Intercept an MCP tool result¶
Goal: alter a tool result before the MCP client consumes it.
Start with the process-backed exercise:
Trigger the traffic in the Lab drawer, select the MCP response, change
/result/structuredContent/risk, and forward modified. The client decision and
effect ledger show exactly which value was consumed.
For Streamable HTTP, save the MCP server as mcp_http, place the AIT listener
in the client's server configuration, and break on response traffic for the
tool call. For stdio, configure the MCP client to launch the packaged AIT/Seam
wrapper instead of launching the server directly.
- Start the explicit relay or wrapper.
- Invoke the tool from the MCP client.
- Select the correlated response.
- Edit only the intended result field in Structured mode.
- Forward modified and inspect what the client received.
- Compare with Original on the next call or disable interception.
Keep authorization headers and credentials referenced rather than copied into reusable edits. Raw captures retain credential values; redacted export replaces them. A saved live rule should describe a bounded field change without storing an unrelated secret.
For stdio, ait intercept start prints the exact replacement command. Use it
unchanged in the MCP client configuration so the wrapper registers with the
same Cockpit session.