Skip to main content

Delegate as an MCP server

The rest of this section is about pointing Delegate agents at your tools. This page is the other direction: connecting an MCP client — Claude, or anything else that speaks the protocol — to your Delegate agents, so you can drive them from wherever you already work.

Who can do what​

TaskUserAgent ownerAdmin
Connect an MCP client to their own agents✅✅✅

The connection acts as you, with your access. It reaches the agents you can reach and nothing else.

Endpoint​

POST https://<your-delegate-host>/mcp

JSON-RPC 2.0 over MCP's Streamable HTTP transport. Protocol version 2025-06-18, with 2025-03-26 and 2024-11-05 also accepted.

Supported methods: initialize, notifications/initialized, ping, tools/list, tools/call.

Authorizing​

The server implements OAuth 2.1 with dynamic client registration, so a compliant client discovers and completes the flow on its own — you'll be asked to sign in and approve the scopes.

Discovery documents are at the standard locations:

/.well-known/oauth-authorization-server
/.well-known/oauth-protected-resource

Scopes​

ScopeGrants
mcp:agents.readView your agents and their activity
mcp:agents.writeCreate, configure, and run agents on your behalf
mcp:kb.readRead your knowledge base
mcp:kb.writeAdd to and edit your knowledge base

A client that doesn't narrow its request receives all four. Narrow deliberately: a client that only needs to ask questions wants mcp:agents.read and mcp:agents.write, not the knowledge-base scopes.

The Origin header is validated against an allow-list, which defeats DNS-rebinding from local browsers. A local client that fails to connect with an origin error is hitting this, not an auth problem.

What the client gets​

Nine tools, each requiring one scope:

ToolScopeDoes
list_agentsagents.readList the agents you can invoke, with ids and descriptions
ask_agentagents.writeStart an agent working and return the session_id immediately
send_messageagents.writeSend a message and wait for the final reply
list_sessionsagents.readRecent conversations with an agent, newest first
get_transcriptagents.readThe full message transcript for a session
get_attachmentagents.readDownload a file the agent attached, base64-encoded
list_projectskb.readDocWorker knowledge-base projects
search_knowledge_basekb.readSearch a knowledge base and return matching passages
upload_documentkb.writeAdd a document to a project so it can be searched

ask_agent vs send_message​

The distinction that matters in practice:

  • send_message waits for the reply. Simple, and right for short work — but it can time out on a long task.
  • ask_agent returns a session_id straight away and lets the agent keep working. Poll with get_transcript when you're ready.

Reach for ask_agent for anything substantial: research, document production, multi-step work. send_message is for quick questions.

What still applies​

Everything. Driving an agent over MCP is driving the same agent:

  • Budgets apply, so a capped agent stops or throttles here too.
  • Sharing applies — you see the agents you'd see in the app.
  • Usage is recorded against the agent as normal.
  • Memory and history are shared with the app. A conversation you start from an MCP client appears in the agent's sessions, and what it learns there is remembered everywhere.

Which integration path is yours​

You want to…Use
Drive your own agents from an MCP clientThis page
Give Delegate agents access to your APIExposing your tools over MCP
Give each of your customers their own agentBuilding an integration
Put an agent on a public web pageEmbedding an agent