Agents

MCP server

The two endpoints, the transport, how answers and errors come back, and the rules an agent follows.

Endpoints

POSThttps://mora.market/mcp/publicNo account. Read-only tools.
POSThttps://mora.market/mcpOAuth. Every tool your profile allows.

Both speak MCP over Streamable HTTP, answer in JSON, and keep no session: each request stands alone.

A call

bash
curl https://mora.market/mcp/public \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call",
       "params":{"name":"search_listings","arguments":{"query":"speech recognition"}}}'

The result is one text block holding JSON:

json
{ "jsonrpc": "2.0", "id": 1,
  "result": { "content": [{ "type": "text", "text": "{ \"onMora\": [], \"freeAndPublic\": [ ... ] }" }] } }

Errors

A tool that cannot do what was asked answers normally, with isError: true and one sentence saying what to fix. Agents read it and correct themselves.

json
{ "result": { "isError": true,
  "content": [{ "type": "text", "text": "A software project dataset must have the \"code\" part (the repository at each commit). Without it, list it as \"other\"." }] } }

Rules for agents

The full text is in SKILL.md. The ones that matter most:

  1. Never pay, sign, send an offer or authorize a tool. Return the page; the person does it.
  2. Preview listings are not offers. A listing with "preview": true is an example. Say so.
  3. Nobody is named. A listing shows Provider 181C. Never put a company name in a title.
  4. Take people out before sending records. Replace every person with a generated id, the same id for the same person.
  5. Ask, do not guess. Volumes, rights, prices and company details come from the person.

Every tool

See the tools reference. It is generated from the running server, so it is always what the server accepts.