---
title: "Update Interface-Source Capability Controls"
method: PATCH
path: "/v1/context-interfaces/{interfaceId}/context-source-mappings/{mappingId}/capability-controls"
tags: ["Context Interface Capability Controls"]
---

# Update Interface-Source Capability Controls

`PATCH /v1/context-interfaces/{interfaceId}/context-source-mappings/{mappingId}/capability-controls`

**Pre-release Endpoint**
This endpoint is currently in beta and is subject to change.

Partially update the capability controls configured for a context interface-source mapping. Omitted deny keys preserve their existing value, an empty array clears a capability, and a non-empty array replaces.

## Request body

- union — The capability controls to merge into the existing configuration for a mapped context source. Omitted deny keys preserve their current value, an empty array clears a capability, and a non-empty array replaces.
  - PatchAPICapabilityControls — Partial capability controls for a mapping to an API MCP resource.
    - `type` 'api', required — The type of the mapped MCP resource.
    - `deny` PatchAPICapabilityControlsDeny, required — The capabilities of the mapped API to deny. Omitted keys preserve their current value, an empty array clears the capability, and a non-empty array replaces.
      - `operations` APICapabilityControlsOperation[] — The API operations that are denied.
        - `path` string, required — The path of the API operation.
        - `methods` string[], required — The HTTP methods of the API operation that are denied.
  - PatchMCPCapabilityControls — Partial capability controls for a mapping to an MCP server MCP resource.
    - `type` 'mcp_server', required — The type of the mapped MCP resource.
    - `deny` PatchMCPCapabilityControlsDeny, required — The capabilities of the mapped MCP server to deny. Omitted keys preserve their current value, an empty array clears the capability, and a non-empty array replaces.
      - `tools` string[] — The names of the tools that are denied.
      - `resources` string[] — The URIs of the resources that are denied.
      - `prompts` string[] — The names of the prompts that are denied.

## Response `200`

A response to updating the capability controls for a Context Interface-Source mapping.

- union — The capabilities of a mapped MCP resource that the MCP server does not expose.
  - APICapabilityControls — Capability controls for a mapping to an API MCP resource.
    - `type` 'api', required — The type of the mapped MCP resource.
    - `deny` APICapabilityControlsDeny, required — The capabilities of the mapped API that are denied.
      - `operations` APICapabilityControlsOperation[], required — The API operations that are denied.
        - `path` string, required — The path of the API operation.
        - `methods` string[], required — The HTTP methods of the API operation that are denied.
  - MCPCapabilityControls — Capability controls for a mapping to an MCP server MCP resource.
    - `type` 'mcp_server', required — The type of the mapped MCP resource.
    - `deny` MCPCapabilityControlsDeny, required — The capabilities of the mapped MCP server that are denied.
      - `tools` string[], required — The names of the tools that are denied.
      - `resources` string[], required — The URIs of the resources that are denied.
      - `prompts` string[], required — The names of the prompts that are denied.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — The MCP resource mapping does not exist, or it has no capability controls configured.

## Changes

- **2026-09-30** `de79e1192f11` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/kong/apis/konnect-api-go-sdk/changes/v1/context-interfaces/:interfaceId/context-source-mappings/:mappingId/capability-controls/patch.md)

---

[API](https://skmtc.dev/kong/apis/konnect-api-go-sdk.md) · [All operations](https://skmtc.dev/kong/apis/konnect-api-go-sdk/llms.txt) · [OpenAPI document](https://skmtc.dev/kong/apis/konnect-api-go-sdk/revisions/de79e1192f11?raw)
