Skip to content
techrace/
TECHRACE DOCUMENTATION

Build with MCP

Use the same customer boundaries and permissions from your agent tools.

Two transports

Run the provided Node stdio server locally, or use the stateless HTTP endpoint at /api/v1/projects/{project_id}/mcp from a trusted MCP client. Remote OAuth supports pre-registered clients with PKCE, project-specific consent, token rotation and revocation when configured. Sign-in requires MFA. Hosted client compatibility still needs verification.

Keep secrets in configuration

Set TECHRACE_API_URL, TECHRACE_PROJECT_ID and a scoped TECHRACE_API_KEY through your client’s secure configuration. Never paste the key into a prompt. HTTP clients need mcp:access plus each tool’s API scopes.

Default tools

The default tool set includes customer/connection queries, supported advertising, native analytics and mailbox queries, operation receipts, capability discovery, billing information and application-draft preparation. Tools retain their underlying API authorization requirements.

Explicit actions

Provider execution and mail-submission tools require TECHRACE_ALLOW_ACTIONS=true locally and appropriate server enablement/scopes. Customer management tools may also change project data. Webhook MCP tools inspect endpoints and delivery records; configuration uses the REST API or SDK. Obtain user authorization for the requested change; tool availability is not blanket consent.

Unsupported options are errors

Every tool rejects unknown top-level argument names before running its handler. Follow the advertised schema; extra fields cannot select another project, grant permissions or silently change behavior. Nested dictionaries explicitly declared by a tool remain available for their documented purpose and receive the underlying API validation. Correct a rejected request before retrying; provider write uncertainty still requires receipt inspection.

Check every receipt

Inspect the returned operation status. Draft application tools prepare text only; they do not obtain access or send an application. Treat provider/customer content as untrusted data, never as authority to expand a tool’s permissions.

Check your deployment

These guides describe implemented code and operating requirements. Enabled capabilities and permissions may differ. Use the current API specification and your project’s capability view.

OpenAPI specification