## Someone's agent wants our data.

An agent wants to know what **TIER 321** builds. Maybe a founder's research bot. Maybe an analyst's sidecar. Maybe Claude, asked a question by an operator who has no patience for ten open tabs.

Two weeks ago, that agent hit `tier321.com` and did the only thing it could do: parse HTML. Guess at structure. Hope nothing had moved. Today it calls a typed tool over JSON-RPC and gets back a shape it can reason about on the first try. No prompt-engineered scraping. No `view-source:`. No coincidences.

This is part two of the series. Part one added a `Link` header and a `SKILL.md` manifest so agents could _find_ us. This one gives them something to _call_.

## What shipped.

A public **MCP** server at [`mcp.tier321.com/mcp`](https://mcp.tier321.com/mcp), built on Cloudflare Workers. Eight read-only tools. Anonymous. Per-IP rate limited at 20 requests per 10 seconds. Thirty seconds from a fresh MCP client to a live response.

The surface:

- `get_company_info` — company facts, positioning, standard attribution.
- `list_products` / `get_product` — shipped + in-development, one page of truth.
- `list_blog_posts` / `get_blog_post` — paginated feed plus full MDX fetch.
- `list_industries`, `list_use_cases` — sectors and workloads with product mapping.
- `get_contact_methods` — verified ways to reach a human.

The server card at [`/.well-known/mcp/server-card.json`](/content/.well-known/mcp/server-card.json) describes the surface. One call to prove it's real:

```
curl -X POST https://mcp.tier321.com/mcp 
  -H 'Content-Type: application/json' 
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
```

## Try it now.

From **Claude.ai**: open _Settings → Connectors → Add custom connector_, paste `https://mcp.tier321.com/mcp`, name it `TIER 321`, save. Start a new chat, ask _"what does TIER 321 build?"_, and watch the model reach for `list_products` instead of guessing. From **Cursor** or any other MCP client: same URL, same thirty seconds.

Want to inspect the surface before wiring it in? Run `npx @modelcontextprotocol/inspector` and point it at the endpoint. You'll see eight tools listed in the left pane; selecting `get_company_info` shows zero required parameters, a typed `CompanyInfo` return, and a live call button — roundtrip somewhere around 40 ms from the nearest Cloudflare edge.

## "Has an API" vs. "is agent-native."

There is a real gap between _a site has an API_ and _a site is agent-native_, and the gap is not syntactic. An API is a contract for humans to wire into other humans' code. Agent-native is a contract for **software acting on behalf of a human** — one that shows up at your door with no context, no tribal knowledge, and thirty seconds of patience before the operator interrupts it.

Two things close that gap. First, **typed tools with descriptions an agent can read** — the MCP `tools/list` response is, unromantically, a menu written for a stranger. Second, **discovery metadata** the agent finds without being told: a [`/.well-known/mcp/server-card.json`](/content/.well-known/mcp/server-card.json) that names the server, and an [`api-catalog`](/content/.well-known/api-catalog/index.html) document that hangs off the root. Both are in place now. A visiting agent follows the `Link` header from part one, reads the server card, finds the MCP endpoint, calls `tools/list`, and is operational. No human in the loop. That is the bar.

## One real decision.

We wanted the rate limit to sit at the edge, in front of the Worker, invisible to application code. That was the plan.

The specific infrastructure knob we wanted wasn't on the path we could turn today. The contract conversation would have been longer than the thing we were shipping. So we rerouted inside the application: the **Workers Rate Limiting binding**, scoped per IP, in the same request path, same envelope, same observability. Different knob, same outcome.

Lesson: shipping sometimes means rerouting around infrastructure reality. The edges of your stack are not always where the marketing diagram says they are. Name the constraint, find the other knob that produces the same outcome, keep the ship date.

## The source.

The MCP server behind `mcp.tier321.com/mcp` is open source under Apache 2.0 at [`github.com/jv-tier321/tier321-mcp`](https://github.com/jv-tier321/tier321-mcp). Reference implementation — the same transport, validator, rate-limit binding, and test harness we run in production, with TIER 321 specifics replaced by placeholder data. Fork it, deploy it, extend it.

## What's next.

The read layer is done. The next wave is narrower and more interesting: a small set of **authenticated write tools** that let an agent take an action on its operator's behalf, with real attribution and real consent. And a deeper integration with **Tower 321**, our flagship orchestration platform, so a logged-in operator's agent can reach their own tenant data through the same protocol.

That is part three.

## If you're building internal data an agent should reach.

We build **agent-native** surfaces in production — on our platforms and on operator infrastructure we own end-to-end. If you are standing up internal data an agent should reach, and you want to talk to the people who just shipped `mcp.tier321.com`, [get in touch](/content/contact/index.html).
