1
MCP client. Claude, Cursor or an agent. Sends a JSON-RPC tools/call to the route, with a bearer token or an OAuth grant.
2
Route. Mcp::web('/mcp/weather', WeatherServer::class) in routes/ai.php, behind auth:sanctum or Passport middleware.
3
Server. A class listing its $tools, $resources and $prompts, with #[Name], #[Version] and #[Instructions].
4
Tool. schema() declares the arguments; handle(Request $request) validates them, then returns a Response.
5
Your app, the models and services behind the tool, resolved by the container. Authorisation is an ordinary can() check.
6
Tool catalogue, optional. ToolSearch::class => [...] hides rarely used tools behind search_tools and execute_tools.