| Category | Authentication behavior |
|---|---|
| Session, Workspace, and discovery | Configure local MCP session state and do not require an existing bearer token. |
| Authentication | Establish, inspect, or clear the bearer token stored for the MCP session. |
| Health | Forward the session token to Admin APIs; downstream Admin authorization controls access. |
| Cloud and alerts | Exist only when a Google Cloud runner is configured and use its server-side credentials. They do not currently add a separate per-tool bearer gate. |
pipeline_status is callable, but its relationship to the current Provider
Pool model is unverified. Treat the name as a compatibility or legacy signal
until its implementation and callers are mapped.