Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
ROUTEBASE_REGIONNoHome region of your account: `us` or `eu` (default: `eu`). Without it, a US key fails as if it were invalid.eu
ROUTEBASE_API_KEYYesAPI key for authentication. Create one under Settings → API Keys.
ROUTEBASE_LOG_LEVELNo`verbose` · `debug` · `info` · `warning` · `error` · `fatal` (default: `warning`). Logs go to stderr — stdout is reserved for the MCP protocol.warning

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_doc_treeA

Get the documentation tree (folders, pages, spec snapshots) for a specific version. Returns a hierarchical structure with sort order. Each node is typed as page, folder, or specSnapshot. Requires project context (call set_context first).

get_environment_variablesA

Get resolved variables for a specific environment. Secret values are always masked for security. Use this to read resolved values; to change them use set_environment_variables. Requires organization context.

get_response_componentA

Get one reusable response component with its schema, headers and rowVersion. Set includeUsage to also list what references it. Use this when you already have the component id; to browse them or find an id use list_response_components. Requires project context.

list_custom_rolesA

List the organization's custom roles with the permission strings each one grants and how many members hold it. Use this to browse custom roles; for one role with its permissions use get_custom_role. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

get_deprecation_policyA

Get the organization's deprecation policy: the minimum grace period, whether a migration guide, a successor or an approval is required, and the reminder schedule. These are the rules manage_deprecation_plan('create') is checked against. Requires organization context.

resolve_governance_alertA

Mark a governance alert as resolved. This cannot be undone, and it does not fix what raised the alert. Alert IDs come from list_governance_alerts. Requires organization context.

search_portal_docsA

Full-text search across a PUBLISHED documentation portal. Searches page titles, headings, and body text of the latest published version and returns matching pages (slug, title, section, snippet). Chain get_portal_page with a returned slug to read the full page. Keyword search only (no semantics). Requires project context (call set_context first).

list_security_guidanceA

List the static security guidance library — one entry per OWASP API-security issue with its remediation text, code examples and references. Pass guidanceId (the guidanceId of a finding) for a single entry. The library is global, not project-specific. Use this for the general library; for advice on one finding use get_finding_remediation.

list_governance_alertsA

List the organization's governance alerts — quality drops, breaking-change spikes, stale drafts, blocked publishes. Unresolved only by default; capped at the 100 most recent. Use this to browse alerts; to mark one resolved use resolve_governance_alert. Requires organization context.

list_documentationsA

List all documentations in the active project with their versions. Returns documentation settings, branding info, and version summaries (status, visibility, dates). Requires project context (call set_context first).

list_alert_policiesA

List the alert policies of a project with their rules. Set includeAssignments to also get which environments, specs and monitors each policy is attached to — that is where the assignmentId for unassigning comes from. Use this to browse policies or find an id; to create or change one use manage_alert_policy. Requires project context.

get_doc_page_revisionA

Get one revision's full title and content — the preview before restoring it with manage_doc_page(action: 'restore_revision'). Get revisionId from list_doc_page_revisions. Requires project context.

validate_specA

Validate an OpenAPI specification against the standard. Provide either content to validate directly, or specId to validate an existing spec. Set mode to 'import' for a dry run of import_spec instead: same errors and warnings, plus what would be created (endpoint, schema and folder counts), the detected format and whether a 3.0 → 3.1 conversion happened. Nothing is written either way.

mark_notification_readA

Mark one notification as read. Get the id from list_notifications. Requires organization context (call set_context first).

get_merge_requestA

Get one merge request with its reviewers, their decisions and the comment thread. The userId values under reviewers are what manage_merge_request('create') expects. Set includeAuditTrail for the who-did-what history of the spec's merge requests. For what the merge would actually change, use get_branch(includeDiff). Use this when you already have the merge request id; to browse them use list_merge_requests. Requires project context.

list_test_casesA

List the test cases of a suite in execution order. Pass testCaseId to get one case in full instead — with its request config, assertions and response extractions — and then testSuiteId is not needed. Use this to browse a suite's cases in order; to change that order use reorder_test_items. Requires project context.

get_security_scoreA

Get the active project's security score (0–100) and the count of open findings by severity. Pass trendDays to also get the daily score history over that many days — that is how you tell whether a project is improving or drifting. Use this for the score and open counts; for the findings behind it use get_security_findings. Requires project context.

list_schemasA

List all schemas of an API specification. Optionally include usage counts showing how many endpoints reference each schema. Set scope to 'project' to look across every spec in the project instead — that returns the groups of structurally identical schemas (candidates for the shared library) plus counts, not the full list, and specId is then ignored. Every entry carries the rowVersion update_schema needs, so a batch of updates does not need a get_schema per schema first. Use this to browse schemas or find a schema id; for one schema with its full definition use get_schema. Requires project context.

list_endpointsA

List all endpoints of an API specification. Optionally filter by version. Set scope to 'project' to look across every spec in the project instead — that returns the groups of endpoints colliding on method and path (gateway routing conflicts) plus counts, not the full list, and specId is then ignored. Use this to browse endpoints or find an endpoint id; for one endpoint in full use get_endpoint. Requires project context (call set_context first).

list_specsA

List all API specifications in the active project. Set scope to 'org' to list the published APIs across every project in the organization instead — each entry carries the projectId and specId to pass to set_context. Use this to browse specs or find a spec id; for one spec by id use get_spec. Requires project context for scope 'project'.

get_versioning_strategyA

Get the versioning strategy configured for an API specification, including version aliases. Use this to read the strategy; to change it use set_versioning_strategy. Requires project context.

get_tagA

Get a single endpoint tag with its description, icon, display order and endpoint count. Use this when you already have the tag id; to browse a spec's tags or find an id use list_tags. Requires project context.

get_monitoring_settingsA

Get the project's monitoring defaults: how long check history is kept, the default check interval, timeout, incident threshold and schema validation mode, and whether monitors are created automatically when a spec is published. Use this to read the defaults; to change them use update_monitoring_settings. Requires project context.

get_org_doc_templateA

Get one organization documentation template with its full content and rowVersion. Use this when you already have the template id; to browse them or find an id use list_org_doc_templates.

get_request_configA

Get the full request configuration of a test case: method, URL, body, scripts and all headers with their ids. Returns null when the case has no request yet — use set_test_case_request to create one. Requires project context.

enable_toolsetA

Enable one or more toolsets for this session so their tools appear in tools/list. Pass a comma-separated list of toolset slugs (see list_toolsets). Sends a tools/list_changed notification; clients that ignore it can still call hidden tools directly.

list_scan_profilesA

List the security scan profiles configured for the active project. A scan profile bundles the target spec/environment and the enabled scanners; its public ID is required by run_security_scan. Pass scanProfileId to get one profile with its full configuration instead. Requires project context.

test_personaA

Probe a persona's credentials against an environment before a scan relies on them — one GET to probePath with the persona's resolved auth. A 2xx, 401 or 403 counts as success: the headers reached the target. Requires project context.

get_resolved_authA

Show which auth a test suite or test case actually uses after inheritance, and where it comes from — the case, the suite, the environment or the project. Secret values are not returned. Use this before debugging a 401 by hand. Requires project context.

list_monitor_checksA

List the individual checks a monitor ran, newest first — status code, response time and the timing breakdown (DNS, connect, TLS, first byte). Set onlyErrors to see just the failures. Use from and to to narrow the window. Use this for the individual checks of one monitor; for the monitor itself use get_monitor. Requires project context.

get_fixture_usageA

Inspect a project fixture. view 'used_by' (default) lists everything referencing it — mock rules, test cases, seeds, doc examples — which is what to check before changing or deleting it; view 'versions' lists its saved versions with their content. Requires project context.

list_personasA

List the security personas of the active project — the identities the authorization scanners impersonate. Pass personaId to get a single one. Secret values in the auth config are always returned masked as '********'; the plain values never leave the server. Use this to browse personas; to create, change or delete one use manage_persona. Requires project context.

lint_specA

Validate an API specification against style guide rules. Returns violations grouped by severity (error, warning, info) with rule details and affected paths. Use this to check against style guide rules; to check against the OpenAPI standard use validate_spec. Requires project context.

list_org_doc_templatesA

List the organization's documentation page templates, optionally filtered to one page type. Returns each template's full content. Use this to browse templates or find an id; to create or change one use manage_org_doc_template.

check_schema_driftA

Check for schema drift between a test case's linked endpoint snapshot and the current spec. Supports two modes: single test case (provide testCaseId) or batch check for all linked test cases of a spec (provide specId). Exactly one of testCaseId or specId must be provided. Use this to compare a linked case against the current spec; to adopt the spec's changes use sync_test_from_spec. Requires project context.

get_my_permissionsA

Get the caller's own role and effective permission strings in the active organization — custom roles resolved. This is the tool to reach for after a permission error: it says what the caller actually holds. Set includeCatalog to also get every permission the product defines with its description, to map a denied action onto a name. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

list_smart_mock_matching_rulesA

List the Smart Mock matching rules of one mock server — the rules that decide which faker value a field name gets. Includes the built-in catalog unless you filter it out. Use this for one mock server's rules; for the organization-wide ones use list_org_smart_mock_rules. Requires project context.

list_scenariosA

List all test scenarios in the active project. Scenarios are multi-step workflows that chain test cases with variable passing and conditional execution. Use this to browse scenarios or find an id; to create one use create_scenario. Requires project context.

get_request_logsA

Get request logs from the mock server showing recent incoming requests and matched rules. Supports filtering by HTTP method, path, status code, and time range. Pass logId to get ONE log with its full request and response bodies and headers instead of the list — that is where you look when a request matched the wrong rule. Requires project context (call set_context first).

list_webhook_deliveriesA

List delivery attempts of one webhook — event type, status, attempt count, HTTP status and error message. This is where you look when a webhook 'does not fire'. Get the webhookId from list_webhooks. Requires organization context.

list_available_specsA

List the project's API specifications with their published status — the candidates for manage_spec_snapshot(action: 'add'). A spec without a published version cannot be snapshotted. Requires project context.

list_incidentsA

List incidents across the organization, newest first, with the monitor that raised each one and its event timeline. Filter by status, by monitor, by environment or spec, and by time window. Works across the organization, no project context needed. Use this to browse incidents; to acknowledge or resolve one use manage_incident.

test_smart_mockA

Test Smart Mock matching for a given field name. Returns which matching rule would apply and what value it would generate. Useful for verifying Smart Mock configuration before generating rules. Requires project context (call set_context first).

list_test_data_setsA

List the data sets of a test suite — the tables that drive data-driven runs. The list gives names and row counts; pass dataSetId to get one set including its columns and rows. Use this to browse data sets; to create, change or import one use manage_test_data_set. Requires project context.

get_shared_schemaA

Get one shared schema with its full JSON Schema and rowVersion. Scope 'project' (default) or 'org'. Set includeUsedBy to also list the specs linking it — do that before deleting one; it only works in project scope. Use this when you already have the schema id; to browse the library use list_shared_schemas.

get_schema_drift_reportA

Get what a monitor's schema validation found: per check whether it passed, and the drift items with their JSON path, severity, expected and actual value. Only returns something for monitors with schema validation on — see manage_drift_watch. Requires project context.

get_scheduled_publishesA

List the scheduled publishes of a version. Pending ones by default; pass includeExecuted or includeCancelled to see the rest. Use this for publishes that have not run yet; for those already done use get_publish_history. Requires project context.

list_linkable_endpointsA

List the endpoints of an API spec that a test case can be linked to, with path, method and the version they come from. Use link_endpoint to establish the link. Requires project context.

get_header_componentA

Get one header component with its schema details and rowVersion. Level 'spec' (needs specId) or 'project'. Set includeUsage to also list what references it — spec level only; do that before deleting one. Use this for spec or project level; for the organization level use get_org_header_component. Requires project context.

get_custom_roleA

Get one custom role by ID: its permission strings, how many members hold it and when it was last changed. Get the ID from list_custom_roles or from a member's customRoleId. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

export_variablesA

Export an environment's variables as .env or JSON text. Secret values are ALWAYS masked — MCP has no path to decrypted secrets; use the web app if you need the real values. The output is suitable for review and for feeding back into import_variables.

list_contract_driftA

List the endpoints of a project whose live responses drift from their contract, grouped by endpoint with the drift items, how long it has lasted and the contract version checked against. Resolved events are left out unless asked for. Use get_schema_drift_report for one monitor's history. Use this for the endpoints that drift; for one drift event in full use get_contract_drift. Requires project context.

list_header_policiesA

List the header policies defined at one level: 'spec' (needs specId) or 'project'. Returns the ids, priorities and rowVersions needed to change them. This lists the policy objects — for the resolved header cascade on an endpoint use get_header_policies, for one response get_resolved_headers. Requires project context.

get_specA

Get detailed information about an API specification, including whether its documentation is internal, authenticated or public and under which slug. Includes the spec's versions (newest first, up to 10) — use their id as versionId for create_endpoint and other version-scoped tools. Use this when you already have the spec id; to browse the project's specs or find an id use list_specs. Requires project context.

list_webhooksA

List configured webhooks for the organization, optionally filtered by project. Returns webhook details including URL, subscribed events, and enabled status. Only accessible by organization admins and owners. Requires organization context (call set_context first).

list_mock_rulesA

List all mock rules for a mock server with pagination. Returns rules sorted by priority (lower = higher precedence) with path pattern, method, status code, and active status. Requires project context (call set_context first).

get_versionA

Get one spec version with its status, release notes, alias, publish and deprecation timestamps, and the rowVersion needed to edit it. Use this when you already have the version id; to browse a spec's versions or find an id use list_versions. Requires project context.

list_deprecationsA

List everything currently deprecated across the organization — endpoints and published versions — with the phase, the sunset date and how many days are left. The starting point for 'what do I have to migrate off'. Requires organization context.

list_project_style_guide_rulesA

List the style guide rules as they apply in this project: the built-in default, the organization override, the project override and the effective severity of each, plus the organization's custom rules. Use get_style_guide_rules for the organization-level view. Requires project context.

get_publish_historyA

List when a version was published, to which target and by whom. Use this for what has already been published; for publishes still ahead use get_scheduled_publishes. Requires project context.

get_schemaA

Get detailed information about a schema including its full JSON Schema definition. Optionally include usage details showing which endpoints reference it. Use this when you already have the schema id; to browse a spec's schemas or find an id use list_schemas. Requires project context.

list_projectsA

List all projects in the active organization. Use this to browse projects or find a project id; for one project in full use get_project. Requires organization context (call set_context first).

list_promotionsA

List how versions of a spec reached their environments: which version, which environment, whether it was a rollback and whether it froze the version. get_environment_pins shows the current state; this is how it got there. Requires project context.

set_contextA

Set the active organization and optionally a project for this session. Must be called before using any module-specific tools. Pass the organization's public ID (GUID) and optionally a project's public ID. Two areas are deliberately incomplete: billing and organization/access are read-only (an agent must not grant rights or trigger cost), and gateway, service catalog and AI assist have no tools at all while they are not generally available. Most toolsets start hidden — call list_toolsets to see them and enable_toolset to add them.

get_header_policyA

Get one header policy with its scopes, assigned header components and rowVersion. Level 'spec' (needs specId) or 'project'. Set includeImpact to also see which endpoints and responses it touches and which policies conflict with it — spec level only. Requires project context. Use this for spec or project level; for the organization level use get_org_header_policy.

list_organizationsA

List all organizations the authenticated user is a member of, including their role in each. Use this to find an organization id; to make one active use set_context.

list_notificationsA

Get notifications for the authenticated user in the active organization. Supports filtering for unread only and pagination. Returns notifications with type, title, message, action URL, and read status. Requires organization context (call set_context first).

get_audit_logA

Read the API design audit log: who changed what, when, and whether it was a person or an API key. Filter by entityId for the history of one endpoint or schema — worth doing before changing something you did not write. Paginated; without filters it returns the whole organization's history newest first. Requires organization context.

get_monitoring_sync_statusA

Compare a spec against the monitors that exist for it in one environment: how much of it is covered, which endpoints have no monitor, which monitors point at endpoints that are gone, and how many are drift-watched. The starting point before generating monitors. Requires project context.

get_environment_authA

Get the environment-level authentication configuration for an environment. Secret values are always masked. Returns {configured:false} when no auth is set. Requires organization context (call set_context first).

get_cli_run_statusA

Poll the live progress of a test run: completed cases out of total, current pass/fail counts and elapsed time. Meant for watching a run that is still going; use get_test_run once it has finished. Requires project context.

list_doc_snippetsA

List the snippets of a documentation version with their slug, content and how many pages use each one. Use this to browse snippets or find an id; to create, change or delete one use manage_doc_snippet. Requires project context.

get_mock_rule_diagnosticsA

Inspect one mock rule. view 'drift' (default) compares the rule against the latest published spec version and lists what changed since it was pinned; view 'state' returns the stored state of a stateful rule. Use this to inspect one rule's drift or match history; to browse the rules use list_mock_rules. Requires project context.

list_foldersA

List the folder structure of an API specification. Each folder has a parentFolderId for hierarchical nesting. Pass folderId to get just that one, with its rowVersion for update_folder. Requires project context (call set_context first).

get_governance_scoreA

Get the quality score. Scope 'org' (default) averages across the organization's specs with the trend and a per-spec breakdown. Scope 'spec' needs specId and recalculates that spec's score on the spot — that writes a new snapshot and may raise alerts, so it is not a free read. Use this for the score itself; for the thresholds and weights behind it use get_governance_config. Requires project context for scope 'spec'.

get_testing_settingsA

Read the project's testing settings. schemaNullMode decides how contract assertions treat null values against a schema. Use this to read the settings; to change them use update_testing_settings. Requires project context.

compare_versionsA

Compare two specification versions and show their differences: added/removed/modified endpoints and schemas. Omit sourceVersionId to compare against the latest published version. detail 'full' (default) returns the changed entities; 'flags' returns only what changed and how — much smaller, and enough to decide where to look. Requires project context. Use this for the raw structural difference; for a written summary of it use generate_changelog.

get_linked_endpoint_contractA

Get the request contract of the spec endpoint a test case is linked to: header parameters, request body schema and example, and the response schemas per status code. This is what the case is expected to send and receive — use it to write assertions that match the contract instead of guessing. Returns null when the case is not linked. Requires project context.

list_test_schedulesA

List the schedules of a test suite with their cron expression, timezone and next run time. Pass scheduleId to get one schedule instead — testSuiteId is then not needed. Use this to browse schedules; to create, change or run one use manage_test_schedule. Requires project context.

get_endpointA

Get detailed information about an endpoint including parameters, request body, responses, and security schemes. Pass endpointIds instead of endpointId to fetch several at once (up to 25) — the same detail per endpoint, in one call. Use this when you already have the endpoint id; to browse a spec's endpoints or find an id use list_endpoints. Requires project context.

get_projectA

Get detailed information about a project, including its environments. Use this when you already have the project id; to browse the organization's projects use list_projects. Requires organization context (call set_context first). If no projectId is given, uses the active project context.

get_alert_policyA

Get one alert policy with its full rule set and how many scopes it is assigned to. Use this when you already have the policy id; to browse a project's policies use list_alert_policies. Requires project context.

list_doc_page_revisionsA

List a page's revision history, newest first. Metadata only — read a revision's content with get_doc_page_revision before restoring it via manage_doc_page. Requires project context.

get_merge_policyA

Get the merge policy of a spec: how many reviewers a merge request needs and which guards apply. isDefault true means no policy was configured and these are the defaults. Use this to read the policy; to change it use update_merge_policy. Requires project context.

list_versionsA

List all versions of an API specification with their status (draft/review/published/deprecated). Set includeSuggestions for the next major, minor and patch number under this spec's versioning strategy — what create_version expects. Use this to browse versions or find a version id; for one version by id use get_version. Requires project context (call set_context first).

get_doc_settingsA

Get a documentation's settings: version numbering scheme, whether publishing needs approval and who may give it, the default code languages of the samples, and how schema names are displayed. Also returns the rowVersion that update_doc_settings takes. Requires project context.

generate_changelogA

Generate a structured changelog for a specification version by comparing it with the previous version. Returns a Markdown changelog. Use this for a readable summary of what changed; for the raw structural diff use compare_versions. Requires project context.

list_monitorsA

List the monitors of a project with their current status. Set grouped to see them as an environment → spec tree the way the sidebar shows them (paging does not apply then). Set includeStats to add 24h uptime, p95 latency and the response-time sparkline per monitor. Use this to browse monitors or find a monitor id; for one monitor with its checks use get_monitor. Requires project context.

list_test_foldersA

List the folders of the active project's test suite tree or scenario tree, flat with parentFolderId per entry. Use this to browse the folder tree; to create, rename or move a folder use manage_test_folder. Requires project context.

list_test_suitesA

List all test suites in the active project with stats (test case count, auth mode). Use this to browse suites or find a suite id; for one suite with its cases use get_test_suite. Requires project context (call set_context first).

get_resolved_headersA

Get the headers that actually apply to one endpoint response after the full cascade — organization, project and spec policies, local overrides and exclusions — each with where it came from. get_header_policies does the same for a whole endpoint, grouped by status code. Requires project context.

get_doc_version_publish_stateA

Whether a documentation version is ready to go live and whether the portal is showing its current content: lifecycle status, visibility, approval state, and whether anything was edited since the last successful portal build. Read this before publishing or building. Requires project context.

pre_publish_impactA

Check what publishing or promoting this version would do to dependent projects: how many are affected, at which severity, and whether the impact has to be acknowledged. Run this before promote_version when the version carries breaking changes. Requires project context.

list_team_projectsA

List the projects a team is assigned to and with which role (read or write). Unlike list_teams this only needs organization membership. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

list_environmentsA

List all environments of a project with variable counts. Use this to browse a project's environments; for the variables of one use get_environment_variables. Requires organization context. If no projectId is given, uses the active project context.

list_header_componentsA

List the header components defined at one level: 'spec' (needs specId) or 'project'. Set includeUsageCounts to see how often each is referenced — spec level only. Returns the ids and rowVersions needed to change them or assign them in a header policy. Requires project context. Use this for spec or project level; for the organization level use list_org_header_components.

list_custom_style_guide_rulesA

List the organization's own style guide rules with their conditions. The ruleId of each ('custom-') is what the severity tools take. Use this for the organization's own rules; for how rules apply in a project use list_project_style_guide_rules. Requires organization context.

list_toolsetsA

List all toolsets (tool groups) with slug, tool count and whether they are visible in this session. Core toolsets are always visible; enable others with enable_toolset. Full-access API keys see every tool; scoped keys and OAuth sessions automatically see every tool their scopes or role allow. Hidden tools stay callable — enabling only affects what tools/list advertises.

get_request_body_componentA

Get a request body component including its schema definition (inline schemaJson or a linked schemaId) and its rowVersion for updates. Optionally include usage details showing which endpoints link it. Use this when you already have the component id; to browse them or find an id use list_request_body_components. Requires project context.

list_oauth2_tokensA

List the OAuth 2.0 tokens cached for an environment, with their grant type and expiry. Access and refresh token values are never returned. Use this to see cached tokens; to request, refresh or drop one use manage_oauth2_token. Requires project context.

get_parameter_componentA

Get one reusable parameter component with its schema details and rowVersion. Set includeUsage to also list the endpoints referencing it — do that before deleting one. Use this when you already have the component id; to browse them or find an id use list_parameter_components. Requires project context.

get_portal_pageA

Retrieve a single PUBLISHED documentation page by slug, with its full Markdown content. Only pages from the latest published version are accessible. Use search_portal_docs to discover slugs. Requires project context (call set_context first).

get_spec_usage_in_docsA

Find which documentation versions embed a given API specification — read this after publishing a spec to see which snapshots are now stale. By default only mutable (Draft/Review) doc versions are listed; set includePublished to also see the live ones. Requires project context.

get_dashboardA

Get dashboard statistics for the active project: spec count, environment count, and project info. Requires project context (call set_context first).

get_security_scheme_componentA

Get one security scheme with its type-specific settings and rowVersion. Set includeUsage to also list the endpoints requiring it. Use this when you already have the scheme id; to browse them or find an id use list_security_scheme_components. Requires project context.

get_test_suiteA

Get detailed information about a test suite including its test cases. Set includeStats for run history and pass rate, includeExtractionVariables for the variables the suite's cases extract and pass on to later cases. Use this when you already have the suite id; to browse the project's suites use list_test_suites. Requires project context.

get_test_runA

Get ONE run with every case it executed: status, timing and a per-case row carrying its own id. testRunId comes from run_test_suite or get_test_results; a case id goes to get_test_result. Requires project context.

list_merge_requestsA

List the merge requests of a spec with their status (open, inReview, approved, merged, rejected, closed) and how many of the assigned reviewers have approved. Requires project context. Use this to browse merge requests or find an id; for one with its reviews use get_merge_request.

get_trialA

Get the organization's trial: which tier it grants, whether it is still running, when it expires and how many days are left. Unlike the other billing tools this one only needs organization membership, not billing:read. Use this for the trial; for the paid plan behind it use get_subscription. Requires organization context. Read-only: plan, seat and top-up changes are not available through MCP by design — a human does those in the web app.

list_security_scheme_componentsA

List the security schemes a spec version defines (OpenAPI components/securitySchemes). Set includeUsageCounts to see how often each is referenced. Use this to browse or find an id; to create, change or delete one use manage_security_scheme_component. Requires project context.

get_environment_verificationA

For every environment of the project: when its contract tests last ran, with what result, against which spec version, and how many cases are still pending. Tells you which environment's results you can trust. Use this for the per-environment overview; for one suite's run history use get_test_results. Requires project context.

list_branchesA

List the branches of a draft version, with their status (active, merged or closed). Use this to browse branches or find a branch id; for one branch with its diff use get_branch. Requires project context.

list_doc_imagesA

List a documentation's inline images: file name, URL, size, dimensions and whether a page still references it — how you find orphaned uploads before calling delete_doc_image. Requires project context (call set_context first).

get_mock_usageA

Read the organization's mock request usage against its plan limit. view 'current' (default) returns the running month with the limit and reset date, 'history' the monthly totals, 'breakdown' the current month split by project. This is what to check when mock requests start being rejected. Use this for request usage against the plan limit; for the individual requests use get_request_logs. Requires organization context.

get_deprecation_planA

Get the deprecation plan of one endpoint or published version, including its phase, sunset date, successor and migration guide. Returns null when nothing is deprecated. Set includeUsage to also see whether anyone still calls it — do that before retiring. Requires project context.

list_scenario_runsA

List the runs of a scenario with pass/fail counts per run. Pass runId to get one run with its per-step results instead — scenarioId is then not needed. Use this for a scenario's run history; to start a new run use run_scenario. Requires project context.

get_contract_summaryA

Get contract test coverage summary for a test suite. Shows how many test cases are linked to spec endpoints, how many have schema drift, and overall endpoint coverage. Use this for a suite's coverage overview; for the drift of one case use check_schema_drift. Requires project context.

list_fixture_importsA

List the organization fixtures the active project has imported, with the alias each is referenced by. Use this for what this project has imported; for what is available to import use list_org_fixtures. Requires project context.

list_maintenance_windowsA

List the maintenance windows of a project across all scopes, with the window ids needed to cancel them. Set activeOnly to see just the ones in effect right now. Requires project context. Use this to browse windows or find an id; to plan or cancel one use manage_maintenance_window.

get_branchA

Get one branch with how many endpoints, schemas and folders live on it. Set includeDiff for the change summary against main, the conflicts and the classified (breaking / non-breaking) changes — that is the read to trust before merging. Set includeRebasePreview to see how far the branch is behind main and what a rebase would have to resolve. Requires project context.

list_shared_responsesA

List the reusable responses of the shared library. Scope 'project' (default) reads the current project's library, 'org' the organization-wide one. Each entry carries the id and rowVersion needed to update or link it. Use this to browse or find an id; to create, change or delete one use manage_shared_response.

get_contract_driftA

One contract drift event in full: per-field deviations with the value that actually arrived, the route, the request that was sent, and the response body they were read from (first 4 KB, credential headers redacted). Ids come from list_contract_drift. Requires project context.

get_notification_preferencesA

Read notification preferences per category. scope 'user' (default) returns your own settings, where isUserOverride tells you whether a category follows the organization default or your own choice; scope 'org' returns the organization defaults. Use this to read preferences; to change your own use update_notification_preferences. Requires organization context.

get_test_resultsA

List the run history of a test suite: each execution with status, timing and pass/fail counts. Returns run ids — pass one to get_test_run for that run's cases, then get_test_result for one case. Requires project context.

export_specA

Export an API specification as OpenAPI YAML, JSON, or Postman Collection. Use this to get the finished document out; to check it against the standard first use validate_spec. Requires project context.

mark_all_notifications_readA

Mark EVERY unread notification of the authenticated user in the active organization as read. This cannot be undone — to clear a single one use mark_notification_read. Requires organization context (call set_context first).

list_request_body_componentsA

List all reusable request body components (OpenAPI components/requestBodies) of an API specification. Optionally include usage counts showing how many endpoints link each component. Use this to browse or find an id; for one component with its schema use get_request_body_component. Requires project context.

list_membersA

List the organization's members with their role, the custom role if they have one, when they joined and when they last logged in. Use this for the organization's members; for the teams they belong to use list_teams. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

list_shared_reportsA

List the share links that exist for a test run, with their access level and expiry. Use this to see existing share links; to create, extend or revoke one use manage_shared_report. Requires project context.

list_tagsA

List the endpoint tags of an API specification, including their Markdown descriptions and display order. Tag descriptions are exported as root-level OpenAPI tags and shown in the documentation portal. Use this to browse tags or find a tag id; for one tag by id use get_tag. Requires project context (call set_context first).

searchA

Search across API specs and endpoints in the active project by name, path, or description. Returns matching specs and endpoints. Use this to find specs and endpoints by text; for the project's counts and activity use get_dashboard. Requires project context.

get_security_findingsA

List security findings for the active project, optionally filtered by status, severity, scanner, or a free-text search. Findings are ordered by severity (most severe first). Pass findingId to get one finding in full, including the raw evidence the scanner captured (request and response) — that blob is omitted from the list to keep it small. Requires project context.

list_shared_schemasA

List the reusable schemas of the shared library. Scope 'project' (default) reads the current project's library, 'org' the organization-wide one. Each entry carries the id and rowVersion needed to update or link it. Use this to browse or find an id; to create, change or delete one use manage_shared_schema.

list_seedsA

List the seeds of the active project — the request sequences that set up and tear down test data. Pass seedId to get one seed with its full step lists and rowVersion. Use this to browse seeds or find a seed id; to execute one use run_seed. Requires project context.

export_findings_sarifA

Export the active project's security findings as a SARIF 2.1.0 document — the format GitHub Code Scanning and comparable CI tools ingest. Defaults to open findings so the export reflects the current posture. Use this to hand findings to CI or GitHub; to read them here use get_security_findings. Requires project context.

get_doc_snippetA

Get one snippet with its full Markdown content and rowVersion. Set includeUsages to also list the pages embedding it — do that before deleting one. Use this when you already have the snippet id; to browse a version's snippets use list_doc_snippets. Requires project context.

get_shared_responseA

Get one shared response with its schema, headers, example and rowVersion. Scope 'project' (default) or 'org'. Set includeUsedBy to also list the specs linking it — project scope only. Use this when you already have the response id; to browse the library use list_shared_responses.

export_test_runA

Export a test run as a report. format 'json' (default), 'html' or 'junit' — use junit for CI systems that consume JUnit XML. Returns the report content inline. Requires project context.

list_script_snippetsA

List the project's reusable pre-request and post-response script snippets, with their code and how often each is used. Use this to browse snippets or find an id; to create, change or delete one use manage_script_snippet. Requires project context.

get_finding_remediationA

Get remediation advice for a single finding as GitHub-flavored markdown. When AI Assist is enabled and within budget this is a suggestion written for this exact finding; otherwise it falls back to the static guidance-library text and says so in 'source'. Unlike the other reads this one can spend AI budget, which is why it is a separate tool. Use this for advice on one finding; for the whole library use list_security_guidance. Requires project context.

get_environment_pinsA

List which version each environment currently pins for this spec, whether the pin is frozen, and where it came from. Use this to see what each environment resolves to; to change a pin use promote_version. Requires project context.

list_header_exclusionsA

List the headers excluded from the policy cascade. Level 'response' (needs specId and responseId) covers one endpoint response, 'project' the whole project. Requires project context. Use this to see what is excluded from the cascade; to add or drop an exclusion use manage_header_exclusion.

get_monitorA

Get one monitor with its recent checks. The include flags pull in what the monitor detail page shows next to it: uptime and latency percentiles over 24h to 90d, the alert policy that applies (inherited or its own), its maintenance windows, and the fire/resolve history of its alerts. Use this when you already have the monitor id; to browse a project's monitors use list_monitors. Requires project context.

list_scan_runsA

List the security scan runs of the active project, newest first. Pass scanRunId to get a single run with its live progress instead — that is how you poll a scan started by run_security_scan. Requires project context.

list_response_componentsA

List the reusable response components of a spec version. Set includeUsageCounts to see how often each one is referenced. Use this to browse or find an id; to create, change or delete one use manage_response_component. Requires project context.

list_fixturesA

List all project-owned fixtures in the active project. Fixtures are structured test data (YAML/JSON) reusable across tests, mocks and docs. Use this for project-owned fixtures; for the shared organization ones use list_org_fixtures. Requires project context.

update_notification_preferencesA

Set YOUR notification preferences for one or more categories. Categories you do not mention keep their current setting. Use resetCategories to drop your override so a category follows the organization default again — an entry in categoriesJson can only set an override, never remove one. Valid categories: api_design, testing, project, mock_server, style_guide, team, portal, monitoring, security, billing, deprecation. Use this for your own preferences; for the organization defaults use update_org_notification_defaults.

list_project_teamsA

List the teams that reach the active project and with which role. The other direction of list_team_projects — this is the tool for 'who can write here'. Requires project context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app.

get_fixtureA

Get a fixture by its public ID including its raw source and normalized JSON content. Use this when you already have the fixture id; to browse the project's fixtures use list_fixtures. Requires project context.

get_breaking_changesA

Identify and classify breaking changes between two specification versions. Returns changes classified as Breaking, NonBreaking, or Deprecated with migration hints. Use this for classified breaking changes; for the full structural diff use compare_versions. Requires project context.

resolve_variablesA

Show the effective variable set for one environment after merging all three scopes — organization, then environment, then your personal overrides — with the scope each winning value came from. This is what a test run or mock request actually sees. Secret values are masked.

list_personal_variablesA

List your personal variables for one environment. They override both organization and environment variables and are visible only to you. Secret values are always masked. Use this for your own layer; for the merged result of all three use resolve_variables. Requires organization context.

list_snapshotsA

List the project's data snapshots — recorded resource states that can be restored to return an environment to a known point. Pass snapshotId to get one snapshot with its recorded resources. Use this to browse snapshots; to record a new one use record_snapshot. Requires project context.

get_header_policiesA

Get the headers that apply to a WHOLE endpoint, grouped by status code, after the org → project → spec cascade. Takes an endpointId; for one response use get_resolved_headers (responseId). Neither returns policy definitions — list those with list_header_policies. Requires project context.

list_shared_component_usagesA

List which shared-library components a spec links, including whether the library has a newer version than the spec is pinned to (hasUpdate). The usage ids returned here are what manage_shared_component_link needs for 'unlink' and 'accept_update'. Requires project context.

list_parameter_componentsA

List the reusable parameter components of a spec version. Set includeUsageCounts to see how often each one is referenced. Use this to browse or find an id; to create, change or delete one use manage_parameter_component. Requires project context.

list_artifact_sync_reviewsA

List what in this project has fallen out of sync with the specs behind it — mocks, tests and monitors whose endpoint changed or disappeared. Worth reading after changing a draft: these are the follow-ups that change created. Requires project context.

get_test_resultA

Get ONE test case's result inside a run: status code, timing, the response body and headers, every assertion outcome, extracted variables and any script output. This is the read to make when a run failed and you need to know why. The id comes from get_test_run's results[].id, not from get_test_results (run ids). Requires project context.

get_session_usageA

Return usage metrics for the current MCP session: total tool calls, error count, aggregate duration and response size, per-tool call counts, and session timestamps. Metrics are in-memory and reset when the server restarts or the session goes idle. Use this for what this session has spent; for which toolsets exist at all use list_toolsets.

get_doc_pageA

Get a documentation page with full content and metadata. Returns title, slug, Markdown content, page type, and timestamps. Requires project context (call set_context first).

get_mock_serverA

Get the mock server status and URL for the active project. Returns server details including MockCode, URL, active status, rule count, and Smart Mock settings. Returns null if no mock server exists yet (use create_mock_server to create one). Set includeStats to also get rule, request-log and spec-coverage statistics. The access token is never returned; when requireToken is on, the only way to obtain one is 'regenerate_mock_server_token' (which invalidates the old token). Requires project context (call set_context first).

preview_smart_mockA

Render a response body template with its {{faker.*}} placeholders replaced by generated values, using the active project's Smart Mock settings. Use this to check a template before saving it on a rule. Requires project context.

Prompts

Interactive templates invoked by user choice

NameDescription
triage_incidentsWork through the monitoring incidents that are still open or acknowledged. Loads them, then guides through diagnosis, acknowledgement and resolution.
review_specReview an existing API specification for best practices, consistency, and completeness. Loads the spec details and validation report to provide actionable improvement suggestions.
triage_security_findingsWork through the open security findings of the active project. Loads them ordered by severity, then guides through verification, remediation and status decisions.
fix_violationsAutomatically fix style guide violations in an API specification. Loads the current lint report and provides instructions to resolve each violation.
document_apiGenerate comprehensive API documentation including guides, tutorials, and examples. Creates documentation pages tailored to the target audience.
generate_testsGenerate test cases for all endpoints in an API specification. Loads the endpoint list and creates a comprehensive test suite with assertions.
generate_mock_rulesGenerate mock server rules for all endpoints in an API specification. Creates realistic mock responses including success and error scenarios.
design_apiDesign a new API from scratch based on a description. Loads the organization's style guide rules and provides step-by-step instructions to create a complete API specification using Routebase tools.
run_deprecationWalk a deprecation through its lifecycle — announce, notify consumers, advance, retire. Loads everything the organization currently has deprecated and the rules it is checked against.
onboard_projectGenerate a project overview for a new team member. Summarizes specs, test health, mock server status, and documentation.
generate_schemaGenerate a JSON Schema from an example JSON object. Analyzes the structure and creates a proper schema definition.
analyze_test_failuresAnalyze failed test cases from a test run and suggest fixes. Loads the test run results and provides diagnosis for each failure.
migrate_versionGuide through creating a new API version with breaking change analysis and migration strategy. Loads existing versions and provides step-by-step migration instructions.

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.6/5.0

Scored across 162 tools

Disambiguation3/5

Descriptions carefully cross-reference and differentiate tools by scope and object, but with 162 tools there is substantial overlap (e.g., multiple drift, monitoring, and documentation reads) making misselection likely.

Naming Consistency4/5

Names predominantly follow a snake_case verb_noun convention (list_, get_, manage_, etc.), with only minor deviations like get_scheduled_publishes for a list operation.

Tool Count1/5

162 tools is an extreme mismatch for any server; even with toolsets, the surface is overwhelmingly large and violates the typical 3-15 tool scope.

Completeness2/5

Core API design CRUD is missing: no manage/create/update tools for specs, endpoints, or schemas are listed, despite references to create_endpoint and update_schema. Significant gaps will cause agent failures for mutation workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues