MCP for AI Agents
Overview
bake mcp
bake mcp starts a local stdio-based MCP server that exposes bake's capabilities to AI agents.
To quickly scaffold a complete agent repository pre-configured for Cursor or Claude Desktop, see the AI Agents Guide (bake agent init).
Safety-first design
Warning: Write tools are UNREGISTERED by default. An agent cannot be tricked into calling a tool it does not know exists.
Two tiers of tools
Read-only tools (always registered):
bake_whoamiโ active wallet(s) + clusterbake_statsโ program activity statsbake_proveโ Level 1 on-chain hash checkbake_logsโ recent log historybake_get_historyโ Recipe Book entries
Write tools (disabled by default):
bake_deployโ deploy a programbake_rollbackโ rollback to a previous entrybake_confirm_actionโ execute a previewed write
Policy file
To enable write tools, create a policy file:
{
"allowWrites": true,
"allowedPrograms": "any",
"maxDeploysPerSession": 5,
"requireConfirmation": true
}Place at .bake/mcp-policy.json or pass via flag:
bake mcp --policy /path/to/policy.json
Without a policy file, bake mcp starts in READ-ONLY mode.
Confirmation flow
When requireConfirmation: true (default):
- Agent calls
bake_deployorbake_rollback - Server returns
status: "confirmation_required"with a preview andconfirmationToken - Agent (or human) calls
bake_confirm_actionwith that token - Server executes the action
This is the human-in-the-loop safety net โ a real deploy cannot complete in a single unsupervised tool call.
Session limits
The MCP server tracks writes per session. Once maxDeploysPerSession is hit, all further write calls are refused. The counter resets only when the MCP server process restarts.
Audit logging
Every write tool call (attempted or executed, allowed or refused) is logged to stderr with an ISO timestamp. Stdout is reserved for the MCP protocol.
cookie-mcp integration
bake_check_token_liquidity spawns the official cookie-mcp npm package as an isolated child MCP process for read-only token/liquidity lookups.
Key constraints:
- Stdio isolation (piped, not inherited)
- No
COOKIE_PRIVATE_KEY(strictly read-only) - Lazy singleton (spawned on first use)
- Requires Node.js โฅ 22
Usage with AI agents
# Start MCP server in read-only mode bake mcp # Or with explicit policy bake mcp --policy .bake/mcp-policy.json
Configure your AI agent (Cursor, Claude Desktop, etc.) to connect to bake's MCP server over stdio.
Related guides & references
- AI Agents Guide โ scaffold a pre-configured agent project with
bake agent init - Command Reference โ full flags and options for
bake mcp