curl --request PATCH \
--url https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enabled: true})
};
fetch('https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId}"
payload = { "enabled": True }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18",
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"signIn": "token",
"kind": "server",
"authHeaderName": "Authorization",
"hasSecret": true,
"status": "connected",
"lastError": null,
"lastSyncedAt": "2026-10-06T10:22:31.402Z",
"tools": [
{
"id": "tool_a2c47e19-3b5d-4f60-8e91-7d0b2c6f4a35",
"name": "check_stock",
"description": "Stock on hand for a product SKU, by warehouse.",
"enabled": true
},
{
"id": "tool_c9e03b72-61f4-4a8d-b257-0e4d9a1c3f86",
"name": "find_order",
"description": "An order's status and courier tracking by order number.",
"enabled": true
},
{
"id": "tool_f1b8d6a4-2e7c-4935-a0d1-6c3e9b5f7a20",
"name": "list_collections",
"description": "The store's current collections.",
"enabled": false
}
],
"createdAt": "2026-10-06T10:22:29.918Z"
}{
"error": "`enabled` must be true or false."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "That tool was not found."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Update Tool Server Tool
Switch one of a server’s tools on or off. On, it is callable from every conversation the agent has. Answers with the server and all its tools. A build key may do this.
curl --request PATCH \
--url https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({enabled: true})
};
fetch('https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/agents/{id}/mcp-servers/{serverId}/tools/{toolId}"
payload = { "enabled": True }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18",
"name": "Inventory",
"url": "https://mcp.urbanloom.in/mcp",
"transport": "http",
"signIn": "token",
"kind": "server",
"authHeaderName": "Authorization",
"hasSecret": true,
"status": "connected",
"lastError": null,
"lastSyncedAt": "2026-10-06T10:22:31.402Z",
"tools": [
{
"id": "tool_a2c47e19-3b5d-4f60-8e91-7d0b2c6f4a35",
"name": "check_stock",
"description": "Stock on hand for a product SKU, by warehouse.",
"enabled": true
},
{
"id": "tool_c9e03b72-61f4-4a8d-b257-0e4d9a1c3f86",
"name": "find_order",
"description": "An order's status and courier tracking by order number.",
"enabled": true
},
{
"id": "tool_f1b8d6a4-2e7c-4935-a0d1-6c3e9b5f7a20",
"name": "list_collections",
"description": "The store's current collections.",
"enabled": false
}
],
"createdAt": "2026-10-06T10:22:29.918Z"
}{
"error": "`enabled` must be true or false."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "That tool was not found."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
The agent's id (ag_…).
The tool server's id, mcp_…. The bare uuid is accepted too.
The tool's id on that server, tool_…, from the server's tools. The bare uuid is accepted too.
Body
true lets the agent call this tool in every conversation; false takes it away.
Response
The server, with the tool switched.
The server's id, mcp_….
"mcp_5e1d2c7a-8b94-4f06-a3d1-2c9e7b5f0a18"
Your name for it.
Its https:// address.
How it is spoken to.
http, sse token for a server reached with a header you sent; browser for one signed in through the console.
token, browser server for a tool server; store for a store connection made in the console, whose tools are a fixed list.
server, store The header the token is sent in.
Whether a token is held. The token itself is never returned.
connected once it answered with its tools; failed when it could not be reached (see lastError); pending before the first answer.
Why the last attempt failed.
When it last listed its tools.
What it offers, by name.
Show child attributes
Show child attributes
When it was connected.