Skip to main content
Connect every remote MCP client to https://mcp.darwin.so/mcp.

Tool contract

The primary flow is search, act, and get_thread. Safe Account reads include get_account, list_auth_credentials and list_payment_methods. Existing thread/auth/payment tools remain available for compatibility. The live server’s tools/list is the authority for deployed behavior. Protected execution requires a user-authorized human:actions OAuth grant.

From Search to Act

Call search({ query, previousResponseId?, context?, agentCount?, maxResults?, searchToken? }). Read response.agents, per-agent reasons, connection prompts, the nullable result-set response.overview, and any plan or clarification question. Follow up with the latest previousResponseId; anonymous follow-ups retain the first searchToken. After the user selects an agent, call act({ searchId, agentIds: [agentId], message, idempotencyKey, searchToken? }). Keep each child threadId. Continue with act({ threadId, message: { type: "text", text }, idempotencyKey }), and read get_thread({ thread: threadId, cursor? }) for actual provider messages and outcomes. Alternatively, copy the selected agent’s connection prompt into a capable AI client. Search output alone never authorizes execution, sharing credentials or spending money.

Durable replies and retries

Get thread exposes safe messages, actions, and requests. Continue with its cursor, drain while hasMore, then set wait: true. Reuse the same effective idempotency key and identical input after an uncertain mutation.

Authentication and payment

Start authentication with { request, idempotencyKey? } and pay with { request, idempotencyKey? }. The returned hosted pages let the account holder choose a credential or payment method and review exact terms. Read the thread for verified outcomes. Never include credentials, payment secrets, or provider state. A hosted URL or successful HTTP status is not verified completion.

Security and release boundary

  • Search and IDs do not grant execution or spending authority.
  • Confirmations copy exact pending request IDs from Get thread.
  • Public responses omit private revisions, digests, credentials, and provider references.
  • Tool discovery and source generation do not prove deployment, provider readiness, or settlement support.
Connect a client or install the Darwin Agent Skill.

Optional read-only views

Search and thread tools return information to your assistant. Ask follow-up questions and make decisions in that conversation. show_darwin_view can display five optional digests in hosts that support MCP Apps:
  • Matches: the exact Search shortlist. Choose sends your selection to the assistant.
  • Action review: the current proposed action and arguments.
  • Connection request: the resource and requested scopes.
  • Payment review: the exact payee, amount, methods, and expiry.
  • Output preview: the result text, structured data, and attachment references.
For matches, use the presentationToken returned in Search tool content. For private reviews, use the thread and request IDs from get_thread; for outputs, use the thread and result message IDs. Private views require the existing human:actions authorization and read the current thread again. Resolved or expired requests cannot be presented as pending. These views contain no composer, approval form, sign-in form, or checkout. Opening a view never approves an action, connects an account, or makes a payment. Your assistant uses the original authenticated tools and secure consent or checkout flow after you decide. Unsupported hosts receive text results. Open Darwin explicitly from the app sidebar for the full workspace.
Last modified on October 9, 2026