MCP tools reference

The tools the V12 MCP server exposes, the scopes each needs, and which ones change data.

The V12 MCP server lists only the tools your token's scopes allow. Calling any other tool returns an insufficient_scope error. Each tool name is its REST operation's operationId in snake case: listFindings becomes list_findings. To connect a client, see Connect an MCP client.

Tools

ToolWhat it doesScopesREST equivalent
get_meGet the token identityuser:readGET /me
list_membersList organization membersuser:readGET /members
list_focusesList focusesrepos:readGET /focuses
get_focusGet a focusrepos:readGET /focuses/{focus}
list_repositoriesList repositoriesrepos:readGET /repositories
list_refsList branches, pull requests and tagsrepos:readGET /repositories/{owner}/{repo}/refs
list_repository_findingsList a repository's findings at a positionfindings:readGET /repositories/{owner}/{repo}/findings
list_findingsList organization findingsfindings:readGET /findings
update_findingsChange findingsfindings:writePATCH /findings
get_findingGet a findingfindings:readGET /findings/{finding}
comment_on_findingComment on a findingfindings:writePOST /findings/{finding}/comments
list_runsList runsruns:readGET /runs
start_runStart a runruns:writePOST /runs
get_runGet a runruns:readGET /runs/{run}
list_run_findingsList a run's findingsruns:read, findings:readGET /runs/{run}/findings
estimate_runEstimate a runruns:writePOST /runs/estimate
cancel_runCancel a runruns:managePOST /runs/{run}/cancel
request_document_uploadRequest a document upload slotruns:writePOST /documents/uploads
create_documentCreate a context documentruns:writePOST /documents
list_documentsList context documentsruns:readGET /documents
archive_documentArchive a context documentruns:writeDELETE /documents/{document}

Tools that change data

Only these tools change data. Every other tool, estimate_run included, only reads, and says so with readOnlyHint: true.

  • update_findings
  • comment_on_finding
  • request_document_upload
  • start_run, which spends credits
  • create_document
  • cancel_run and archive_document, which also carry destructiveHint: true

Retrying start_run or comment_on_finding with the same requestId returns the original result instead of starting a second run or posting a second comment.

Results and errors

A successful call returns the same JSON as the REST response, as structured content and as text. A failed call sets isError and returns the REST error body; its codes are listed under Errors.

On this page