Does MCP Support Tool Definition Validation? A Deep Dive into Codebase-Memory-MCP

Yes, the Codebase-Memory-MCP server validates every tool definition at registration time, rejecting malformed schemas with JSON-RPC error code -32602 before they become available to agents.

The DeusData/codebase-memory-mcp repository implements strict MCP tool definition validation to ensure that only well-formed tools are exposed to AI agents. This validation occurs during the registration phase, preventing runtime errors and security issues caused by malformed tool schemas.

How MCP Tool Definition Validation Works

When an agent attempts to register a new tool, the MCP server performs a multi-step validation process before accepting the definition.

The Registration Flow

The validation sequence follows these steps:

  1. Registration Request – An agent sends a registerTool JSON-RPC 2.0 request containing the tool definition.
  2. Schema Verification – The server parses the request and validates three critical fields:
    • name must be a non-empty string
    • description must be present
    • params must be a valid JSON-Schema object with proper type definitions and required fields
  3. Error Handling – If validation fails, the server returns a JSON-RPC error with code -32602 (Invalid params) and a descriptive message.
  4. Tool Activation – Only after successful validation does the tool become available for subsequent callTool invocations.

Required Schema Fields

The MCP server enforces strict compliance with JSON-Schema standards. A valid tool definition must include:

  • name: A unique identifier string
  • description: Human-readable explanation of the tool's purpose
  • params: A complete JSON-Schema object defining the tool's input parameters, including type constraints and required fields

Validation Implementation in Source Code

The core validation logic resides in the MCP server's tool registration handler. In src/mcp/mcp.c, the server implements the validation path that checks incoming tool definitions against the expected JSON-RPC 2.0 schema.

The code verifies that the params object contains valid JSON-Schema structures, ensuring that parameters like type, properties, and required arrays are properly formatted before the tool is stored in the server's registry.

Error Handling for Invalid Definitions

When validation fails, the MCP server provides clear feedback to prevent debugging difficulties. The server returns a standard JSON-RPC error response:

{
  "jsonrpc": "2.0",
  "id": 1,
  "error": {
    "code": -32602,
    "message": "Invalid tool definition: 'params' must be a valid JSON‑Schema object"
  }
}

This immediate failure prevents malformed tools from being exposed to agents, ensuring that all registered tools conform to the expected interface contract.

Practical Example of Valid Tool Registration

A properly formatted tool registration request that passes validation looks like this:

{
  "jsonrpc": "2.0",
  "method": "registerTool",
  "id": 1,
  "params": {
    "name": "search_graph",
    "description": "Search the knowledge graph",
    "params": {
      "type": "object",
      "properties": {
        "name_pattern": { "type": "string" },
        "label": { "type": "string" }
      },
      "required": ["name_pattern"]
    }
  }
}

If the params object omitted the "type": "object" field or contained an invalid schema, the server would reject the registration with error code -32602 before the tool could be invoked.

Testing Coverage for Validation Logic

The repository includes comprehensive test coverage to ensure validation works correctly. The test suite in tests/test_mcp.c contains explicit validation checks around line 3304 in the "Tool handlers with validation" test case.

This test deliberately feeds malformed tool definitions to the server and asserts that the registration fails with appropriate error codes. The tests verify that missing required fields, invalid JSON-Schema structures, and malformed parameter definitions are all caught during the registration phase.

Summary

  • MCP tool definition validation occurs at registration time in src/mcp/mcp.c, not at runtime
  • The server validates that name, description, and params fields conform to JSON-RPC 2.0 and JSON-Schema standards
  • Invalid definitions trigger JSON-RPC error code -32602 with descriptive messages
  • The test suite in tests/test_mcp.c (line 3304) explicitly validates this rejection behavior
  • This validation prevents malformed tools from being exposed to agents, ensuring system stability

Frequently Asked Questions

What specific fields does MCP validate in tool definitions?

The MCP server validates three critical fields: name must be a non-empty string, description must be present, and params must be a valid JSON-Schema object containing proper type definitions, property schemas, and required field arrays. Any deviation from these requirements results in registration failure.

What error code does MCP return for invalid tool definitions?

The server returns JSON-RPC error code -32602 (Invalid params) when tool definition validation fails. This standard error code is accompanied by a human-readable message explaining which specific field or schema requirement caused the rejection, such as missing required properties or invalid JSON-Schema syntax.

Where is the validation logic implemented in the codebase?

The validation logic is implemented in src/mcp/mcp.c within the tool registration handler. This core MCP server file contains the code that parses incoming registerTool requests and verifies that the tool definitions conform to the expected JSON-RPC 2.0 schema before storing them in the server's tool registry.

Does MCP validate tool calls or just tool definitions?

According to the source analysis, MCP validates tool definitions at registration time, ensuring that the schema is well-formed before the tool becomes available. The validation described in src/mcp/mcp.c and tested in tests/test_mcp.c specifically covers the registration phase, rejecting malformed tool definitions before they can be invoked by agents.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →