Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Local MCP integration

The optional palcommand-mcp bridge lets an MCP host use the PalCommand desktop that is already running. It does not start a second server manager, read a profile directly, or perform account login. The desktop must stay open and signed in.

Enable and pair

In App settings > MCP, enable the integration and choose a scope:

  • Read (default): list/status/log/metrics-style observation only.
  • Operate: routine non-destructive server operations allowed by the current entitlement.
  • Admin: the broadest local tool set; destructive tools still require explicit confirmation.

Changing scope rotates the pairing secret and disconnects existing sessions. Disabling MCP stops the local pipe and deletes the pairing credential. The bridge works only for the same signed-in Windows user; no TCP port is opened.

Configure the MCP host to launch the bundled palcommand-mcp.exe by its installed path. Stdout is reserved for MCP protocol messages. Do not add OAuth tokens, device tokens, or pairing keys to the host configuration, arguments, or environment.

What failures mean

  • Desktop unavailable: open PalCommand; the bridge never auto-starts it.
  • Authentication unavailable: enable/pair MCP again and check Windows Credential Manager.
  • Scope denied: choose a broader scope only if the host genuinely needs it.
  • Safety Mode denied: restore account access; changing MCP scope cannot bypass Safety Mode.
  • Confirmation required: inspect the exact target and retry with the tool’s explicit confirm field. Never automate blanket confirmation.

Audit entries contain only time, tool name, selected scope, and outcome. Arguments, tool output, player names, chat text, and account credentials are excluded.