MCP server integration2026Lead engineer2 months

Agent Tooling

A Model Context Protocol server exposing internal order and catalogue APIs to AI agents with typed tools, scoped permissions and audit logging.

  • TypeScript
  • MCP
  • Node.js
  • Zod
-70%
time to answer an order question
100%
tool calls audited

The problem

Support agents copied data between five dashboards to answer one customer question. Early AI experiments called internal APIs with full admin keys.

Constraints

Architecture

Key decisions

Decision 01
Schemas as the tool contract

Each tool declares its input with Zod; the same schema validates calls and generates the description the model sees.

Trade-off: Tool descriptions need real copywriting to be used well.

In the code

mcp/src/tools/orders.ts
1server.tool(2  "get_order",3  "Look up an order by id. Returns status, items and shipping, never payment data.",4  { orderId: z.string().regex(/^ORD-\d{8}$/) },5  async ({ orderId }, ctx) => {6    await audit.record(ctx.user, "get_order", { orderId });7    const order = await orders.get(orderId);8    return { content: [{ type: "text", text: JSON.stringify(redact(order)) }] };9  },10);

What I learned