Scout Trails Docs

MCP server

The Scout Trails MCP server lets an AI assistant such as Claude Code, Codex CLI or Cursor query your organization’s agent telemetry directly. Once it is connected, you can ask questions in plain language, such as “which sessions yesterday hit errors?” or “what did my agents spend on models this week?”, and the assistant calls Scout Trails tools to answer them. The server is read-only and exposes the same data as the query API: sessions, tool calls, model cost, risk flags and external domains.

Endpoint

https://mcp.scoutmonitoring.io/mcp
PropertyValue
TransportStreamable HTTP (MCP’s remote transport). Requests are JSON-RPC POSTs to /mcp.
SessionsStateless. The server issues no session id, and each request stands alone.
AuthenticationAuthorization: Bearer <api-key> on every request. OAuth is not used.
CapabilitiesTools only. The server offers no resources or prompts.
Request sizeAt most 1 MiB per request.

Authentication

The MCP server accepts the same organization API keys as the query API. Create one under Manage > API keys in the dashboard; see API keys. An actor’s ingest key does not work here.

The key gives the assistant read access to all of your organization’s telemetry, the same as an API key used with the API. Anyone who can use the assistant’s configuration can read that data, so keep the key in an environment variable rather than in a file you commit.

A request without a usable key is rejected with HTTP 401 and a JSON-RPC error body:

{"jsonrpc":"2.0","id":null,"error":{"code":-32600,"message":"unknown bearer key"}}
messageCause
missing authorization headerNo Authorization header was sent.
authorization header must use Bearer schemeThe header does not start with Bearer (case-sensitive, one space).
authorization Bearer value is emptyNothing follows Bearer .
unknown bearer keyThe key does not exist or has been revoked. Ingest keys also get this message.
keystore unavailableReturned with HTTP 503: the key could not be checked at that moment. Retry.

Most clients show these as a failed connection or an authentication error for the server.

What the assistant can do

The server offers twelve tools. Every tool reads only your organization’s data.

ToolAnswers
list_sessions, get_sessionWhich sessions ran, and everything that happened in one
list_tool_calls, get_tool_callIndividual tool calls, filtered by session, actor, tool, category or outcome, with full arguments
activityTool calls, model calls and cost over time
top_toolsThe most-used tools, how often they ran and succeeded
outlier_sessionsSessions with unusually many tool calls or unusually high cost
cost_summaryModel cost and tokens by model, agent or session
risk_feedRisk flags such as detected credentials or destructive commands
external_domainsExternal hosts referenced in your agents’ tool calls
ping, whoamiConnection checks

See Tools for every tool’s inputs and output.

MCP server or API

Both read the same data with the same key. The MCP server suits questions asked through an assistant; the API suits scripts and dashboards. They differ in a few places:

  • MCP tools take free-form time windows such as 6h or 14d, up to 90 days, and finer buckets down to one minute. The API’s insight endpoints take 7d, 30d or 90d.
  • MCP results include model calls inside get_session and per-severity risk counts, which the API does not.
  • The API offers filter values (facets), the per-session domain filter and page sizes up to 500. MCP list tools return up to 200 rows per call.

In this section

  • Setup: connect Claude Code, Codex CLI, Cursor or another MCP client.
  • Tools: every tool’s inputs, output and example prompts.
  • API keys: create and revoke the key the server accepts.