0.1.5 supports SDK v1 and SDK v2 clients, including legacy 2025-11-25 and modern 2026-07-28 protocol revisions. Workspace OAuth tokens retain the read-only communicate_list_agents tool. Explicitly MCP-bound account credentials expose the registered management tools allowed by their live scopes.
Create an MCP management credential
Use the CLI bootstrap workflow with a private input file containing verified email/password proof, a credential name, the scopes your workflow needs, and this explicit audience:COMMUNICATE_MCP_TOKEN. Account credentials expire within 24 hours and cannot outlive their issuer session.
Each tool declares its input/output schema. Missing scopes remove tools from discovery; native membership, role, agent access and entitlement checks still apply. Writes are never automatically retried. Source file uploads take
{ "file": { "name": "guide.txt", "base64": "..." } } plus workspace/agent IDs, with a 10 MB decoded limit. The server does not read filesystem paths.
REST-bound ca_ credentials and REST OAuth tokens cannot call MCP. Existing ck_ workspace secrets never gain account management permissions automatically. Coverage remains partial; billing, inbox/prospect reply and other unfinished workflows are not established by this increment.
Legacy read-only workspace OAuth
Create an API key withagents:read, then exchange its client ID and one-time ck_ secret for a token bound to the MCP resource.
Configure your client
Use Streamable HTTP and send the token as a bearer credential:OAuth discovery
MCP clients can discover the authentication contract from:agents:read; this restriction does not apply to explicitly scoped MCP account credentials. Use a separate REST token with chat:write for agent conversations.