# MCP

Tarsana has a hosted MCP server, so an AI assistant or agent can use your Tarsana account directly. It offers one tool for every [API operation](/api), with the same name, the same arguments and the same answers.

## Connect

| Setting | Value |
|---|---|
| Address | `https://mcp.tarsana.io/sse` |
| Transport | HTTP with server-sent events (SSE) |
| Header | `X-Tarsana-Access-Token`: an API access token |
| Header | `X-Tarsana-Tenant`: your tenant ID |

Create the access token with [`issue-access-token`](/api/issue-access-token), as in step 5 of [Build your first image](/quickstarts/first-image). Give each client its own token, with a `token_label` that says which client it is, so that you can [revoke](/api/revoke-access-token) one without the others.

Most MCP clients take a configuration like this one:

```json
{
  "mcpServers": {
    "tarsana": {
      "type": "sse",
      "url": "https://mcp.tarsana.io/sse",
      "headers": {
        "X-Tarsana-Access-Token": "YOUR-ACCESS-TOKEN",
        "X-Tarsana-Tenant": "acme"
      }
    }
  }
}
```

Every request is checked against your access token before it reaches a tool. A request without a valid token is refused, and you get no tool list.

## Call a tool

A tool takes the operation's parameters as arguments. A request body, such as a spec, is the `body` argument. For example:

```json
{
  "method": "tools/call",
  "params": {
    "name": "status",
    "arguments": {
      "tenant": "acme",
      "submission": "sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1"
    }
  }
}
```

The answer is the same JSON the API returns. A refused call comes back as a tool result with `isError` set, and its text is the API's refusal, with the same `error` object, `code` and `doc_url`; see [Errors](/api/errors).

Tools that only read have the read-only hint set, so your client can run them without asking you first. Tools that change something, and especially the ones marked **Destructive**, should be confirmed by you.

## Tools

| Tool | | What it does |
|---|---|---|
| [`describe`](/api/describe) | Read | Get the full API description as JSON |
| [`submit`](/api/submit) | Change | Submit a spec to build an image |
| [`validate`](/api/validate) | Read | Check a spec without submitting it |
| [`status`](/api/status) | Read | See the status of a submission |
| [`fetch`](/api/fetch) | Read | Download a record of a submission |
| [`attestation`](/api/attestation) | Read | Get what you need to verify an image yourself |
| [`audit`](/api/audit) | Read | Read your audit trail |
| [`provision`](/api/provision) | Change | Install a built image on one of your servers |
| [`create-server`](/api/create-server) | Change | Create a server from your spec |
| [`servers`](/api/servers) | Read | List the servers in your cloud account that Tarsana did not create |
| [`destroy-server`](/api/destroy-server) | Destructive | Delete a server that Tarsana did not create |
| [`decommission-server`](/api/decommission-server) | Destructive | Decommission a server that Tarsana created |
| [`install-command`](/api/install-command) | Change | Get the one-line command that installs Tarsana on a server you have |
| [`request-update`](/api/request-update) | Change | Update a server to the release your channel carries |
| [`update-status`](/api/update-status) | Read | See how a server's update went |
| [`provider-credential`](/api/provider-credential) | Read | Check whether your provider credential is stored |
| [`set-provider-credential`](/api/set-provider-credential) | Change | Store or replace your provider credential |
| [`remove-provider-credential`](/api/remove-provider-credential) | Destructive | Remove your provider credential |
| [`login`](/api/login) | Session | Sign in and start a session |
| [`logout`](/api/logout) | Session | End your session |
| [`issue-access-token`](/api/issue-access-token) | Change | Create an API access token |
| [`revoke-access-token`](/api/revoke-access-token) | Destructive | Revoke an API access token |
| [`list-access-tokens`](/api/list-access-tokens) | Read | List your API access tokens |
| [`signup`](/api/signup) | Change | Create your Tarsana account |
| [`complete-signup`](/api/complete-signup) | Change | Finish creating your account |
