MCP server

After Action runs a Model Context Protocol server so an AI agent — Claude Code, Claude Desktop, or one you built — can answer questions about exercises, gaps, readiness scores and action items without anyone opening the portal.

Endpoint
POST https://afteraction.dev/api/mcp

What it exposes

Read-only tools. These are the same tools the in-portal assistant uses, so an MCP client and the portal never answer the same question differently. Tools that would change data are deliberately not exposed: in the portal they require a person to confirm, and an MCP client has no confirmation step.

ToolReturns
list_exercisesList tabletop exercises for the organization, most recent first.
list_gapsList gap findings identified across the organization's exercises.
get_readiness_scoresGet the organization's readiness score history, most recent first.
list_action_itemsList After-Action Report action items for the organization.
get_compliance_mappingsLook up which compliance framework controls (NIST CSF, SOC 2, ISO 27001, HIPAA, PCI-DSS, CIS) map to a gap category.
search_knowledgeSemantic search across the organization's own exercise history — AAR narratives, findings, gap descriptions, action-item remediation notes, generated deliverables, and prior exercise memory.
get_industry_benchmarkGet per-dimension industry benchmark readiness scores for comparison.

Authentication

  • An API key with the mcp scope, sent as X-API-Key or Authorization: Bearer. There is no cookie path.
  • Missing or invalid key: HTTP 401. A valid key without the mcp scope: HTTP 403.
  • Keys are created and revoked on the API keys page of the carrier portal (Exports). Revocation takes effect on the next request. Client portal accounts cannot create keys today — contact us if you need one.
  • Results are scoped to the organization the key belongs to. Each request that calls a tool is written to that organization's audit log with the names of the tools called.

Connect

Claude Code
claude mcp add --transport http after-action \
  https://afteraction.dev/api/mcp \
  --header "X-API-Key: $AFTER_ACTION_API_KEY"

Any client that takes a URL and a header works the same way. To check the connection by hand:

List tools with curl
curl -s -X POST https://afteraction.dev/api/mcp \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $AFTER_ACTION_API_KEY" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Calling a tool:

tools/call request
{
  "jsonrpc": "2.0",
  "id": 2,
  "method": "tools/call",
  "params": {
    "name": "list_gaps",
    "arguments": { "severity": "critical", "status": "open" }
  }
}

Protocol

  • Streamable HTTP transport, JSON-RPC 2.0 over POST. Protocol revision 2025-06-18; 2025-03-26 and 2024-11-05 are accepted at initialize.
  • Methods: initialize, notifications/initialized, ping, tools/list, tools/call. Anything else returns METHOD_NOT_FOUND.
  • Batch requests are supported. A batch made only of notifications returns HTTP 202 with no body.
  • A tool that cannot answer returns a normal result with isError: true, not a protocol error.
  • GET /api/mcp returns HTTP 405 with a JSON description of the server: this server never opens a server-initiated stream.

Rate limit

120 requests per minute per key. Beyond that the server answers HTTP 429 with a Retry-After header in seconds.

Related