Enable the MCP surface
In the desktop app or extension, turn it on under Settings → MCP and mint an access token there. On a self-hosted server (daemon stopped):Connect an agent
The MCP endpoint is streamable HTTP at/mcp on the same bind as
everything else, authenticated with your token as a bearer:
/mcp are refused outright, and failed
token attempts feed the per-peer rate limit.