Skip to main content
AoA exposes a JSON-RPC 2.0 MCP endpoint at /companies/:companyId/mcp. Agents, Commander, the board UI, and external MCP clients can call it to read and write company data.

Authentication

Three actor types are accepted: Requests with neither → 401 in authenticated deployments. In local_trusted mode, no-token loopback requests are treated as trusted board context, and requests carrying a valid run id may be treated as the running agent.

Tool Call Format

Read Tools

Write Tools

Protocol Workflow Tools

Document Tools

Approval Tools

Resources

MCP resources are read via resources/list and resources/read. They are separate from tools and are not counted in the tool total.

Actor Gate

Most tools are open to all authenticated protocol actors unless listed in the server’s toolAllowedActors map. Actor gates are enforced before the tool handler runs; handlers still perform company, scope, and RBAC checks.

Key Behaviors

  • debrief-push vs create-task: Use debrief-push for unstructured content that needs extraction into tasks + memory. Use create-task when the task title/fields are already known. Revised Decision #14 allows authenticated direct task writes because RBAC is the quality gate; anonymous MCP traffic is rejected outside local_trusted.
  • Task ownership fields: assigneeAgentId and assigneeUserId identify the executor doing the work. responsibleUserId identifies the accountable human for outcome and escalation; it does not dispatch execution or change the single-assignee checkout model. reviewerUserId identifies the human expected to review output when review is needed.
  • Task assignment permission: Explicitly setting responsibleUserId or clearing it with responsibleUserId: null in create-task or update-task requires tasks:assign. Omitting responsibleUserId does not require that permission.
  • Memory write gate: Agents cannot write memory directly to approved status except into their own personal scope via memory.retain + scopeToSelf: true. All other memory writes land in pending status awaiting founder review (Critical Rule #6).
  • Artifact immutability: attach-artifact-version and upsert-task-document always create new versions. Existing versions are never modified (Decisions #43, #45).
  • RBAC enforcement: All tools enforce company isolation. team_member actors see only their project-scoped data. Cross-company access returns 404.
The runtime registry in server/src/mcp/tools/index.ts is authoritative. Avoid copying its total into prose: the catalog changes as tools are generated and registered.