One endpoint between your agent and everything it touches.
Tier Two is a hosted MCP server: streamable HTTP, OAuth, nothing to install. Point your host at it and your agent gets your workspace’s tools with your workspace’s modes already applied.
npx -y tiertwoRegisters every host, finds the systems your agents already use, and opens the browser to sign in.
One command. Every host.
Every snippet below is generated from one file (packages/shared/src/hosts.ts), so the docs, the dashboard, and this page cannot drift. Claude Code and Cursor are walked end to end each release; the rest are each host's own documented config.
# Registers the endpoint in every MCP host, finds the systems your agents
# already use, and opens the browser so you can connect them
npx -y tiertwo
# Put the direct entries back, any time
npx -y tiertwo undoOne terminal session. add-mcp runs inside it; after you sign in it offers to route each system you connect through Tier Two (reversible with undo). Local stdio servers are left alone.
Paste this into your agent.
It registers the endpoint, waits while you sign in, then reports what it can now do, and is told, in the prompt itself, not to route around a block.
Add the Tier Two MCP server to this machine: run `npx -y add-mcp https://trytiertwo.com/mcp -g -y`. If that fails, add an HTTP MCP server named `trytiertwo` with URL `https://trytiertwo.com/mcp` using this host's own MCP config. Then reconnect MCP servers and call any `trytiertwo` tool once; a browser window will ask me to sign in. Tell me when it does and wait for me. After I sign in, list the available tools and summarize what you can do. Never try to work around a tool that is blocked or waiting for approval; report it to me instead.What happens on a write.
The agent calls a namespaced tool. Tier Two resolves the person behind the token, looks up that tool's mode, and either forwards the call, pauses it for a human, or refuses it. Either way the ledger gets a row.
The agent’s original call is the one that completes. It does not have to retry, and there is no second, unreviewed attempt.
What your agent sees.
No Tier Two SDK, no wrapper API. Your agent gets ordinary MCP tools; the governance is in which tools appear and what happens when they are called.
<connection>__<tool>
Every tool of every connection your workspace enabled, namespaced by the connection slug: linear__create_issue, posthog__query_insights, metabase__execute_sql. Tools set to Block are not listed at all. There is nothing for the agent to try. Tools set to Ask carry a trailer in their description so the agent expects the pause.
tiertwo__status
Who the agent is signed in as, which workspace it acts in, and what is connected. When setup is incomplete this returns the link a human needs to finish it, so the agent can hand it over instead of guessing.
tiertwo__await_approval
Waits on a paused call. An Ask returns an approval request id; this tool blocks until a person approves, denies, or the request expires. It is not a way around a Block, and it says so in its own description.
Plain MCP, plain OAuth.
Nothing proprietary on the wire. If your client speaks streamable HTTP MCP and can follow an OAuth challenge, it can connect.
- Endpoint
- https://trytiertwo.com/mcp
- Transport
- Streamable HTTP (POST/GET/DELETE), SSE responses, stateful sessions keyed by mcp-session-id.
- Authorization
- Bearer token. An unauthenticated call answers 401 with WWW-Authenticate pointing at the protected-resource metadata, which is what starts your host’s sign-in flow.
- Discovery
- /.well-known/oauth-protected-resource/mcp
Verifying a Tier Two signature downstream (the Ed25519 JWT and the published JWKS) is documented in Docs → Security.
