Call authenticated MCP endpoint
OAuth scopes read/act bound access but do not grant device functions. Every device tool also checks current owner grant. The separate public /docs-mcp service is read-only documentation.
/mcpAuthorizationBearer token (ol_agent token) · headerrequiredOwner-issued agent API connection; access ceiling and live device grants are checked separately.
AuthorizationBearer token (OAuth access token) · headerrequiredOAuth read/act scope is a ceiling. Scopes do not create device grants.
MCP-Protocol-VersionstringRequired for modern requests; must match params._meta protocolVersion.
Mcp-MethodstringRequired for modern requests; must match the JSON-RPC method.
Mcp-NamestringRequired for modern tools/call and resources/read; match tool name or resource URI. Unicode values use the protocol's base64 header encoding.
application/jsonjsonrpcstringrequiredidinteger | stringmethodstringrequiredparamsobjectMCP JSON response or server-sent event stream
JSON-RPC or MCP protocol error
Authentication required
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringScope or live device grant required
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringAccept must include application/json and text/event-stream
Content-Type must be application/json