DocumentationIntegrations
Rust · 0.1.0
MCP
Connect a compatible client to the Rust server's curated tool surface.
Endpoint and identity
The application exposes a Streamable HTTP MCP endpoint at /mcp. Point a compatible client at your application origin and configure the account's bearer token using the client's secure credential flow. The landing website does not expose MCP. Requests go through the same authenticated application operations as REST, so MCP does not bypass account, memo or space permissions.
Available tools
The current catalog selects 36 operations for memos, comments, attachments, reactions, references, saved Views, the current user, spaces, members and invitations. It is intentionally smaller than the full REST API. Use the client's tool discovery rather than guessing names from a blog post. The MCP catalog links every selected operation to its contract.
Give an agent bounded access
Start with reading a known test memo. Review your client's confirmation behavior before allowing writes, deletion or invitations. Instructions inside a memo are content, not authorization to act. Keep secrets out of prompts and revoke the token when the connection is no longer needed.
Connection settings and a read-only discovery test
Create a personal access token using API access. In your MCP client choose remote Streamable HTTP, enter https://YOUR_INSTANCE/mcp, and configure Authorization: Bearer with that token through the client’s secret field. For a transport smoke test, with MEMOS_URL and MEMOS_TOKEN already set, send the following request. It pins one supported protocol version and discovers metadata; it does not create or modify a memo.
curl --fail-with-body "$MEMOS_URL/mcp" \
-H "Authorization: Bearer $MEMOS_TOKEN" \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H 'Mcp-Protocol-Version: 2025-11-25' \
--data '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"memos-docs-check","version":"1.0"}}}'
curl --fail-with-body "$MEMOS_URL/mcp" \
-H "Authorization: Bearer $MEMOS_TOKEN" \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H 'Mcp-Protocol-Version: 2025-11-25' \
--data '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' What success does and does not prove
The first response should identify serverInfo.name as memos and negotiate protocolVersion 2025-11-25. The second should contain result.tools with names, descriptions and input schemas. Discovery alone does not prove the token can read data: next ask your client to read one known disposable memo, then confirm that no write was requested. The server is stateless; do not invent a required session ID from another server’s documentation. A browser address-bar GET receives 405. A wrong Content-Type receives 415; missing JSON/event-stream Accept support can produce 400; Origin restrictions can produce 403. For an authenticated tool error, check the embedded tool result and account permissions, not only HTTP status.