Routebase
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ROUTEBASE_REGION | No | Home region of your account: `us` or `eu` (default: `eu`). Without it, a US key fails as if it were invalid. | eu |
| ROUTEBASE_API_KEY | Yes | API key for authentication. Create one under Settings → API Keys. | |
| ROUTEBASE_LOG_LEVEL | No | `verbose` · `debug` · `info` · `warning` · `error` · `fatal` (default: `warning`). Logs go to stderr — stdout is reserved for the MCP protocol. | warning |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_doc_treeA | Get the documentation tree (folders, pages, spec snapshots) for a specific version. Returns a hierarchical structure with sort order. Each node is typed as page, folder, or specSnapshot. Requires project context (call set_context first). |
| get_environment_variablesA | Get resolved variables for a specific environment. Secret values are always masked for security. Use this to read resolved values; to change them use set_environment_variables. Requires organization context. |
| get_response_componentA | Get one reusable response component with its schema, headers and rowVersion. Set includeUsage to also list what references it. Use this when you already have the component id; to browse them or find an id use list_response_components. Requires project context. |
| list_custom_rolesA | List the organization's custom roles with the permission strings each one grants and how many members hold it. Use this to browse custom roles; for one role with its permissions use get_custom_role. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| get_deprecation_policyA | Get the organization's deprecation policy: the minimum grace period, whether a migration guide, a successor or an approval is required, and the reminder schedule. These are the rules manage_deprecation_plan('create') is checked against. Requires organization context. |
| resolve_governance_alertA | Mark a governance alert as resolved. This cannot be undone, and it does not fix what raised the alert. Alert IDs come from list_governance_alerts. Requires organization context. |
| search_portal_docsA | Full-text search across a PUBLISHED documentation portal. Searches page titles, headings, and body text of the latest published version and returns matching pages (slug, title, section, snippet). Chain get_portal_page with a returned slug to read the full page. Keyword search only (no semantics). Requires project context (call set_context first). |
| list_security_guidanceA | List the static security guidance library — one entry per OWASP API-security issue with its remediation text, code examples and references. Pass guidanceId (the guidanceId of a finding) for a single entry. The library is global, not project-specific. Use this for the general library; for advice on one finding use get_finding_remediation. |
| list_governance_alertsA | List the organization's governance alerts — quality drops, breaking-change spikes, stale drafts, blocked publishes. Unresolved only by default; capped at the 100 most recent. Use this to browse alerts; to mark one resolved use resolve_governance_alert. Requires organization context. |
| list_documentationsA | List all documentations in the active project with their versions. Returns documentation settings, branding info, and version summaries (status, visibility, dates). Requires project context (call set_context first). |
| list_alert_policiesA | List the alert policies of a project with their rules. Set includeAssignments to also get which environments, specs and monitors each policy is attached to — that is where the assignmentId for unassigning comes from. Use this to browse policies or find an id; to create or change one use manage_alert_policy. Requires project context. |
| get_doc_page_revisionA | Get one revision's full title and content — the preview before restoring it with manage_doc_page(action: 'restore_revision'). Get revisionId from list_doc_page_revisions. Requires project context. |
| validate_specA | Validate an OpenAPI specification against the standard. Provide either content to validate directly, or specId to validate an existing spec. Set mode to 'import' for a dry run of import_spec instead: same errors and warnings, plus what would be created (endpoint, schema and folder counts), the detected format and whether a 3.0 → 3.1 conversion happened. Nothing is written either way. |
| mark_notification_readA | Mark one notification as read. Get the id from list_notifications. Requires organization context (call set_context first). |
| get_merge_requestA | Get one merge request with its reviewers, their decisions and the comment thread. The userId values under reviewers are what manage_merge_request('create') expects. Set includeAuditTrail for the who-did-what history of the spec's merge requests. For what the merge would actually change, use get_branch(includeDiff). Use this when you already have the merge request id; to browse them use list_merge_requests. Requires project context. |
| list_test_casesA | List the test cases of a suite in execution order. Pass testCaseId to get one case in full instead — with its request config, assertions and response extractions — and then testSuiteId is not needed. Use this to browse a suite's cases in order; to change that order use reorder_test_items. Requires project context. |
| get_security_scoreA | Get the active project's security score (0–100) and the count of open findings by severity. Pass trendDays to also get the daily score history over that many days — that is how you tell whether a project is improving or drifting. Use this for the score and open counts; for the findings behind it use get_security_findings. Requires project context. |
| list_schemasA | List all schemas of an API specification. Optionally include usage counts showing how many endpoints reference each schema. Set scope to 'project' to look across every spec in the project instead — that returns the groups of structurally identical schemas (candidates for the shared library) plus counts, not the full list, and specId is then ignored. Every entry carries the rowVersion update_schema needs, so a batch of updates does not need a get_schema per schema first. Use this to browse schemas or find a schema id; for one schema with its full definition use get_schema. Requires project context. |
| list_endpointsA | List all endpoints of an API specification. Optionally filter by version. Set scope to 'project' to look across every spec in the project instead — that returns the groups of endpoints colliding on method and path (gateway routing conflicts) plus counts, not the full list, and specId is then ignored. Use this to browse endpoints or find an endpoint id; for one endpoint in full use get_endpoint. Requires project context (call set_context first). |
| list_specsA | List all API specifications in the active project. Set scope to 'org' to list the published APIs across every project in the organization instead — each entry carries the projectId and specId to pass to set_context. Use this to browse specs or find a spec id; for one spec by id use get_spec. Requires project context for scope 'project'. |
| get_versioning_strategyA | Get the versioning strategy configured for an API specification, including version aliases. Use this to read the strategy; to change it use set_versioning_strategy. Requires project context. |
| get_tagA | Get a single endpoint tag with its description, icon, display order and endpoint count. Use this when you already have the tag id; to browse a spec's tags or find an id use list_tags. Requires project context. |
| get_monitoring_settingsA | Get the project's monitoring defaults: how long check history is kept, the default check interval, timeout, incident threshold and schema validation mode, and whether monitors are created automatically when a spec is published. Use this to read the defaults; to change them use update_monitoring_settings. Requires project context. |
| get_org_doc_templateA | Get one organization documentation template with its full content and rowVersion. Use this when you already have the template id; to browse them or find an id use list_org_doc_templates. |
| get_request_configA | Get the full request configuration of a test case: method, URL, body, scripts and all headers with their ids. Returns null when the case has no request yet — use set_test_case_request to create one. Requires project context. |
| enable_toolsetA | Enable one or more toolsets for this session so their tools appear in tools/list. Pass a comma-separated list of toolset slugs (see list_toolsets). Sends a tools/list_changed notification; clients that ignore it can still call hidden tools directly. |
| list_scan_profilesA | List the security scan profiles configured for the active project. A scan profile bundles the target spec/environment and the enabled scanners; its public ID is required by run_security_scan. Pass scanProfileId to get one profile with its full configuration instead. Requires project context. |
| test_personaA | Probe a persona's credentials against an environment before a scan relies on them — one GET to probePath with the persona's resolved auth. A 2xx, 401 or 403 counts as success: the headers reached the target. Requires project context. |
| get_resolved_authA | Show which auth a test suite or test case actually uses after inheritance, and where it comes from — the case, the suite, the environment or the project. Secret values are not returned. Use this before debugging a 401 by hand. Requires project context. |
| list_monitor_checksA | List the individual checks a monitor ran, newest first — status code, response time and the timing breakdown (DNS, connect, TLS, first byte). Set onlyErrors to see just the failures. Use from and to to narrow the window. Use this for the individual checks of one monitor; for the monitor itself use get_monitor. Requires project context. |
| get_fixture_usageA | Inspect a project fixture. view 'used_by' (default) lists everything referencing it — mock rules, test cases, seeds, doc examples — which is what to check before changing or deleting it; view 'versions' lists its saved versions with their content. Requires project context. |
| list_personasA | List the security personas of the active project — the identities the authorization scanners impersonate. Pass personaId to get a single one. Secret values in the auth config are always returned masked as '********'; the plain values never leave the server. Use this to browse personas; to create, change or delete one use manage_persona. Requires project context. |
| lint_specA | Validate an API specification against style guide rules. Returns violations grouped by severity (error, warning, info) with rule details and affected paths. Use this to check against style guide rules; to check against the OpenAPI standard use validate_spec. Requires project context. |
| list_org_doc_templatesA | List the organization's documentation page templates, optionally filtered to one page type. Returns each template's full content. Use this to browse templates or find an id; to create or change one use manage_org_doc_template. |
| check_schema_driftA | Check for schema drift between a test case's linked endpoint snapshot and the current spec. Supports two modes: single test case (provide testCaseId) or batch check for all linked test cases of a spec (provide specId). Exactly one of testCaseId or specId must be provided. Use this to compare a linked case against the current spec; to adopt the spec's changes use sync_test_from_spec. Requires project context. |
| get_my_permissionsA | Get the caller's own role and effective permission strings in the active organization — custom roles resolved. This is the tool to reach for after a permission error: it says what the caller actually holds. Set includeCatalog to also get every permission the product defines with its description, to map a denied action onto a name. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| list_smart_mock_matching_rulesA | List the Smart Mock matching rules of one mock server — the rules that decide which faker value a field name gets. Includes the built-in catalog unless you filter it out. Use this for one mock server's rules; for the organization-wide ones use list_org_smart_mock_rules. Requires project context. |
| list_scenariosA | List all test scenarios in the active project. Scenarios are multi-step workflows that chain test cases with variable passing and conditional execution. Use this to browse scenarios or find an id; to create one use create_scenario. Requires project context. |
| get_request_logsA | Get request logs from the mock server showing recent incoming requests and matched rules. Supports filtering by HTTP method, path, status code, and time range. Pass logId to get ONE log with its full request and response bodies and headers instead of the list — that is where you look when a request matched the wrong rule. Requires project context (call set_context first). |
| list_webhook_deliveriesA | List delivery attempts of one webhook — event type, status, attempt count, HTTP status and error message. This is where you look when a webhook 'does not fire'. Get the webhookId from list_webhooks. Requires organization context. |
| list_available_specsA | List the project's API specifications with their published status — the candidates for manage_spec_snapshot(action: 'add'). A spec without a published version cannot be snapshotted. Requires project context. |
| list_incidentsA | List incidents across the organization, newest first, with the monitor that raised each one and its event timeline. Filter by status, by monitor, by environment or spec, and by time window. Works across the organization, no project context needed. Use this to browse incidents; to acknowledge or resolve one use manage_incident. |
| test_smart_mockA | Test Smart Mock matching for a given field name. Returns which matching rule would apply and what value it would generate. Useful for verifying Smart Mock configuration before generating rules. Requires project context (call set_context first). |
| list_test_data_setsA | List the data sets of a test suite — the tables that drive data-driven runs. The list gives names and row counts; pass dataSetId to get one set including its columns and rows. Use this to browse data sets; to create, change or import one use manage_test_data_set. Requires project context. |
| get_shared_schemaA | Get one shared schema with its full JSON Schema and rowVersion. Scope 'project' (default) or 'org'. Set includeUsedBy to also list the specs linking it — do that before deleting one; it only works in project scope. Use this when you already have the schema id; to browse the library use list_shared_schemas. |
| get_schema_drift_reportA | Get what a monitor's schema validation found: per check whether it passed, and the drift items with their JSON path, severity, expected and actual value. Only returns something for monitors with schema validation on — see manage_drift_watch. Requires project context. |
| get_scheduled_publishesA | List the scheduled publishes of a version. Pending ones by default; pass includeExecuted or includeCancelled to see the rest. Use this for publishes that have not run yet; for those already done use get_publish_history. Requires project context. |
| list_linkable_endpointsA | List the endpoints of an API spec that a test case can be linked to, with path, method and the version they come from. Use link_endpoint to establish the link. Requires project context. |
| get_header_componentA | Get one header component with its schema details and rowVersion. Level 'spec' (needs specId) or 'project'. Set includeUsage to also list what references it — spec level only; do that before deleting one. Use this for spec or project level; for the organization level use get_org_header_component. Requires project context. |
| get_custom_roleA | Get one custom role by ID: its permission strings, how many members hold it and when it was last changed. Get the ID from list_custom_roles or from a member's customRoleId. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| export_variablesA | Export an environment's variables as .env or JSON text. Secret values are ALWAYS masked — MCP has no path to decrypted secrets; use the web app if you need the real values. The output is suitable for review and for feeding back into import_variables. |
| list_contract_driftA | List the endpoints of a project whose live responses drift from their contract, grouped by endpoint with the drift items, how long it has lasted and the contract version checked against. Resolved events are left out unless asked for. Use get_schema_drift_report for one monitor's history. Use this for the endpoints that drift; for one drift event in full use get_contract_drift. Requires project context. |
| list_header_policiesA | List the header policies defined at one level: 'spec' (needs specId) or 'project'. Returns the ids, priorities and rowVersions needed to change them. This lists the policy objects — for the resolved header cascade on an endpoint use get_header_policies, for one response get_resolved_headers. Requires project context. |
| get_specA | Get detailed information about an API specification, including whether its documentation is internal, authenticated or public and under which slug. Includes the spec's versions (newest first, up to 10) — use their id as versionId for create_endpoint and other version-scoped tools. Use this when you already have the spec id; to browse the project's specs or find an id use list_specs. Requires project context. |
| list_webhooksA | List configured webhooks for the organization, optionally filtered by project. Returns webhook details including URL, subscribed events, and enabled status. Only accessible by organization admins and owners. Requires organization context (call set_context first). |
| list_mock_rulesA | List all mock rules for a mock server with pagination. Returns rules sorted by priority (lower = higher precedence) with path pattern, method, status code, and active status. Requires project context (call set_context first). |
| get_versionA | Get one spec version with its status, release notes, alias, publish and deprecation timestamps, and the rowVersion needed to edit it. Use this when you already have the version id; to browse a spec's versions or find an id use list_versions. Requires project context. |
| list_deprecationsA | List everything currently deprecated across the organization — endpoints and published versions — with the phase, the sunset date and how many days are left. The starting point for 'what do I have to migrate off'. Requires organization context. |
| list_project_style_guide_rulesA | List the style guide rules as they apply in this project: the built-in default, the organization override, the project override and the effective severity of each, plus the organization's custom rules. Use get_style_guide_rules for the organization-level view. Requires project context. |
| get_publish_historyA | List when a version was published, to which target and by whom. Use this for what has already been published; for publishes still ahead use get_scheduled_publishes. Requires project context. |
| get_schemaA | Get detailed information about a schema including its full JSON Schema definition. Optionally include usage details showing which endpoints reference it. Use this when you already have the schema id; to browse a spec's schemas or find an id use list_schemas. Requires project context. |
| list_projectsA | List all projects in the active organization. Use this to browse projects or find a project id; for one project in full use get_project. Requires organization context (call set_context first). |
| list_promotionsA | List how versions of a spec reached their environments: which version, which environment, whether it was a rollback and whether it froze the version. get_environment_pins shows the current state; this is how it got there. Requires project context. |
| set_contextA | Set the active organization and optionally a project for this session. Must be called before using any module-specific tools. Pass the organization's public ID (GUID) and optionally a project's public ID. Two areas are deliberately incomplete: billing and organization/access are read-only (an agent must not grant rights or trigger cost), and gateway, service catalog and AI assist have no tools at all while they are not generally available. Most toolsets start hidden — call list_toolsets to see them and enable_toolset to add them. |
| get_header_policyA | Get one header policy with its scopes, assigned header components and rowVersion. Level 'spec' (needs specId) or 'project'. Set includeImpact to also see which endpoints and responses it touches and which policies conflict with it — spec level only. Requires project context. Use this for spec or project level; for the organization level use get_org_header_policy. |
| list_organizationsA | List all organizations the authenticated user is a member of, including their role in each. Use this to find an organization id; to make one active use set_context. |
| list_notificationsA | Get notifications for the authenticated user in the active organization. Supports filtering for unread only and pagination. Returns notifications with type, title, message, action URL, and read status. Requires organization context (call set_context first). |
| get_audit_logA | Read the API design audit log: who changed what, when, and whether it was a person or an API key. Filter by entityId for the history of one endpoint or schema — worth doing before changing something you did not write. Paginated; without filters it returns the whole organization's history newest first. Requires organization context. |
| get_monitoring_sync_statusA | Compare a spec against the monitors that exist for it in one environment: how much of it is covered, which endpoints have no monitor, which monitors point at endpoints that are gone, and how many are drift-watched. The starting point before generating monitors. Requires project context. |
| get_environment_authA | Get the environment-level authentication configuration for an environment. Secret values are always masked. Returns {configured:false} when no auth is set. Requires organization context (call set_context first). |
| get_cli_run_statusA | Poll the live progress of a test run: completed cases out of total, current pass/fail counts and elapsed time. Meant for watching a run that is still going; use get_test_run once it has finished. Requires project context. |
| list_doc_snippetsA | List the snippets of a documentation version with their slug, content and how many pages use each one. Use this to browse snippets or find an id; to create, change or delete one use manage_doc_snippet. Requires project context. |
| get_mock_rule_diagnosticsA | Inspect one mock rule. view 'drift' (default) compares the rule against the latest published spec version and lists what changed since it was pinned; view 'state' returns the stored state of a stateful rule. Use this to inspect one rule's drift or match history; to browse the rules use list_mock_rules. Requires project context. |
| list_foldersA | List the folder structure of an API specification. Each folder has a parentFolderId for hierarchical nesting. Pass folderId to get just that one, with its rowVersion for update_folder. Requires project context (call set_context first). |
| get_governance_scoreA | Get the quality score. Scope 'org' (default) averages across the organization's specs with the trend and a per-spec breakdown. Scope 'spec' needs specId and recalculates that spec's score on the spot — that writes a new snapshot and may raise alerts, so it is not a free read. Use this for the score itself; for the thresholds and weights behind it use get_governance_config. Requires project context for scope 'spec'. |
| get_testing_settingsA | Read the project's testing settings. schemaNullMode decides how contract assertions treat null values against a schema. Use this to read the settings; to change them use update_testing_settings. Requires project context. |
| compare_versionsA | Compare two specification versions and show their differences: added/removed/modified endpoints and schemas. Omit sourceVersionId to compare against the latest published version. detail 'full' (default) returns the changed entities; 'flags' returns only what changed and how — much smaller, and enough to decide where to look. Requires project context. Use this for the raw structural difference; for a written summary of it use generate_changelog. |
| get_linked_endpoint_contractA | Get the request contract of the spec endpoint a test case is linked to: header parameters, request body schema and example, and the response schemas per status code. This is what the case is expected to send and receive — use it to write assertions that match the contract instead of guessing. Returns null when the case is not linked. Requires project context. |
| list_test_schedulesA | List the schedules of a test suite with their cron expression, timezone and next run time. Pass scheduleId to get one schedule instead — testSuiteId is then not needed. Use this to browse schedules; to create, change or run one use manage_test_schedule. Requires project context. |
| get_endpointA | Get detailed information about an endpoint including parameters, request body, responses, and security schemes. Pass endpointIds instead of endpointId to fetch several at once (up to 25) — the same detail per endpoint, in one call. Use this when you already have the endpoint id; to browse a spec's endpoints or find an id use list_endpoints. Requires project context. |
| get_projectA | Get detailed information about a project, including its environments. Use this when you already have the project id; to browse the organization's projects use list_projects. Requires organization context (call set_context first). If no projectId is given, uses the active project context. |
| get_alert_policyA | Get one alert policy with its full rule set and how many scopes it is assigned to. Use this when you already have the policy id; to browse a project's policies use list_alert_policies. Requires project context. |
| list_doc_page_revisionsA | List a page's revision history, newest first. Metadata only — read a revision's content with get_doc_page_revision before restoring it via manage_doc_page. Requires project context. |
| get_merge_policyA | Get the merge policy of a spec: how many reviewers a merge request needs and which guards apply. isDefault true means no policy was configured and these are the defaults. Use this to read the policy; to change it use update_merge_policy. Requires project context. |
| list_versionsA | List all versions of an API specification with their status (draft/review/published/deprecated). Set includeSuggestions for the next major, minor and patch number under this spec's versioning strategy — what create_version expects. Use this to browse versions or find a version id; for one version by id use get_version. Requires project context (call set_context first). |
| get_doc_settingsA | Get a documentation's settings: version numbering scheme, whether publishing needs approval and who may give it, the default code languages of the samples, and how schema names are displayed. Also returns the rowVersion that update_doc_settings takes. Requires project context. |
| generate_changelogA | Generate a structured changelog for a specification version by comparing it with the previous version. Returns a Markdown changelog. Use this for a readable summary of what changed; for the raw structural diff use compare_versions. Requires project context. |
| list_monitorsA | List the monitors of a project with their current status. Set grouped to see them as an environment → spec tree the way the sidebar shows them (paging does not apply then). Set includeStats to add 24h uptime, p95 latency and the response-time sparkline per monitor. Use this to browse monitors or find a monitor id; for one monitor with its checks use get_monitor. Requires project context. |
| list_test_foldersA | List the folders of the active project's test suite tree or scenario tree, flat with parentFolderId per entry. Use this to browse the folder tree; to create, rename or move a folder use manage_test_folder. Requires project context. |
| list_test_suitesA | List all test suites in the active project with stats (test case count, auth mode). Use this to browse suites or find a suite id; for one suite with its cases use get_test_suite. Requires project context (call set_context first). |
| get_resolved_headersA | Get the headers that actually apply to one endpoint response after the full cascade — organization, project and spec policies, local overrides and exclusions — each with where it came from. get_header_policies does the same for a whole endpoint, grouped by status code. Requires project context. |
| get_doc_version_publish_stateA | Whether a documentation version is ready to go live and whether the portal is showing its current content: lifecycle status, visibility, approval state, and whether anything was edited since the last successful portal build. Read this before publishing or building. Requires project context. |
| pre_publish_impactA | Check what publishing or promoting this version would do to dependent projects: how many are affected, at which severity, and whether the impact has to be acknowledged. Run this before promote_version when the version carries breaking changes. Requires project context. |
| list_team_projectsA | List the projects a team is assigned to and with which role (read or write). Unlike list_teams this only needs organization membership. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| list_environmentsA | List all environments of a project with variable counts. Use this to browse a project's environments; for the variables of one use get_environment_variables. Requires organization context. If no projectId is given, uses the active project context. |
| list_header_componentsA | List the header components defined at one level: 'spec' (needs specId) or 'project'. Set includeUsageCounts to see how often each is referenced — spec level only. Returns the ids and rowVersions needed to change them or assign them in a header policy. Requires project context. Use this for spec or project level; for the organization level use list_org_header_components. |
| list_custom_style_guide_rulesA | List the organization's own style guide rules with their conditions. The ruleId of each ('custom-') is what the severity tools take. Use this for the organization's own rules; for how rules apply in a project use list_project_style_guide_rules. Requires organization context. |
| list_toolsetsA | List all toolsets (tool groups) with slug, tool count and whether they are visible in this session. Core toolsets are always visible; enable others with enable_toolset. Full-access API keys see every tool; scoped keys and OAuth sessions automatically see every tool their scopes or role allow. Hidden tools stay callable — enabling only affects what tools/list advertises. |
| get_request_body_componentA | Get a request body component including its schema definition (inline schemaJson or a linked schemaId) and its rowVersion for updates. Optionally include usage details showing which endpoints link it. Use this when you already have the component id; to browse them or find an id use list_request_body_components. Requires project context. |
| list_oauth2_tokensA | List the OAuth 2.0 tokens cached for an environment, with their grant type and expiry. Access and refresh token values are never returned. Use this to see cached tokens; to request, refresh or drop one use manage_oauth2_token. Requires project context. |
| get_parameter_componentA | Get one reusable parameter component with its schema details and rowVersion. Set includeUsage to also list the endpoints referencing it — do that before deleting one. Use this when you already have the component id; to browse them or find an id use list_parameter_components. Requires project context. |
| get_portal_pageA | Retrieve a single PUBLISHED documentation page by slug, with its full Markdown content. Only pages from the latest published version are accessible. Use search_portal_docs to discover slugs. Requires project context (call set_context first). |
| get_spec_usage_in_docsA | Find which documentation versions embed a given API specification — read this after publishing a spec to see which snapshots are now stale. By default only mutable (Draft/Review) doc versions are listed; set includePublished to also see the live ones. Requires project context. |
| get_dashboardA | Get dashboard statistics for the active project: spec count, environment count, and project info. Requires project context (call set_context first). |
| get_security_scheme_componentA | Get one security scheme with its type-specific settings and rowVersion. Set includeUsage to also list the endpoints requiring it. Use this when you already have the scheme id; to browse them or find an id use list_security_scheme_components. Requires project context. |
| get_test_suiteA | Get detailed information about a test suite including its test cases. Set includeStats for run history and pass rate, includeExtractionVariables for the variables the suite's cases extract and pass on to later cases. Use this when you already have the suite id; to browse the project's suites use list_test_suites. Requires project context. |
| get_test_runA | Get ONE run with every case it executed: status, timing and a per-case row carrying its own id. testRunId comes from run_test_suite or get_test_results; a case id goes to get_test_result. Requires project context. |
| list_merge_requestsA | List the merge requests of a spec with their status (open, inReview, approved, merged, rejected, closed) and how many of the assigned reviewers have approved. Requires project context. Use this to browse merge requests or find an id; for one with its reviews use get_merge_request. |
| get_trialA | Get the organization's trial: which tier it grants, whether it is still running, when it expires and how many days are left. Unlike the other billing tools this one only needs organization membership, not billing:read. Use this for the trial; for the paid plan behind it use get_subscription. Requires organization context. Read-only: plan, seat and top-up changes are not available through MCP by design — a human does those in the web app. |
| list_security_scheme_componentsA | List the security schemes a spec version defines (OpenAPI components/securitySchemes). Set includeUsageCounts to see how often each is referenced. Use this to browse or find an id; to create, change or delete one use manage_security_scheme_component. Requires project context. |
| get_environment_verificationA | For every environment of the project: when its contract tests last ran, with what result, against which spec version, and how many cases are still pending. Tells you which environment's results you can trust. Use this for the per-environment overview; for one suite's run history use get_test_results. Requires project context. |
| list_branchesA | List the branches of a draft version, with their status (active, merged or closed). Use this to browse branches or find a branch id; for one branch with its diff use get_branch. Requires project context. |
| list_doc_imagesA | List a documentation's inline images: file name, URL, size, dimensions and whether a page still references it — how you find orphaned uploads before calling delete_doc_image. Requires project context (call set_context first). |
| get_mock_usageA | Read the organization's mock request usage against its plan limit. view 'current' (default) returns the running month with the limit and reset date, 'history' the monthly totals, 'breakdown' the current month split by project. This is what to check when mock requests start being rejected. Use this for request usage against the plan limit; for the individual requests use get_request_logs. Requires organization context. |
| get_deprecation_planA | Get the deprecation plan of one endpoint or published version, including its phase, sunset date, successor and migration guide. Returns null when nothing is deprecated. Set includeUsage to also see whether anyone still calls it — do that before retiring. Requires project context. |
| list_scenario_runsA | List the runs of a scenario with pass/fail counts per run. Pass runId to get one run with its per-step results instead — scenarioId is then not needed. Use this for a scenario's run history; to start a new run use run_scenario. Requires project context. |
| get_contract_summaryA | Get contract test coverage summary for a test suite. Shows how many test cases are linked to spec endpoints, how many have schema drift, and overall endpoint coverage. Use this for a suite's coverage overview; for the drift of one case use check_schema_drift. Requires project context. |
| list_fixture_importsA | List the organization fixtures the active project has imported, with the alias each is referenced by. Use this for what this project has imported; for what is available to import use list_org_fixtures. Requires project context. |
| list_maintenance_windowsA | List the maintenance windows of a project across all scopes, with the window ids needed to cancel them. Set activeOnly to see just the ones in effect right now. Requires project context. Use this to browse windows or find an id; to plan or cancel one use manage_maintenance_window. |
| get_branchA | Get one branch with how many endpoints, schemas and folders live on it. Set includeDiff for the change summary against main, the conflicts and the classified (breaking / non-breaking) changes — that is the read to trust before merging. Set includeRebasePreview to see how far the branch is behind main and what a rebase would have to resolve. Requires project context. |
| list_shared_responsesA | List the reusable responses of the shared library. Scope 'project' (default) reads the current project's library, 'org' the organization-wide one. Each entry carries the id and rowVersion needed to update or link it. Use this to browse or find an id; to create, change or delete one use manage_shared_response. |
| get_contract_driftA | One contract drift event in full: per-field deviations with the value that actually arrived, the route, the request that was sent, and the response body they were read from (first 4 KB, credential headers redacted). Ids come from list_contract_drift. Requires project context. |
| get_notification_preferencesA | Read notification preferences per category. scope 'user' (default) returns your own settings, where isUserOverride tells you whether a category follows the organization default or your own choice; scope 'org' returns the organization defaults. Use this to read preferences; to change your own use update_notification_preferences. Requires organization context. |
| get_test_resultsA | List the run history of a test suite: each execution with status, timing and pass/fail counts. Returns run ids — pass one to get_test_run for that run's cases, then get_test_result for one case. Requires project context. |
| export_specA | Export an API specification as OpenAPI YAML, JSON, or Postman Collection. Use this to get the finished document out; to check it against the standard first use validate_spec. Requires project context. |
| mark_all_notifications_readA | Mark EVERY unread notification of the authenticated user in the active organization as read. This cannot be undone — to clear a single one use mark_notification_read. Requires organization context (call set_context first). |
| list_request_body_componentsA | List all reusable request body components (OpenAPI components/requestBodies) of an API specification. Optionally include usage counts showing how many endpoints link each component. Use this to browse or find an id; for one component with its schema use get_request_body_component. Requires project context. |
| list_membersA | List the organization's members with their role, the custom role if they have one, when they joined and when they last logged in. Use this for the organization's members; for the teams they belong to use list_teams. Requires organization context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| list_shared_reportsA | List the share links that exist for a test run, with their access level and expiry. Use this to see existing share links; to create, extend or revoke one use manage_shared_report. Requires project context. |
| list_tagsA | List the endpoint tags of an API specification, including their Markdown descriptions and display order. Tag descriptions are exported as root-level OpenAPI tags and shown in the documentation portal. Use this to browse tags or find a tag id; for one tag by id use get_tag. Requires project context (call set_context first). |
| searchA | Search across API specs and endpoints in the active project by name, path, or description. Returns matching specs and endpoints. Use this to find specs and endpoints by text; for the project's counts and activity use get_dashboard. Requires project context. |
| get_security_findingsA | List security findings for the active project, optionally filtered by status, severity, scanner, or a free-text search. Findings are ordered by severity (most severe first). Pass findingId to get one finding in full, including the raw evidence the scanner captured (request and response) — that blob is omitted from the list to keep it small. Requires project context. |
| list_shared_schemasA | List the reusable schemas of the shared library. Scope 'project' (default) reads the current project's library, 'org' the organization-wide one. Each entry carries the id and rowVersion needed to update or link it. Use this to browse or find an id; to create, change or delete one use manage_shared_schema. |
| list_seedsA | List the seeds of the active project — the request sequences that set up and tear down test data. Pass seedId to get one seed with its full step lists and rowVersion. Use this to browse seeds or find a seed id; to execute one use run_seed. Requires project context. |
| export_findings_sarifA | Export the active project's security findings as a SARIF 2.1.0 document — the format GitHub Code Scanning and comparable CI tools ingest. Defaults to open findings so the export reflects the current posture. Use this to hand findings to CI or GitHub; to read them here use get_security_findings. Requires project context. |
| get_doc_snippetA | Get one snippet with its full Markdown content and rowVersion. Set includeUsages to also list the pages embedding it — do that before deleting one. Use this when you already have the snippet id; to browse a version's snippets use list_doc_snippets. Requires project context. |
| get_shared_responseA | Get one shared response with its schema, headers, example and rowVersion. Scope 'project' (default) or 'org'. Set includeUsedBy to also list the specs linking it — project scope only. Use this when you already have the response id; to browse the library use list_shared_responses. |
| export_test_runA | Export a test run as a report. format 'json' (default), 'html' or 'junit' — use junit for CI systems that consume JUnit XML. Returns the report content inline. Requires project context. |
| list_script_snippetsA | List the project's reusable pre-request and post-response script snippets, with their code and how often each is used. Use this to browse snippets or find an id; to create, change or delete one use manage_script_snippet. Requires project context. |
| get_finding_remediationA | Get remediation advice for a single finding as GitHub-flavored markdown. When AI Assist is enabled and within budget this is a suggestion written for this exact finding; otherwise it falls back to the static guidance-library text and says so in 'source'. Unlike the other reads this one can spend AI budget, which is why it is a separate tool. Use this for advice on one finding; for the whole library use list_security_guidance. Requires project context. |
| get_environment_pinsA | List which version each environment currently pins for this spec, whether the pin is frozen, and where it came from. Use this to see what each environment resolves to; to change a pin use promote_version. Requires project context. |
| list_header_exclusionsA | List the headers excluded from the policy cascade. Level 'response' (needs specId and responseId) covers one endpoint response, 'project' the whole project. Requires project context. Use this to see what is excluded from the cascade; to add or drop an exclusion use manage_header_exclusion. |
| get_monitorA | Get one monitor with its recent checks. The include flags pull in what the monitor detail page shows next to it: uptime and latency percentiles over 24h to 90d, the alert policy that applies (inherited or its own), its maintenance windows, and the fire/resolve history of its alerts. Use this when you already have the monitor id; to browse a project's monitors use list_monitors. Requires project context. |
| list_scan_runsA | List the security scan runs of the active project, newest first. Pass scanRunId to get a single run with its live progress instead — that is how you poll a scan started by run_security_scan. Requires project context. |
| list_response_componentsA | List the reusable response components of a spec version. Set includeUsageCounts to see how often each one is referenced. Use this to browse or find an id; to create, change or delete one use manage_response_component. Requires project context. |
| list_fixturesA | List all project-owned fixtures in the active project. Fixtures are structured test data (YAML/JSON) reusable across tests, mocks and docs. Use this for project-owned fixtures; for the shared organization ones use list_org_fixtures. Requires project context. |
| update_notification_preferencesA | Set YOUR notification preferences for one or more categories. Categories you do not mention keep their current setting. Use resetCategories to drop your override so a category follows the organization default again — an entry in categoriesJson can only set an override, never remove one. Valid categories: api_design, testing, project, mock_server, style_guide, team, portal, monitoring, security, billing, deprecation. Use this for your own preferences; for the organization defaults use update_org_notification_defaults. |
| list_project_teamsA | List the teams that reach the active project and with which role. The other direction of list_team_projects — this is the tool for 'who can write here'. Requires project context. Read-only: members, roles, teams and SSO are not changeable through MCP by design — a human does those in the web app. |
| get_fixtureA | Get a fixture by its public ID including its raw source and normalized JSON content. Use this when you already have the fixture id; to browse the project's fixtures use list_fixtures. Requires project context. |
| get_breaking_changesA | Identify and classify breaking changes between two specification versions. Returns changes classified as Breaking, NonBreaking, or Deprecated with migration hints. Use this for classified breaking changes; for the full structural diff use compare_versions. Requires project context. |
| resolve_variablesA | Show the effective variable set for one environment after merging all three scopes — organization, then environment, then your personal overrides — with the scope each winning value came from. This is what a test run or mock request actually sees. Secret values are masked. |
| list_personal_variablesA | List your personal variables for one environment. They override both organization and environment variables and are visible only to you. Secret values are always masked. Use this for your own layer; for the merged result of all three use resolve_variables. Requires organization context. |
| list_snapshotsA | List the project's data snapshots — recorded resource states that can be restored to return an environment to a known point. Pass snapshotId to get one snapshot with its recorded resources. Use this to browse snapshots; to record a new one use record_snapshot. Requires project context. |
| get_header_policiesA | Get the headers that apply to a WHOLE endpoint, grouped by status code, after the org → project → spec cascade. Takes an endpointId; for one response use get_resolved_headers (responseId). Neither returns policy definitions — list those with list_header_policies. Requires project context. |
| list_shared_component_usagesA | List which shared-library components a spec links, including whether the library has a newer version than the spec is pinned to (hasUpdate). The usage ids returned here are what manage_shared_component_link needs for 'unlink' and 'accept_update'. Requires project context. |
| list_parameter_componentsA | List the reusable parameter components of a spec version. Set includeUsageCounts to see how often each one is referenced. Use this to browse or find an id; to create, change or delete one use manage_parameter_component. Requires project context. |
| list_artifact_sync_reviewsA | List what in this project has fallen out of sync with the specs behind it — mocks, tests and monitors whose endpoint changed or disappeared. Worth reading after changing a draft: these are the follow-ups that change created. Requires project context. |
| get_test_resultA | Get ONE test case's result inside a run: status code, timing, the response body and headers, every assertion outcome, extracted variables and any script output. This is the read to make when a run failed and you need to know why. The id comes from get_test_run's results[].id, not from get_test_results (run ids). Requires project context. |
| get_session_usageA | Return usage metrics for the current MCP session: total tool calls, error count, aggregate duration and response size, per-tool call counts, and session timestamps. Metrics are in-memory and reset when the server restarts or the session goes idle. Use this for what this session has spent; for which toolsets exist at all use list_toolsets. |
| get_doc_pageA | Get a documentation page with full content and metadata. Returns title, slug, Markdown content, page type, and timestamps. Requires project context (call set_context first). |
| get_mock_serverA | Get the mock server status and URL for the active project. Returns server details including MockCode, URL, active status, rule count, and Smart Mock settings. Returns null if no mock server exists yet (use create_mock_server to create one). Set includeStats to also get rule, request-log and spec-coverage statistics. The access token is never returned; when requireToken is on, the only way to obtain one is 'regenerate_mock_server_token' (which invalidates the old token). Requires project context (call set_context first). |
| preview_smart_mockA | Render a response body template with its {{faker.*}} placeholders replaced by generated values, using the active project's Smart Mock settings. Use this to check a template before saving it on a rule. Requires project context. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| triage_incidents | Work through the monitoring incidents that are still open or acknowledged. Loads them, then guides through diagnosis, acknowledgement and resolution. |
| review_spec | Review an existing API specification for best practices, consistency, and completeness. Loads the spec details and validation report to provide actionable improvement suggestions. |
| triage_security_findings | Work through the open security findings of the active project. Loads them ordered by severity, then guides through verification, remediation and status decisions. |
| fix_violations | Automatically fix style guide violations in an API specification. Loads the current lint report and provides instructions to resolve each violation. |
| document_api | Generate comprehensive API documentation including guides, tutorials, and examples. Creates documentation pages tailored to the target audience. |
| generate_tests | Generate test cases for all endpoints in an API specification. Loads the endpoint list and creates a comprehensive test suite with assertions. |
| generate_mock_rules | Generate mock server rules for all endpoints in an API specification. Creates realistic mock responses including success and error scenarios. |
| design_api | Design a new API from scratch based on a description. Loads the organization's style guide rules and provides step-by-step instructions to create a complete API specification using Routebase tools. |
| run_deprecation | Walk a deprecation through its lifecycle — announce, notify consumers, advance, retire. Loads everything the organization currently has deprecated and the rules it is checked against. |
| onboard_project | Generate a project overview for a new team member. Summarizes specs, test health, mock server status, and documentation. |
| generate_schema | Generate a JSON Schema from an example JSON object. Analyzes the structure and creates a proper schema definition. |
| analyze_test_failures | Analyze failed test cases from a test run and suggest fixes. Loads the test run results and provides diagnosis for each failure. |
| migrate_version | Guide through creating a new API version with breaking change analysis and migration strategy. Loads existing versions and provides step-by-step migration instructions. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 162 tools
Descriptions carefully cross-reference and differentiate tools by scope and object, but with 162 tools there is substantial overlap (e.g., multiple drift, monitoring, and documentation reads) making misselection likely.
Names predominantly follow a snake_case verb_noun convention (list_, get_, manage_, etc.), with only minor deviations like get_scheduled_publishes for a list operation.
162 tools is an extreme mismatch for any server; even with toolsets, the surface is overwhelmingly large and violates the typical 3-15 tool scope.
Core API design CRUD is missing: no manage/create/update tools for specs, endpoints, or schemas are listed, despite references to create_endpoint and update_schema. Significant gaps will cause agent failures for mutation workflows.