Delete an MCP server

View as Markdown
Removes a server from the workspace and from every agent that uses it. To take it away from a single agent only, use `DELETE /api/agents/{agentId}/mcp-servers/{mcpServerId}`. The server is detached agent by agent first (each agent's list is re-pushed to the voice engine, with retries). If any agent cannot be detached, that agent keeps the server, nothing is deleted, and `502` is returned: deleting it would leave that agent pointing at a server that does not exist, which breaks its calls. Agents detached before the failure stay detached. Retry later. Per-agent gateway rows managed by the platform answer 404. **Side effects.** Updates every affected agent in the voice engine, deletes the registration there (a provider-side failure is queued for automatic retry and does not fail the request), then soft-deletes the server. Writes an `mcp.manage` audit entry. **Idempotency.** Safe to retry: a repeat call answers `404`. A retry after a `502` continues with the agents that are still attached. **Webhook events.** `audit.log_recorded` for the audit entry, if you subscribe to it. See [Webhooks](/webhooks). **Access** - **Required scope:** `write`. Any workspace role. - **Rate limit:** General API — 120 (Starter), 200 (Growth), 300 (Business) or 600 (Enterprise) requests/min per workspace, checked by two counters of the same size. See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Path parameters

mcpServerIdstringRequiredformat: "uuid"

UUID of the MCP server registration. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/mcp-servers.

Response

Deleted. No body.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error
502
Bad Gateway Error