Retrieve an MCP server

View as Markdown
Returns one MCP server of the workspace, including the per-tool approval decisions currently applied in the voice engine (`toolOverrides`). The token and custom headers are never returned; there is no endpoint that reveals them. **Consistency.** Cached for up to 5 minutes; updates and deletes clear the entry before responding. **Idempotency.** Read-only and safe to retry. **Access** - **Required scope:** `read` (or `write`). Any workspace role. - **Rate limit:** General API — 120 (Starter), 200 (Growth), 300 (Business) or 600 (Enterprise) requests/min per workspace. See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Path parameters

mcpServerIdstringRequiredformat: "uuid"

UUID of the MCP server registration. It must belong to the authenticated workspace; an id from another workspace answers 404, exactly like an unknown one. Returned as id by GET /api/mcp-servers.

Response

The MCP server.
dataobject

A single MCP server as returned by the create, retrieve and update endpoints: the summary fields plus deleted_at and the applied per-tool decisions. secret_token and custom_headers are never returned.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error