If you are asking “can MCP write?”, the answer depends on which. Yes for
the connector — that is Peeve calling your tools. No for the server on this
page — that is an assistant asking Peeve what your product can do.
What
tools/call returns today. On the current release this endpoint
returns a grounded guide — where the capability lives in your product and how
to complete it — and does not itself perform the action.Writes through MCP happen in the other direction, via the
Custom MCP connector, where they route through the
kill switch, the writes switch, the permission mode, a per-tool allow-list and
a mandatory human confirmation. Build against the role model above rather than
assuming nothing anywhere can change.What it exposes
Tools are projected from your workspace’s verified capabilities — the ones Peeve has confirmed exist in your product by mapping it. A capability appears as a tool only when all of the following hold:- it belongs to the current production version of your product map;
- its status is verified — not draft, stale or broken;
- its agent access is set to allowed — not human-only or blocked;
- it has not been disabled by a builder.
The two endpoints
Workspace-level
https://mcp.peeve.ai/{workspace}A teammate’s API token, acting for the workspace. Any role (read).
The token’s workspace must match the URL.Per-user
https://mcp.peeve.ai/{workspace}/u/{contact}Scoped to one contact. Takes a pv_grant_… token, or a teammate’s user
token with reply (owner, admin or responder).Protocol
JSON-RPC 2.0 over HTTP. Protocol version2024-11-05, negotiated in the
initialize handshake.
Anything else returns
-32601 Method not found.
Notifications — a message with no id, or any method in the notifications/*
namespace — get no reply. A batch consisting only of notifications is answered
202 with no body.
Batches are supported: send an array, get an array back.
There is no version segment in the URL, on purpose. MCP negotiates its
protocol version in the handshake and tool changes are additive, so the URL
you paste into an assistant stays valid indefinitely.
What a tools/call actually returns
read, write, write — needs the user's confirmation,
and destructive — needs the user's confirmation.
Auditing
Everytools/call and every initialize lands in your activity log, recorded
after the response so it never slows a call.
The record carries the capability key, the method and the outcome — never the
arguments. On the per-user endpoint it is attributed to the granted contact,
so you can see which person’s assistant did what.
Next
Workspace endpoint
Full request and response shapes.
Per-user grants
Issuing and revoking
pv_grant_… tokens.Connect a client
Claude, Cursor and generic MCP client configuration.
Custom MCP connector
The other direction — Peeve calling your MCP server, where writes do happen.