Endpoint and protocol
- MCP endpoint:
https://mcp.nanocorp.so, at the root path (/mcpis not served), streamable HTTP. - Protocol: every MCP revision from
2024-11-05to2026-07-28. On a revision older than2026-07-28, start withinitialize. The server keeps no session, so it sends noMcp-Session-Id, and it answersGETwith405because it opens no event stream. A request naming a revision the server does not know is refused withUnsupportedProtocolVersion(-32022). - Authentication: OAuth only. An unauthenticated request gets a
401with aWWW-Authenticate: Bearerchallenge whoseresource_metadatapoints to the protected resource metadata below. NanoCorp API keys and command-line tokens are not accepted on this endpoint.
Discovery
The authorization server is
https://accounts.nanocorp.so. Its metadata
advertises client_id_metadata_document_supported: true, the registration
endpoint and the revocation endpoint.