A FIELD GUIDE TO LARAVEL · VOLUME II · THE ECOSYSTEM
ENTRY II.42 · MCP SERVERS
Laravel MCP
Laravel\Mcp · Package · first recorded 12 August 2025, v0.1.0 on Packagist; public beta 18 September 2025; v1.0.0 on 14 September 2026
A third entry point to the app beside the web and the API: tools, resources and prompts an AI client can call, written as classes and registered in routes/ai.php. The same Passport and Sanctum guards apply.
Specification
Kind Package. A server class per endpoint, with tools as classes
Protocol Model Context Protocol over HTTP (Mcp::web) or stdio (Mcp::local)
Client Claude, ChatGPT, Cursor, any MCP client; Boost uses the local form
Installed by composer require laravel/mcp · vendor:publish --tag=ai-routes
Voice make:mcp-server · make:mcp-tool · mcp:start · mcp:inspector
Scales by ToolSearch catalogues: tools/list stays one size at 10 or 100 tools
Range Cloud: yes. An HTTP route like any other
Forge, VPS: yes, the same route
Vapor: yes, as a route; a streamed reply arrives whole, as Vapor buffers it
Neighbours
Boost is an MCP server built on this package, for coding agents working on the app. The AI SDK faces the other way: your app calls models, and can hand them tools from an MCP client. Laravel MCP's distinction is that a tool is validated, authorised and resolved like a controller, behind Sanctum or Passport.
Field marks
routes/ai.php
app/Mcp/Servers/ · app/Mcp/Tools/
config/mcp.php
Mcp::web() / Mcp::local()
Fig. II.42.1 · One tool call, exploded
Parts
1 MCP client. Claude, Cursor or an agent. Sends a JSON-RPC tools/call to the route, with a bearer token or an OAuth grant.
2 Route. Mcp::web('/mcp/weather', WeatherServer::class) in routes/ai.php, behind auth:sanctum or Passport middleware.
3 Server. A class listing its $tools, $resources and $prompts, with #[Name], #[Version] and #[Instructions].
4 Tool. schema() declares the arguments; handle(Request $request) validates them, then returns a Response.
5 Your app, the models and services behind the tool, resolved by the container. Authorisation is an ordinary can() check.
6 Tool catalogue, optional. ToolSearch::class => [...] hides rarely used tools behind search_tools and execute_tools.
Hidden joinery
A catalogue search is lexical, not embeddings: name, then description, then the input schema, so rainfall_mm matches 'rainfall'. A batched call runs through the same ToolInvoker as a direct one and shouldRegister() is re-checked at execution, so a search result is never a grant. Cache hints default to TTL 0, private scope.
Every line checked on 2026-10-08 against docs, source, Packagist and The Monitor; see the ledger.
TITLE
Laravel MCP · a third entry point
SOURCES
laravel.com/docs/13.x/mcp · github.com/laravel/mcp · packagist.org/packages/laravel/mcp · laravel.com/blog/introducing-laravel-mcp-build-with-the-universal-ai-standard · laravel.com/blog/a-better-way-to-build-mcp-servers-with-laravel · github.com/laravel/vapor-core · Monitor 645, 547
STATUS
Verified · 2026-10-08
SHEET
II.42 of 48
REV
A · 2026-10-08
DRAWN
BS
FINISH
All faces, including the back