MCP - Model Context Protocol
The mcp module connects external MCP servers. Their tools become
virtual Digitorn tools (naming like mcp_<server>__<tool>),
not a fixed catalog of mcp.connect / mcp.call_tool agent
actions.
| Property | Value |
|---|---|
| Module id | mcp |
| Fixed agent tools | none (dynamic) |
| Transports | stdio / SSE / HTTP (Go client) |
Configure servers
tools:
modules:
mcp:
config:
auto_install: false
servers:
filesystem:
transport: stdio
command: npx
args: ["-y", "@modelcontextprotocol/server-filesystem", "/tmp"]
capabilities:
grant:
- module: mcp
Hub catalog / OAuth flows exist in the daemon - prefer the live Hub install flow over hand-written server entries when one is available.
Remote servers (SSE / streamable HTTP)
A server that already runs somewhere else - not something Digitorn spawns
as a local process - connects over the network instead of stdio:
tools:
modules:
mcp:
config:
servers:
hosted:
transport: streamable_http # or: sse
url: "https://example.com/mcp"
headers:
Authorization: "Bearer {{secret.HOSTED_MCP_TOKEN}}"
timeout: 30 # seconds, default 30
command/args/env only apply to stdio (they spawn the process);
url/headers only apply to sse/streamable_http (there's nothing to
spawn). Pick streamable_http unless the server specifically documents
itself as SSE-only - it's the newer of the two wire formats. headers is
a plain map, most often used for a bearer token the same way any other
secret is referenced ({{secret.X}}).
For a server that needs a real OAuth exchange rather than a static bearer
token, an inline auth: block (type, client_id, client_secret,
scopes, authorize_url, token_url, pkce, ...) exists for advanced
cases, but prefer the Hub's managed OAuth install flow first - it's what
the install howto covers, and it
avoids hand-rolling a token refresh cycle in your own app.
How agents call MCP tools
Once connected, tools appear in the tool index like any other
module action (subject to injection mode and grants). Use
search_tools / get_tool / direct call / execute_tool.
Resources and prompts may be exposed as additional virtual tools when the server advertises them.