Skip to content

MCP module

What it does

MCP presents NOW's local Streamable HTTP endpoint and the selected classic Mac's explicit ceiling on what an agent may observe or change. The catalog, dispatcher, and listener live inside NOW; there is no separately installed MCP service or Standard Input transport.

The macOS MCP module showing transport and grant state

Availability

The host app owns the transport and all projections. PowerPC provides the machine consent page. NOW-68K does not expose this MCP consent surface.

On the modern Mac

The host exposes controls for:

  • HTTP (Recommended), a loopback listener running directly inside the normal NOW app. Its card exposes an editable loopback port and an Access mode while stopped, and shows and copies the derived URL. Access has three settings, applied the next time HTTP starts:
    • Bearer token (the default): requests must carry NOW's private token. The card copies it without rendering the secret in the module or logs.
    • OAuth: NOW acts as the authorization server for standard MCP clients — discovery metadata, dynamic client registration, and a PKCE authorization-code flow. A client's first sign-in parks on the card as an Approve / Deny consent row; nothing is issued until a person answers, and Revoke OAuth Clients & Tokens forgets every registration and cancels outstanding tokens.
    • No authentication: any process on this Mac can drive NOW over the port. The card says so in warning copy; the loopback Host and Origin checks still apply.

Migrate a client to HTTP

  1. Open MCP > HTTP (Recommended) in New Old World.
  2. Select Bearer token, OAuth, or the explicitly warned No authentication loopback mode. Bearer is the default, not a migration requirement.
  3. Start HTTP and copy the displayed http://127.0.0.1:<port>/mcp URL.
  4. For bearer or OAuth, use the matching copyable client recipe on the HTTP card. Do not copy credentials into logs or documentation.
  5. Initialize the client over HTTP and exercise its normal tool workflow.

New Old World --mcp-stdio has been removed. A stale configuration receives one diagnostic on stderr and no MCP protocol output; update it to the URL and access mode shown here.

An HTTP credential identifies and authenticates a transport session; it does not grant a modern-Mac workspace. Ordinary external HTTP sessions start with no host-readable root. The embedded Chat lane can redeem one bounded, session-scoped workspace grant without retargeting another session.

The HTTP card has Start and Stop controls, which affect the current app session. The persisted Start HTTP automatically policy lives in the Settings window's MCP tab because it is read once at launch and never mid-session. It applies the next time NOW opens.

The module also shows the shared catalog, selected machine, available capabilities, grant state, and auditable calls. A running transport is not a machine grant.

The page is two columns of cards — recent agent activity on the right by default, everything else on the left. Every card collapses from its header chevron, the handle at its top-left drags it anywhere in either column (a context menu offers the same moves for the keyboard), and the arrangement persists across launches. Each transport card also discloses a Session log: the host log's lines for that transport from this run of the app.

The activity card reads a durable record, not a per-launch ring: every audited call lands in a private database beside NOW's other application data, kept 180 days. Rows filter by outcome, agent, and machine; the agent and machine chips on a row — and the row itself — open a detail sheet for that record, which pivots between an agent, its sessions, the machines it drove, and individual actions. The record stores what the audit line already said — capability, face, machine, outcome, bounded refusal reason, plus the client name an MCP client stated about itself — and never arguments or payloads.

Historical Standard Input initialization and action rows remain readable in the installation-local activity database. They are migration evidence, not a live transport or telemetry. Paths, arguments, payloads, file bytes, and credentials are not displayed.

On the classic Mac

The PowerPC MCP page sets the machine's ceiling. It cannot supply host-local credentials or prove that an MCP client can reach the host.

The PowerPC MCP consent page

Common tasks

  • Confirm the selected machine and requested capability before granting.
  • Start HTTP for supported clients.
  • Copy connection details from the HTTP card rather than locating a helper executable.
  • Read the recent call record after an agent action.

Global transport availability, HTTP authentication, and per-machine grants are separate controls. Do not weaken the same-user socket, loopback bind, bearer, Host, Origin, session, or framing limits to connect a client.

Failure states

Transport stopped, local socket unavailable, HTTP authentication failure, not addressed, not granted, capability unavailable, stale reference, and machine refusal are typed.

Current limitations

The 68K guest has no matching consent UI. Experimental semantic tools inherit Mirror's narrower observation and act evidence.

For developers

See agent boundary and MCP coverage.