---
title: "Update an MCP server."
method: PUT
path: "/mcpservers/{id}"
tags: ["AI"]
---

# Update an MCP server.

`PUT /mcpservers/{id}`

Every field is optional. Omitting a field leaves its current value unchanged; a full resend of every field is NOT required to update a single field (e.g. `PUT { "name": "new name" }` only renames the server and leaves url/status/auth_type/api_key_header/secret exactly as they were).

## Path parameters

- `id` string, uuid, required

## Request body

- object
  - `name` string — Omit to leave the current name unchanged.
  - `detail` string — Omit to leave the current detail unchanged.
  - `url` string, uri — Streamable-HTTP MCP endpoint. Must be https. Omit to leave the current URL unchanged. Immutable while auth_type is oauth (the OAuth flow, not this field, wrote it to the vendor's fixed endpoint): a request that changes it is rejected with MCP_SERVER_OAUTH_URL_IMMUTABLE, while re-submitting the current value is accepted so a client that resends every field on every save is never rejected.
  - `status` 'active' | 'disabled' — Set to disabled to stop VoIPBin connecting to this server, without deleting it: it is skipped during tool discovery immediately, and its tools will be excluded from every referencing AI when tool use ships. Omit to leave the current status unchanged.
  - `auth_type` '' | 'bearer' | 'api_key' | 'oauth' — Omit to leave the current auth_type unchanged. NOTE: an explicit empty string ("") is a valid value meaning no-auth, distinct from omitting the field. "oauth" is accepted only on a server that is already OAuth-connected, so a client that re-submits the current auth_type unchanged is never rejected; moving a server INTO oauth is done by completing the OAuth authorization flow, not by this field, and is rejected with INVALID_MCP_SERVER_AUTH_TYPE. Moving a connected server OUT of oauth is allowed and erases its stored OAuth tokens.
  - `api_key_header` string — Omit to leave the current api_key_header unchanged.
  - `secret` string — Omit this field to leave the existing secret unchanged. Send an empty string to clear it.

## Response `200`

Details of the updated MCP server.

- AIManagerMcpServer — A customer-registered remote MCP (Model Context Protocol) server. Excludes the stored secret entirely; `has_secret` indicates whether one is configured. Whitelist a server for an AI via that AI's `mcp_server_ids` field. **Tool use scope:** a whitelisted server's tools are presented to that AI's Normal-type, single-AI sessions; `type=insight` AIs, team-typed AI calls, and realtime voice call sessions never receive MCP tools.
  - `id` string, uuid — The unique identifier of the MCP server.
  - `customer_id` string, uuid — The unique identifier of the associated customer. Returned from the `GET /customers` response.
  - `name` string — Name of the MCP server.
  - `detail` string — Detailed description of the MCP server.
  - `url` string, uri — Streamable-HTTP MCP endpoint.
  - `status` 'active' | 'disabled' — disabled servers are excluded from tool list resolution and tool calls.
  - `auth_type` '' | 'bearer' | 'api_key' | 'oauth', required — How the outbound MCP call authenticates. Empty string sends no Authorization header. A server is moved INTO "oauth" only by completing POST /mcpservers/oauth/complete; sending "oauth" on a server that is not already connected is rejected. Re-sending the current "oauth" value on an already-connected server is accepted. Moving a connected server OUT of "oauth" is allowed and irreversibly erases its stored OAuth access and refresh tokens.
  - `api_key_header` string — Header name used when auth_type is api_key.
  - `oauth_vendor` 'github' | 'linear' — Which OAuth vendor this server is connected to. Only set when auth_type is "oauth"; it is cleared along with the stored tokens when a server is moved out of "oauth".
  - `has_secret` boolean, required — Whether a bearer token / API key / OAuth access token is configured. The secret/token value itself is never returned.
  - `tm_create` string, date-time — Timestamp when the MCP server was registered.
  - `tm_update` string, date-time — Timestamp when the MCP server was last updated.
  - `tm_delete` string, date-time — Timestamp when the MCP server was deleted.

## Other responses

- `400` — Invalid request (INVALID_ARGUMENT).
- `401` — Authentication required (UNAUTHENTICATED).
- `403` — Insufficient permission (PERMISSION_DENIED).
- `404` — Resource not found (NOT_FOUND).
- `500` — Internal error (INTERNAL).

## Changes

- **2026-09-28** `ad318d5b7879` — 1 info
  - added the new `oauth` enum value to the request property `auth_type`
- **2026-09-24** `3c004713c5fa` — 1 info
  - the response property `auth_type` became required for the status `200`
- **2026-09-12** `a5e92b1a8467` — 1 warning, 1 info
  - added the new `oauth` enum value to the `auth_type` response property for the response status `200`
  - added the optional property `oauth_vendor` to the response with the `200` status
- **2026-09-10** `f3996b9c5c48` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/voipbin/apis/voipbin-api/changes/mcpservers/:id/put.md)

---

[API](https://skmtc.dev/voipbin/apis/voipbin-api.md) · [All operations](https://skmtc.dev/voipbin/apis/voipbin-api/llms.txt) · [OpenAPI document](https://skmtc.dev/voipbin/apis/voipbin-api/revisions/6a2b13260ccc?raw)
