MCP server
Let your agents and IDEs ask about your own system, read-only, through the Waltz MCP server.
Last updated
The Waltz MCP server lets your agents and IDEs ask about your own system: what evolved in checkout this week, which decisions are on record, what a term means. It reads; it never writes and never calls a model. Your agent does the reasoning, on your account.
Connect
| URL | https://api.waltz.run/v1/mcp |
| Transport | Streamable HTTP, stateless: one JSON-RPC message per request, no session |
| Auth | Authorization: Bearer wltz_mcp_… |
Any client that speaks Streamable HTTP and sends a bearer header can connect. Current and earlier protocol versions are both answered.
Make a token
- In the console, open Settings → MCP.
- Choose New MCP token and name what it's for, such as Claude Code on your laptop.
- Copy it with the server URL and header shown. It is shown once; Waltz keeps only a fingerprint.
A token reads one org, as the member who made it, and nothing else. It stops working at once when it is revoked, or when its maker leaves the org, is made a viewer or is suspended. Members list and revoke their own tokens; admins any of the org's. Viewers can't make one.
An MCP token can't upload, and a CLI token can't read: each does one job.
Tools
All read-only, listed in this order, each with an input and an output schema.
| Tool | Returns |
|---|---|
briefs.list |
The org's Briefs, newest week first, with their editions and headlines |
briefs.get |
One Brief edition, the latest or the one named, as plain text and as structured JSON |
facts.query |
Facts by kind, week, subject or hashed identity, in a stable order, paged |
decisions.list |
Decisions recorded in your repositories (architecture decision records and decision logs), by week |
glossary.lookup |
Key terms from the latest analysis of each included repo, by name |
capabilities.list |
What your software can do, with confidence and where each capability lives |
briefs.get returns exactly what the Brief shows. Facts carry hashed identities, never names or addresses.
Limits and logging
- 120 requests a minute per token. Past it, the server answers 429 with
Retry-After. - Every call is logged as org, token, method, tool and whether it failed; never its arguments or results.
- Requests from a browser origin other than Waltz's own are refused.
Next
OAuth sign-in in place of tokens, listings in MCP directories, and tools for snapshots, entity timelines and evidence.