Per-organization MCP Streamable HTTP endpoint
Model Context Protocol server (Streamable HTTP, stateless) for a single organization. Accepts JSON-RPC 2.0 messages (initialize, tools/list, tools/call). The tools it declares follow the caller's permissions: the read-only set (search_operations, describe_operation, read_file, read_skill, validate_package_file, get_runtime_capabilities, and get_me unless the client injects its own caller context) is always present, while the acting tools — invoke_operation (mcp:invoke), run_and_wait (mcp:invoke plus agents:run and a run-read permission), list_files (whatever guards the listFiles operation's own route) and import_package_file — are declared only to a caller whose grants make them usable, so tools/list differs by role. Together they let an MCP client discover and call platform API operations, plus launch and wait for agent runs, with the caller's own credentials and confined to the organization in the path. Each organization has its own endpoint: a token obtained for this endpoint is audience-bound (RFC 8707) to the per-org resource URI <APP_URL>/api/mcp/o/{org} and cannot drive any other organization. To use several organizations, configure one MCP server entry per organization. Requires the mcp:read permission (and mcp:invoke to call operations).
/api/mcp/o/{org}OIDC-issued JWT (device-flow access token for the interactive CLI, or authorization-code access token for dashboard second-party apps). X-Org-Id is required for org-scoped routes when the token is instance-level.
In: header
Path Parameters
Organization id (uuid). Identifies the organization this MCP endpoint is bound to.
Request Body
application/json
curl -X POST "https://your-instance/api/mcp/o/string" \ -H "Content-Type: application/json" \ -d '{ "jsonrpc": "2.0", "method": "string" }'{}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}