List MCP endpoints
const url = 'https://example.com/v1/mcp/endpoints?limit=25&transport=stdio&scopeKind=tenant&inherit=true';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/mcp/endpoints?limit=25&transport=stdio&scopeKind=tenant&inherit=true' \ --header 'Authorization: Bearer <token>'Cursor-paginated. Optional ?transport= narrows to a single variant (stdio | http-sse | streamable-http). ?scopeKind + ?scopeId + ?inherit narrow to a specific scope; inherit is LOAD-BEARING here (policy/config-scoped binding — controls the upward-hierarchy walk).
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
MCP transport variant. stdio — local subprocess (spawn a command). http-sse — the older MCP HTTP+SSE transport (separate POST + SSE endpoints). streamable-http — the Streamable HTTP transport (single endpoint, session id via header).
Filter to endpoints of a single transport variant. Values: stdio | http-sse | streamable-http.
Discriminator for the ?scopeKind + ?scopeId + ?inherit triplet. Tenant carries no id (implicit from session); org/project require scopeId.
Optional scope discriminator. If absent, no scope filter is applied.
Required IF scopeKind is org or project. MUST be absent if scopeKind=tenant (tenant is implicit from the session). Malformed combinations return 400 scope-invalid.
Default true. false = literal-at-this-scope only (admin/audit view). Load-bearing for policy/config-scoped resources (mcp-endpoints); documented no-op for content-scoped resources (agents/flows/tools/…).
Responses
Section titled “Responses”Page of MCP endpoints.
object
object
Human-readable display name.
MCP transport variant. stdio — local subprocess (spawn a command). http-sse — the older MCP HTTP+SSE transport (separate POST + SSE endpoints). streamable-http — the Streamable HTTP transport (single endpoint, session id via header).
object
object
object
Optional distinct SSE endpoint if the server splits them.
object
object
object
The secret an MCP endpoint authenticates with: a name in the deployment’s secrets store, resolved at the endpoint’s tenant scope when the runtime connects (the shape webhooks and providers use). It is sent as the endpoint’s bearer. The endpoint keeps only this reference.
object
Optional pass-through to the MCP client serverInfo.instructions.
Optional caller-defined metadata bag.
object
Example
{ "data": [ { "transport": "stdio", "config": { "transport": "stdio" } } ]}Malformed query parameter.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}