Tool boundary
- Make Search available as a read-only tool.
- Keep each Act operation separate so thread messages, authentication, and payment remain visible.
- Store target/capability IDs,
threadId, revision, cursor, and retry identifiers in application state. - Return Darwin’s typed events and operation states to the agent without rewriting them as success.
https://mcp.darwin.so/mcp for MCP or install @darwinso/sdk for direct server integration.
Recommended tool shape
Return structured Darwin responses to the application layer. Let the UI own sensitive interactions and exact approvals instead of asking the model to simulate them.