MCP
also called Model Context Protocol
An open protocol that lets an AI agent read and write real systems — files, APIs, trackers — instead of being told the state of the world in every prompt.
Practically: the difference between an assistant you brief from scratch each time and one that can look things up and write back.
Before MCP, every integration was bespoke: your agent, your glue code, your auth, repeated per tool. MCP standardises the shape — a server advertises tools with typed inputs, a client calls them — so one agent can reach many systems and one system can serve many agents.
The interesting design question it creates is not what to expose but what to withhold. A server is defined by its omissions. RelayWork exposes eleven tools and no way to approve a spec: not permission-gated, absent — so no misconfiguration, and no persuasive prompt, can produce a machine-signed approval.
Two more things worth getting right. Scope tokens read-or-write, and revoke them from a UI rather than a redeploy. And attribute machine writes to the token, not to a person — otherwise an agent silently borrows a human’s authority, and your audit trail becomes fiction.
MCP is an open specification with reference servers and SDKs, not a vendor feature. If your tool cannot be reached this way, an agent has to be told about it every session.
claude mcp add relaywork --transport http https://api.relaywork.app/api/v3/relay/mcp --header "Authorization: Bearer <api-token>"
- MCP server
A service exposing tools an agent may call. A well-designed one is defined as much by what it omits — RelayWork has no approve tool at all, so no misconfiguration can let a machine sign off its own work.
- Tool scope
Whether a token may read or also write, and which tools it can reach. Scoped, revocable tokens are what make agent access auditable rather than a shared password.
- Machine attribution
Recording an automated write as the token that made it rather than as a person. Without it, an agent’s edit silently borrows a human’s authority.