Skip to main content

apiome mcp

Global options such as --base-url, --tenant and --json go before the command — see CLI reference. Exit codes are listed in Exit codes.

apiome mcp​

MCP catalog endpoints and tenant governance (policy / key capabilities).

apiome mcp [OPTIONS] COMMAND [ARGS]...

Subcommands: conformance, conformance-rules, discover, key, lint, list, policy, probe, probe-catalog, probe-runs, probe-target-add, probe-target-list, register, shadowing, show, source, trust-baseline-approve, trust-baseline-show, trust-drift, trust-posture, trust-posture-rules.

apiome mcp conformance​

Evaluate MCP protocol conformance + agent-readiness (GET .../versions/{id}/conformance).

The server evaluates the selected rule profile against a discovered surface snapshot and computes the CI gate from --fail-on / --min-score; this command exits non-zero whenever that gate fails — including under --format sarif|junit, which echo the raw gate artifact for CI ingestion (the gate is always read from the JSON report, never inferred from the artifact). Rules that need a protocol transcript are reported as skipped (not passing) when no transcript was captured.

apiome mcp conformance [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--versionuuidVersion snapshot UUID to evaluate (default: the endpoint's current version).
--profiletextmcp-conformanceRule profile: mcp-conformance (default), mcp-protocol, or mcp-agent-readiness.
--formattextjsonGate output format: json (default), sarif, or junit.
--fail-ontexterrorExit non-zero when findings at this severity or higher are present: error (default), warning, info, or none.
--min-scoreinteger rangeExit non-zero when the conformance score is below this floor (0-100).
--outputtextOutput format: table (default) or json.

apiome mcp conformance-rules​

List the MCP conformance rule catalog (GET /v1/mcp/conformance/rules).

Each rule cites the MCP specification version it was written against and a source reference, so a failing gate can be traced back to the spec text that motivated it.

apiome mcp conformance-rules [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--profiletextOnly list rules in this profile: mcp-conformance, mcp-protocol, or mcp-agent-readiness (default: all).
--outputtextOutput format: table (default) or json.

apiome mcp discover​

Trigger a discovery run and poll it to completion.

Posts POST /v1/mcp/{tenant}/endpoints/{id}/discover to enqueue a manual discovery job, then (unless --no-wait) polls GET …/endpoints/{id}/jobs/{job_id} until the run reaches a terminal state and prints the new version, change summary, and best-effort quality score. Exits non-zero on a failed run or a timeout.

apiome mcp discover [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--wait / --no-waitflag--waitPoll the discovery job until terminal (default: wait).
--poll-intervalfloat range1.0Seconds between discovery-job status polls when waiting.
--import-timeoutfloat rangeMax seconds to wait for the discovery run to finish, and the per-request HTTP timeout used while waiting (default 120). Overrides --timeout.
--outputtextOutput format: table (default) or json.

apiome mcp key​

Manage per-key MCP capability grants (session / tenant admin).

apiome mcp key [OPTIONS] COMMAND [ARGS]...

Subcommands: capabilities.

apiome mcp key capabilities​

Get and set MCP API key capability grants.

apiome mcp key capabilities [OPTIONS] COMMAND [ARGS]...

Subcommands: get, set.

apiome mcp key capabilities get​

Print capability grants for one MCP key (projects GET …/mcp-keys/{id}).

apiome mcp key capabilities get [OPTIONS] KEY_ID

Arguments

ArgumentTypeRequiredDescription
KEY_IDuuidyesMCP API key UUID.

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput format: table (default) or json.

apiome mcp key capabilities set​

Replace per-key capability grants (PUT …/mcp-keys/{id}/capabilities).

Supply --file / stdin and/or --mode / --tool. With only flags, the current grants are loaded from the key GET and merged before PUT.

apiome mcp key capabilities set [OPTIONS] KEY_ID

Arguments

ArgumentTypeRequiredDescription
KEY_IDuuidyesMCP API key UUID.

Options

OptionTypeDefaultRequiredDescription
--filetextCapabilities JSON file, or '-' for stdin ({mode, enabled_tools}).
--modetextCapability mode: inherit or explicit.
--tooltext (repeatable)Enabled tool id when mode=explicit (repeatable).
--outputtextOutput format: table (default) or json.

apiome mcp lint​

Score a version snapshot and list its lint findings (GET .../versions/{id}/lint).

The MCP-catalog analogue of the project lint command: the server computes a deterministic 0-100 quality score, an A-F grade, and itemized findings for a discovered surface snapshot. --version targets a specific snapshot; omitted, the endpoint's current version is scored. --min-grade turns the report into a CI gate; --fail-on-policy also evaluates style-guide policy gates (GET .../lint/policy).

apiome mcp lint [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--versionuuidVersion snapshot UUID to score (default: the endpoint's current version).
--min-gradetextExit non-zero when the grade is worse than this (A best, F worst).
--fail-on-policyflagFetch lint policy evaluation and exit non-zero when policy gates fail.
--outputtextOutput format: table (default) or json.

apiome mcp list​

List MCP catalog endpoints (GET /v1/mcp/{tenant}/endpoints).

apiome mcp list [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput format: table (default) or json.

apiome mcp policy​

Inspect and replace tenant MCP governance policy (session / tenant admin).

apiome mcp policy [OPTIONS] COMMAND [ARGS]...

Subcommands: get, set.

apiome mcp policy get​

Print the tenant MCP policy (GET /v1/tenants/{slug}/mcp-policy).

apiome mcp policy get [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput format: table (default) or json.

apiome mcp policy set​

Replace the tenant MCP policy (PUT /v1/tenants/{slug}/mcp-policy).

Supply --file / stdin and/or --default-mode / --allow-anonymous. With only flags, the current policy is fetched and merged before PUT.

apiome mcp policy set [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--filetextPolicy JSON file, or '-' for stdin (TenantMcpPolicyPutRequest shape).
--default-modetextdefault_mode: all, inherit_registry, or explicit.
--allow-anonymoustextallow_anonymous_mcp kill switch: true or false.
--outputtextOutput format: table (default) or json.

apiome mcp probe​

Run a dynamic probe against a version snapshot (POST .../versions/{id}/probe).

The default 'passive' profile is read-only: it re-reads the captured transcript, sends nothing, and classifies observed protocol behaviour. Active profiles require the target to be allowlisted (see 'probe-target-add'), the global kill switch to be on, and — for payload-fuzzing — --i-approve-hostile-payloads. Nothing here is 'proven' unless a probe demonstrated it against a live server in isolation (an exploited-in-test finding).

apiome mcp probe [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--versionuuidVersion snapshot UUID (default: the endpoint's current version).
--profiletextpassiveProfile: passive (default, read-only), safe-active, or payload-fuzzing.
--i-approve-hostile-payloadsflagExplicit per-run approval, required for payload-fuzzing.
--outputtextOutput: table (default) or json.

apiome mcp probe-catalog​

List the MCP probe catalog (GET /v1/mcp/probes/catalog).

Shows every probe, which profile runs it, and the strongest classification tier it can reach — so you know, before running anything, what a probe can and cannot demonstrate.

apiome mcp probe-catalog [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--profiletextOnly list probes in this profile: passive, safe-active, or payload-fuzzing.
--outputtextOutput: table (default) or json.

apiome mcp probe-runs​

Show an endpoint's probe-run audit trail (GET .../probe-runs).

apiome mcp probe-runs [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--limitinteger range50Max audit rows to return.
--outputtextOutput: table (default) or json.

apiome mcp probe-target-add​

Enrol an endpoint on the active-probe allowlist (POST .../probe-targets).

Active probing may only ever fire at an allowlisted target. Enrolling records, on the record, that you asserted ownership/authorization and (optionally) the dedicated test identity a probe uses.

apiome mcp probe-target-add [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID to enrol on the allowlist.

Options

OptionTypeDefaultRequiredDescription
--i-own-or-am-authorizedflagAssert you own or are authorized to probe this target (required).
--test-credentialuuidThe dedicated (non-production) test credential a probe authenticates as.
--outputtextOutput: table (default) or json.

apiome mcp probe-target-list​

List an endpoint's active-probe allowlist entries (GET .../probe-targets).

apiome mcp probe-target-list [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput: table (default) or json.

apiome mcp register​

Register an MCP server in the tenant catalog (POST /v1/mcp/{tenant}/endpoints).

apiome mcp register [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--nametextyesHuman-readable endpoint name.
--urltextyesMCP server URL (http/https for streamable_http/sse).
--transporttextstreamable_httpMCP transport: streamable_http (default), sse, or stdio.
--slugtextOptional catalog slug; derived from --name and uniquified when omitted.
--descriptiontextOptional endpoint description.
--categorytextOptional catalog category.
--visibilitytextprivateCatalog visibility: private (default) or public.
--bearertextSeal a bearer token as the endpoint's outbound credential.
--headertextSeal a custom header secret as 'Name:Value'.
--outputtextOutput format: table (default) or json.

apiome mcp shadowing​

List tool/resource/prompt names shadowed across enabled endpoints (GET .../data-quality/shadowing).

apiome mcp shadowing [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput: table (default) or json.

apiome mcp show​

Show one MCP catalog endpoint (GET /v1/mcp/{tenant}/endpoints/{id}).

apiome mcp show [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput format: table (default) or json.

apiome mcp source​

Link and manage the source artifacts an MCP endpoint is built from (CLX-3.2).

apiome mcp source [OPTIONS] COMMAND [ARGS]...

Subcommands: link, list, retire.

Link a source artifact to an MCP endpoint (POST .../endpoints/{id}/sources).

The pin strength is derived by the server from whether the reference actually carries an immutable digest — a branch stays 'unverified', a commit sha becomes 'digest_pinned'.

apiome mcp source link [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--kindtextyesSource kind: git, package, image, or registry.
--referencetextyesSource reference: a git URL, a purl, an OCI image ref, or a registry server id.
--revisiontextFor git, the branch/tag/commit. A full 40-hex commit sha pins the source.
--provenancetextoperator_declaredHow the link is known: operator_declared (default), registry_published, discovery_advertised, or attested.
--outputtextOutput: table (default) or json.

apiome mcp source list​

List an endpoint's linked sources (GET .../endpoints/{id}/sources).

apiome mcp source list [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--include-retiredflagInclude retired source links.
--outputtextOutput: table (default) or json.

apiome mcp source retire​

Retire a linked source (DELETE .../sources/{id}). Soft delete — it stays readable.

apiome mcp source retire [OPTIONS] ENDPOINT_ID SOURCE_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.
SOURCE_IDuuidyesSource association UUID to retire.

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput: table (default) or json.

apiome mcp trust-baseline-approve​

Approve a trust baseline for an endpoint (POST .../trust-baseline).

Pins the trust manifest of the approved snapshot as the reference every later rediscovery/release is diffed against. The rationale is required and recorded as a governance policy event; approving a new baseline supersedes the prior one.

apiome mcp trust-baseline-approve [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID to approve a baseline for.

Options

OptionTypeDefaultRequiredDescription
--rationaletextyesWhy this snapshot is approved (required; recorded as a policy event).
--versionuuidVersion snapshot UUID to approve (default: the current version).
--gatetext (repeatable)Drift categories that block the gate (repeatable): security_regression, coverage_loss, quality_regression, normal_change. Default: security_regression + coverage_loss.
--outputtextOutput: table (default) or json.

apiome mcp trust-baseline-show​

Show an endpoint's active trust baseline and approval history (GET .../trust-baseline).

apiome mcp trust-baseline-show [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--outputtextOutput: table (default) or json.

apiome mcp trust-drift​

Diff an endpoint's current snapshot against its approved baseline (GET .../trust-drift).

Every material surface/source change is classified as a normal change, a quality regression, a security regression, or coverage loss, and carries an old→new evidence reference. The gate reflects the baseline's configured risk deltas.

apiome mcp trust-drift [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--notifyflagFan out a push-webhook alert when a regression is found.
--outputtextOutput: table (default) or json.

apiome mcp trust-posture​

Evaluate MCP source / supply-chain / trust posture (GET .../versions/{id}/trust-posture).

Assesses what the server is built from — advertised metadata, linked source, dependencies — mapped to the OWASP MCP Top 10, and gates the result. Every finding is a SIGNAL a reviewer should confirm, never a demonstrated exploit: nothing is 'proven' until a dynamic probe exists (CLX-3.3). Rules whose evidence is absent are reported as skipped, never as passes.

apiome mcp trust-posture [OPTIONS] ENDPOINT_ID

Arguments

ArgumentTypeRequiredDescription
ENDPOINT_IDuuidyesMCP endpoint UUID.

Options

OptionTypeDefaultRequiredDescription
--versionuuidVersion snapshot UUID (default: the endpoint's current version).
--profiletextmcp-trust-postureProfile: mcp-trust-posture (default), mcp-metadata-posture, or mcp-supply-chain.
--formattextjsonGate output format: json (default), sarif, or junit.
--fail-ontexterrorExit non-zero on findings at this severity or higher: error (default), warning, info, or none.
--min-scoreinteger rangeExit non-zero when the score is below this floor.
--require-full-coverageflagFail the gate when any rule was skipped for lack of evidence.
--outputtextOutput: table (default) or json.

apiome mcp trust-posture-rules​

List the MCP trust-posture rule catalog (GET /v1/mcp/trust-posture/rules).

Each rule declares its evidence lane, the OWASP MCP risk it maps to, and what it needs to run — so you can see what the scan can and cannot tell you before running it.

apiome mcp trust-posture-rules [OPTIONS]

Options

OptionTypeDefaultRequiredDescription
--profiletextOnly list rules in this profile: mcp-trust-posture, mcp-metadata-posture, or mcp-supply-chain (default: all).
--outputtextOutput: table (default) or json.