TooliesDocs

For developers

Transport, authorization and metadata details of Toolies’s MCP server.

Toolies is a standard remote MCP server, so any compliant client works without special setup.

TopicDetails
Endpointhttps://toolies.social/mcp, Streamable HTTP, stateless, JSON responses, POST only
Protocol2026-07-28 (per-request metadata, server/discover), plus 2025-11-25, 2025-06-18 and 2025-03-26 through initialize
AuthorizationOAuth 2.1 authorization code with PKCE (S256), resource indicators (RFC 8707), iss in authorization responses (RFC 9207)
Scopesread and write (write includes read)
ClientsClient ID Metadata Documents, or dynamic client registration (RFC 7591)
TokensAccess tokens last 1 hour, refresh tokens rotate and last 90 days; authorization codes last 5 minutes and are single-use
RevocationRFC 7009 at /oauth/revoke
Limits240 requests per minute per connection, 1 MB per request

Metadata#

Discovery
GET https://toolies.social/.well-known/oauth-protected-resource/mcp
GET https://toolies.social/.well-known/oauth-authorization-server

Endpoints: /oauth/authorize, /oauth/token, /oauth/register and /oauth/revoke.

Interactive UI#

get_calendar and schedule_posts render ui://toolies/calendar.html (MCP Apps, text/html;profile=mcp-app). Every result also carries text and structuredContent, so clients without MCP Apps still get the full answer.

Tool hints#

Every tool declares title, readOnlyHint, destructiveHint, idempotentHint and openWorldHint. Each call checks the member’s role first, then the connection’s scope. See the tools reference.

Something unclear or missing? Contact your workspace administrator.