Inside the AMS MCP bridge

Inside the AMS MCP bridge An architecture diagram generated by Archify. Agent MCP client · Memory-user API key · Architecture component Agent MCP client Memory-user API key AMS HTTP gateway · Per-request user authentication · mcp container · request processes stay private · :8425 /mcp AMS HTTP gateway Per-request user authentication :8425 /mcp Official MCP SDK · HTTP ↔ stdio transports · mcp container · request processes stay private · In-process bridge Official MCP SDK HTTP ↔ stdio transports In-process bridge Stock TDAI MCP · One child per HTTP request · mcp container · request processes stay private · Upstream tool contract Stock TDAI MCP One child per HTTP request Upstream tool contract Core · Users, teams, assets and ACL · Architecture component Core Users, teams, assets and ACL AMS access bridge · User + resource permissions · Architecture component · access:8080 AMS access bridge User + resource permissions access:8080 TDAI Knowledge · Wiki and code resource tools · Architecture component · knowledge:8421 TDAI Knowledge Wiki and code resource tools knowledge:8421 Streamable HTTP HTTP request MCP over stdio HTTP tools + user key Verify user Check permissions HTTP + service header mcp container · request processes stay private Legend Backend Security External

Upstream tool contract

  • • Tool names, schemas and results come from unchanged TDAI stdio.
  • • AMS connects official SDK transports without a private HTTP server.

Checks before execution

  • • Every HTTP POST checks the active user before starting TDAI.
  • • Access checks resource permissions and adds the service header.

Request lifecycle

  • • Each POST starts its own stock stdio process with the caller key.
  • • Response completion or disconnect closes the child. No persistent sessions.