Skip to main content

MCP keys

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: mcp-keys · 7 operations

GET /v1/tenants/{tenant_slug}/mcp-keys​

List MCP API keys

List MCP API key metadata for the tenant (prefix, label, scope, capability_mode, enabled_tools, timestamps). Includes revoked keys for audit. Never returns secret or hash. Tenant administrators only (MTG-3.2, #4776).

Operation id: list_mcp_api_keys_v1_tenants__tenant_slug__mcp_keys_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list mcp api keys.application/json McpApiKeyListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/mcp-keys​

Create MCP API key

Issue a new MCP API key. Returns plaintext secret once; subsequent reads never include it. Defaults to capability_mode=inherit. Tenant administrators only (MTG-3.2, #4776).

Operation id: create_mcp_api_key_v1_tenants__tenant_slug__mcp_keys_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create mcp api key.

Responses

StatusDescriptionBody
201Successful response for create mcp api key.application/json McpApiKeyCreateResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/mcp-keys/{key_id}​

Get MCP API key

Return one MCP API key's public metadata. Never returns secret or hash. Tenant administrators only (MTG-3.2, #4776).

Operation id: get_mcp_api_key_v1_tenants__tenant_slug__mcp_keys__key_id__get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get mcp api key.application/json McpApiKeyMetadata
422Validation Errorapplication/json HTTPValidationError

PATCH /v1/tenants/{tenant_slug}/mcp-keys/{key_id}​

Update MCP API key

Update label, expires_at, and/or scope_json on an active (non-revoked) MCP API key. Capability grants use PUT …/capabilities (MTG-3.3). Tenant administrators only (MTG-3.2, #4776).

Operation id: patch_mcp_api_key_v1_tenants__tenant_slug__mcp_keys__key_id__patch

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for update mcp api key.

Responses

StatusDescriptionBody
200Successful response for update mcp api key.application/json McpApiKeyMetadata
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/tenants/{tenant_slug}/mcp-keys/{key_id}​

Revoke MCP API key

Soft-revoke an MCP API key (sets revoked_at). Idempotent for already-revoked keys. MCP auth rejects the key immediately. Tenant administrators only (MTG-3.2, #4776).

Operation id: revoke_mcp_api_key_v1_tenants__tenant_slug__mcp_keys__key_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for revoke mcp api key.—
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/mcp-keys/{key_id}/capabilities​

Update MCP API key capabilities

Set per-key capability grants: mode inherit|explicit and optional enabled_tools. inherit clears the explicit list; explicit lists must be ⊆ the tenant ceiling (422 with offending_tool_ids otherwise). Tenant administrators only (MTG-3.3, #4777).

Operation id: put_mcp_api_key_capabilities_v1_tenants__tenant_slug__mcp_keys__key_id__capabilities_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for update mcp api key capabilities.

Responses

StatusDescriptionBody
200Successful response for update mcp api key capabilities.application/json McpKeyCapabilitiesResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/tenants/{tenant_slug}/mcp-keys/{key_id}/capabilities/preview​

Preview MCP API key effective capabilities

Dry-run effective enable-set for the given mode/enabled_tools against the tenant policy, using the same MTG-1.4 resolver as MCP tools/call. Does not persist. Ceiling violations yield 422 with offending_tool_ids. Tenant administrators only (MTG-3.3, #4777).

Operation id: preview_mcp_api_key_capabilities_v1_tenants__tenant_slug__mcp_keys__key_id__capabilities_preview_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
key_idpathstring (uuid)yesPath parameter identifying the key id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for preview mcp api key effective capabilities.

Responses

StatusDescriptionBody
200Successful response for preview mcp api key effective capabilities.application/json McpKeyCapabilitiesPreviewResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

McpApiKeyCreateRequest​

Issue a new MCP API key.

PropertyTypeRequiredDescription
labelstringyesHuman label for admin UX.
expires_atstring (date-time) or nullnoOptional absolute expiry; omit for no expiry.
scope_jsonMcpKeyScopeJsonnoRead scope: {"tenants":[...],"projects":[...]}.

McpApiKeyCreateResponse​

Create response: metadata plus one-time plaintext secret.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
prefixstringyesPrefix.
labelstringyesLabel.
scope_jsonMcpKeyScopeJsonyesScope JSON.
capability_modeenum "inherit", "explicit"yesCapability Mode.
enabled_toolsarray of stringnoExplicit enable-set when capability_mode=explicit; empty under inherit.
created_atstring (date-time)yesCreation timestamp (ISO 8601).
expires_atstring (date-time) or nullnoExpires At timestamp (ISO 8601).
revoked_atstring (date-time) or nullnoRevoked At timestamp (ISO 8601).
last_used_atstring (date-time) or nullnoLast Used At timestamp (ISO 8601).
created_bystring or nullnoCreated By.
secretstringyesPlaintext MCP API key; shown only in this response.

McpApiKeyListResponse​

Tenant MCP API key listing.

PropertyTypeRequiredDescription
keysarray of McpApiKeyMetadatayesKeys.

McpApiKeyMetadata​

Public MCP API key metadata (never includes secret or hash).

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
prefixstringyesPrefix.
labelstringyesLabel.
scope_jsonMcpKeyScopeJsonyesScope JSON.
capability_modeenum "inherit", "explicit"yesCapability Mode.
enabled_toolsarray of stringnoExplicit enable-set when capability_mode=explicit; empty under inherit.
created_atstring (date-time)yesCreation timestamp (ISO 8601).
expires_atstring (date-time) or nullnoExpires At timestamp (ISO 8601).
revoked_atstring (date-time) or nullnoRevoked At timestamp (ISO 8601).
last_used_atstring (date-time) or nullnoLast Used At timestamp (ISO 8601).
created_bystring or nullnoCreated By.

McpApiKeyPatchRequest​

Partial update of label, expiry, and/or scope (active keys only).

PropertyTypeRequiredDescription
labelstring or nullnoReplace label when set.
expires_atstring (date-time) or nullnoReplace expiry when field is present; null clears expiry.
scope_jsonMcpKeyScopeJson or nullnoReplace scope_json when set.

McpKeyCapabilitiesPreviewResponse​

Effective enable-set table for a key (matches MCP call gate).

PropertyTypeRequiredDescription
toolsarray of McpKeyEffectiveToolRowyesTools.

McpKeyCapabilitiesRequest​

Writable per-key capability grants (MTG-3.3).

PropertyTypeRequiredDescription
modeenum "inherit", "explicit"yesinherit = clear enabled_tools and follow tenant defaults; explicit = enabled_tools is authoritative (must be ⊆ ceiling).
enabled_toolsarray of string or nullnoTool ids when mode=explicit. Ignored (cleared) when mode=inherit.

McpKeyCapabilitiesResponse​

Stored per-key capability grants.

PropertyTypeRequiredDescription
modeenum "inherit", "explicit"yesMode.
enabled_toolsarray of stringyesEnabled Tools.