MCP
Connect a trusted local client to the first-party loopback MCP plugin.
MCP is provided by the bundled first-party Turboism MCP Server plugin. It is an integration path for trusted local external clients, not a fourth in-process extension type and not part of the in-process SDK lifecycle.
Connection requirements
The plugin listens only on 127.0.0.1 and uses authenticated Streamable HTTP. A local client must send the bearer secret issued for that connection. Give the generated connection metadata only to a client you trust on the same machine: anyone who obtains the secret may be able to act through the available MCP capability. Treat the connection file as sensitive local state—do not copy, log, share, synchronize, or publish its contents.
Connect a local client
- Start a Full or Thin installation and make sure the Turboism MCP Server plugin is enabled.
- In a trusted local MCP client, create a Streamable HTTP connection to the loopback endpoint reported by the plugin.
- Configure the client to send the bearer secret for that connection.
- Have the client send
initializeand retain theMCP-Session-Idreturned for the session. - After initialization, send the initialized notification required by MCP, then use only the operations the installed plugin exposes.
The endpoint, secret, available operations, and client compatibility are capability-sensitive and can change between builds. If a client cannot complete this sequence, do not bypass loopback or authentication controls.
Keep extension paths separate
Use MCP when an external client needs a controlled local connection. Use a Java plugin for process-internal SDK lifecycle and services. Use GraalJS Scripts only when a Java caller explicitly runs a limited script through PluginContext.scripts() and ScriptService.run.
ACP is internal and used only with fx. It is not an MCP endpoint or another way to extend Turboism.