bootstrap

An HTTPS startup service that returns per-user JSON configuration, including MCP servers and skills, to an Office add-in.

In plain words
What is it for?
Use it to provide user-specific servers, skills, token settings, region choices, and other structured configuration when the add-in starts.
Why use it?
Flat extension settings can carry only short strings, while structured configuration needs arrays and nested data. The service also lets each user receive different settings based on their identity.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/anthropics/financial-services/bootstrap
Clone the repo
git clone --depth 1 https://github.com/anthropics/financial-services
Per session 14 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,610 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00014 $0.03610
Opus 5 $0.00007 $0.01805
Sonnet 5 $0.00003 $0.00722
Haiku 4.5 $0.00001 $0.00361

Measured 2d ago against content hash 5dbe9ffa03b0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bootstrap scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

The presigned-URL one bites hardest because `curl` works (curl ignores CORS),
claude-for-msft-365-install/commands/bootstrap.md · 326 lines

How it starts

The opening of the file, as written. The whole thing — 326 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bootstrap endpoint

You host an HTTPS GET handler. The add-in calls it at startup with the user's Entra token, you return per-user JSON, the response overrides manifest and extension attrs for that user. This is how you push structured config — mcp_servers, skills — that flat string attrs can't carry.

Ask first

Figure out which mode you're in before walking the spec:

  • Just want to understand it? Answer from the sections below. Common questions: what's the response shape, how does {{...}} work, why is CORS biting me.
  • Building one? Ask: new handler or editing an existing one? Lambda, Cloud Function, Express, Python, something else? Then jump to Scaffolding — the sections in between are the contract you're coding against.

This vs extension attrs

Both deliver per-user config. Pick by what you're carrying.

Extension attrs Bootstrap endpoint
You write az rest PATCH per user An HTTPS service
Carries Flat strings, ≤256 chars Any JSON — arrays, nested, base64
Good for Token rotation, region override mcp_servers, skills, anything structured
Refresh Token cache, ~1hr lag bootstrap_expires_at, you control it
Auth Entra token claims (passive) You validate the JWT (active)

If you only need to swap gateway_token per user, attrs are less work. The moment you want a Linear MCP server for one team and a Jira one for another, you're here.

Template interpolation

Any string value can contain {{key}}. The add-in substitutes against the merged config chain — manifest params, then extension attrs, then this response, each layer overriding the last. You don't echo a value back just so a template can see it; if gateway_token is already in the manifest or an attr, {{gateway_token}} resolves.

Two phases, because the request has to happen before the response exists:

  1. bootstrap_url itself resolves against manifest + attrs only. So the manifest can carry bootstrap_url=https://config.internal/bootstrap?project={{gcp_project_id}} and you run one endpoint that branches on a query param instead of stamping per-team URLs into attrs.
  2. Response fields resolve against the full merge — manifest + attrs + whatever this response just returned. An mcp_servers entry can reference a gateway_token that lives three lines up in the same JSON.

Read the full file on GitHub · 326 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 326 lines · 14 tokens per session scan A 5dbe9ffa03b0

Subscribe to this mod's changes

bootstrap is a command published in the GitHub repository anthropics/financial-services (34,627 stars, last pushed 7d ago), licensed Apache-2.0. It adds 14 tokens to every session and 3,610 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.