Skip to main content

diagrid mcpserver access test

Test whether a caller is allowed to call a tool on an MCP server

Description​

Test whether a caller is allowed to call a tool on an MCP server.

The server's access policy is checked locally, against the same rules that are applied when a call really runs. Nothing is sent to the MCP server itself, so this is safe to run against a live server at any time.

It answers the tool-grant question only: may this caller call this tool? If the server also requires an end user's identity, a call carrying none is refused before that question is reached — so an ALLOWED verdict here can still be refused in practice. Check that half with:

diagrid mcpserver access user-identity get <mcpserver>

diagrid mcpserver access test <mcpserver> [flags]

Examples​


# Check whether agent-a is allowed to call the "query" tool on my-mcp.
diagrid mcpserver access test my-mcp --project my-project --caller agent-a --tool query

# Check the any-caller grant.
diagrid mcpserver access test my-mcp --project my-project --caller '*' --tool query

Options​

-p, --project string Name of existing project
--caller string id of the caller to simulate (use '*' to test the any-caller grant)
--tool string Name of the tool the caller attempts to call
-o, --output string Output format, supported [table, yaml, json] (default "table")
-h, --help help for test

Options inherited from parent commands​

--api-key string Diagrid Cloud API key

SEE ALSO​