Revoke the MCP access token
Deletes the stored MCP access token, so external clients using it stop being authenticated. Admin only.
curl -X DELETE "https://example.com/api/ai/mcp/token"MCP JSON-RPC endpoint POST
A Model Context Protocol server over JSON-RPC (Streamable HTTP). Supports `initialize`, `ping`, `tools/list`, and `tools/call`. Authenticate with the MCP bearer token (external clients) or a signed-in session. A client sees only the tools switched on in the MCP tab of the Assistant settings (`mcpTools` on `GET /api/ai/settings`; null means the recommended set), and each call is gated by the token's (or user's) role. `initialize` returns an `Mcp-Session-Id` header to send on later requests. Protocol versions 2024-11-05, 2025-03-26, and 2025-06-18 are accepted. Send `Accept: text/event-stream` to receive the reply as a Server-Sent Event; a `tools/call` that carries a progress token streams progress notifications before its result.
Send a user message POST
Stores a user message and starts the turn server-side, so it runs to completion even if the client navigates away. Open the stream endpoint to follow along.