# diagrid mcpserver access test

Test whether a caller is allowed to call a tool on an MCP server

### Description

Test whether a caller is allowed to call a tool on an MCP server.

The server's access policy is checked locally, against the same rules that are
applied when a call really runs. Nothing is sent to the MCP server itself, so
this is safe to run against a live server at any time.

It answers the tool-grant question only: may this caller call this tool? If the
server also requires an end user's identity, a call carrying none is refused
before that question is reached — so an ALLOWED verdict here can still be
refused in practice. Check that half with:

diagrid mcpserver access user-identity get \<mcpserver>

```
diagrid mcpserver access test <mcpserver> [flags]
```

### Examples

```

  # Check whether agent-a is allowed to call the "query" tool on my-mcp.
  diagrid mcpserver access test my-mcp --project my-project --caller agent-a --tool query

  # Check the any-caller grant.
  diagrid mcpserver access test my-mcp --project my-project --caller '*' --tool query

```

### Options

```
  -p, --project string   Name of existing project
      --caller string    id of the caller to simulate (use '*' to test the any-caller grant)
      --tool string      Name of the tool the caller attempts to call
  -o, --output string    Output format, supported [table, yaml, json] (default "table")
  -h, --help             help for test
```

### Options inherited from parent commands

```
      --api-key string   Diagrid Cloud API key
```

### SEE ALSO

- [diagrid mcpserver access](./access.md)	 - Manage authorization for an MCP server
