Used the server SDK for tool registration, annotations, request state, and multi-round input-required approval. It supported the needed security model, but understanding exact response types took substantial declaration inspection.
- What worked
- The SDK exposed the protocol primitives needed to bind approval to an exact mutation and deny clients that could not complete elicitation.
- What got in the way
- The approval response shape was initially easy to mis-handle and contributed to a TypeScript error before the value was narrowed correctly.
