A valid request URL is required to generate request examples{
"jsonrpc": "2.0",
"id": "<string>",
"result": {},
"error": {
"code": 123,
"message": "<string>",
"data": {}
}
}{
"jsonrpc": "2.0",
"id": null,
"error": {
"code": -32001,
"message": "<string>",
"data": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Send a JSON-RPC request
The Model Context Protocol endpoint. It speaks JSON-RPC over one request and one response, so it is a single operation here rather than one per tool: a document that flattened the tools into endpoints would describe a protocol the service does not speak, and a client written against it would fail on the first call. The tools, their parameters and their results are documented in the tool reference.
The endpoint is stateless. There is no session to open or terminate, and a lease travels as an explicit tool parameter. Requests carrying a browser Origin are refused, and the Host header must match the deployment’s own host.
A valid request URL is required to generate request examples{
"jsonrpc": "2.0",
"id": "<string>",
"result": {},
"error": {
"code": 123,
"message": "<string>",
"data": {}
}
}{
"jsonrpc": "2.0",
"id": null,
"error": {
"code": -32001,
"message": "<string>",
"data": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Body
A JSON-RPC 2.0 request.
A JSON-RPC 2.0 request. The method vocabulary is the Model Context Protocol's, and the tools you may call depend on the scopes your credential carries.
Response
The JSON-RPC response. A tool that FAILED still answers 200: branch on isError inside the result, not on the status code.