WalkPic documentation
Local MCP server
Eight approved read tools, delivered through a local stdio process.
Build the packages using the installation guide and provide an approved token through your trusted launcher. MCP is a local child process, not a remote URL on this documentation host.
node packages/mcp/dist/bin.jsDetailed usage
WalkPic MCP 0.1.0
Node 24.21.0, official @modelcontextprotocol/server 2.3.0. Run walkpic-mcp as a stdio server. JSON-RPC is the only stdout output during service operation; help/version are separate CLI modes. Protocol revisions 2026-07-28 and 2025-11-25 are supported.
With no configuration, tools/list is empty. HTTPS is required outside loopback. Set WALKPIC_BASE_URL and a wp_int. WALKPIC_ACCESS_TOKEN in the launching process environment to expose eight walkpic_v2_integration... read tools. These derive from the SDK's reviewed starter policy; current server grants/resource access remain required. A local allowlist does not establish deployed authorization. Human sessions, deletion receipts, publication links, writer capabilities and MeshAgent administrator credentials are not tool inputs. Do not put secrets in command arguments or committed MCP configuration files. There is no persisted storage, login, refresh or scope escalation.
Tool request/output JSON Schemas derive from authoritative operation metadata. The SDK also enforces source annotations and checks every real HTTP success/error response. The adapter explicitly validates isError envelopes because the official SDK skips automatic output-schema checks for errors. Tool failures have safe messages; raw exception messages, tokens and contract-invalid backend bodies are withheld.
Two reads may run concurrently, with at most sixteen waiting. Each has a 30 second deadline and bounded SDK reads/output (1 MiB). Cancellation propagates into SDK transport and late responses are withheld. Shutdown, stdin EOF and process signals cancel active/queued reads and clear memory credentials. No retries, reconnects, refreshes or silent activation of more operations. Binary/audio/JPEG/streams, writes and authentication/admin/token-producing tools remain denied.
Stdio only. Remote MCP audience validation, per-request identity, OAuth/device flows and backend grants require separate reviewed implementation; transport sessions must not be treated as user identity.
Build SDK and CLI first, then npm ci && npm run build && npm test under Node 24.21.0. npm run pack:local stages a tarball with versioned SDK/CLI dependencies without publishing. Tests use the official client through actual child stdio, local HTTP/SQLite and intentional transport faults. Local integration-grant fixtures prove adapter behavior through the production-shaped SQLite port, not deployed least privilege.
Explicit credential refresh is a separate CLI operation with private descriptor output. MCP tools cannot issue/refresh credentials. Stop/restart the local MCP child with the newly delivered access token; do not place a refresh token in MCP arguments, tool input/output or model context. Automatic refresh remains disabled.
The live personal-approval page is https://app.walkpic.com/integrations; set WALKPIC_BASE_URL=https://walkpic.com in your trusted launcher. An owned production QA account verified all eight read operations, insufficient-scope denial, revocation and actor access loss across SDK/CLI/MCP. The CLI also verified explicit credential rotation through its private descriptor. Tokens remain launcher secrets; MCP receives only the approved access token. Evidence: docs/evidence/resumed-delivery-20261005/integration-acceptance/public-verification-r4.json.