Update Server
PUThttps://api.confident-ai.com/v2/mcp-servers/{mcpServerId}
Updates an MCP server and returns it. Only the fields you send change, and the merged result must be valid — switching transport needs that transport's required field in the same call. Omit authConfig.clientSecret to keep the stored secret; the masked clientSecretPreview you read back is ignored if you send it. Any successful update resets connected to false, so connect again afterwards.
curl -X PUT "https://api.confident-ai.com/v2/mcp-servers/{mcpServerId}" \
-H "CONFIDENT_API_KEY: <PROJECT-API-KEY>" \
-H "Content-Type: application/json" \
-d '{
"name": "Internal Tools",
"transport": "STDIO",
"description": "Internal engineering tools",
"url": "https://mcp.internal.example.com/sse",
"headers": {
"Authorization": "Bearer YOUR-TOKEN"
},
"authType": "HEADERS",
"authConfig": {
"tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
"clientId": "9a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d",
"clientSecret": "abc123~ExampleClientSecretValue",
"scope": "api://internal-tools/.default"
},
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem"
]
}'{
"success": true,
"data": {
"id": "<MCP-SERVER-ID>",
"name": "Internal Tools",
"description": "Internal engineering tools",
"transport": "STDIO",
"connected": true,
"url": "https://mcp.internal.example.com/sse",
"headers": {
"Authorization": "Bearer YOUR-TOKEN"
},
"authType": "HEADERS",
"authConfig": {
"tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
"clientId": "9a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d",
"scope": "api://internal-tools/.default",
"clientSecretPreview": "••••••••Xk3mZq"
},
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem"
],
"availableTools": [
{
"name": "search_issues",
"description": "Search issues in a repository",
"inputSchema": {
"type": "object"
},
"annotations": {
"readOnlyHint": true
}
}
]
},
"deprecated": false
}Headers
CONFIDENT_API_KEYstringRequiredThe API key of your Confident AI project.
Path parameters
mcpServerIdstringRequiredThe id of the MCP server.
Request body
namestringThe name of the MCP server, unique within the project.
transportenumHow Confident AI reaches the server.
HTTPrequiresurland is the only transport that authenticates;STDIOrequirescommandand launches the server as a local process.Show 2 enum valuesHide 2 enum values
STDIOHTTP
descriptionstring | nullWhat the MCP server is for. Send null to leave it unset.
urlstring | nullThe URL of the server. Required when
transportisHTTP, and cleared otherwise.headersobject | nullStatic headers sent with every request. Only used when
authTypeisHEADERS, and cleared otherwise. This map is stored as a whole rather than merged, so send every header you want to keep.authTypeenumHow Confident AI authenticates to the server.
HEADERSsends the staticheadersmap,OAUTH_CLIENT_CREDENTIALSandAZURE_ADfetch a token fromauthConfigbefore every call.HTTPtransport only; aSTDIOserver is alwaysHEADERS.Show 3 enum valuesHide 3 enum values
HEADERSOAUTH_CLIENT_CREDENTIALSAZURE_AD
authConfigobject | nullCredentials for a non-
HEADERSauth type. Unlikeheaders, these fields merge into what is stored, so send only the ones you are changing. Unknown keys are ignored, which is what lets you send back an object you read from the API without stripping itsclientSecretPreviewfirst.Show 4 propertiesHide 4 properties
tenantIdstringThe Azure AD directory (tenant) id. Required when
authTypeisAZURE_AD.clientIdstringThe OAuth client id. Required when
authTypeisAZURE_ADorOAUTH_CLIENT_CREDENTIALS.clientSecretstringThe OAuth client secret. Write-only: it is never returned, and
clientSecretPreviewcomes back in its place. Omit this field to leave the stored secret exactly as it is, or send a new value to replace it. ChangingauthTypediscards the stored secret, so a new one must be sent in the same call.scopestringThe OAuth scope to request. Required when
authTypeisAZURE_AD.
commandstring | nullThe command that launches the server. Required when
transportisSTDIO, and cleared otherwise.argslist of stringsThe arguments passed to
command.STDIOtransport only. This list is stored as a whole rather than appended to.
Response
Update Server succeeded.
successbooleanIndicates if the request was successful.
dataobjectAn MCP server registered with your project: how Confident AI reaches it, how it authenticates, and the tools the last connection found. The stored OAuth client secret is never returned —
authConfig.clientSecretPreviewmasks it.Show 12 propertiesHide 12 properties
idstringThe id of the MCP server, generated by Confident AI.
namestringThe name of the MCP server.
descriptionstring | nullWhat the MCP server is for.
transportenumHow Confident AI reaches the server.
HTTPrequiresurland is the only transport that authenticates;STDIOrequirescommandand launches the server as a local process.Show 2 enum valuesHide 2 enum values
STDIOHTTP
connectedbooleanWhether the last connection attempt succeeded. Set by the connect route, and reset to false by any update.
urlstring | nullThe URL of the server. Only set when
transportisHTTP.headersobject | nullThe static headers sent with every request, returned as stored. Only set when
authTypeisHEADERS.authTypeenumHow Confident AI authenticates to the server.
HEADERSsends the staticheadersmap,OAUTH_CLIENT_CREDENTIALSandAZURE_ADfetch a token fromauthConfigbefore every call.HTTPtransport only; aSTDIOserver is alwaysHEADERS.Show 3 enum valuesHide 3 enum values
HEADERSOAUTH_CLIENT_CREDENTIALSAZURE_AD
authConfigobject | nullThe stored credentials with the secret removed:
clientSecretnever leaves Confident AI, and a maskedclientSecretPreviewstands in for it.Show 4 propertiesHide 4 properties
tenantIdstringThe Azure AD directory (tenant) id, as stored.
clientIdstringThe OAuth client id, as stored.
scopestringThe OAuth scope requested, as stored.
clientSecretPreviewstringA mask of the stored OAuth client secret — bullets followed by its last six characters — so you can tell which secret is stored without reading it. This is not a credential and sending it back sets nothing: to leave the stored secret alone omit
clientSecretfrom your update, and to change it send the new secret inclientSecret.
commandstring | nullThe command that launches the server. Only set when
transportisSTDIO.argslist of stringsThe arguments passed to
command. Empty unlesstransportisSTDIO.availableToolslist of objects | nullShow 4 propertiesHide 4 properties
namestringThe name of the tool, as the server reports it.
descriptionstring | nullWhat the tool does, or null when the server describes it.
inputSchemaobjectThe JSON Schema describing the tool's arguments.
annotationsobject | null
deprecatedbooleanIndicates if this endpoint is deprecated.