The WorkerKit MCP server.

mcp.workerkit.ai turns your worker fleet into something the AI client you already use can read, run and maintain: AI worker fleet orchestration over the Model Context Protocol, with nothing to install.

Any MCP client

Two endpoints, one host.

The catalog is public, so it is never walled behind a sign-in; the fleet is yours, so it is never anonymous. A client can connect to one, the other, or both.

EndpointWhat it isAuth
https://mcp.workerkit.ai/workersYour fleet and authoring on one connection: 91 tools in the full profile (84 manager tools plus 7 public discovery reads), or 20 tools in the decision profile. Discover sources, create classifiers, run and configure workers; the full profile also includes fleet administration, publishing and connection management.Sign-in required
https://mcp.workerkit.ai/directoryThe public kits catalog: 9 read-only tools, including what WorkerKit is and when to use it, written for an agent, plus the guide, the vocabulary and the app-by-app tool explorer a kit is written from.None at all
  • Your fleet claude mcp add --transport http workerkit https://mcp.workerkit.ai/workers
  • The public catalog claude mcp add --transport http workerkit-directory https://mcp.workerkit.ai/directory

Clients with OAuth support connect with no key at all: the sign-in flow is discovered from the server and approved on a WorkerKit consent page. Clients without it send a key issued under Fleet access as a bearer header. Either way the client's reach is exactly the key's scopes, revocable at any time, and the key grants no access to any connected app: workers reach apps, the fleet endpoint does not.

One client has a walkthrough of its own: AI workers for Grok Bot makes the case, and its setup guide takes the Grok Bot agent through both mounts, the manager key and the skill file it installs. Every other MCP client needs only the two addresses above.

The full setup walkthrough and scope table live in the glossary under WorkerKit MCP server, and the pattern it unlocks has its own page: AI worker fleet orchestration.

Classification on demand

Create a decision worker from your questions.

Categorize, score or triage connected data, then reuse and adjust the worker.

Reuse an existing worker or decision kit when its questions fit. For a custom classification task, creation compiles a supported source recipe and typed questions into a private kit and an installed decision worker. Optional deploy:true adds deployment; creation never starts a run or adds a schedule. The kit can be edited and published later through the normal kit lifecycle.

  • Creation request JSON { "requestId": "customer-email-triage-001", "name": "Customer email triage", "source": { "recipe": "email-previews", "args": { "after": "-7d" } }, "questions": [ { "key": "category", "type": "choice", "instructions": "Which category best describes this message?", "options": { "followup": "A customer asks for a reply", "other": "A different topic" } } ], "confidenceFloor": 0.7, "maxItems": 20, "deploy": false }

On the workers connection, call kit_app_tools(purpose:"decision") for recipes, argument schemas, permissions and examples, then kit_authoring_guide(section:"decision"). Check account connections with apps_list; public discovery does not check them. Send the request to decision_worker_create, follow nextCall, then use worker_run and run_get. Running needs runWorkers; results need readRuns. Use instruction_get / instruction_set for saved category or level answers, or answers on one run. Structural question/source changes need a revised kit and a replacement install. Check receipt status, coverage, omissions, warnings and cost before claiming completion.

Start with email-previews, calendar-events or sheets-rows. These recipes return judgments without app writes. Email previews do not include full threads; calendar events are invitation data, not transcripts; Sheets needs a Google file ID, a finite tab-qualified range and a columns map. A connected app alone does not make every tool a supported source. Source filters select evidence, not permissions: the Sheets recipe grants spreadsheet reads across the linked Drive account.

Supply 1–8 questions: choice with named options, score with ordered levels, or noul for the probability of a statement. Choice adds unclear automatically. Set an explicit confidenceFloor between 0 and 1; it routes uncertainty and does not promise accuracy. maxItems is 1–50, default 20. Creation requires publishKits and installKits; optional deployment also needs manageDeployments.

Use a fresh requestId for each new worker. Retry with the same ID and identical body to recover the original receipt; a changed body returns 409. The response includes tokenId for MCP/CLI worker commands, stable workerId, kitSlug, readiness and nextCall. A deploymentError means the worker already exists: fix deployment on that worker. The receipt is a snapshot; check current worker readiness before running. No worker API secret is returned.

The workers connection includes discovery and authoring, so classification needs one MCP connection. Its full profile has 91 tools (84 manager tools and 7 public discovery reads); only decision_worker_create is new. For a smaller list, a client that supports custom headers can send X-WorkerKit-Profile: decision on every request, including initialization, listing and calls, to select 20 workflow tools. A server operator can instead set MCP_WORKERS_PROFILE=decision. The endpoint and existing sign-in stay the same; a profile grants no additional permissions. Reconnect and relist after changing profiles. Use the advertised tool list: fleet administration, publishing and event-stream tools require the full profile. Successful responses include structured content and a text fallback; creation declares an output schema.

The tools

What the fleet endpoint can do.

The full workers profile, by group. A key's scopes decide which of them answer, and a refusal names the scope it wanted.

GroupToolsWhat it covers
Keykey_infoWhat your key is and exactly which scopes the other tools will honour. Call it first.
Fleetworkers_list, worker_get, worker_set_enabled, worker_permissions_getEvery worker with live run state, one worker in full, start or stop, and what a worker may touch, read-only, in the same vocabulary a kit is written in.
Runsworker_run, run_bulk, worker_runs, run_get, run_events, run_transcript, run_cancel, run_score, run_clear_digestTrigger a run with a prompt for that run, or one prompt across up to 20 workers; watch it step by step, read the receipt and the stored process log, cancel or grade it. On a decision worker it decides instead and acts on what it routes: sourceArgs and maxItems narrow and cap what is judged, and waitSeconds waits for the settled receipt, which carries the per-item decisions.
Fleet activityruns_feed, fleet_pulse, fleet_health, account_usageEvery worker’s runs in one feed, everything running right now, what is quietly wrong across the fleet, and the account’s headroom before you spend a slot or a run. One call each, instead of asking each worker in turn.
Two-way runsrun_question, run_answerA run that needs an answer ends by asking; the answer starts a linked follow-on run.
Memorymemory_get, memory_add, memory_update, memory_deleteThe rules and facts a worker carries into every run.
Schedulesschedules_list, schedule_create, schedule_update, schedule_deleteWhen a worker starts on its own, in its own time zone.
Instructioninstruction_get, instruction_set, instruction_versions, instruction_version_get, instruction_restoreThe standing instruction, versioned on every change, with the history to compare against and roll back to. On a decision worker it reads the routing table and the install questions instead, and writes their answers.
Deliveriesdelivery_list, delivery_channels, delivery_create, delivery_update, delivery_secret_rotate, delivery_deleteWhere a run report goes when the worker finishes: email, Slack, Teams, Telegram, Notion, Discord, SMS or a signed webhook.
Deploymentmodels_list, deployments_list, deployment_get, worker_deploy, deployment_update, worker_undeployWhat makes an installed worker actually run: pick its model from the priced catalog, cap its spend, pause or resume it, take it off again. A worker with no deployment fires no schedule and refuses a run with not_deployed.
Budgetsbudget_get, budget_set, fleet_budget_get, fleet_budget_setA worker’s spend and run ceilings, and the account-wide fleet ceiling. Their own scope, because raising a dollar cap is the one management action that can cost money.
Creationworker_clone_preview, worker_clone, worker_clone_bulkClone a worker into new ones, singly or in bulk, with a dry run first. A clone carries only permissions a person already approved on the source.
Deletionworker_deleteRemove a worker for good, with its sub-workers. Permanent, where stopping one is not — which is why it is a scope of its own.
Kitskit_install_preview, kit_installPreview a directory kit against your account, then install it as a new worker — with deploy set, in the same call, which is what makes it run.
Kit authoringkit_validate, kit_publish, kit_update, kit_replace, kit_unpublish, kit_relist, kit_make_private, kit_delete, kit_scan_get, my_kits_list, publisher_get_mine, publisher_setValidate a kit in one dry run that reports every gate at once, publish it from content or from a worker you own, keep it private or list it, and keep your publisher profile. A private kit installed with kit_install is how an agent builds a worker from scratch.
Connected appsapps_list, app_connect, app_disconnectWhich apps an operator can use right now, in the kit vocabulary, and connecting the rest by credential: validated live, stored encrypted, never returned. Browser sign-ins stay on the Apps page.
Model keysmodel_keys_list, model_key_set, model_key_deleteYour own model-provider API keys, so runs bill your provider account instead of the wallet.
Onboarding and walletonboarding_get, wallet_get, wallet_checkout_create, wallet_checkout_getCheck model funding, hand off BYOK setup, inspect wallet balance, and request a human-confirmed Stripe checkout. A purchase is complete only when its status is credited.
Custom MCP serversmcp_servers_list, mcp_server_get, mcp_server_create, mcp_server_discover, mcp_server_set_tools, mcp_server_deleteAn app the platform does not offer, reached through its MCP server: register it as your own custom MCP app with its credential in the same call, enable the tools a job needs, and bind it in a kit.
Decision authoringdecision_worker_createCompile typed questions and a supported source recipe into a private kit and installed decision worker. Optional deploy; never starts a run. Requires publishKits and installKits, plus manageDeployments when deploying. Retry the same requestId and body to recover the receipt.
Discovery and authoring readsworkerkit_about, directory_overview, kits_search, kit_get, kit_app_tools, kit_authoring_guide, kit_vocabularyPublic reads also available on the workers connection. Discover classification sources with kit_app_tools(purpose:"decision") and read kit_authoring_guide(section:"decision"). These reads never forward the manager bearer upstream.

The anonymous directory endpoint carries workerkit_about (what WorkerKit is and when to use it, written for an agent), directory_overview, kits_search, kit_get, kit_stats, publisher_get, and the three reads a kit is written from: kit_app_tools, kit_authoring_guide and kit_vocabulary. Read-only by construction, because installing or publishing a kit takes a signed-in human or the fleet endpoint's own opt-in scopes.

The same tools reach your terminal through the wk CLI, and both surfaces are generated from the open-source packages on npm.