MCP
Register an MCP upstream
POST
/api/w/:wid/mcp-upstreamsOwners and admins. Immiscible then asks the upstream what it offers (see discovery in the response). HTTPS only; private and internal addresses are refused as written and as resolved.
| Field | Description |
|---|---|
name | how people and the proxy URL know it |
url | the upstream’s address |
transport | mcp (Streamable HTTP) or http (a plain API described in httpTools) |
auth | { kind, secret, name } with kind one of none, bearer, header, query |
allowedTools | tool names, or ["*"]; empty means none |
toolMap | per-tool meaning: type, targetPath, amountPath, amountUnit, currency, merchantPath |
#Authentication
Session cookie
A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.
#Path parameters
widstringrequired
Workspace id