MCP API
The MCP runtime endpoint, OAuth discovery and the console endpoints that manage MCP servers, imports, credentials and logs.
Updated 07/10/2026
On this page
Runtime
| Method | Path | Description |
|---|---|---|
POST | /mcp | JSON-RPC 2.0 over Streamable HTTP |
DELETE | /mcp | Ends the session in MCP-Session-Id. Returns 204, or 404 if the session is not active. |
GET | /mcp | 405: no standalone SSE stream |
GET | /.well-known/oauth-protected-resource and /.well-known/oauth-protected-resource/mcp | Protected-resource metadata: resource, authorization_servers, scopes_supported, bearer_methods_supported |
Request headers
| Header | Notes |
|---|---|
Authorization | Bearer <token>. Required. |
MCP-Protocol-Version | Required after initialize: 2025-11-25, 2025-06-18 or 2025-03-26 |
MCP-Session-Id | Returned by initialize; required afterwards |
Origin | Optional; if sent it must be an allowed origin |
Methods
initialize, notifications/initialized, tools/list, tools/call, resources/list, resources/read, prompts/list and prompts/get.
Notifications return 202. Other calls return 200 with a JSON-RPC result or error:
| Code | Meaning |
|---|---|
-32600 | Invalid request (including batches) |
-32601 | Method not found |
-32602 | Invalid parameters |
-32003 | Forbidden: not approved, not permitted, rate limited or disabled |
-32004 | Not found, or unknown session |
-32009 | Conflict, for example an idempotency key reused with different input |
-32603 | Internal error |
The endpoint allows 60 requests a minute per client address, plus each tool's own per-credential limit.
Console
These paths start with /api/console/apps/:appId/mcp. They need a session token and the mcp.manage permission (owners, administrators, developers, security administrators and approvers).
| Method | Path | Body and notes |
|---|---|---|
GET | /templates | Server templates |
GET | /capabilities | Platform capabilities that can be published |
POST | /imports/preview | {sourceUrl} or {spec}: an OpenAPI 3.0 or 3.1 JSON document (HTTPS, up to 1 MB). Returns candidate tools. |
POST | /imports | Saves an import for review |
GET | /imports | Saved imports |
GET | /imports/:importId | One import |
PATCH | /imports/:importId/review | A decision for every candidate: selected tools with 1–20 scopes, a timeout of 100–60,000 ms and a rate limit of 1–1,000 a minute. Write operations must keep approval. |
GET | /servers | Servers |
POST | /servers | {name, description?, templateKey?, capabilities?, changeSummary?, importIds?}. Creates a draft. |
GET | /servers/:serverId | One server with its versions |
PATCH | /servers/:serverId | Name and description |
POST | /servers/:serverId/versions | {capabilities[], changeSummary}. Creates a draft version. |
POST | /servers/:serverId/versions/:versionId/publish | Publishes the version and archives the previous one |
POST | /servers/:serverId/versions/:versionId/rollback | Copies an archived version into a new published version |
POST | /servers/:serverId/disable | Disables the server and revokes its credentials |
GET | /credentials | Credentials without secrets |
POST | /credentials | {name?, serverId?, capabilities?, expiresAt?}. Returns {credential, secret, revealPolicy}; the secret is shown once. |
POST | /credentials/:credentialId/revoke | Revokes the credential |
GET | /logs?status=&capability= | The 100 most recent tool calls |
If capabilities is omitted when creating a credential, the credential gets every capability published on the server. expiresAt must be in the future.
See Use the Nexra MCP server for the tool list, scopes and approval flow.