persona.mcps (+ persona.mcps.oauth) — /api/v1/developer/mcps.
MCP (Model Context Protocol) connectors let your Agents call tools and read resources from
external MCP servers. Project-owned, or — with externalUserId — owned by that end user.
Methods
Plus
persona.mcps.oauth for OAuth flows — see
OAuth connection flows below.
create(input, idempotencyKey?)
name, transport, and url are required.
McpOAuthInput is { clientId: string, clientSecret: string, scopes?: string[] }.
Creating an
authType: 'oauth' MCP synchronously probes the target URL’s OAuth discovery
endpoints — pointing it at a URL that doesn’t actually implement OAuth discovery will fail the
create() call itself, not just a later connection test.list(params?)
PaginatedResult<Mcp>.
testConnection(mcpId)
Connects to the MCP server right now, lists its tools/resources/resource templates, and persists that summary onto the stored MCP document — soget()/list() reflect it afterward.
- Returns
{ tools, resources, resourceTemplates }. - Until
testConnection()has been called at least once, an MCP’stools/resources/resourceTemplatesare empty arrays.
readResource(mcpId, uri)
Reads one MCP resource by URI (as opposed to calling a tool).uricomes frommcp.resources/mcp.resourceTemplates(after filling any template params).- Returns
{ text: string, mimeType: string }.
callTool(mcpId, name, args?)
Invokes one tool exposed by this MCP server.name— tool name, frommcp.tools.args— arguments matching that tool’s own input schema (optional).- Returns
unknown— the return shape is whatever the underlying MCP tool returns, inherently dynamic.
getUsage / delete
getUsage(mcpId)returnsResourceUsage— check beforedelete(); an MCP still referenced by an Agent rejects the delete.delete(mcpId)deletes the MCP server. Returnsvoid.
OAuth connection flows (mcps.oauth)
For authType: 'oauth' MCPs, mcps.oauth drives the owner- and user-mode authorization flows:
- Owner-mode (
authMode: 'owner') authorizes the MCP itself, shared by every user of your Project. CallgetOwnerAuthorizeUrl()from a control-plane client and redirect your admin through it once. - User-mode (
authMode: 'user') authorizes one specific end user’s own token. CallgetUserAuthorizeUrl()from a runtime-plane client (externalUserIdset) and redirect that user through it;returnTois an optional client-chosen URL to send them back to once the flow completes.getUserConnectionStatus()/disconnectUserConnection()also require the runtime-plane client — the server rejects them with a 400 otherwise. getOwnerAuthorizeUrl()/disconnectOwnerConnection()are control-plane calls.