MCP endpoint
POST /mcp speaks the Model Context Protocol over Streamable HTTP (stateless; JSON responses). It is protected by the same OAuth bearer tokens as the REST API, and discovery follows the MCP authorization spec: a 401 carries WWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource", and the authorization server supports dynamic client registration and PKCE.
Tools
| Tool | Annotations | Scope |
|---|---|---|
search_catalog, get_product, get_variant_availability, list_collections, get_collection, validate_address |
read-only | catalog:read |
get_me |
read-only | profile |
get_checkout, list_orders, get_order, list_support_requests |
read-only | orders:read |
create_quote, send_receipt, request_support |
write | orders:write |
create_checkout, cancel_checkout, cancel_order |
destructive (sensitive write) | orders:write |
Every tool returns both a text rendering and structuredContent with the same JSON the REST API returns. Errors are returned as tool errors whose text includes the stable error code.
Claude Desktop / Claude Code example
{
"mcpServers": {
"snappy": { "type": "http", "url": "https://sandbox.agents.snappy.com/mcp" }
}
}
The client discovers the authorization server, registers itself, and opens the browser for sign-in and consent.
Server instructions
The server advertises instructions that describe the recommended flow (search → product → availability → one quote per item → confirm with the user → checkout → poll → receipt → cancel or support). Hosts that honour instructions need no extra prompting.