urlRequired
string
Absolute http or https URL of a Streamable HTTP MCP endpoint, without embedded credentials.
headersOptional
Readonly<Record<string, string>> | undefined
Non-secret HTTP headers sent with every request. Use bearerTokenVariable for an Authorization token.
bearerTokenVariableOptional
string | undefined
Name of a declared variable whose value is sent as Authorization: Bearer. It cannot be combined with an Authorization header.
oauthOptional
"login" | McpClientCredentials | undefined
“login” copies the MCP OAuth login that Claude Code, Codex or Kimi stored on the host; client credentials work only in the built-in harness, which requests the token from the sandbox. Excludes bearerTokenVariable and an Authorization header.
toolsOptional
McpToolFilter | undefined
Tool filter by exact MCP tool name. include keeps only the listed tools and exclude removes tools afterwards. Harnesses that cannot apply a part refuse it when the agent is composed.
startupTimeoutMsOptional
number | undefined
Server start limit in milliseconds, 1 to 2147483647; the built-in harness defaults to 60000. Codex and Kimi apply it per server, Claude Code as one MCP_TIMEOUT that must be equal on every server that sets it, and Copilot and Antigravity refuse it.