garden in your coding agent: the MCP server

garden mcp runs a local MCP server over standard input and output. A coding agent that speaks MCP starts it as a subprocess and calls six tools, one for each of garden's reads. It comes with the garden command (the command's guide); nothing else needs installing.

Availability today. The garden command is built locally and is not published to any registry, and there is no public download. Its hosted endpoint is https://garden-api.fernworks.dev/ and requires a valid access key. The server itself starts and lists its tools without a key and without contacting the service.

Harnesses#

The MCP objective passed in Codex against the saved package and a fixture service; hosted current and historical reads were verified separately. Claude Code has no fresh proof against the current package and service. Every other MCP client stays unverified until it is proven: it may work, and garden makes no claim that it does.

Codex#

codex mcp add garden --env GARDEN_API_KEY=<your key> -- garden mcp

This follows the form codex mcp add --help documents: it adds garden to the MCP servers in ~/.codex/config.toml, started as garden mcp with the key in its environment. Add --url <endpoint> after garden mcp to use another endpoint than the hosted default. The accepted Codex objective used the saved package command and a fixture endpoint, so it does not separately certify this global-command form against the hosted default.

Claude Code#

claude mcp add garden -e GARDEN_API_KEY=<your key> -- garden mcp

This follows the form claude mcp add --help documents. Use --scope user to make garden available in every project, or --scope project to share the entry through the project's .mcp.json. Do not commit a file that holds your key. Add --url <endpoint> after garden mcp to use another endpoint than the hosted default. This configuration has not been freshly proven with Claude Code against the current package and service.

What the server fixes at start#

The server reads the key from GARDEN_API_KEY and the endpoint from its own --url flag, then GARDEN_URL, then the hosted default, once, when it starts. No tool argument can name another endpoint or key, and no tool asks the model for a secret, runs a command or reads a file of your project. Standard output carries the MCP protocol only; the server's own diagnostics go to standard error. The server stops when its input ends.

When garden mcp's own command line is refused (an unknown flag, or --help or --version after mcp), no server starts: standard output stays empty, standard error has one line, garden mcp: invalid-request: SUBJECT, and the exit status is 2. Its help is garden help mcp.

The tools#

Every tool takes the optional arguments callId (your identity for the call, echoed in the reply) and timeoutMs (the call's one deadline in milliseconds, at most 30000). A call with any argument a tool does not list is refused whole.

ToolArgumentsWhat it reads
garden_snapshotsnapshot: current or an exact idthe publication, current resolved once
garden_vocabularysnapshotevery value a facet, kind or responsibility may carry
garden_listsnapshot; at least one value among language, purpose, technology, task, concern, kind, responsibility, each a listthe matching units' listing metadata, in id order; nothing is ranked
garden_readsnapshot, ids; optional requires, exclude, maxUnits (at most 16), maxBytes (at most 262144)full units, their exact text with revision and content hash
garden_resolvesnapshot, anchorthe unit that carries the anchor
garden_changesfrom, to: two exact idsa comparison by revision and content hash; no unit text

Resolve current once with garden_snapshot, then pass the exact id it answered to every later tool, so the whole task reads one publication.

What a tool answers#

Each tool answers with garden's reply document, garden.result/v1, as the tool result's structured content and as its text: the same document the garden command prints, described in the command's guide. A refusal is marked as an error result, with its typed error.kind, so an agent never reads a refused call as guidance. A tool call the client cancels stops its read.

Without a key#

Without a key the server still starts, and your agent can list the six tools. Every tool call then answers unauthorized, marked as an error, and sends nothing.