Skip to main content
Glama

integrations_add_endpoints

Add one or more API endpoints to an HTTP-API integration as callable tools, merged additively into the integration for base_url (created if none exists). Each endpoint becomes a tool with params + request/response schemas inferred from the samples you pass. When CREATING a new integration, provide auth: either identity (saved Browser Identity name/id) for cookie-session APIs, OR an auth block for token/header APIs, e.g. {type:'bearer', token:'...'} or {type:'api_key', token:'...', header_name:'X-API-Key'}. Updates keep the existing auth unless a new auth is passed. Returns the new tool count and names. Refresh the tools list afterwards to use them.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
authNoAuth block for a NEW token/header integration (or to change auth on update): {type: none|bearer|api_key|basic|custom_headers, ...}. bearer/basic → {token}; api_key → {token, header_name?}; custom_headers → {headers:{name:value,...}}. Token values are encrypted. Omit for browser_identity (use `identity`) or to keep existing auth.
nameNoDisplay name. OMIT to keep an existing integration's name, or to name a NEW one after its host.
extractNoExplicit browser_identity auth extract for a NEW integration when auto-detect can't find one. One block, e.g. {kind:'cookie', name:'_session', value_format:'raw', header_name:'Cookie', header_template:'{{name}}={{value}}'} — or a LIST of blocks, merged, which is what a session-cookie API needs: the session in Cookie AND a CSRF header echoing one cookie back: {kind:'composite', blocks:[{kind:'cookies', origin:'https://app.example.com'}, {kind:'cookie', name:'xsrf_token', header_name:'x-xsrf-token'}]}; add value_format:'urlencoded' when the site keeps that cookie percent-encoded (Laravel's XSRF-TOKEN; a 419 means this). kind 'cookies' sends every live cookie for that origin (the only way to send an HttpOnly session cookie); its origin must cover the integration's base_url host. Updates reuse existing auth, so omit then.
base_urlYesAPI base URL of the integration, e.g. https://api.boomnow.com
identityNoSaved Browser Identity name or numeric id — one way to auth a NEW cookie-session integration (updates reuse existing auth). For token/header APIs use `auth` instead.
endpointsYesEndpoints to add. Each: {method, path, query?(object), request_body?(object sample), response_body?(object/array sample)}. path is relative to base_url, e.g. /api/conversations/all.
const_fieldsNoRequest-body fields that NEVER vary, as dotted paths into the sample body — e.g. ['query', 'operationName'] for a GraphQL endpoint, or ['envelope.version']. Their value is taken from the sample, pinned server-side, and HIDDEN from the model: it can neither see nor mistype them, and only the parts that actually change (variables, ids, dates) stay in the tool's arguments. Use for GraphQL documents, SOAP envelopes, API versions and tenant ids.
in_workspaceNoRun this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.
keepalive_operationNooperationId the session keep-alive should ping to hold a cookie session open, e.g. 'getHomeWidgetAlerts'. Must be a param-less GET on this integration. Set it when the API has no obvious session probe in its names (the sweeper looks for validate/session/me/whoami/health) AND its session idles out in hours: without it such an integration only gets the hourly origin warm and dies overnight. Carried over on later updates; OMIT to leave it unchanged.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / extract / description
      Previous value: -"Explicit browser_identity auth extract for a NEW integration when auto-detect can't find one. One block, e.g. {kind:'cookie', name:'_session', value_format:'raw', header_name:'Cookie', header_template:'{{name}}={{value}}'} — or a LIST of blocks, merged, which is what a session-cookie API needs: the session in Cookie AND a CSRF header echoing one cookie back: {kind:'composite', blocks:[{kind:'cookies', origin:'https://app.example.com'}, {kind:'cookie', name:'xsrf_token', header_name:'x-xsrf-token'}]}. kind 'cookies' sends every live cookie for that origin (the only way to send an HttpOnly session cookie); its origin must cover the integration's base_url host. Updates reuse existing auth, so omit then."New value: +"Explicit browser_identity auth extract for a NEW integration when auto-detect can't find one. One block, e.g. {kind:'cookie', name:'_session', value_format:'raw', header_name:'Cookie', header_template:'{{name}}={{value}}'} — or a LIST of blocks, merged, which is what a session-cookie API needs: the session in Cookie AND a CSRF header echoing one cookie back: {kind:'composite', blocks:[{kind:'cookies', origin:'https://app.example.com'}, {kind:'cookie', name:'xsrf_token', header_name:'x-xsrf-token'}]}; add value_format:'urlencoded' when the site keeps that cookie percent-encoded (Laravel's XSRF-TOKEN; a 419 means this). kind 'cookies' sends every live cookie for that origin (the only way to send an HttpOnly session cookie); its origin must cover the integration's base_url host. Updates reuse existing auth, so omit then."
  2. Changed1 schema field changed
    • addedInput schema / properties / in_workspace
      Added value: +{
      +  "description": "Run this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.",
      +  "type": "integer"
      +}
  3. Changed1 schema field changed
    • changedInput schema / properties / name / description
      Previous value: -"Display name when creating a new integration. OMIT to default to the host."New value: +"Display name. OMIT to keep an existing integration's name, or to name a NEW one after its host."
  4. Added
  5. Removed
  6. Changed1 schema field changed
    • changedInput schema / properties / name / description
      Previous value: -"Display name when creating a new integration (defaults to the host)."New value: +"Display name when creating a new integration. OMIT to default to the host."
  7. Changed2 schema fields changed
    • addedInput schema / properties / auth
      Added value: +{
      +  "description": "Auth block for a NEW token/header integration (or to change auth on update): {type: none|bearer|api_key|basic|custom_headers, ...}. bearer/basic → {token}; api_key → {token, header_name?}; custom_headers → {headers:{name:value,...}}. Token values are encrypted. Omit for browser_identity (use `identity`) or to keep existing auth.",
      +  "type": "object"
      +}
    • changedInput schema / properties / identity / description
      Previous value: -"Saved Browser Identity name or numeric id — required only when creating a NEW integration (updates reuse existing auth)."New value: +"Saved Browser Identity name or numeric id — one way to auth a NEW cookie-session integration (updates reuse existing auth). For token/header APIs use `auth` instead."
  8. Changed1 schema field changed
    • addedInput schema / properties / extract
      Added value: +{
      +  "description": "Explicit browser_identity auth extract for a NEW integration when auto-detect can't find one, e.g. {kind:'cookie', name:'_session', value_format:'raw', header_name:'Cookie', header_template:'{{name}}={{value}}'}. Updates reuse existing auth, so omit then.",
      +  "type": "object"
      +}
  9. Added

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.