Skip to content

MCP

Register an MCP upstream

POST/api/w/:wid/mcp-upstreams

Owners and admins. Immiscible then asks the upstream what it offers (see discovery in the response). HTTPS only; private and internal addresses are refused as written and as resolved.

FieldDescription
namehow people and the proxy URL know it
urlthe upstream’s address
transportmcp (Streamable HTTP) or http (a plain API described in httpTools)
auth{ kind, secret, name } with kind one of none, bearer, header, query
allowedToolstool names, or ["*"]; empty means none
toolMapper-tool meaning: type, targetPath, amountPath, amountUnit, currency, merchantPath

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

#Path parameters

widstringrequired

Workspace id