diagrid mcpserver access test
Test whether a caller is allowed to call a tool on an MCP server
Description
Test whether a caller is allowed to call a tool on an MCP server.
The server's access policy is checked locally, against the same rules that are applied when a call really runs. Nothing is sent to the MCP server itself, so this is safe to run against a live server at any time.
It answers the tool-grant question only: may this caller call this tool? If the server also requires an end user's identity, a call carrying none is refused before that question is reached — so an ALLOWED verdict here can still be refused in practice. Check that half with:
diagrid mcpserver access user-identity get <mcpserver>
diagrid mcpserver access test <mcpserver> [flags]
Examples
# Check whether agent-a is allowed to call the "query" tool on my-mcp.
diagrid mcpserver access test my-mcp --project my-project --caller agent-a --tool query
# Check the any-caller grant.
diagrid mcpserver access test my-mcp --project my-project --caller '*' --tool query
Options
-p, --project string Name of existing project
--caller string id of the caller to simulate (use '*' to test the any-caller grant)
--tool string Name of the tool the caller attempts to call
-o, --output string Output format, supported [table, yaml, json] (default "table")
-h, --help help for test
Options inherited from parent commands
--api-key string Diagrid Cloud API key
SEE ALSO
- diagrid mcpserver access - Manage authorization for an MCP server