Skip to main content
persona.mcps (+ persona.mcps.oauth) — /api/v1/developer/mcps. MCP (Model Context Protocol) connectors let your Agents call tools and read resources from external MCP servers. Project-owned, or — with externalUserId — owned by that end user.

Methods

Plus persona.mcps.oauth for OAuth flows — see OAuth connection flows below.

create(input, idempotencyKey?)

name, transport, and url are required.
Optional fields and defaults: McpOAuthInput is { clientId: string, clientSecret: string, scopes?: string[] }.
Creating an authType: 'oauth' MCP synchronously probes the target URL’s OAuth discovery endpoints — pointing it at a URL that doesn’t actually implement OAuth discovery will fail the create() call itself, not just a later connection test.

list(params?)

Lists/searches MCP servers visible to this credential. Returns PaginatedResult<Mcp>.

testConnection(mcpId)

Connects to the MCP server right now, lists its tools/resources/resource templates, and persists that summary onto the stored MCP document — so get()/list() reflect it afterward.
  • Returns { tools, resources, resourceTemplates }.
  • Until testConnection() has been called at least once, an MCP’s tools/resources/ resourceTemplates are empty arrays.

readResource(mcpId, uri)

Reads one MCP resource by URI (as opposed to calling a tool).
  • uri comes from mcp.resources/mcp.resourceTemplates (after filling any template params).
  • Returns { text: string, mimeType: string }.

callTool(mcpId, name, args?)

Invokes one tool exposed by this MCP server.
  • name — tool name, from mcp.tools.
  • args — arguments matching that tool’s own input schema (optional).
  • Returns unknown — the return shape is whatever the underlying MCP tool returns, inherently dynamic.

getUsage / delete

  • getUsage(mcpId) returns ResourceUsage — check before delete(); an MCP still referenced by an Agent rejects the delete.
  • delete(mcpId) deletes the MCP server. Returns void.

OAuth connection flows (mcps.oauth)

For authType: 'oauth' MCPs, mcps.oauth drives the owner- and user-mode authorization flows:
  • Owner-mode (authMode: 'owner') authorizes the MCP itself, shared by every user of your Project. Call getOwnerAuthorizeUrl() from a control-plane client and redirect your admin through it once.
  • User-mode (authMode: 'user') authorizes one specific end user’s own token. Call getUserAuthorizeUrl() from a runtime-plane client (externalUserId set) and redirect that user through it; returnTo is an optional client-chosen URL to send them back to once the flow completes. getUserConnectionStatus()/disconnectUserConnection() also require the runtime-plane client — the server rejects them with a 400 otherwise.
  • getOwnerAuthorizeUrl()/disconnectOwnerConnection() are control-plane calls.

Complete example