Version. OpenShell 0.1.2. Observed 2026-09-29.
Observed. On an endpoint declared protocol: mcp, access: read-only fails policy validation. The form that works is an explicit tools/call params.name allowlist plus the handshake methods. The validator message says the preset is rejected but not what to write instead.
Why it matters. read-only is the first thing anyone writes for an MCP endpoint, and the natural reading of "rejected" is "MCP does not support access control", not "write the explicit list". We only found the working form by reading l7_validate.rs.
Ask. Either of:
- An MCP access preset that means handshake +
tools/list only (the MCP equivalent of read-only), or
- A validator message that names the required explicit form, e.g. "
access presets do not apply to protocol: mcp; declare tools/call params.name entries plus initialize, notifications/initialized, tools/list".
Version. OpenShell 0.1.2. Observed 2026-09-29.
Observed. On an endpoint declared
protocol: mcp,access: read-onlyfails policy validation. The form that works is an explicittools/callparams.nameallowlist plus the handshake methods. The validator message says the preset is rejected but not what to write instead.Why it matters.
read-onlyis the first thing anyone writes for an MCP endpoint, and the natural reading of "rejected" is "MCP does not support access control", not "write the explicit list". We only found the working form by readingl7_validate.rs.Ask. Either of:
tools/listonly (the MCP equivalent of read-only), oraccesspresets do not apply toprotocol: mcp; declaretools/callparams.nameentries plusinitialize,notifications/initialized,tools/list".