Skip to main content
Version: Latest (1.9.x dev)

MCP Gateway API

Use the MCP Gateway API when an agent needs governed access to registered tool servers. DVARA applies workspace policy, PII controls, approvals, loop detection, budgets, and audit before and after the upstream call.

Enterprise only

Not included in DVARA Open Source.

Choose the endpoint your client supports​

EndpointContractUse it for
POST /mcpMCP JSON-RPC over Streamable HTTPNative MCP clients; initialize, tools/list, and tools/call
DELETE /mcpMCP Streamable HTTPClose a native session
POST /mcp/{serverId}/tools/listJSON request and responseList one registered server's tools
POST /mcp/{serverId}/tools/callJSON request and responseCall one registered server's tool
POST /mcp/{serverId}/server/discoverJSON request and responseRead one server's advertised capabilities
POST /mcp/{serverId}/resources/{path}JSON request and responseUse resource operations on the server-scoped bridge
POST /mcp/{serverId}/prompts/{path}JSON request and responseUse prompt operations on the server-scoped bridge

The native endpoint implements tools in 1.8. It does not expose resources or prompts; use the server-scoped paths for those operations.

Authenticate the call​

Send a DVARA workspace API key as a bearer token. When OAuth is enabled, the native and server-scoped endpoints also accept an OAuth access token; API keys remain enabled by default. See Authenticate MCP clients with OAuth 2.1.

List the tools in a workspace​

Replace the host and credential before running this request:

curl --silent https://<dvara-host>/mcp \
--header 'Authorization: Bearer <your-credential>' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json, text/event-stream' \
--data '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {}
}'

A workspace with one support server receives namespaced tool names:

{
"jsonrpc": "2.0",
"id": 1,
"result": {
"tools": [
{
"name": "support__search_articles",
"description": "Search approved customer-support articles",
"inputSchema": {
"type": "object",
"properties": {"query": {"type": "string"}},
"required": ["query"]
}
}
]
}
}

Open Agents → Tool Calls to inspect calls. Tool discovery and calls also write MCP events to Governance → Audit.

Handle authentication and size failures​

A missing or invalid credential returns 401. An OAuth token without the required scope returns 403; an API key restricted away from the operation is also refused before the upstream runs.

The native endpoint limits the complete HTTP request body with dvara.mcp-gateway.limits.max-request-bytes. The default is 4 MiB. This is separate from the 1 MiB default limit applied to serialized tool arguments. A request over the body limit is refused before JSON-RPC processing, so reduce the payload or raise the operator-controlled limit deliberately.

For policy, PII, approvals, sessions, transports, and detailed JSON-RPC errors, continue with Govern tool calls with the MCP Gateway.