Home/Docs/Guides/MCP for AI Agents

Let AI agents inspect and deploy programs via Model Context Protocol.

MCP for AI Agents

Overview

bash
bake mcp

bake mcp starts a local stdio-based MCP server that exposes bake's capabilities to AI agents.

To quickly scaffold a complete agent repository pre-configured for Cursor or Claude Desktop, see the AI Agents Guide (bake agent init).

Safety-first design

Warning: Write tools are UNREGISTERED by default. An agent cannot be tricked into calling a tool it does not know exists.

Two tiers of tools

Read-only tools (always registered):

  • bake_whoami โ€” active wallet(s) + cluster
  • bake_stats โ€” program activity stats
  • bake_prove โ€” Level 1 on-chain hash check
  • bake_logs โ€” recent log history
  • bake_get_history โ€” Recipe Book entries

Write tools (disabled by default):

  • bake_deploy โ€” deploy a program
  • bake_rollback โ€” rollback to a previous entry
  • bake_confirm_action โ€” execute a previewed write

Policy file

To enable write tools, create a policy file:

json
{
  "allowWrites": true,
  "allowedPrograms": "any",
  "maxDeploysPerSession": 5,
  "requireConfirmation": true
}

Place at .bake/mcp-policy.json or pass via flag:

bash
bake mcp --policy /path/to/policy.json

Without a policy file, bake mcp starts in READ-ONLY mode.

Confirmation flow

When requireConfirmation: true (default):

  1. Agent calls bake_deploy or bake_rollback
  2. Server returns status: "confirmation_required" with a preview and confirmationToken
  3. Agent (or human) calls bake_confirm_action with that token
  4. Server executes the action

This is the human-in-the-loop safety net โ€” a real deploy cannot complete in a single unsupervised tool call.

Session limits

The MCP server tracks writes per session. Once maxDeploysPerSession is hit, all further write calls are refused. The counter resets only when the MCP server process restarts.

Audit logging

Every write tool call (attempted or executed, allowed or refused) is logged to stderr with an ISO timestamp. Stdout is reserved for the MCP protocol.

cookie-mcp integration

bake_check_token_liquidity spawns the official cookie-mcp npm package as an isolated child MCP process for read-only token/liquidity lookups.

Key constraints:

  • Stdio isolation (piped, not inherited)
  • No COOKIE_PRIVATE_KEY (strictly read-only)
  • Lazy singleton (spawned on first use)
  • Requires Node.js โ‰ฅ 22

Usage with AI agents

bash
# Start MCP server in read-only mode
bake mcp

# Or with explicit policy
bake mcp --policy .bake/mcp-policy.json

Configure your AI agent (Cursor, Claude Desktop, etc.) to connect to bake's MCP server over stdio.

Related guides & references

Sourced from local MDX in docs/content/docs