Skip to content

Expose Drupal to external AI (MCP)

Briefing, not authority. (R) rule at linked source · (O) dated upstream fact · (P) procedure · (C) open work · (G) not established.

WHAT THIS MEANS IN DRUPAL

External agents (Claude, Cursor, other MCP clients) call Drupal capabilities through MCP. The capability is a Tool API plugin; MCP is only the adapter (R) standard §7.3.

OWNER

  • Capability contract: Tool API #[Tool] (R) standard §7.1-7.2.
  • Common operations: Tool Belt (R) how-we-build §9.
  • Protocol: mcp_server + mcp_server_tool_bridge (R) standard §9.
  • Drupal calling external MCP tools: mcp_client (R) standard §9.

PREREQUISITES

  1. (P) The capability exists as a Tool, or Tool Belt already covers it. If not, write the #[Tool] first.

DO THIS

  1. (P) Enable only the tools the client needs; read before write.
  2. (P) Each tool declares operation (read/write), destructive, typed input/output (R) standard §7.2.
  3. (P) checkAccess() delegates to entity access, permissions and moderation (R) standard §7.2.
  4. (P) Agent entity/layout writes land in draft; publish is explicit unless required and governed (R) standard §7.5.

WATCH FOR

  • Tool API is beta, not security-covered, accepted as foundational (O 2026-09-20) matrix.
  • Keep MCP permission-constrained and staging-gated (R, reference) architecture ref.
  • Prompt injection must not bypass Drupal access (R) architecture ref.

DO NOT

  • Custom REST endpoint for tool access (R) Rule D; MCP capability outside Tool API (R) standard §7.1.
  • Business logic in the MCP layer (R) Rule G, standard §7.3.
  • Bypass Drupal access inside a tool (R) standard §7.2.

OWNERSHIP / CAN-SHOULD-MAY

  • CAN: per-tool enable/disable in MCP server config.
  • SHOULD: the module owning the domain owns its Tool plugins; protocol modules own nothing domain-specific.
  • MUST: machine principals use their own identity (R) STD-SEC-001 §5.
  • MAY: mutate only through the Cedar gate (R) AGENTS.

DO NOT REDISCOVER

  • Define the capability once; call it from MCP, ECA, agents, Drush (R) standard §7.3.

CONFLICTS

ID A B Resolution
C-TOOL-MATURITY architecture ref: Tool API, MCP Client, MCP Tools, MCPIO are controlled pilots standard §7: Tool API is the default contract; matrix: tool KEEP Undecided. Proposed: matrix KEEP for Tool API; pilot caution for MCP modules.

GO DEEPER

Anchored sources: frontmatter authority_sources. Expires last_verified + 30d.