Expose Drupal to external AI (MCP)¶
Briefing, not authority. (R) rule at linked source · (O) dated upstream fact · (P) procedure · (C) open work · (G) not established.
WHAT THIS MEANS IN DRUPAL¶
External agents (Claude, Cursor, other MCP clients) call Drupal capabilities through MCP. The capability is a Tool API plugin; MCP is only the adapter (R) standard §7.3.
OWNER¶
- Capability contract: Tool API
#[Tool](R) standard §7.1-7.2. - Common operations: Tool Belt (R) how-we-build §9.
- Protocol:
mcp_server+mcp_server_tool_bridge(R) standard §9. - Drupal calling external MCP tools:
mcp_client(R) standard §9.
PREREQUISITES¶
- (P) The capability exists as a Tool, or Tool Belt already covers it. If not, write the
#[Tool]first.
DO THIS¶
- (P) Enable only the tools the client needs; read before write.
- (P) Each tool declares operation (read/write),
destructive, typed input/output (R) standard §7.2. - (P)
checkAccess()delegates to entity access, permissions and moderation (R) standard §7.2. - (P) Agent entity/layout writes land in draft; publish is explicit unless required and governed (R) standard §7.5.
WATCH FOR¶
- Tool API is beta, not security-covered, accepted as foundational (O 2026-09-20) matrix.
- Keep MCP permission-constrained and staging-gated (R, reference) architecture ref.
- Prompt injection must not bypass Drupal access (R) architecture ref.
DO NOT¶
- Custom REST endpoint for tool access (R) Rule D; MCP capability outside Tool API (R) standard §7.1.
- Business logic in the MCP layer (R) Rule G, standard §7.3.
- Bypass Drupal access inside a tool (R) standard §7.2.
OWNERSHIP / CAN-SHOULD-MAY¶
- CAN: per-tool enable/disable in MCP server config.
- SHOULD: the module owning the domain owns its Tool plugins; protocol modules own nothing domain-specific.
- MUST: machine principals use their own identity (R) STD-SEC-001 §5.
- MAY: mutate only through the Cedar gate (R) AGENTS.
DO NOT REDISCOVER¶
- Define the capability once; call it from MCP, ECA, agents, Drush (R) standard §7.3.
CONFLICTS¶
| ID | A | B | Resolution |
|---|---|---|---|
| C-TOOL-MATURITY | architecture ref: Tool API, MCP Client, MCP Tools, MCPIO are controlled pilots | standard §7: Tool API is the default contract; matrix: tool KEEP |
Undecided. Proposed: matrix KEEP for Tool API; pilot caution for MCP modules. |
GO DEEPER¶
Anchored sources: frontmatter authority_sources. Expires last_verified + 30d.