> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nasiko.com/llms.txt
> Use this file to discover all available pages before exploring further.

# `GET /api/mcp/agents/{agent_id}/connectors` — connectors + per-agent status.

> Same relaxed gate as `list_tool_rules` below (and `set_connector_access`/
`list_connector_tools`, already relaxed by `a9012ded`/`56e46b07`): a caller
who can't manage the whole agent still sees the connector(s) they
themselves can reach (narrowed, not blocked outright) — otherwise this
endpoint (the natural first call before `agent-tools enable`/`set-rule`)
would be the one sibling still hard-denying the exact caller those other
endpoints already permit, making them undiscoverable in practice. This
works with zero relationship to the agent itself, e.g. a connector owner
whose connector was granted to someone else's agent.

If that per-connector filter finds nothing at all (no connector the
caller can manage happens to be attached here), it used to hard-403
unconditionally — but an empty result is also the normal, legitimate
state for a caller who has ordinary access to the agent
([`can_access_agent`] — owner, public, or a plain share) and simply
hasn't attached any connector of their own yet (e.g. they're about to
attach their first one). Only a caller with NEITHER a manageable
connector already here NOR any relationship to the agent at all still
gets the 403.



## OpenAPI

````yaml /api-reference/openapi.json get /api/mcp/agents/{agent_id}/connectors
openapi: 3.1.0
info:
  title: Nasiko API
  description: >-
    HTTP API for the Nasiko OpenRuntime: agents, coding harnesses, TokenOps,
    routing, MCP, and secrets. Spec is generated from annotated routes; some
    surfaces are documented on the hand-written pages alongside this file.
  license:
    name: ''
  version: 0.1.0
servers: []
security: []
tags:
  - name: secrets
    description: Encrypted per-user agent secrets
  - name: catalog
    description: >-
      Agent catalog: registration, discovery, versions, per-agent secrets, and
      source import
  - name: agents
    description: >-
      Agent lifecycle: deployments, LLM routing config, update/rollback,
      upload-and-deploy
  - name: orchestrator
    description: >-
      A2A dispatch: routing-engine/ReAct orchestrator and direct agent chat,
      plus routing stats
  - name: users
    description: >-
      User management: CRUD, roles, credentials, accessible agents
      (superuser-only)
  - name: usage
    description: Per-user token usage and cost reporting
  - name: observability
    description: Sessions, traces, spans, agent logs, and FinOps reporting
  - name: llm-router
    description: LLM routing presets, provider/model catalog, and tier→model registry
  - name: mcp
    description: >-
      MCP gateway: agent-facing JSON-RPC tool calls, connector
      registration/upload/sharing, credentials & OAuth, and per-agent tool
      permissions
paths:
  /api/mcp/agents/{agent_id}/connectors:
    get:
      tags:
        - mcp
      summary: >-
        `GET /api/mcp/agents/{agent_id}/connectors` — connectors + per-agent
        status.
      description: >-
        Same relaxed gate as `list_tool_rules` below (and
        `set_connector_access`/

        `list_connector_tools`, already relaxed by `a9012ded`/`56e46b07`): a
        caller

        who can't manage the whole agent still sees the connector(s) they

        themselves can reach (narrowed, not blocked outright) — otherwise this

        endpoint (the natural first call before `agent-tools enable`/`set-rule`)

        would be the one sibling still hard-denying the exact caller those other

        endpoints already permit, making them undiscoverable in practice. This

        works with zero relationship to the agent itself, e.g. a connector owner

        whose connector was granted to someone else's agent.


        If that per-connector filter finds nothing at all (no connector the

        caller can manage happens to be attached here), it used to hard-403

        unconditionally — but an empty result is also the normal, legitimate

        state for a caller who has ordinary access to the agent

        ([`can_access_agent`] — owner, public, or a plain share) and simply

        hasn't attached any connector of their own yet (e.g. they're about to

        attach their first one). Only a caller with NEITHER a manageable

        connector already here NOR any relationship to the agent at all still

        gets the 403.
      operationId: list_connectors
      parameters:
        - name: agent_id
          in: path
          description: Agent id
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: Connectors + per-agent status — `data.connectors` is a list
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpEnvelope'
        '403':
          description: >-
            Caller cannot manage this agent, has no manageable connector already
            attached, and has no other relationship to it
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpEnvelope'
components:
  schemas:
    McpEnvelope:
      type: object
      description: |-
        Doc-only schema for the standard MCP `ApiResponse` envelope
        (`{"data": …, "status_code": N, "message": "…"}`). Most `/api/mcp/*`
        payloads are service-layer `serde_json::Value` views, so `data` is
        documented as a free-form object; each route's response description says
        what it carries.
      required:
        - data
        - status_code
        - message
      properties:
        data:
          type:
            - object
            - 'null'
        message:
          type: string
        status_code:
          type: integer
          format: int32
          example: 200
          minimum: 0

````