Overview
MCP-endpoint catalog (list, get, register, unregister). Tenants declare the remote MCP servers (stdio / http-sse / streamable-http) they want the runtime to consume. The runtime discovers each endpoint’s tools and registers them into ToolRegistryBinding under the same tenant — remote MCP tools become native Kindgi tools without a recompile. Secrets never cross the wire: secretRef names a secret in the deployment’s store, resolved at the endpoint’s tenant scope. A deployment refuses stdio endpoints unless KINDGI_TENANT_HOST_ACCESS=local. Caller-plugged via MCPEndpointRegistryBinding.