OptionalapiRequired as Authorization: Bearer KEY or X-API-Key: KEY when set; it may run every tool.
OptionalauditCalled after every run, for an audit log.
OptionalconcurrencyAsync jobs run at the same time (default: the number of CPUs).
OptionalcwdWorking directory tools run in (default: the server's).
OptionalfilterWhich tools to serve at all (with the root's allow/deny settings).
OptionalkeysNamed keys, each limited to the tools its allow/deny globs let through.
OptionalmaxLargest request body accepted: JSON, multipart, or spooled for an async job (default 10 MiB).
OptionalmaxKeep at most this many bytes of a tool's stdout and stderr (0 or unset: all). Streamed stdout is not kept.
OptionalmcpAlso serve the tools over MCP (streamable HTTP) at /mcp (default: true).
OptionalnameAPI title (default: the root's name).
OptionalonCalled after each reload when watching.
OptionalpositionalsPositionals before or after options (default: first).
Tools directory or dispatcher definition file.
OptionaltimeoutKill a tool after this long (0: never).
OptionalversionServer version advertised to clients.
OptionalwatchPick up added, changed and removed tools without a restart (default: false; call close() to stop).
OptionalwithinPath-valued inputs must resolve inside these directories.
Tool root, authorization, execution limits, and lifecycle settings for the HTTP server.