For developers
Transport, authorization and metadata details of Toolies’s MCP server.
Toolies is a standard remote MCP server, so any compliant client works without special setup.
| Topic | Details |
|---|---|
| Endpoint | https://toolies.social/mcp, Streamable HTTP, stateless, JSON responses, POST only |
| Protocol | 2026-07-28 (per-request metadata, server/discover), plus 2025-11-25, 2025-06-18 and 2025-03-26 through initialize |
| Authorization | OAuth 2.1 authorization code with PKCE (S256), resource indicators (RFC 8707), iss in authorization responses (RFC 9207) |
| Scopes | read and write (write includes read) |
| Clients | Client ID Metadata Documents, or dynamic client registration (RFC 7591) |
| Tokens | Access tokens last 1 hour, refresh tokens rotate and last 90 days; authorization codes last 5 minutes and are single-use |
| Revocation | RFC 7009 at /oauth/revoke |
| Limits | 240 requests per minute per connection, 1 MB per request |
Metadata#
GET https://toolies.social/.well-known/oauth-protected-resource/mcp
GET https://toolies.social/.well-known/oauth-authorization-server
Endpoints: /oauth/authorize, /oauth/token, /oauth/register and /oauth/revoke.
Interactive UI#
get_calendar and schedule_posts render ui://toolies/calendar.html (MCP Apps, text/html;profile=mcp-app). Every result also carries text and structuredContent, so clients without MCP Apps still get the full answer.
Tool hints#
Every tool declares title, readOnlyHint, destructiveHint, idempotentHint and openWorldHint. Each call checks the member’s role first, then the connection’s scope. See the tools reference.