Conceptual
Login

Scoping Server File Access with MCP Roots

Roots are the file:// directories a client shares with a server so the server knows where to focus its work. They are advisory, not access control: the protocol does not enforce them, so real confinement comes from the client's permissions and from the server validating every path, and the current spec deprecates roots in favour of passing paths through tool parameters, resource URIs or server configuration.