AI

Complete the vendor OAuth flow for an MCP server connection.

Verifies the state/link_token belongs to the authenticated customer, exchanges the vendor authorization code for tokens, encrypts them at rest, and creates (or updates, for a reconnect) the customer's McpServer row.

post/mcpservers/oauth/complete

Request body

statestring required

The link_token returned by POST /mcpservers/oauth/start.

codestring required

The vendor authorization code from the GET /mcpservers/oauth/callback redirect.

Example request

{
  "state": "9f2c1e7a4b3d4f5e8a9b0c1d2e3f4a5b",
  "code": "8a3b1c9d0e2f"
}

Response

The connected MCP server.

idstring uuid

The unique identifier of the MCP server.

customer_idstring uuid

The unique identifier of the associated customer. Returned from the GET /customers response.

namestring

Name of the MCP server.

detailstring

Detailed description of the MCP server.

urlstring uri

Streamable-HTTP MCP endpoint.

status'active' | 'disabled'

disabled servers are excluded from tool list resolution and tool calls.

auth_type'' | 'bearer' | 'api_key' | 'oauth' required

How the outbound MCP call authenticates. Empty string sends no Authorization header. A server is moved INTO "oauth" only by completing POST /mcpservers/oauth/complete; sending "oauth" on a server that is not already connected is rejected. Re-sending the current "oauth" value on an already-connected server is accepted. Moving a connected server OUT of "oauth" is allowed and irreversibly erases its stored OAuth access and refresh tokens.

api_key_headerstring

Header name used when auth_type is api_key.

oauth_vendor'github' | 'linear'

Which OAuth vendor this server is connected to. Only set when auth_type is "oauth"; it is cleared along with the stored tokens when a server is moved out of "oauth".

has_secretboolean required

Whether a bearer token / API key / OAuth access token is configured. The secret/token value itself is never returned.

tm_createstring date-time

Timestamp when the MCP server was registered.

tm_updatestring date-time

Timestamp when the MCP server was last updated.

tm_deletestring date-time

Timestamp when the MCP server was deleted.

Example response

{
  "id": "550e8400-e29b-41d4-a716-446655440000",
  "customer_id": "7c4d2f3a-1b8e-4f5c-9a6d-3e2f1a0b4c5d",
  "name": "Internal Ticketing System",
  "detail": "Exposes ticket lookup/creation tools to the LLM.",
  "url": "https://mcp.example.com/mcp",
  "status": "active",
  "auth_type": "bearer",
  "api_key_header": "X-API-Key",
  "oauth_vendor": "github",
  "has_secret": true,
  "tm_create": "2026-01-15T09:30:00.000000Z",
  "tm_update": "2026-01-15T09:30:00.000000Z",
  "tm_delete": "2026-01-15T09:30:00.000000Z"
}

Changes

Changed in 2 of the 97 revisions of this API.2