vsmsconnect — API — mcp

← all endpoints

GET/api/v1/mcp/connection auth: jwt

Return the public MCP server URL, transport, and tool list. Does NOT require an MCP token — only a valid JWT. Used by the app to display connection details before the user creates their first token.

handlers: McpController.getConnection

Inputs

No parameters.

Outputs

200
APIResponseDataObject<McpConnectionInfoDTO>
{ url, transport: 'streamable-http', tools: [...] } — URL is MCP_PUBLIC_URL/mcp.
POST/api/v1/mcp/tokens auth: jwt

Issue a 90-day RS256 personal-access token (typ='mcp') for AI agents. jti = McpTokens.McpTokenId UUID. Only SHA-256(rawToken) is persisted; the raw token is returned ONCE on creation and never again.

handlers: McpController.createToken

Inputs

namerequireddefaultdescription
name body
string
yes—Operator-facing label (1..100 chars), e.g. 'Claude Desktop on laptop'.

Outputs

201
APIResponseDataObject<CreateMcpTokenResponse>
McpTokenDTO + raw `token` (RS256 JWT). Save the raw token — it will not be shown again.
422
APIError
VALIDATION_ERROR — schema violation.
GET/api/v1/mcp/tokens auth: jwt

List the caller's active MCP tokens (non-revoked, non-expired). Raw token hash is never exposed — only id, name, createdAt, lastUsedAt, expiresAt.

handlers: McpController.listTokens

Inputs

No parameters.

Outputs

200
APIResponseDataList<McpTokenDTO>
Active tokens for the caller.
DELETE/api/v1/mcp/tokens/:tokenId auth: jwt

Soft-revoke an MCP token (sets RevokedAt). Idempotent — re-calling on an already-revoked token is a no-op.

handlers: McpController.revokeToken

Inputs

namerequireddefaultdescription
tokenId path
uuid
yes—McpTokens.McpTokenId to revoke (must belong to the caller).

Outputs

204
void
Token revoked (or already-revoked).
404
APIError
MCP_TOKEN_NOT_FOUND — tokenId does not exist for this user.
GET/api/v1/mcp/agent-config auth: jwt

Return a Claude Desktop / mcp.json configuration snippet referencing the MCP server URL and a placeholder Authorization header. The raw token is not returned — the user must substitute the value they saved at creation time.

handlers: McpController.getAgentConfig

Inputs

No parameters.

Outputs

200
APIResponseDataObject<McpAgentConfigResult>
{ url, transport, activeToken: { id, name } | null, configSnippet: { mcpServers: { vsmsconnect: { url, headers: { Authorization: 'Bearer <your_mcp_token>' } } } } }.
404
APIError
MCP_TOKEN_NOT_FOUND — caller has no active MCP token; create one via POST /mcp/tokens first.