Skip to content
DocsUnitley Docs home
MCP reference

The MCP server

Unitley's MCP server: its URL, transport and protocol versions, how an access token signs you in, and the rules it sends every agent.

Unitley runs one remote MCP server. Any MCP client that can send an Authorization header can connect to it, including Claude Code, Claude Desktop, Cursor and Hermes Agent. It offers 20 tools, Unitley's knowledge notes as resources, and 3 prompts.

Server URL

https://console.unitley.com/api/mcp

The URL is the same for everyone. Your access token decides whose account the tools act on.

  • Server name: unitley
  • Server version: 0.1.0

To set up a specific client, see Connect to Claude or Any MCP client.

Authentication

Send an access token from the Connect page with every request:

Every request
Authorization: Bearer YOUR_UNITLEY_TOKEN

A missing token, or one not shaped like a Unitley token, gets HTTP 401 with a Bearer challenge:

401 · no token
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer error="invalid_token", error_description="Send a Unitley access token as Authorization: Bearer unt_... (create one on the Connect page)."
Content-Type: application/json

{"error":"invalid_token","error_description":"Send a Unitley access token as Authorization: Bearer unt_... (create one on the Connect page)."}

A token that is unknown, revoked or expired gets the same 401, with the description "This access token is unknown, revoked or expired. Create a new one on the Connect page."

The token sets what the tools can do. A read-only token can read your data and run the calculators. A token with write access can also use log_bet, settle_bet and save_recommendation. See Tokens and security.

Transport

The server speaks Streamable HTTP and is stateless. It keeps no sessions and issues no Mcp-Session-Id, and every request is served on its own.

  • POST carries every JSON-RPC message. Send Content-Type: application/json, or the server answers 415.
  • GET and DELETE get 405 Method not allowed. With no sessions, there is no stream to open and nothing to end.
  • A POST that holds only notifications gets 202 with no body.

Protocol versions

Your client picks the protocol version. You do not need to set it.

VersionHow requests work
2026-07-28Each request is self-contained and carries its own protocol version. The answer is one JSON response. One message per request.
2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07The client starts with initialize. Each POST must accept both application/json and text/event-stream (406 otherwise), and the answer comes back as a short event stream that closes after the response. A POST may hold a JSON-RPC batch of up to 100 messages.

Capabilities

The server declares three capabilities:

  • tools, with listChanged: false. The tool list does not change while you are connected. See Every tool.
  • resources: the knowledge notes. There are no resource templates. See Resources.
  • prompts. See Prompts.

Unitley publishes no change events. A subscriptions/listen request gets the JSON-RPC error -32601 Method not found: subscriptions/listen., and resource subscriptions are not offered.

Tools over MCP

tools/list returns every tool, including the write tools, whatever your token's scope. Each entry has a title, a description, a JSON Schema for its input, and annotations: readOnlyHint, destructiveHint, idempotentHint and openWorldHint. The hints describe the tool. The scope check is what enforces it.

A successful tools/call returns:

  • one text item that holds the result as JSON, and
  • structuredContent with the same object, when the result is a JSON object.

A tool that fails returns a result with isError: true, not a protocol error. The text item holds the message, and structuredContent.error holds the same code, message and issues the REST API sends, plus retryAfterSeconds when you should wait. Errors lists every code.

A read-only token that calls a write tool gets an isError result with the code insufficient_scope.

Checks on every request

Each request meets these checks in this order:

  1. Host. The request must reach the console's own hostname. Any other host gets 403.
  2. Origin. A browser may call only from the console itself. A request from another site gets 403. Desktop apps, command-line tools and servers send no Origin header and pass.
  3. Per-address budget. 300 a minute from one IP address, counted before the token is checked. A refusal is 429 with Retry-After. See Rate limits.
  4. Token shape. A missing or malformed token gets 401.
  5. Body. A JSON body over 256 KB gets 413, and one that is not valid JSON gets 400.
  6. Token owner. An unknown, revoked or expired token gets 401.
  7. The call. Tools run as you, so they can only see and change your own data. Each tool call counts against your per-token and per-user budgets.

The server does not send CORS headers. Every response carries Cache-Control: no-store.

Errors before the tools run

These come back as JSON-RPC error objects with id: null, except the 401s, which use the Bearer challenge above.

StatusJSON-RPC codeWhen
400-32700The body is not valid JSON.
400-32600A 2025-era batch of more than 100 messages.
401noneNo token, or one that is unknown, revoked or expired.
403-32000The wrong host, or a browser on another site.
405-32000GET or DELETE.
406-32000A 2025-era POST that does not accept both application/json and text/event-stream.
413-32000The body is over 256 KB.
415-32000A POST without Content-Type: application/json.
429-32000Too many requests from your address. Retry-After says when to try again.
500-32603Something failed on Unitley's side.
503-32000Unitley could not serve the request just then.

Your client's name

Your client names itself in clientInfo: in initialize under the 2025-era versions, or with each request under 2026-07-28. Unitley keeps that name with the token and shows it on the Connect page.

Bets and picks saved over MCP carry a client label: the clientInfo name when the request includes it, otherwise the client's User-Agent. The label is for your records only. It never changes what a request may do.

Server instructions

The server sends these rules to every client as its MCP instructions. The REST API returns the same text from GET /api/v1/tools.

Unitley is analysis, not a guarantee; use only Unitley tools and allowlisted sources for facts; never use social media as a source; always show reasoning, risks, and suggested stake in units; respect the user's loss limits and stake caps from get_bankroll.

Facts: odds, lines, player props, schedules, results, stats, injuries, weather and every piece of betting math (implied probability, no-vig odds, EV, Kelly stakes, parlays) come only from Unitley's tools. Never take a price, line or stat from anywhere else, never read odds off a sportsbook's website, and never size a stake by hand: use calc_kelly_stake.

Research: you may do your own web research for news and context (team news, coaching, travel, motivation), browsing as the user. Prefer reputable sports news outlets. Never use social media: no X (Twitter), Instagram, TikTok, Facebook or Reddit. Label anything from your own research as unverified context in your reasoning, keep it apart from Unitley's data, and never let it override Unitley's odds, stats, injuries or weather. jev_classify answers set questions about text you have already read: pass that text and the URL it came from, treat its answers as unverified context too, and never ask it about odds.

Injuries: get_injury_report is updated about twice a day and does not cover game-day inactives. Say so whenever an injury matters to a pick.

Prices: say how old each price is (updatedAgo), and pass on any priceNote or note a tool returns.

Bankroll: call get_bankroll before suggesting any stake. Never suggest more than calc_kelly_stake returns, the user's max stake, or the room left under their daily and weekly loss limits. Suggest no stake for a parlay with two legs from one game: the legs are correlated, so its combined probability is unreliable; say so and leave the stake to the user. If the user asks to bet past their limits, decline, and mention that help is available at 1-800-GAMBLER and ncpgambling.org. Betting is for adults of legal age, where it is legal.

Saving: call log_bet, settle_bet or save_recommendation only when the user asks. They need an access token with write access.

Next

21+ · Gambling problem? Call 1-800-GAMBLER or visit ncpgambling.org

Unitley is an analysis tool, not a sportsbook: it takes no bets and holds no money. Nothing in these docs is a guarantee or financial advice. Only bet where it is legal for you. Unitley is not affiliated with the NFL, its teams, or any sportsbook.

©︎ 2026 Unitley · Analysis, not a guarantee.