AI

Update an MCP server.

Every field is optional. Omitting a field leaves its current value unchanged; a full resend of every field is NOT required to update a single field (e.g. PUT { "name": "new name" } only renames the server and leaves url/status/auth_type/api_key_header/secret exactly as they were).

put/mcpservers/{id}

Path parameters

idstring uuid required

The MCP server ID.

Request body

namestring

Omit to leave the current name unchanged.

detailstring

Omit to leave the current detail unchanged.

urlstring uri

Streamable-HTTP MCP endpoint. Must be https. Omit to leave the current URL unchanged. Immutable while auth_type is oauth (the OAuth flow, not this field, wrote it to the vendor's fixed endpoint): a request that changes it is rejected with MCP_SERVER_OAUTH_URL_IMMUTABLE, while re-submitting the current value is accepted so a client that resends every field on every save is never rejected.

status'active' | 'disabled'

Set to disabled to stop VoIPBin connecting to this server, without deleting it: it is skipped during tool discovery immediately, and its tools will be excluded from every referencing AI when tool use ships. Omit to leave the current status unchanged.

auth_type'' | 'bearer' | 'api_key' | 'oauth'

Omit to leave the current auth_type unchanged. NOTE: an explicit empty string ("") is a valid value meaning no-auth, distinct from omitting the field. "oauth" is accepted only on a server that is already OAuth-connected, so a client that re-submits the current auth_type unchanged is never rejected; moving a server INTO oauth is done by completing the OAuth authorization flow, not by this field, and is rejected with INVALID_MCP_SERVER_AUTH_TYPE. Moving a connected server OUT of oauth is allowed and erases its stored OAuth tokens.

api_key_headerstring

Omit to leave the current api_key_header unchanged.

secretstring

Omit this field to leave the existing secret unchanged. Send an empty string to clear it.

Example request

{
  "status": "active"
}

Response

Details of the updated MCP server.

idstring uuid

The unique identifier of the MCP server.

customer_idstring uuid

The unique identifier of the associated customer. Returned from the GET /customers response.

namestring

Name of the MCP server.

detailstring

Detailed description of the MCP server.

urlstring uri

Streamable-HTTP MCP endpoint.

status'active' | 'disabled'

disabled servers are excluded from tool list resolution and tool calls.

auth_type'' | 'bearer' | 'api_key' | 'oauth' required

How the outbound MCP call authenticates. Empty string sends no Authorization header. A server is moved INTO "oauth" only by completing POST /mcpservers/oauth/complete; sending "oauth" on a server that is not already connected is rejected. Re-sending the current "oauth" value on an already-connected server is accepted. Moving a connected server OUT of "oauth" is allowed and irreversibly erases its stored OAuth access and refresh tokens.

api_key_headerstring

Header name used when auth_type is api_key.

oauth_vendor'github' | 'linear'

Which OAuth vendor this server is connected to. Only set when auth_type is "oauth"; it is cleared along with the stored tokens when a server is moved out of "oauth".

has_secretboolean required

Whether a bearer token / API key / OAuth access token is configured. The secret/token value itself is never returned.

tm_createstring date-time

Timestamp when the MCP server was registered.

tm_updatestring date-time

Timestamp when the MCP server was last updated.

tm_deletestring date-time

Timestamp when the MCP server was deleted.

Example response

{
  "id": "550e8400-e29b-41d4-a716-446655440000",
  "customer_id": "7c4d2f3a-1b8e-4f5c-9a6d-3e2f1a0b4c5d",
  "name": "Internal Ticketing System",
  "detail": "Exposes ticket lookup/creation tools to the LLM.",
  "url": "https://mcp.example.com/mcp",
  "status": "active",
  "auth_type": "bearer",
  "api_key_header": "X-API-Key",
  "oauth_vendor": "github",
  "has_secret": true,
  "tm_create": "2026-01-15T09:30:00.000000Z",
  "tm_update": "2026-01-15T09:30:00.000000Z",
  "tm_delete": "2026-01-15T09:30:00.000000Z"
}

Changes

Changed in 4 of the 97 revisions of this API.14

    • ○

      added the new oauth enum value to the request property

      request-property-enum-value-added

    • ○

      the response property became required for the status

      response-property-became-required

  • a5e92b1a846711See the full diff
    • ●

      added the new oauth enum value to the response property for the response status

      response-property-enum-value-added

    • ○

      added the optional property to the response with the status

      response-optional-property-added

    • ○

      endpoint added

      endpoint-added