> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nasiko.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent-facing MCP JSON-RPC gateway. Generic `tools/list` / `tools/call`

> Authorization rules (docs/MCP_GATEWAY_AGENT_AUTH.md §2.4), all failing
closed:
1. bearer token missing/unknown/revoked → 401
2. `tools/list` (and initialize/ping) → allowed with agent-only identity
3. `tools/call` with no/unknown/dead-flow traceparent → 403
4. `tools/call` where the agent is not a recorded flow participant → 403
5. identity store unreachable → 403



## OpenAPI

````yaml /api-reference/openapi.json post /api/mcp
openapi: 3.1.0
info:
  title: Nasiko API
  description: >-
    HTTP API for the Nasiko OpenRuntime: agents, coding harnesses, TokenOps,
    routing, MCP, and secrets. Spec is generated from annotated routes; some
    surfaces are documented on the hand-written pages alongside this file.
  license:
    name: ''
  version: 0.1.0
servers: []
security: []
tags:
  - name: secrets
    description: Encrypted per-user agent secrets
  - name: catalog
    description: >-
      Agent catalog: registration, discovery, versions, per-agent secrets, and
      source import
  - name: agents
    description: >-
      Agent lifecycle: deployments, LLM routing config, update/rollback,
      upload-and-deploy
  - name: orchestrator
    description: >-
      A2A dispatch: routing-engine/ReAct orchestrator and direct agent chat,
      plus routing stats
  - name: users
    description: >-
      User management: CRUD, roles, credentials, accessible agents
      (superuser-only)
  - name: usage
    description: Per-user token usage and cost reporting
  - name: observability
    description: Sessions, traces, spans, agent logs, and FinOps reporting
  - name: llm-router
    description: LLM routing presets, provider/model catalog, and tier→model registry
  - name: mcp
    description: >-
      MCP gateway: agent-facing JSON-RPC tool calls, connector
      registration/upload/sharing, credentials & OAuth, and per-agent tool
      permissions
paths:
  /api/mcp:
    post:
      tags:
        - mcp
      summary: Agent-facing MCP JSON-RPC gateway. Generic `tools/list` / `tools/call`
      description: |-
        Authorization rules (docs/MCP_GATEWAY_AGENT_AUTH.md §2.4), all failing
        closed:
        1. bearer token missing/unknown/revoked → 401
        2. `tools/list` (and initialize/ping) → allowed with agent-only identity
        3. `tools/call` with no/unknown/dead-flow traceparent → 403
        4. `tools/call` where the agent is not a recorded flow participant → 403
        5. identity store unreachable → 403
      operationId: mcp_gateway
      parameters:
        - name: Authorization
          in: header
          description: >-
            `Bearer <MCP_GATEWAY_TOKEN>` — the per-agent gateway credential
            injected into the container env at deploy time
          required: true
          schema:
            type: string
        - name: traceparent
          in: header
          description: >-
            W3C trace context naming the flow this call belongs to — required
            for `tools/call`; the user identity is resolved from the flow record
          required: false
          schema:
            type:
              - string
              - 'null'
      requestBody:
        description: 'JSON-RPC 2.0 request: `tools/list` or `tools/call`'
        content:
          application/json:
            schema:
              type: object
        required: true
      responses:
        '200':
          description: JSON-RPC 2.0 response (result or error object)
          content:
            application/json:
              schema:
                type: object
        '202':
          description: Notification accepted (no `id` in request); empty object body
          content:
            application/json:
              schema:
                type: object
        '401':
          description: Missing/unknown/revoked gateway token
        '403':
          description: >-
            `tools/call` outside a live flow the agent participates in, or
            identity store unavailable

````