For developers
What a client needs to know about the server, and how to call it without an assistant in between.
The protocol as we serve it
-
Streamable HTTP at
https://api.publicwww.com/mcp: one JSON-RPC message perPOST(a batch is accepted too), answers are plainapplication/json. No server-sent events, no sessions - every request carries its token.GETis405. -
Both generations of the protocol are served at the same URL: the
revisions with the
initializehandshake (2024-11-05 to 2025-11-25) and 2026-07-28 withserver/discover, where the version and client capabilities travel inparams._metaof every request andMcp-Method/Mcp-Namemust match the body. -
No token, or one that was deleted, is
401on any request, with aWWW-Authenticateheader naming the protected resource metadata (RFC 9728), from which an OAuth client finds the authorization server. The flow is in OAuth 2.1 for applications. -
Tools:
searchandaccount, described in Tools. No resources, no prompts, and the list does not change between calls.
Calling it with curl
The server keeps no state between calls, so a tool can be called straight away, without the handshake:
curl https://api.publicwww.com/mcp \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call",
"params":{"name":"search","arguments":{"query":"\"angular.min.js\"","rows":3}}}'
The list of tools with their input schemas:
curl https://api.publicwww.com/mcp \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
These calls and an account check, as one script: mcp-curl.sh.
For a script that only needs search results, the REST API is the simpler road: the same search and token, with CSV, NDJSON and the other formats.