API Referencev1

MCP API

The MCP runtime endpoint, OAuth discovery and the console endpoints that manage MCP servers, imports, credentials and logs.

Updated 07/10/2026

On this page

Runtime

MethodPathDescription
POST/mcpJSON-RPC 2.0 over Streamable HTTP
DELETE/mcpEnds the session in MCP-Session-Id. Returns 204, or 404 if the session is not active.
GET/mcp405: no standalone SSE stream
GET/.well-known/oauth-protected-resource and /.well-known/oauth-protected-resource/mcpProtected-resource metadata: resource, authorization_servers, scopes_supported, bearer_methods_supported

Request headers

HeaderNotes
AuthorizationBearer <token>. Required.
MCP-Protocol-VersionRequired after initialize: 2025-11-25, 2025-06-18 or 2025-03-26
MCP-Session-IdReturned by initialize; required afterwards
OriginOptional; if sent it must be an allowed origin

Methods

initialize, notifications/initialized, tools/list, tools/call, resources/list, resources/read, prompts/list and prompts/get.

Notifications return 202. Other calls return 200 with a JSON-RPC result or error:

CodeMeaning
-32600Invalid request (including batches)
-32601Method not found
-32602Invalid parameters
-32003Forbidden: not approved, not permitted, rate limited or disabled
-32004Not found, or unknown session
-32009Conflict, for example an idempotency key reused with different input
-32603Internal error

The endpoint allows 60 requests a minute per client address, plus each tool's own per-credential limit.

Console

These paths start with /api/console/apps/:appId/mcp. They need a session token and the mcp.manage permission (owners, administrators, developers, security administrators and approvers).

MethodPathBody and notes
GET/templatesServer templates
GET/capabilitiesPlatform capabilities that can be published
POST/imports/preview{sourceUrl} or {spec}: an OpenAPI 3.0 or 3.1 JSON document (HTTPS, up to 1 MB). Returns candidate tools.
POST/importsSaves an import for review
GET/importsSaved imports
GET/imports/:importIdOne import
PATCH/imports/:importId/reviewA decision for every candidate: selected tools with 1–20 scopes, a timeout of 100–60,000 ms and a rate limit of 1–1,000 a minute. Write operations must keep approval.
GET/serversServers
POST/servers{name, description?, templateKey?, capabilities?, changeSummary?, importIds?}. Creates a draft.
GET/servers/:serverIdOne server with its versions
PATCH/servers/:serverIdName and description
POST/servers/:serverId/versions{capabilities[], changeSummary}. Creates a draft version.
POST/servers/:serverId/versions/:versionId/publishPublishes the version and archives the previous one
POST/servers/:serverId/versions/:versionId/rollbackCopies an archived version into a new published version
POST/servers/:serverId/disableDisables the server and revokes its credentials
GET/credentialsCredentials without secrets
POST/credentials{name?, serverId?, capabilities?, expiresAt?}. Returns {credential, secret, revealPolicy}; the secret is shown once.
POST/credentials/:credentialId/revokeRevokes the credential
GET/logs?status=&capability=The 100 most recent tool calls

If capabilities is omitted when creating a credential, the credential gets every capability published on the server. expiresAt must be in the future.

See Use the Nexra MCP server for the tool list, scopes and approval flow.

Need a hand?

Ask Nexra AI for implementation steps or error guidance.

Ask Nexra AI