Skip to content

Reference

MCP server

Let your agents and IDEs ask about your own system, read-only, through the Waltz MCP server.

Last updated

The Waltz MCP server lets your agents and IDEs ask about your own system: what evolved in checkout this week, which decisions are on record, what a term means. It reads; it never writes and never calls a model. Your agent does the reasoning, on your account.

Connect

URL https://api.waltz.run/v1/mcp
Transport Streamable HTTP, stateless: one JSON-RPC message per request, no session
Auth Authorization: Bearer wltz_mcp_…

Any client that speaks Streamable HTTP and sends a bearer header can connect. Current and earlier protocol versions are both answered.

Make a token

  1. In the console, open Settings → MCP.
  2. Choose New MCP token and name what it's for, such as Claude Code on your laptop.
  3. Copy it with the server URL and header shown. It is shown once; Waltz keeps only a fingerprint.

A token reads one org, as the member who made it, and nothing else. It stops working at once when it is revoked, or when its maker leaves the org, is made a viewer or is suspended. Members list and revoke their own tokens; admins any of the org's. Viewers can't make one.

An MCP token can't upload, and a CLI token can't read: each does one job.

Tools

All read-only, listed in this order, each with an input and an output schema.

Tool Returns
briefs.list The org's Briefs, newest week first, with their editions and headlines
briefs.get One Brief edition, the latest or the one named, as plain text and as structured JSON
facts.query Facts by kind, week, subject or hashed identity, in a stable order, paged
decisions.list Decisions recorded in your repositories (architecture decision records and decision logs), by week
glossary.lookup Key terms from the latest analysis of each included repo, by name
capabilities.list What your software can do, with confidence and where each capability lives

briefs.get returns exactly what the Brief shows. Facts carry hashed identities, never names or addresses.

Limits and logging

  • 120 requests a minute per token. Past it, the server answers 429 with Retry-After.
  • Every call is logged as org, token, method, tool and whether it failed; never its arguments or results.
  • Requests from a browser origin other than Waltz's own are refused.

Next

OAuth sign-in in place of tokens, listings in MCP directories, and tools for snapshots, entity timelines and evidence.