Skip to main content

MCP policy

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: mcp-policy · 3 operations

GET /v1/tenants/{tenant_slug}/mcp-policy​

Get tenant MCP policy

Return the tenant's MCP tool governance policy (ceiling, default enable-set, anonymous flags). Tenant members may read; an unseeded tenant synthesizes default_mode=all with an empty tools list (MTG-3.1, #4775).

Operation id: get_tenant_mcp_policy_v1_tenants__tenant_slug__mcp_policy_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get tenant mcp policy.application/json TenantMcpPolicyResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/tenants/{tenant_slug}/mcp-policy​

Replace tenant MCP policy

Replace the tenant MCP policy (default_mode, anonymous kill switch, and full per-tool flag list). Tenant administrators with a signed-in session only; API keys cannot mutate governance. Unknown tool ids and default_enabled without in_ceiling yield 422 (MTG-3.1, #4775; MTG-3.4, #4778). Non-noop writes append a policy change audit row (MTG-5.2, #4786).

Operation id: put_tenant_mcp_policy_v1_tenants__tenant_slug__mcp_policy_put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for replace tenant mcp policy.

Responses

StatusDescriptionBody
200Successful response for replace tenant mcp policy.application/json TenantMcpPolicyResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/tenants/{tenant_slug}/mcp-policy/history​

List tenant MCP policy change history

Return newest-first append-only MCP policy change events with before/after tool-enablement snapshots (MTG-5.2, #4786). Tenant members may read.

Operation id: list_tenant_mcp_policy_history_v1_tenants__tenant_slug__mcp_policy_history_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
limitqueryintegernoMax change rows to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list tenant mcp policy change history.application/json TenantMcpPolicyHistoryResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

TenantMcpPolicyHistoryResponse​

Newest-first list of tenant MCP policy changes.

PropertyTypeRequiredDescription
changesarray of TenantMcpPolicyChangeEntrynoChanges.

TenantMcpPolicyPutRequest​

Writable tenant MCP policy body for PUT …/mcp-policy.

PropertyTypeRequiredDescription
default_modeenum "all", "inherit_registry", "explicit"yesHow missing tool rows resolve: all, inherit_registry, or explicit.
allow_anonymous_mcpbooleannoKill switch for anonymous tools/call against this tenant policy.
toolsarray of TenantMcpPolicyToolnoFull replace-all list of per-tool policy flags.

TenantMcpPolicyResponse​

Stored (or synthesized unseeded) tenant MCP policy snapshot.

PropertyTypeRequiredDescription
default_modeenum "all", "inherit_registry", "explicit"yesDefault Mode.
allow_anonymous_mcpbooleanyesAllow Anonymous MCP.
toolsarray of TenantMcpPolicyToolyesTools.
updated_atstring (date-time) or nullnoLast policy write time; null when no row has been persisted.
updated_bystring or nullnoUser id of the last writer; null until first admin PUT after seed.