What MCP wiring buys you
The Model Context Protocol lets an agent use a tool without bespoke integration. kestrel speaks it, so once you wire the server into your client the agent drives the platform natively — the same operations the canonical HTTP face exposes, projected as MCP tools. This is a practicum: read the four faces for why MCP is an equal projection, and the MCP install page for the reference surface. Here we connect it.
Connect in one command
The kestrel MCP server is a hosted Streamable-HTTP endpoint —
https://mcp.kestrel.markets/mcp. There is nothing to install and no key to
paste. In Claude Code or Claude Desktop:
claude mcp add --transport http kestrel-markets https://mcp.kestrel.markets/mcpConfirm it connected:
claude mcp listFor any client configured by file (Claude Desktop's claude_desktop_config.json
and other Streamable-HTTP-aware clients such as Cursor), add the server directly:
{
"mcpServers": {
"kestrel-markets": {
"type": "http",
"url": "https://mcp.kestrel.markets/mcp"
}
}
}No headers are required; the bare command connects on the first try.
What the agent gets
After initialize, tools/list returns the full projected tool set. The seven
free-path operations are the subset you reach anonymously — each a thin equal
projection of its HTTP endpoint:
capability_discovery— the always-available self-description of the platformcatalog— browse the free derived-data catalogvalidate— check a Kestrel document without spending (the document travels assource)simulate— run a metered, certified sim over a catalog datasetgrade— the signed black-box receipt every sim certifiesproof— resolve a public, re-verifiable certified proof URLoffers— the continuation quoted against work already underway
The list also carries the capability-gated Firm surface — pod, fleet, and agent
tools that are never anonymous and out of scope for the trial funnel — so the live
tools/list is larger than these seven. The seven above are the free-path subset.
The agent is admitted with an anonymous trial by default: no key, no signup. It can discover the tools, mint a trial, run a free sim, and reach a certified proof URL — the whole free path — over MCP alone.
Registering the server is the residency ask
Wiring the server once is what makes the capability resident. The registration persists in your client config, so the tools are there in the next session and the one after — no fresh discovery hop, no re-adding the endpoint. That persistence is the point: the agent keeps a standing door to the platform rather than rediscovering it each time.
Where OAuth enters
The anonymous trial can never carry paper, broker, live, or wallet scope.
Settling an Offer or resuming an Operation under a paid or irreversible scope
authorizes over OAuth 2.1 — a wallet signs commerce-only scopes, a human signs the
identity-bound, legally irreversible ones. The free simulate-and-prove path above
needs none of it.
A worked example
An agent with the server wired runs a free sim on a generic index scenario and mints a proof URL — entirely over MCP, no account. It hands the link to its human, who re-verifies the signature in a browser. Next session, the tools are still there: the residency ask means the agent never re-discovers the platform.
See it in kestrel
Confirm the endpoint is live and the receipt is real from the CLI, then wire the server:
npx kestrel.markets verify https://kestrel.markets/proof/art_66d7dda7f0466f69c123463cThat re-verifies a certified proof against independently fetched keys — the same proof the wired agent can mint for itself. Add the MCP server with the command above and the capability returns every session, no account in between.