/api/v1/mcp/connection
auth: jwtReturn the public MCP server URL, transport, and tool list. Does NOT require an MCP token — only a valid JWT. Used by the app to display connection details before the user creates their first token.
handlers: McpController.getConnection
No parameters.
APIResponseDataObject<McpConnectionInfoDTO>/api/v1/mcp/tokens
auth: jwtIssue a 90-day RS256 personal-access token (typ='mcp') for AI agents. jti = McpTokens.McpTokenId UUID. Only SHA-256(rawToken) is persisted; the raw token is returned ONCE on creation and never again.
handlers: McpController.createToken
| name | required | default | description |
|---|---|---|---|
name bodystring | yes | — | Operator-facing label (1..100 chars), e.g. 'Claude Desktop on laptop'. |
APIResponseDataObject<CreateMcpTokenResponse>APIError/api/v1/mcp/tokens
auth: jwtList the caller's active MCP tokens (non-revoked, non-expired). Raw token hash is never exposed — only id, name, createdAt, lastUsedAt, expiresAt.
handlers: McpController.listTokens
No parameters.
APIResponseDataList<McpTokenDTO>/api/v1/mcp/tokens/:tokenId
auth: jwtSoft-revoke an MCP token (sets RevokedAt). Idempotent — re-calling on an already-revoked token is a no-op.
handlers: McpController.revokeToken
| name | required | default | description |
|---|---|---|---|
tokenId pathuuid | yes | — | McpTokens.McpTokenId to revoke (must belong to the caller). |
voidAPIError/api/v1/mcp/agent-config
auth: jwtReturn a Claude Desktop / mcp.json configuration snippet referencing the MCP server URL and a placeholder Authorization header. The raw token is not returned — the user must substitute the value they saved at creation time.
handlers: McpController.getAgentConfig
No parameters.
APIResponseDataObject<McpAgentConfigResult>APIError