MCP
MCP proxy
/mcp/proxy/:uidThe gated path to one registered upstream tool server. initialize is answered locally, tools/list is filtered to what this agent may use, and every tools/call goes through the gate before anything is sent; the upstream’s credential is injected only into an allowed call. See the MCP proxy.
Errors: -32003 denied (with reasons), -32006 already forwarded once. An approval needed comes back as a tool result with isError: true and the approval link.
#Authentication
Agent key
An agent-scoped key (ask_...) bound to exactly one agent, or an OAuth access token (aat_...) issued to an MCP client for that agent, sent as Authorization: Bearer. An agent key may ask, poll and settle. It can never approve, widen a mandate or lift a freeze.
#Path parameters
uidstringrequired
MCP upstream id