curl --request POST \
--url https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"authHeaderName": "Authorization",
"secret": "Bearer ul_mcp_4Rt9…"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Inventory',
url: 'https://mcp.urbanloom.in/mcp',
transport: 'http',
authHeaderName: 'Authorization',
secret: 'Bearer ul_mcp_4Rt9…'
})
};
fetch('https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers"
payload = {
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"authHeaderName": "Authorization",
"secret": "Bearer ul_mcp_4Rt9…"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18",
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"signIn": "token",
"kind": "server",
"authHeaderName": "Authorization",
"hasSecret": true,
"status": "connected",
"lastError": null,
"lastSyncedAt": "2026-10-06T10:22:31.402Z",
"tools": [
{
"id": "tool_a2c47e19-3b5d-4f60-8e91-7d0b2c6f4a35",
"name": "check_stock",
"description": "Stock on hand for a product SKU, by warehouse.",
"enabled": false
},
{
"id": "tool_c9e03b72-61f4-4a8d-b257-0e4d9a1c3f86",
"name": "find_order",
"description": "An order's status and courier tracking by order number.",
"enabled": false
},
{
"id": "tool_f1b8d6a4-2e7c-4935-a0d1-6c3e9b5f7a20",
"name": "list_collections",
"description": "The store's current collections.",
"enabled": false
}
],
"createdAt": "2026-10-06T10:22:29.918Z",
"message": "Found 3 tools. All start off."
}Connect Tool Server
Connect an MCP tool server that takes a token (or none). It is asked for its tools at once and every tool arrives off — switch each on with PATCH …/tools/{toolId}. A server that cannot be reached is still saved and answers 201 with status: "failed" and the reason in message, so you can fix it and sync. A server that signs in through a browser must be connected in the console. A build key may do this.
curl --request POST \
--url https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"authHeaderName": "Authorization",
"secret": "Bearer ul_mcp_4Rt9…"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Inventory',
url: 'https://mcp.urbanloom.in/mcp',
transport: 'http',
authHeaderName: 'Authorization',
secret: 'Bearer ul_mcp_4Rt9…'
})
};
fetch('https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers"
payload = {
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"authHeaderName": "Authorization",
"secret": "Bearer ul_mcp_4Rt9…"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18",
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"signIn": "token",
"kind": "server",
"authHeaderName": "Authorization",
"hasSecret": true,
"status": "connected",
"lastError": null,
"lastSyncedAt": "2026-10-06T10:22:31.402Z",
"tools": [
{
"id": "tool_a2c47e19-3b5d-4f60-8e91-7d0b2c6f4a35",
"name": "check_stock",
"description": "Stock on hand for a product SKU, by warehouse.",
"enabled": false
},
{
"id": "tool_c9e03b72-61f4-4a8d-b257-0e4d9a1c3f86",
"name": "find_order",
"description": "An order's status and courier tracking by order number.",
"enabled": false
},
{
"id": "tool_f1b8d6a4-2e7c-4935-a0d1-6c3e9b5f7a20",
"name": "list_collections",
"description": "The store's current collections.",
"enabled": false
}
],
"createdAt": "2026-10-06T10:22:29.918Z",
"message": "Found 3 tools. All start off."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
The agent's id (ag_…).
Body
Your name for it, 2 to 200 characters.
2 - 200Its https:// address. It must be publicly reachable: private and internal addresses are refused.
2000http (streamable HTTP) or sse.
http, sse The header to send the token in, e.g. Authorization. Required when secret is sent.
200The header's value, e.g. Bearer …. Write-only: sealed on arrival; responses say only hasSecret.
8000Response
Saved — check status to see whether discovery worked.
The server's id, mcp_….
"mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18"
Your name for it.
Its https:// address.
How it is spoken to.
http, sse token for a server reached with a header you sent; browser for one signed in through the console.
token, browser server for a tool server; store for a store connection made in the console, whose tools are a fixed list.
server, store The header the token is sent in.
Whether a token is held. The token itself is never returned.
connected once it answered with its tools; failed when it could not be reached (see lastError); pending before the first answer.
Why the last attempt failed.
When it last listed its tools.
What it offers, by name.
Show child attributes
Show child attributes
When it was connected.
What happened — how many tools were found, or why it could not be reached.