Agents and MCP
Every Neutron instance answers on one endpoint that an agent can hold: POST /mcp. Behind it sit the same routes the screens call, the same gates a person meets, and the same audit log. An agent connected here is not a second way into the product. It is the product, driven from a keyboard somewhere else.
- What it is for
- One endpoint any agent can hold, reaching the same routes the screens call.
- Who uses it
- Agents in a harness, other programs, and operators driving an instance without a browser.
- Where in the UI
- Settings › Access & Security › API, where the token is minted. Nowhere else.
- What it writes
- The same rows the screens write, plus an audit line for every call.
- Which gate governs it
- Every gate the screens meet, plus the token's own scopes.
Full map: Map of Neutron Core
This section is written for two readers. One is an operator wiring a harness up for the first time and wanting the shortest path to a working connection. The other is an agent reading this page to learn what it may do here. Both want the same facts, so they are written once.
What is on the other end
flowchart LR
H["Your harness<br/>Claude Code, Codex, OpenCode, ChatGPT"] -->|"POST /mcp<br/>Bearer nck_…"| M["The MCP endpoint"]
M --> T["A tool"]
T --> R["The instance's own route<br/>the same one a screen calls"]
R --> G{"The gate"}
G -->|"allowed"| W["The write lands"]
G -->|"refused"| X["A sentence naming what was missing"]
W --> L["The audit log and the ledger"]
X --> L
Read it left to right and notice what is missing: there is no path from a tool to the database that goes around the route. A tool composes a request and hands it to the instance’s own router, carrying the token’s principal. Whatever stops a person stops the call.