.

每个工具、资源和提示都列在由服务器自身生成的页面上:MCP 工具、MCP 资源和MCP 提示。

Listing the tools

Bash
curl -X POST "https://api.clepit.com/mcp" \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Mcp-Protocol-Version: 2026-07-28" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'