Quickstart
One paragraph into your agent, one approval in the browser, one real answer from live federal data. Or skip the agent and make three calls by hand.
Paste one paragraph
Create an account, then paste this into your agent. If your client can edit its own MCP configuration it will do so and tell you when to approve; if it cannot, it will tell you which settings screen to open. Either way you sign in once and approve the connection.
Connect to my HARBOR Port MCP server at https://port.harborgovcon.com/mcp and answer one question with live federal data. Add it as a remote HTTP MCP server and sign in with OAuth: if you can change your own configuration, do that and tell me when the browser opens so I can approve it, and if you cannot, tell me which settings screen to open and what to paste in, then wait for me. If neither works in your host, stop and tell me instead of guessing: there is more than one way in, and https://port.harborgovcon.com/llms.txt has the details. Call harbor_meta_ping and show me the result, which should say pong, then harbor_meta_list_servers and tell me how many sources I can reach. Then answer this from live federal data rather than a web search: in NAICS 541512, who won the most federal contract dollars in fiscal year 2026, is that market concentrated or fragmented, and how big is that federal market next to the industry as a whole? Use the usaspending tools for the federal side and the census tools for the industry. Put it on a single self-contained HTML page, dark and editorial rather than a dashboard.The same paragraph is on the home page. It names the source rather than the tool on purpose, so a catalogue change cannot leave it naming a tool that no longer exists.
What success looks like
- The browser opens and asks you to sign in. If you are already signed in to HARBOR Port, it asks you to approve instead. The consent screen names the client, says where it will send you back, and states how much of your quota it can reach.
harbor_meta_pingreturnspong. This is the cheapest possible call and it proves the credential, the session and the routing in one round trip.harbor_meta_list_serversnames your sources. The count reflects your plan, so it is also the quickest way to see what you can reach.- A real answer with real figures. The worked example asks for the largest federal contract winners in NAICS 541512 for fiscal year 2026, built into a page your agent writes itself. If it answers from a web search instead, it is not using the tools.
If the agent says it cannot discover an authorization server, see
the troubleshooting note. It names the one
discovery path this gateway does not serve and the client behaviour that trips on it.
Or three calls by hand
MCP is session based, so the first request is a handshake and every later request
carries the session id it returns. Take a key from API keys
and replace $HARBOR_KEY.
# 1. Initialize and keep the session id. Without this every later call is
# rejected with "Missing session ID".
SID=$(curl -sD - -o /dev/null https://port.harborgovcon.com/mcp \
-H "Authorization: Bearer $HARBOR_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"1"}}}' \
| tr -d '\r' | awk -F': ' 'tolower($1)=="mcp-session-id"{print $2}')
# 2. Tell the server the handshake is done.
curl -s https://port.harborgovcon.com/mcp \
-H "Authorization: Bearer $HARBOR_KEY" \
-H "Mcp-Session-Id: $SID" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","method":"notifications/initialized"}'
# 3. Verify the key. This must return pong.
curl -s https://port.harborgovcon.com/mcp \
-H "Authorization: Bearer $HARBOR_KEY" \
-H "Mcp-Session-Id: $SID" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"harbor_meta_ping","arguments":{}}}'