# Hosted agent front door

Free workshop: [how to burn a trillion tokens and get good results](/tokenmaxx#interested).

## What it does

`apps/mischief` hosts the public documentation and its agent interfaces. Discovery cards describe MCP and A2A; [OpenAPI](/openapi.json) describes the HTTP capability surface. The [agent guide](/llms.txt) explains connection and search → read → graph traversal. The hosted registry exposes `search`, `read`, `backlinks`, `neighbors`, `mentions`, `path`, and `execute`.

MCP supports protocol versions 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26, and 2024-11-05. The newest is stateless; older clients initialize sessions backed by a Durable Object. A2A answers documentation questions through search and read. Browser RPC is a separate projection, not another agent interface.

## The standard

- Domain calls use the shared capability schemas and handlers. Discovery and static pages are routing, not extra domain handlers.
- Public API access needs no account or access token; [interest signup](/systems/interest) has its own consent and confirmation boundary.
- `execute` runs an async function body in a fresh Dynamic Worker with `globalOutbound: null`. Imports, exports, and `fetch` are unavailable. It can call declared capabilities, not arbitrary network services.
- API and MCP allow 120 requests per IP per 60 seconds. Execute also allows 6 per IP and 300 total per 60 seconds. Native Cloudflare counters apply separately per location.
- These routes exist today. Extracting a generic front-door cartridge is coming; it is not the status of the hosted routes.

## How to check

- Read the [MCP connection card](/.well-known/mcp.json), [A2A card](/.well-known/agent-card.json), and [OpenAPI](/openapi.json). Compare their descriptions with `apps/mischief/src/capabilities/index.ts`.
- Use the worked `tools/list` request in [llms.txt](/llms.txt), then search and read a public document.
- Run `pnpm --filter @rat-stack/mischief test` for protocol routing, rate limiting, and sandbox behavior.
- Local tests do not prove a new deploy. Confirm the live cards and capability list before advertising a new agent path.


## Sources

1. [Hosted application routes](<https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/app.ts>)
   GitHub joelhooks/rat-stack. Discovery, content negotiation, and protocol routing. Accessed 2026-10-01.

2. [Agent discovery content](<https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/content.ts>)
   GitHub joelhooks/rat-stack. MCP versions, connection examples, and discovery cards. Accessed 2026-10-01.

3. [Hosted capability registry](<https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/capabilities/index.ts>)
   GitHub joelhooks/rat-stack. The hosted content and execute capability list. Accessed 2026-10-01.

4. [Code-mode Worker loader](<https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/sandbox-worker-loader.ts>)
   GitHub joelhooks/rat-stack. Isolated execution and outbound network limits. Accessed 2026-10-01.

5. [Native rate limits](<https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/rate-limits.ts>)
   GitHub joelhooks/rat-stack. Request counters and per-stage namespaces. Accessed 2026-10-01.

## Lore on this page

- [Cartridges](/lore/cartridges)


## Linked from

- Agent guide → An Effect stack so pure (aspirational) Kit Langton will blush. → [Read page](<https://ratstack.sh/llms.txt>)
- Change log → What changed in the files served here, newest first. → [Read page](<https://ratstack.sh/log>)
- Full agent guide → An Effect stack so pure (aspirational) Kit Langton will blush. → [Read page](<https://ratstack.sh/llms-full.txt>)
- log.md → The generated change log as Markdown. → [Read page](<https://ratstack.sh/log.md>)
- Rat Stack systems | rat-stack → The systems rat-stack ships, the standard each keeps, and how to check it. → [Read page](<https://ratstack.sh/systems>)
