Two transports
Run the provided Node stdio server locally, or use the stateless HTTP endpoint at /api/v1/projects/{project_id}/mcp from a trusted MCP client. Remote OAuth supports pre-registered clients with PKCE, project-specific consent, token rotation and revocation when configured. Sign-in requires MFA. Hosted client compatibility still needs verification.
Keep secrets in configuration
Set TECHRACE_API_URL, TECHRACE_PROJECT_ID and a scoped TECHRACE_API_KEY through your client’s secure configuration. Never paste the key into a prompt. HTTP clients need mcp:access plus each tool’s API scopes.
Default tools
The default tool set includes customer/connection queries, supported advertising, native analytics and mailbox queries, operation receipts, capability discovery, billing information and application-draft preparation. Tools retain their underlying API authorization requirements.
Explicit actions
Provider execution and mail-submission tools require TECHRACE_ALLOW_ACTIONS=true locally and appropriate server enablement/scopes. Customer management tools may also change project data. Webhook MCP tools inspect endpoints and delivery records; configuration uses the REST API or SDK. Obtain user authorization for the requested change; tool availability is not blanket consent.
Unsupported options are errors
Every tool rejects unknown top-level argument names before running its handler. Follow the advertised schema; extra fields cannot select another project, grant permissions or silently change behavior. Nested dictionaries explicitly declared by a tool remain available for their documented purpose and receive the underlying API validation. Correct a rejected request before retrying; provider write uncertainty still requires receipt inspection.
Check every receipt
Inspect the returned operation status. Draft application tools prepare text only; they do not obtain access or send an application. Treat provider/customer content as untrusted data, never as authority to expand a tool’s permissions.
These guides describe implemented code and operating requirements. Enabled capabilities and permissions may differ. Use the current API specification and your project’s capability view.
OpenAPI specification