apiome mcp
Global options such as --base-url, --tenant and --json go before the command — see CLI reference. Exit codes are listed in Exit codes.
apiome mcp
MCP catalog endpoints and tenant governance (policy / key capabilities).
apiome mcp [OPTIONS] COMMAND [ARGS]...
Subcommands: conformance, conformance-rules, discover, key, lint, list, policy, probe, probe-catalog, probe-runs, probe-target-add, probe-target-list, register, shadowing, show, source, trust-baseline-approve, trust-baseline-show, trust-drift, trust-posture, trust-posture-rules.
apiome mcp conformance
Evaluate MCP protocol conformance + agent-readiness (GET .../versions/{id}/conformance).
The server evaluates the selected rule profile against a discovered surface snapshot and computes the CI gate from --fail-on / --min-score; this command exits non-zero whenever that gate fails — including under --format sarif|junit, which echo the raw gate artifact for CI ingestion (the gate is always read from the JSON report, never inferred from the artifact). Rules that need a protocol transcript are reported as skipped (not passing) when no transcript was captured.
apiome mcp conformance [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--version | uuid | Version snapshot UUID to evaluate (default: the endpoint's current version). | ||
--profile | text | mcp-conformance | Rule profile: mcp-conformance (default), mcp-protocol, or mcp-agent-readiness. | |
--format | text | json | Gate output format: json (default), sarif, or junit. | |
--fail-on | text | error | Exit non-zero when findings at this severity or higher are present: error (default), warning, info, or none. | |
--min-score | integer range | Exit non-zero when the conformance score is below this floor (0-100). | ||
--output | text | Output format: table (default) or json. |
apiome mcp conformance-rules
List the MCP conformance rule catalog (GET /v1/mcp/conformance/rules).
Each rule cites the MCP specification version it was written against and a source reference, so a failing gate can be traced back to the spec text that motivated it.
apiome mcp conformance-rules [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--profile | text | Only list rules in this profile: mcp-conformance, mcp-protocol, or mcp-agent-readiness (default: all). | ||
--output | text | Output format: table (default) or json. |
apiome mcp discover
Trigger a discovery run and poll it to completion.
Posts POST /v1/mcp/{tenant}/endpoints/{id}/discover to enqueue a manual discovery job, then (unless --no-wait) polls GET …/endpoints/{id}/jobs/{job_id} until the run reaches a terminal state and prints the new version, change summary, and best-effort quality score. Exits non-zero on a failed run or a timeout.
apiome mcp discover [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--wait / --no-wait | flag | --wait | Poll the discovery job until terminal (default: wait). | |
--poll-interval | float range | 1.0 | Seconds between discovery-job status polls when waiting. | |
--import-timeout | float range | Max seconds to wait for the discovery run to finish, and the per-request HTTP timeout used while waiting (default 120). Overrides --timeout. | ||
--output | text | Output format: table (default) or json. |
apiome mcp key
Manage per-key MCP capability grants (session / tenant admin).
apiome mcp key [OPTIONS] COMMAND [ARGS]...
Subcommands: capabilities.
apiome mcp key capabilities
Get and set MCP API key capability grants.
apiome mcp key capabilities [OPTIONS] COMMAND [ARGS]...
apiome mcp key capabilities get
Print capability grants for one MCP key (projects GET …/mcp-keys/{id}).
apiome mcp key capabilities get [OPTIONS] KEY_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
KEY_ID | uuid | yes | MCP API key UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output format: table (default) or json. |
apiome mcp key capabilities set
Replace per-key capability grants (PUT …/mcp-keys/{id}/capabilities).
Supply --file / stdin and/or --mode / --tool. With only flags, the current grants are loaded from the key GET and merged before PUT.
apiome mcp key capabilities set [OPTIONS] KEY_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
KEY_ID | uuid | yes | MCP API key UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--file | text | Capabilities JSON file, or '-' for stdin ({mode, enabled_tools}). | ||
--mode | text | Capability mode: inherit or explicit. | ||
--tool | text (repeatable) | Enabled tool id when mode=explicit (repeatable). | ||
--output | text | Output format: table (default) or json. |
apiome mcp lint
Score a version snapshot and list its lint findings (GET .../versions/{id}/lint).
The MCP-catalog analogue of the project lint command: the server computes a deterministic 0-100 quality score, an A-F grade, and itemized findings for a discovered surface snapshot. --version targets a specific snapshot; omitted, the endpoint's current version is scored. --min-grade turns the report into a CI gate; --fail-on-policy also evaluates style-guide policy gates (GET .../lint/policy).
apiome mcp lint [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--version | uuid | Version snapshot UUID to score (default: the endpoint's current version). | ||
--min-grade | text | Exit non-zero when the grade is worse than this (A best, F worst). | ||
--fail-on-policy | flag | Fetch lint policy evaluation and exit non-zero when policy gates fail. | ||
--output | text | Output format: table (default) or json. |
apiome mcp list
List MCP catalog endpoints (GET /v1/mcp/{tenant}/endpoints).
apiome mcp list [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output format: table (default) or json. |
apiome mcp policy
Inspect and replace tenant MCP governance policy (session / tenant admin).
apiome mcp policy [OPTIONS] COMMAND [ARGS]...
apiome mcp policy get
Print the tenant MCP policy (GET /v1/tenants/{slug}/mcp-policy).
apiome mcp policy get [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output format: table (default) or json. |
apiome mcp policy set
Replace the tenant MCP policy (PUT /v1/tenants/{slug}/mcp-policy).
Supply --file / stdin and/or --default-mode / --allow-anonymous. With only flags, the current policy is fetched and merged before PUT.
apiome mcp policy set [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--file | text | Policy JSON file, or '-' for stdin (TenantMcpPolicyPutRequest shape). | ||
--default-mode | text | default_mode: all, inherit_registry, or explicit. | ||
--allow-anonymous | text | allow_anonymous_mcp kill switch: true or false. | ||
--output | text | Output format: table (default) or json. |
apiome mcp probe
Run a dynamic probe against a version snapshot (POST .../versions/{id}/probe).
The default 'passive' profile is read-only: it re-reads the captured transcript, sends nothing, and classifies observed protocol behaviour. Active profiles require the target to be allowlisted (see 'probe-target-add'), the global kill switch to be on, and — for payload-fuzzing — --i-approve-hostile-payloads. Nothing here is 'proven' unless a probe demonstrated it against a live server in isolation (an exploited-in-test finding).
apiome mcp probe [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--version | uuid | Version snapshot UUID (default: the endpoint's current version). | ||
--profile | text | passive | Profile: passive (default, read-only), safe-active, or payload-fuzzing. | |
--i-approve-hostile-payloads | flag | Explicit per-run approval, required for payload-fuzzing. | ||
--output | text | Output: table (default) or json. |
apiome mcp probe-catalog
List the MCP probe catalog (GET /v1/mcp/probes/catalog).
Shows every probe, which profile runs it, and the strongest classification tier it can reach — so you know, before running anything, what a probe can and cannot demonstrate.
apiome mcp probe-catalog [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--profile | text | Only list probes in this profile: passive, safe-active, or payload-fuzzing. | ||
--output | text | Output: table (default) or json. |
apiome mcp probe-runs
Show an endpoint's probe-run audit trail (GET .../probe-runs).
apiome mcp probe-runs [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--limit | integer range | 50 | Max audit rows to return. | |
--output | text | Output: table (default) or json. |
apiome mcp probe-target-add
Enrol an endpoint on the active-probe allowlist (POST .../probe-targets).
Active probing may only ever fire at an allowlisted target. Enrolling records, on the record, that you asserted ownership/authorization and (optionally) the dedicated test identity a probe uses.
apiome mcp probe-target-add [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID to enrol on the allowlist. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--i-own-or-am-authorized | flag | Assert you own or are authorized to probe this target (required). | ||
--test-credential | uuid | The dedicated (non-production) test credential a probe authenticates as. | ||
--output | text | Output: table (default) or json. |
apiome mcp probe-target-list
List an endpoint's active-probe allowlist entries (GET .../probe-targets).
apiome mcp probe-target-list [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output: table (default) or json. |
apiome mcp register
Register an MCP server in the tenant catalog (POST /v1/mcp/{tenant}/endpoints).
apiome mcp register [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--name | text | yes | Human-readable endpoint name. | |
--url | text | yes | MCP server URL (http/https for streamable_http/sse). | |
--transport | text | streamable_http | MCP transport: streamable_http (default), sse, or stdio. | |
--slug | text | Optional catalog slug; derived from --name and uniquified when omitted. | ||
--description | text | Optional endpoint description. | ||
--category | text | Optional catalog category. | ||
--visibility | text | private | Catalog visibility: private (default) or public. | |
--bearer | text | Seal a bearer token as the endpoint's outbound credential. | ||
--header | text | Seal a custom header secret as 'Name:Value'. | ||
--output | text | Output format: table (default) or json. |
apiome mcp shadowing
List tool/resource/prompt names shadowed across enabled endpoints (GET .../data-quality/shadowing).
apiome mcp shadowing [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output: table (default) or json. |
apiome mcp show
Show one MCP catalog endpoint (GET /v1/mcp/{tenant}/endpoints/{id}).
apiome mcp show [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output format: table (default) or json. |
apiome mcp source
Link and manage the source artifacts an MCP endpoint is built from (CLX-3.2).
apiome mcp source [OPTIONS] COMMAND [ARGS]...
Subcommands: link, list, retire.
apiome mcp source link
Link a source artifact to an MCP endpoint (POST .../endpoints/{id}/sources).
The pin strength is derived by the server from whether the reference actually carries an immutable digest — a branch stays 'unverified', a commit sha becomes 'digest_pinned'.
apiome mcp source link [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--kind | text | yes | Source kind: git, package, image, or registry. | |
--reference | text | yes | Source reference: a git URL, a purl, an OCI image ref, or a registry server id. | |
--revision | text | For git, the branch/tag/commit. A full 40-hex commit sha pins the source. | ||
--provenance | text | operator_declared | How the link is known: operator_declared (default), registry_published, discovery_advertised, or attested. | |
--output | text | Output: table (default) or json. |
apiome mcp source list
List an endpoint's linked sources (GET .../endpoints/{id}/sources).
apiome mcp source list [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--include-retired | flag | Include retired source links. | ||
--output | text | Output: table (default) or json. |
apiome mcp source retire
Retire a linked source (DELETE .../sources/{id}). Soft delete — it stays readable.
apiome mcp source retire [OPTIONS] ENDPOINT_ID SOURCE_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
SOURCE_ID | uuid | yes | Source association UUID to retire. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output: table (default) or json. |
apiome mcp trust-baseline-approve
Approve a trust baseline for an endpoint (POST .../trust-baseline).
Pins the trust manifest of the approved snapshot as the reference every later rediscovery/release is diffed against. The rationale is required and recorded as a governance policy event; approving a new baseline supersedes the prior one.
apiome mcp trust-baseline-approve [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID to approve a baseline for. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--rationale | text | yes | Why this snapshot is approved (required; recorded as a policy event). | |
--version | uuid | Version snapshot UUID to approve (default: the current version). | ||
--gate | text (repeatable) | Drift categories that block the gate (repeatable): security_regression, coverage_loss, quality_regression, normal_change. Default: security_regression + coverage_loss. | ||
--output | text | Output: table (default) or json. |
apiome mcp trust-baseline-show
Show an endpoint's active trust baseline and approval history (GET .../trust-baseline).
apiome mcp trust-baseline-show [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--output | text | Output: table (default) or json. |
apiome mcp trust-drift
Diff an endpoint's current snapshot against its approved baseline (GET .../trust-drift).
Every material surface/source change is classified as a normal change, a quality regression, a security regression, or coverage loss, and carries an old→new evidence reference. The gate reflects the baseline's configured risk deltas.
apiome mcp trust-drift [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--notify | flag | Fan out a push-webhook alert when a regression is found. | ||
--output | text | Output: table (default) or json. |
apiome mcp trust-posture
Evaluate MCP source / supply-chain / trust posture (GET .../versions/{id}/trust-posture).
Assesses what the server is built from — advertised metadata, linked source, dependencies — mapped to the OWASP MCP Top 10, and gates the result. Every finding is a SIGNAL a reviewer should confirm, never a demonstrated exploit: nothing is 'proven' until a dynamic probe exists (CLX-3.3). Rules whose evidence is absent are reported as skipped, never as passes.
apiome mcp trust-posture [OPTIONS] ENDPOINT_ID
Arguments
| Argument | Type | Required | Description |
|---|---|---|---|
ENDPOINT_ID | uuid | yes | MCP endpoint UUID. |
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--version | uuid | Version snapshot UUID (default: the endpoint's current version). | ||
--profile | text | mcp-trust-posture | Profile: mcp-trust-posture (default), mcp-metadata-posture, or mcp-supply-chain. | |
--format | text | json | Gate output format: json (default), sarif, or junit. | |
--fail-on | text | error | Exit non-zero on findings at this severity or higher: error (default), warning, info, or none. | |
--min-score | integer range | Exit non-zero when the score is below this floor. | ||
--require-full-coverage | flag | Fail the gate when any rule was skipped for lack of evidence. | ||
--output | text | Output: table (default) or json. |
apiome mcp trust-posture-rules
List the MCP trust-posture rule catalog (GET /v1/mcp/trust-posture/rules).
Each rule declares its evidence lane, the OWASP MCP risk it maps to, and what it needs to run — so you can see what the scan can and cannot tell you before running it.
apiome mcp trust-posture-rules [OPTIONS]
Options
| Option | Type | Default | Required | Description |
|---|---|---|---|---|
--profile | text | Only list rules in this profile: mcp-trust-posture, mcp-metadata-posture, or mcp-supply-chain (default: all). | ||
--output | text | Output: table (default) or json. |