> For the complete documentation index, see [llms.txt](https://mcp-test-kitchen-docs.cakewalk.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mcp-test-kitchen-docs.cakewalk.security/reference/scope-and-limits.md).

# Scope and Limits

What this server does not do, stated plainly, so you do not design a test around something it cannot produce.

Everything here is a real boundary, not a caveat.

***

## It Returns No Verdict

Nothing on this server checks your client against the specification. There is no pass, no fail and no score. The server produces a failure you configured and records what it received. Reading the outcome is your job.

If you want a verdict, the [official conformance suite](https://github.com/modelcontextprotocol/conformance) answers that question and needs a server that behaves. This one is the opposite instrument.

***

## It Does Not Test Your Server

The direction is fixed. This server misbehaves and your client responds. Pointing it at your own MCP server is not a thing you can do here. [MCP Inspector](https://github.com/modelcontextprotocol/inspector) is built for that direction.

***

## The Transport Is Stateless

Sessions are not enabled. Three consequences follow.

* The server cannot hold state across a live connection, so anything requiring a durable session is unavailable.
* The older revision's bridged elicitation path, where the SDK converts a round trip request into an `elicitation/create` call on a live session, cannot be tested here.
* Two of the four cells in the [C# SDK v2](/scenarios/scenarios/sdk-v2-compat.md) compatibility matrix are marked unavailable for this reason, and the tool says so rather than pretending otherwise.

***

## Six Scenarios Are Registered

Twenty scenario implementations sit in the codebase. Six are switched on and the rest are not reachable from the console, so knowing what exists saves you designing a test around something you cannot select.

| Not registered            | What it would cover                                                                                                         |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------- |
| Four timeout variants     | A hang that ignores cancellation, a delayed `initialize`, a late result after the caller gave up and a cooperative deadline |
| Four further error shapes | Connection close, malformed payload, a status code chosen per method and a non compliant envelope                           |
| Token lifecycle           | Authentication and token expiry behavior                                                                                    |
| Three catalog scenarios   | Catalog mutation, pagination and a facet reported unavailable                                                               |
| Two elicitation variants  | A scripted decline, cancel or timeout outcome, and URL mode prompts                                                         |

Nothing in the console enables these. Registering one is a code change.

What ships is the six on the [Scenarios](/scenarios/scenarios.md) page.

***

## Failures Arrive Cleanly

Every failure the six registered scenarios produce is a well formed HTTP response. None of them produces DNS failures, TLS failures, connection resets, half open sockets, truncated bodies or incomplete server sent event streams.

Most of those need a proxy sitting between your client and the network rather than a server. One is different: an abrupt connection close during `initialize` or `tools/call` is implemented in the codebase and simply not registered, so it is unavailable rather than impossible.

Either way, treat what you can exercise here as the friendly end of the range.

One exception. The always on `invalid_resource` and `invalid_prompt` items do return schema invalid bodies, described in [Resources and Prompts](/reference/resources-and-prompts.md). The envelope is still valid; the contents are not.

***

## One Session at a Time

You hold one active scenario session. Concurrency, parallel sessions on one token, notification storms and load behavior are outside what you can arrange here.

***

## Records Expire

Seven days, then entries are deleted. See [Data Handling](/reference/data-handling.md).
