/mcp and authenticates with an access key in the Authorization header. (At the protocol level the agent is the MCP client and Steerholm is the MCP server.)
Endpoint
holm serve if you changed the defaults.
Authentication
Every request must include a Bearer token:Configuring the connection
Configure your agent to use Steerholm as a Streamable HTTP server:holm command.
HTTP statuses
Authenticated policy denials are returned as MCP errors, not HTTP auth failures. Unauthorized tool calls return
AUTHORIZATION_DENIED (-31001). Downstream server failures return SERVER_UNAVAILABLE (-31002).