AppEngine exposes a Model Context Protocol endpoint, so an MCP-capable AI client can discover what the platform can do and call it directly — against your organization's data, with your permissions.
The endpoint exists in code but is not live in production. It works locally now; the production URL becomes available after the next image build and rollout. Build against it locally, but do not point production clients at it yet.
Endpoint
/mcpJWT| Environment | URL | Status |
|---|---|---|
| Local | http://localhost:3300/mcp | Available now |
| Production | https://appengine.appmint.io/mcp | After the next build and rollout |
It speaks JSON-RPC 2.0 and supports initialize, tools/list, tools/call and resources/list.
Authentication
The same two headers as every other call — the tenant and a credential:
orgid: <org>
Authorization: Bearer <token>An MCP client acts as you. It can reach whatever your token can reach and nothing more, so the permission model applies unchanged.
Client configuration
{
"mcpServers": {
"appengine": {
"url": "https://appengine.appmint.io/mcp",
"headers": {
"orgid": "<org>",
"Authorization": "Bearer <token>"
}
}
}
}Swap the URL for http://localhost:3300/mcp while it is local-only.
The three tools
| Tool | What it does |
|---|---|
list_services | Every backend service exposed to MCP, with a one-line description and the methods each offers |
describe_service | Method signatures for one service — parameter names, types, which are required, and the return shape |
call_service | Invoke a method on a registered service |
The shape is deliberate: a client discovers what exists, reads the signature of the method it wants, then calls it. An agent does not need the API memorized or hard-coded, and new services become reachable without the client changing.
Arguments are passed in declaration order, with orgId omitted — the tenant comes from the header, not the argument list. Read the signature with describe_service first rather than guessing.
Checking it works
curl -s http://localhost:3300/mcp \
-H 'Content-Type: application/json' \
-H 'orgid: demo' \
-H 'Authorization: Bearer <token>' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'A working server returns list_services, describe_service and call_service.
If it returns a JSON-RPC error instead, check the two headers before anything else — a missing orgid fails before the request reaches the MCP handler at all.
How services get exposed
A service method becomes reachable through MCP when it is annotated for AI use, the same mechanism behind runtime discovery. Annotating a method makes it discoverable; leaving the annotation off keeps it out of an agent's reach.
That is the control surface — what an agent can do is decided by what is annotated, not by what the client asks for.