Skip to content

MCP

MCP proxy

POST/mcp/proxy/:uid

The gated path to one registered upstream tool server. initialize is answered locally, tools/list is filtered to what this agent may use, and every tools/call goes through the gate before anything is sent; the upstream’s credential is injected only into an allowed call. See the MCP proxy.

Errors: -32003 denied (with reasons), -32006 already forwarded once. An approval needed comes back as a tool result with isError: true and the approval link.

#Authentication

Agent key

An agent-scoped key (ask_...) bound to exactly one agent, or an OAuth access token (aat_...) issued to an MCP client for that agent, sent as Authorization: Bearer. An agent key may ask, poll and settle. It can never approve, widen a mandate or lift a freeze.

#Path parameters

uidstringrequired

MCP upstream id