Quickstart
Integrator appendix. From a connection artifact to a first successful authenticated tool call. Buyers evaluating the pattern should use Overview and an infrastructure review, not this page as the primary CTA.
Before you start
Prerequisites: Connect completed. Pack available on Integration Surfaces. Signing material stays on the peer.
Expected outcome: A read tool returns structured JSON without 401 / 403 on an entitled surface.
1. Point the client
Remote (preferred)
- URL: HTTPS MCP endpoint from Connect (Streamable HTTP)
- Auth: Bearer token (step 2)
Local stdio: trusted machines only. Use operator install config.
2. Authenticate
Authorization: Bearer <short-lived-token>
Token must be audience-bound to your Legate resource URI. Details: Authentication.
Unauthenticated remote calls receive 401 with a WWW-Authenticate challenge pointing at protected-resource metadata.
3. First tool call
- List tools (
tools/listor your client UI). - Call a read tool covered by
legate.read(usetools/listfor the names your pack publishes). Synthetic success shape:
{
"scope_id": "scope-demo-001",
"height": 12450,
"currentBlockHash": "0xexample…"
}
Args and field names vary by pack. Do not treat this sample as a schema contract. 3. On failure, map status to Errors.
You have succeeded when a read tool returns without 401 / 403 and the surface is entitled.
4. Writes (when entitled)
simulate: dry-run / endorsement previewprepare: proposal + review payload (does not commit)- External signature: human or dedicated signer
submit_signed: commit the signed proposal
Write scopes require an explicit consent claim. Hot-wallet invoke inside the MCP process is not a production path. See Access model.
Done when
- Connection obtained without exporting signing material
- First read tool succeeds on an entitled surface
- Write path (if used) follows simulate → prepare → external sign → submit_signed
Full operator gate: Production Checklist.