Skip to main content
Steerholm exposes an MCP endpoint over HTTP — the MCP Streamable HTTP transport — directly from the daemon. An MCP-capable agent — the client you run, such as Claude Code — connects to /mcp and authenticates with an access key in the Authorization header. (At the protocol level the agent is the MCP client and Steerholm is the MCP server.)

Endpoint

Use the host and port configured for holm serve if you changed the defaults.

Authentication

Every request must include a Bearer token:
The daemon resolves the agent from the Bearer token by checking it against stored key hashes. The caller does not declare which agent it is.

Configuring the connection

Configure your agent to use Steerholm as a Streamable HTTP server:
This keeps the admin CLI separate from agent access. Agents connect only to the MCP endpoint; users manage servers, agents, policies, and daemon lifecycle through the holm command.

HTTP statuses

Authenticated policy denials are returned as MCP errors, not HTTP auth failures. Unauthorized tool calls return AUTHORIZATION_DENIED (-31001). Downstream server failures return SERVER_UNAVAILABLE (-31002).