The MCP server
Unitley's MCP server: its URL, transport and protocol versions, how an access token signs you in, and the rules it sends every agent.
Unitley runs one remote MCP server. Any MCP client that can send an Authorization header can connect to it, including Claude Code, Claude Desktop, Cursor and Hermes Agent. It offers 20 tools, Unitley's knowledge notes as resources, and 3 prompts.
Server URL
https://console.unitley.com/api/mcp
The URL is the same for everyone. Your access token decides whose account the tools act on.
- Server name:
unitley - Server version: 0.1.0
To set up a specific client, see Connect to Claude or Any MCP client.
Authentication
Send an access token from the Connect page with every request:
Authorization: Bearer YOUR_UNITLEY_TOKENA missing token, or one not shaped like a Unitley token, gets HTTP 401 with a Bearer challenge:
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer error="invalid_token", error_description="Send a Unitley access token as Authorization: Bearer unt_... (create one on the Connect page)."
Content-Type: application/json
{"error":"invalid_token","error_description":"Send a Unitley access token as Authorization: Bearer unt_... (create one on the Connect page)."}A token that is unknown, revoked or expired gets the same 401, with the description "This access token is unknown, revoked or expired. Create a new one on the Connect page."
The token sets what the tools can do. A read-only token can read your data and run the calculators. A token with write access can also use log_bet, settle_bet and save_recommendation. See Tokens and security.
Transport
The server speaks Streamable HTTP and is stateless. It keeps no sessions and issues no Mcp-Session-Id, and every request is served on its own.
- POST carries every JSON-RPC message. Send
Content-Type: application/json, or the server answers 415. - GET and DELETE get 405
Method not allowed.With no sessions, there is no stream to open and nothing to end. - A POST that holds only notifications gets 202 with no body.
Protocol versions
Your client picks the protocol version. You do not need to set it.
| Version | How requests work |
|---|---|
| 2026-07-28 | Each request is self-contained and carries its own protocol version. The answer is one JSON response. One message per request. |
| 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07 | The client starts with initialize. Each POST must accept both application/json and text/event-stream (406 otherwise), and the answer comes back as a short event stream that closes after the response. A POST may hold a JSON-RPC batch of up to 100 messages. |
Capabilities
The server declares three capabilities:
- tools, with
listChanged: false. The tool list does not change while you are connected. See Every tool. - resources: the knowledge notes. There are no resource templates. See Resources.
- prompts. See Prompts.
Unitley publishes no change events. A subscriptions/listen request gets the JSON-RPC error -32601 Method not found: subscriptions/listen., and resource subscriptions are not offered.
Tools over MCP
tools/list returns every tool, including the write tools, whatever your token's scope. Each entry has a title, a description, a JSON Schema for its input, and annotations: readOnlyHint, destructiveHint, idempotentHint and openWorldHint. The hints describe the tool. The scope check is what enforces it.
A successful tools/call returns:
- one text item that holds the result as JSON, and
structuredContentwith the same object, when the result is a JSON object.
A tool that fails returns a result with isError: true, not a protocol error. The text item holds the message, and structuredContent.error holds the same code, message and issues the REST API sends, plus retryAfterSeconds when you should wait. Errors lists every code.
A read-only token that calls a write tool gets an isError result with the code insufficient_scope.
Checks on every request
Each request meets these checks in this order:
- Host. The request must reach the console's own hostname. Any other host gets 403.
- Origin. A browser may call only from the console itself. A request from another site gets 403. Desktop apps, command-line tools and servers send no
Originheader and pass. - Per-address budget. 300 a minute from one IP address, counted before the token is checked. A refusal is 429 with
Retry-After. See Rate limits. - Token shape. A missing or malformed token gets 401.
- Body. A JSON body over 256 KB gets 413, and one that is not valid JSON gets 400.
- Token owner. An unknown, revoked or expired token gets 401.
- The call. Tools run as you, so they can only see and change your own data. Each tool call counts against your per-token and per-user budgets.
The server does not send CORS headers. Every response carries Cache-Control: no-store.
Errors before the tools run
These come back as JSON-RPC error objects with id: null, except the 401s, which use the Bearer challenge above.
| Status | JSON-RPC code | When |
|---|---|---|
| 400 | -32700 | The body is not valid JSON. |
| 400 | -32600 | A 2025-era batch of more than 100 messages. |
| 401 | none | No token, or one that is unknown, revoked or expired. |
| 403 | -32000 | The wrong host, or a browser on another site. |
| 405 | -32000 | GET or DELETE. |
| 406 | -32000 | A 2025-era POST that does not accept both application/json and text/event-stream. |
| 413 | -32000 | The body is over 256 KB. |
| 415 | -32000 | A POST without Content-Type: application/json. |
| 429 | -32000 | Too many requests from your address. Retry-After says when to try again. |
| 500 | -32603 | Something failed on Unitley's side. |
| 503 | -32000 | Unitley could not serve the request just then. |
Your client's name
Your client names itself in clientInfo: in initialize under the 2025-era versions, or with each request under 2026-07-28. Unitley keeps that name with the token and shows it on the Connect page.
Bets and picks saved over MCP carry a client label: the clientInfo name when the request includes it, otherwise the client's User-Agent. The label is for your records only. It never changes what a request may do.
Server instructions
The server sends these rules to every client as its MCP instructions. The REST API returns the same text from GET /api/v1/tools.
Unitley is analysis, not a guarantee; use only Unitley tools and allowlisted sources for facts; never use social media as a source; always show reasoning, risks, and suggested stake in units; respect the user's loss limits and stake caps from get_bankroll.
Facts: odds, lines, player props, schedules, results, stats, injuries, weather and every piece of betting math (implied probability, no-vig odds, EV, Kelly stakes, parlays) come only from Unitley's tools. Never take a price, line or stat from anywhere else, never read odds off a sportsbook's website, and never size a stake by hand: use calc_kelly_stake.
Research: you may do your own web research for news and context (team news, coaching, travel, motivation), browsing as the user. Prefer reputable sports news outlets. Never use social media: no X (Twitter), Instagram, TikTok, Facebook or Reddit. Label anything from your own research as unverified context in your reasoning, keep it apart from Unitley's data, and never let it override Unitley's odds, stats, injuries or weather. jev_classify answers set questions about text you have already read: pass that text and the URL it came from, treat its answers as unverified context too, and never ask it about odds.
Injuries: get_injury_report is updated about twice a day and does not cover game-day inactives. Say so whenever an injury matters to a pick.
Prices: say how old each price is (updatedAgo), and pass on any priceNote or note a tool returns.
Bankroll: call get_bankroll before suggesting any stake. Never suggest more than calc_kelly_stake returns, the user's max stake, or the room left under their daily and weekly loss limits. Suggest no stake for a parlay with two legs from one game: the legs are correlated, so its combined probability is unreliable; say so and leave the stake to the user. If the user asks to bet past their limits, decline, and mention that help is available at 1-800-GAMBLER and ncpgambling.org. Betting is for adults of legal age, where it is legal.
Saving: call log_bet, settle_bet or save_recommendation only when the user asks. They need an access token with write access.
Next
- Every tool, with each tool's inputs and outputs
- Resources and Prompts
- Rate limits
- The REST API, for the same tools without MCP