MCP server
After Action runs a Model Context Protocol server so an AI agent — Claude Code, Claude Desktop, or one you built — can answer questions about exercises, gaps, readiness scores and action items without anyone opening the portal.
Endpoint
POST https://afteraction.dev/api/mcpWhat it exposes
Read-only tools. These are the same tools the in-portal assistant uses, so an MCP client and the portal never answer the same question differently. Tools that would change data are deliberately not exposed: in the portal they require a person to confirm, and an MCP client has no confirmation step.
| Tool | Returns |
|---|---|
list_exercises | List tabletop exercises for the organization, most recent first. |
list_gaps | List gap findings identified across the organization's exercises. |
get_readiness_scores | Get the organization's readiness score history, most recent first. |
list_action_items | List After-Action Report action items for the organization. |
get_compliance_mappings | Look up which compliance framework controls (NIST CSF, SOC 2, ISO 27001, HIPAA, PCI-DSS, CIS) map to a gap category. |
search_knowledge | Semantic search across the organization's own exercise history — AAR narratives, findings, gap descriptions, action-item remediation notes, generated deliverables, and prior exercise memory. |
get_industry_benchmark | Get per-dimension industry benchmark readiness scores for comparison. |
Authentication
- An API key with the
mcpscope, sent asX-API-KeyorAuthorization: Bearer. There is no cookie path. - Missing or invalid key: HTTP 401. A valid key without the
mcpscope: HTTP 403. - Keys are created and revoked on the API keys page of the carrier portal (Exports). Revocation takes effect on the next request. Client portal accounts cannot create keys today — contact us if you need one.
- Results are scoped to the organization the key belongs to. Each request that calls a tool is written to that organization's audit log with the names of the tools called.
Connect
Claude Code
claude mcp add --transport http after-action \
https://afteraction.dev/api/mcp \
--header "X-API-Key: $AFTER_ACTION_API_KEY"Any client that takes a URL and a header works the same way. To check the connection by hand:
List tools with curl
curl -s -X POST https://afteraction.dev/api/mcp \
-H "Content-Type: application/json" \
-H "X-API-Key: $AFTER_ACTION_API_KEY" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Calling a tool:
tools/call request
{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/call",
"params": {
"name": "list_gaps",
"arguments": { "severity": "critical", "status": "open" }
}
}Protocol
- Streamable HTTP transport, JSON-RPC 2.0 over POST. Protocol revision
2025-06-18;2025-03-26and2024-11-05are accepted atinitialize. - Methods:
initialize,notifications/initialized,ping,tools/list,tools/call. Anything else returnsMETHOD_NOT_FOUND. - Batch requests are supported. A batch made only of notifications returns HTTP 202 with no body.
- A tool that cannot answer returns a normal result with
isError: true, not a protocol error. GET /api/mcpreturns HTTP 405 with a JSON description of the server: this server never opens a server-initiated stream.
Rate limit
120 requests per minute per key. Beyond that the server answers HTTP 429 with a Retry-After header in seconds.