List an agent's MCP servers
Authentication
Path parameters
UUID of the agent. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/agents.
UUID of the agent. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/agents.
Returns the MCP servers assigned to the agent, i.e. the external tool sources the agent can
call. Credentials and per-tool decisions are never included; use
GET /api/mcp-servers/{mcpServerId} for a server’s toolOverrides.
Not paginated: at most 50 servers are returned, in no guaranteed order. The list includes the
platform’s own gateway row for the agent (it may carry a non-null agent_id) and hosted
providers attached automatically; it excludes the connected-apps tool surface managed under
Integrations. An agent id that does not exist in the workspace returns an empty list, not 404.
Consistency. Cached for up to 2 minutes; assigning or removing a server clears the cache before responding.
Idempotency. Read-only and safe to retry.
Access
read (or write). Any workspace role.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.