MCP tools
Authenticated Referential tools over the same use cases, queries, permissions, actor context, and audit evidence as REST.
The backend serves an authenticated Streamable HTTP MCP endpoint at /mcp when
the mcp profile is enabled.
Tool model
Referential exposes one tool class per aggregate family. Tool names follow:
referential_<verb>_<noun>Examples include carrier registration and lifecycle, topology catalogs, vehicle records and permits, service catalog operations, eligibility, and beneficiary reads.
Same domain, second adapter
MCP does not duplicate domain logic. It calls the same use cases and queries as REST.
Authorization and actor context
Every tool declares the permission demanded by its HTTP twin. Architecture and integration tests fail on an unguarded addition.
Commands that record an actor resolve the authenticated principal through the same current-user boundary as HTTP. Beneficiary reads create the same sensitive access audit evidence.
Schema limits
Tool descriptions communicate field constraints, but MCP schemas cannot express every enum and format carried by OpenAPI. Runtime validation remains authoritative.
Permit import accepts CSV text inline because MCP has no multipart upload transport. The content reaches the same import use case unchanged.
Discovery is not authorization
Seeing a tool never grants permission to invoke it. Authentication and operation-level authorization still apply to every call.