An MCP server is an item in the project.
Connect a Model Context Protocol server the way you connect a broker: over stdio with a command, or over HTTP. Its tools become forms, its resources and prompts are a click away, the whole JSON-RPC conversation is in the log, and Themis can use the server as its own hands.
At a glance
Call it, read it, sign in to it.
The same JSON-RPC frames the model would see, every one of them in the log, both ways.
Tools
Arguments as a form from the schema, with completions where the server offers them. The result as text or structured content, with the isError flag and the duration. A call waits up to ten minutes. The server's stderr is in the log for stdio servers.
Resources and prompts
Read a resource, including templated URIs. Get a prompt with its arguments. Set the server's log level. Ping it. Refresh the lists.
OAuth, the MCP way
The 401's WWW-Authenticate points at the resource metadata; the authorization server's metadata is discovered; a client is registered dynamically or a typed client id is used; the browser does authorization code with PKCE with the server URL as the resource. The token is kept as the item's OAuth 2 auth, so it refreshes like any other.