The Stats Desk agent and MCP beta

The remote MCP endpoint is /mcp using Streamable HTTP. It is an invite beta and requires either an OAuth bearer grant or a new csd_sk_ service secret. Browser csd_pub_, legacy csd_, and widget credentials are never accepted.

Tool tiers

Raw SQL is limited to explicit columns in standard tables. Advanced tables, filesystem/network functions, catalogs, multiple statements, cross joins, and raw advanced SQL are unavailable.

Limits and errors

Every call shares platform admission and durable minute/daily quotas. Results have row, byte, timeout, and concurrency bounds. Errors have stable codes and a request ID; they never include SQL, prompts, secrets, or internal exception text. Owners can inspect /api/mcp/usage, /api/mcp/quotas, and /api/mcp/errors, and revoke secrets through DELETE /api/mcp/credentials/{id}.

Data and attribution

Standard descriptive data is derived from Cricsheet and returned with ODbL attribution. Use discover_cricket_data for the exact deployed coverage watermark and metric definitions. CricBit-derived answers retain CricBit attribution; restricted advanced data is not exposed through MCP.

OAuth discovery

Protected-resource metadata is available at /.well-known/oauth-protected-resource/mcp. OAuth scopes are necessary but do not replace local invitation entitlements or source policy.