The workspace MCP

    POST /api/build/mcp takes a build key, which starts cc_build_ and is a different thing from a serving key. It opens a whole workspace rather than one tool, which is why only an owner can create one and why it refuses any request carrying an Origin header outright.

    Every key gets eight read tools: list_datasets, get_dataset, list_contracts, get_readiness, list_review_items, get_receipts, list_value_sets and get_run. Read-only, and not by convention. They run inside a read-only database transaction, so a write cannot happen even if something tried. list_contracts includes each value's definition and examples, what the field is for, where its definitions come from, and the PDFs it reads.

    A key made to build gets seven more. Choose *Read and build* when you make the key: create_dataset (a table as CSV, TSV or JSON), create_field, update_field, create_value_set, import_value_set_version, start_run and publish_release. Each goes through the same checks as the dashboard, so an agent can't make a field the editor would refuse, and a refused call leaves nothing half-made. Each change is recorded as made by that key, never as a person, and definitions an agent writes are marked as drafted in the field's history. On a safety field an agent can add values but never remove one or make it a normal field. A read-only key is never offered these tools, and is refused if it calls one.

    An agent publishes only when the accuracy gate passes by itself: the dataset has a published answer key, today's fields have been measured on it, and no safety value is found less often than in the last release. It can't give the reason a person gives to publish past the gate, and without an answer key there's no gate to pass, so a person publishes. The release names the key that published it, and a tool with scenarios still holds it back if they fail.

    A secret is shown once. It's stored only as a hash, so it can't be shown again. Lost one? Give the key a new secret in the dashboard: the key keeps its name, access and limits, and the old secret stops working at once.

    Record contents are off by default. list_review_items will not return the record itself unless the key was explicitly granted that. An agent can triage a queue by field and reason without ever reading your data.