Register an MCP endpoint
const url = 'https://example.com/v1/mcp/endpoints';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"endpointId":"example","name":"example","transport":"stdio","config":{"transport":"stdio","command":"example","args":["example"],"env":{"additionalProperty":"example"}},"secretRef":{"envName":"example","name":"example"},"instructions":"example","metadata":{},"scopeKind":"tenant","scopeId":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/mcp/endpoints \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "endpointId": "example", "name": "example", "transport": "stdio", "config": { "transport": "stdio", "command": "example", "args": [ "example" ], "env": { "additionalProperty": "example" } }, "secretRef": { "envName": "example", "name": "example" }, "instructions": "example", "metadata": {}, "scopeKind": "tenant", "scopeId": "example" }'Body is a full MCPEndpoint plus the scope to register it in (scopeKind + scopeId); authorization checks that scope. Server validates the closed transport enum + the config.transport matches transport guardrail + per-variant required fields (command for stdio; url for http-sse / streamable-http), and refuses unknown fields. secretRef names a secret in the deployment’s store — plaintext secrets never cross the wire. A deployment with KINDGI_TENANT_HOST_ACCESS=deployed (the default outside development) refuses a stdio endpoint, which would run a command on the server’s host: 403 host-access-denied.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”Caller-supplied idempotency key. Retries with the same key return the original response byte-identical (per docs/API-ROUTE-CONVENTIONS.md §3.1).
Request Bodyrequired
Section titled “Request Bodyrequired”object
Human-readable display name.
MCP transport variant. stdio — local subprocess (spawn a command). http-sse — the older MCP HTTP+SSE transport (separate POST + SSE endpoints). streamable-http — the Streamable HTTP transport (single endpoint, session id via header).
object
object
object
Optional distinct SSE endpoint if the server splits them.
object
object
object
The secret an MCP endpoint authenticates with: a name in the deployment’s secrets store, resolved at the endpoint’s tenant scope when the runtime connects (the shape webhooks and providers use). It is sent as the endpoint’s bearer. The endpoint keeps only this reference.
object
Optional pass-through to the MCP client serverInfo.instructions.
Optional caller-defined metadata bag.
object
Discriminator for the ?scopeKind + ?scopeId + ?inherit triplet. Tenant carries no id (implicit from session); org/project require scopeId.
Required when scopeKind is org or project; absent for tenant (implicit from the session).
Responses
Section titled “Responses”MCP endpoint registered.
object
Examplegenerated
{ "endpointId": "example"}Validation failed (see details.reason).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}host-access-denied: a stdio endpoint on a deployment that refuses commands on its host (KINDGI_TENANT_HOST_ACCESS=deployed); or authz-denied.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}MCP endpoint already registered at that id.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Server error (unmapped domain code or framework crash).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}