McpServer
Parameters and properties
Section titled “Parameters and properties”The fields below cover all variants; the signature specifies their allowed combinations.
commandVariant-dependentstringExecutable started in the sandbox. Literal text; it cannot contain ${ or NUL.argumentsVariant-dependentreadonly string[] | undefinedLiteral arguments passed to the command, without ${ references.environmentVariant-dependentReadonly<Record<string, string>> | undefinedNon-secret environment values set for the server, written verbatim into the configuration.variablesVariant-dependentreadonly string[] | undefinedNames of declared variables forwarded to the server. Values never appear in arguments or files; a missing variable fails before the agent starts.toolsOptionalMcpToolFilter | undefinedTool filter by exact MCP tool name. include keeps only the listed tools and exclude removes tools afterwards. Harnesses that cannot apply a part refuse it when the agent is composed.startupTimeoutMsOptionalnumber | undefinedServer start limit in milliseconds, 1 to 2147483647; the built-in harness defaults to 60000. Codex and Kimi apply it per server, Claude Code as one MCP_TIMEOUT that must be equal on every server that sets it, and Copilot and Antigravity refuse it.urlVariant-dependentstringAbsolute http or https URL of a Streamable HTTP MCP endpoint, without embedded credentials.headersVariant-dependentReadonly<Record<string, string>> | undefinedNon-secret HTTP headers sent with every request. Use bearerTokenVariable for an Authorization token.bearerTokenVariableVariant-dependentstring | undefinedName of a declared variable whose value is sent as Authorization: Bearer. It cannot be combined with an Authorization header.oauthVariant-dependent"login" | McpClientCredentials | undefined“login” copies the MCP OAuth login that Claude Code, Codex or Kimi stored on the host; client credentials work only in the built-in harness, which requests the token from the sandbox. Excludes bearerTokenVariable and an Authorization header.