Per-organization MCP Streamable HTTP (GET)
The GET channel of the per-organization MCP Streamable HTTP transport. This server runs in stateless mode (no standalone server-initiated SSE stream), so GET returns 405; clients POST JSON-RPC messages instead. Requires the mcp:read permission.
GET
/api/mcp/o/{org}AuthorizationBearer <token>
OIDC-issued JWT (device-flow access token for the interactive CLI, or authorization-code access token for dashboard second-party apps). X-Org-Id is required for org-scoped routes when the token is instance-level.
In: header
Path Parameters
org*string
Organization id (uuid). Identifies the organization this MCP endpoint is bound to.
curl -X GET "https://your-instance/api/mcp/o/string"{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"param": "string",
"retry_after": 0,
"errors": [
{
"field": "string",
"code": "string",
"message": "string",
"title": "string",
"candidate_connections": [
{
"id": "string",
"label": "string",
"account_id": "string",
"owned_by_actor": true,
"needs_reconnection": true
}
],
"connection_id": "string",
"missing_scopes": [
"string"
],
"owned_by_actor": true,
"required_scopes": [
"string"
],
"auth_key": "string",
"required_auth_key": "string",
"available_auth_keys": [
"string"
],
"connect_url": "http://example.com",
"expiresAt": "2019-08-24T14:15:22Z",
"packageId": "string"
}
]
}