# Neotask remote MCP Launch state: **Live**. Agents can register at /auth.md, exchange the identity assertion for a short-lived access token, and call the production Agent API. Endpoint: `POST https://neotask.ai/mcp` OAuth resource: `https://neotask.ai/mcp` Neotask uses Streamable HTTP MCP with protocol version `2026-07-28`. The server adapter is stateless across the fleet, so every request carries and revalidates the MCP-audience bearer token. No local install, desktop process, internal HMAC key, or sticky server session is required. Use `server/discover` when capability discovery is useful, then call `tools/list` or a known tool directly. Protocol `2026-07-28` has no `initialize` handshake or `Mcp-Session-Id`. Every request sends `MCP-Protocol-Version: 2026-07-28` and an exact `Mcp-Method` header; `tools/call` also sends an exact `Mcp-Name` header. List responses include private cache hints. Available tools cover capabilities, agents, tasks, runs, usage, effective skills, effective models, paid-plan handoff, approval handoff, and registration revocation. Approval tools can create, inspect, and cancel human approval handoffs without granting authority; approval events are available through the same opaque-cursor JSON resource and SSE stream. `neotask_skills_list` and `neotask_models_list` return the same server-derived catalogs as REST; `neotask_agent_model_set` changes only a claimed agent owned by the authenticated tenant. MCP calls invoke the same Site domain owners and MongoDB idempotency records as REST. Mutation tools require an `idempotencyKey` argument. For 24 hours a call repeating a key and its arguments returns the recorded result, a failure as the same tool error (`isError: true`). As over REST, a readiness refusal returned before the operation started is not recorded. Run tools use the same principal-scoped runner state as REST. With no enrolled runner they return `setup_required` and `runner_not_enrolled`; an enrolled but unreachable runner returns `temporarily_disabled` and `runner_offline`. REST tokens are rejected at MCP because their audience differs.