Skip to main content
POST
Sync Tool Server

Authorizations

Authorization
string
header
required

Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.

Headers

Thinnest-Workspace
string

Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.

Example:

"org_3fKq9TzQ1mN8vB2xR7cLpA"

Path Parameters

id
string
required

The agent's id (ag_…).

serverId
string
required

The tool server's id, mcp_…. The bare uuid is accepted too.

Response

The server after the sync.

id
string
required

The server's id, mcp_….

Example:

"mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18"

name
string
required

Your name for it.

url
string
required

Its https:// address.

transport
enum<string>
required

How it is spoken to.

Available options:
http,
sse
signIn
enum<string>
required

token for a server reached with a header you sent; browser for one signed in through the console.

Available options:
token,
browser
kind
enum<string>
required

server for a tool server; store for a store connection made in the console, whose tools are a fixed list.

Available options:
server,
store
authHeaderName
string | null
required

The header the token is sent in.

hasSecret
boolean
required

Whether a token is held. The token itself is never returned.

status
string
required

connected once it answered with its tools; failed when it could not be reached (see lastError); pending before the first answer.

lastError
string | null
required

Why the last attempt failed.

lastSyncedAt
string<date-time> | null
required

When it last listed its tools.

tools
object[]
required

What it offers, by name.

createdAt
string<date-time>
required

When it was connected.

message
string | null
required

What happened — how many tools were found, or why it could not be reached.