List hosted MCP providers

View as Markdown
Returns the catalogue of hosted MCP providers a workspace can connect with a single token (currently Make, Zapier and Alegra, in that order): their endpoint, recognised hostnames, transport, default approval mode, auth scheme, where the token is minted and the description the agent receives. Use it to build a "connect provider" screen, then call `POST /api/mcp-servers` with `provider` and `secretToken`. The content is static and identical for every workspace; it changes only with a Jelliu release. Nothing in it is secret. **Idempotency.** Read-only and safe to retry. **Access** - **Required scope:** `read` (or `write`). Any workspace role. - **Rate limit:** General API — 120 (Starter), 200 (Growth), 300 (Business) or 600 (Enterprise) requests/min per workspace. See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Response

The provider catalogue.
datalist of objects

Errors

401
Unauthorized Error
403
Forbidden Error
429
Too Many Requests Error