Authorization: Bearer or X-Api-Key. Any valid key can connect; each
tool enforces its own scope — a missing scope
returns a structured tool error with "status": 403.
Tools
Document upload is deliberately REST/dashboard-only — MCP has no multipart
transport. Long screenings and executions return a run id immediately; poll
the matching
get* tool.