curl --request PATCH \
--url https://app.base44.com/api/apps/platform/{app_id}/mcp/config \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"auth": "oauth",
"tools": {
"entity_overrides": {
"Invoice": {
"operations": []
}
},
"excluded_agents": [
"support_bot"
],
"functions": []
}
}
'import requests
url = "https://app.base44.com/api/apps/platform/{app_id}/mcp/config"
payload = {
"auth": "oauth",
"tools": {
"entity_overrides": { "Invoice": { "operations": [] } },
"excluded_agents": ["support_bot"],
"functions": []
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
auth: 'oauth',
tools: {
entity_overrides: {Invoice: {operations: []}},
excluded_agents: ['support_bot'],
functions: []
}
})
};
fetch('https://app.base44.com/api/apps/platform/{app_id}/mcp/config', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/platform/{app_id}/mcp/config",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'auth' => 'oauth',
'tools' => [
'entity_overrides' => [
'Invoice' => [
'operations' => [
]
]
],
'excluded_agents' => [
'support_bot'
],
'functions' => [
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/platform/{app_id}/mcp/config"
payload := strings.NewReader("{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://app.base44.com/api/apps/platform/{app_id}/mcp/config")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/platform/{app_id}/mcp/config")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}"
response = http.request(request)
puts response.read_body{
"config": {
"auth": "oauth",
"tools": {
"entity_overrides": {
"Invoice": {
"operations": []
}
},
"excluded_agents": [
"support_bot"
],
"functions": []
}
},
"tools": [],
"pending_removal": []
}Update MCP config
Changes how the app’s MCP server authenticates clients, which tools it serves, or both. The app needs an MCP server first, which the builder sets up when you ask it to in chat.
Send only the keys you want to change. tools replaces the stored tools object whole, so read the current one with Get MCP config, change it, and send all of it back.
Changes reach AI clients once you deploy the app. The response shows the config as saved, and each tool’s published tells you whether the live server already matches it.
Switching to none needs the app to be open to visitors without logging in. A workspace can also turn MCP off for its apps, or require oauth.
This is limited to 60 requests a minute for each app. Some workspaces have a different limit.
curl --request PATCH \
--url https://app.base44.com/api/apps/platform/{app_id}/mcp/config \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"auth": "oauth",
"tools": {
"entity_overrides": {
"Invoice": {
"operations": []
}
},
"excluded_agents": [
"support_bot"
],
"functions": []
}
}
'import requests
url = "https://app.base44.com/api/apps/platform/{app_id}/mcp/config"
payload = {
"auth": "oauth",
"tools": {
"entity_overrides": { "Invoice": { "operations": [] } },
"excluded_agents": ["support_bot"],
"functions": []
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
auth: 'oauth',
tools: {
entity_overrides: {Invoice: {operations: []}},
excluded_agents: ['support_bot'],
functions: []
}
})
};
fetch('https://app.base44.com/api/apps/platform/{app_id}/mcp/config', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/platform/{app_id}/mcp/config",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'auth' => 'oauth',
'tools' => [
'entity_overrides' => [
'Invoice' => [
'operations' => [
]
]
],
'excluded_agents' => [
'support_bot'
],
'functions' => [
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/platform/{app_id}/mcp/config"
payload := strings.NewReader("{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://app.base44.com/api/apps/platform/{app_id}/mcp/config")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/platform/{app_id}/mcp/config")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"auth\": \"oauth\",\n \"tools\": {\n \"entity_overrides\": {\n \"Invoice\": {\n \"operations\": []\n }\n },\n \"excluded_agents\": [\n \"support_bot\"\n ],\n \"functions\": []\n }\n}"
response = http.request(request)
puts response.read_body{
"config": {
"auth": "oauth",
"tools": {
"entity_overrides": {
"Invoice": {
"operations": []
}
},
"excluded_agents": [
"support_bot"
],
"functions": []
}
},
"tools": [],
"pending_removal": []
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Body
The MCP config keys to change.
How clients authenticate. Either "oauth", where clients sign in, or "none", where anyone can call the entity read tools without signing in. Leave it out to keep the current mode.
none, oauth "oauth"
The whole tools object, which replaces the stored one. excluded_agents lists agents to hold back. entity_overrides maps an entity name to the operations to serve, where an empty list holds the entity back. functions lists the custom tools, and one with disabled set to true is held back. Leave it out to keep the current tools.
{
"entity_overrides": { "Invoice": { "operations": [] } },
"excluded_agents": ["support_bot"],
"functions": []
}
Response
The config as saved, and its tools.
The app's editable MCP config and the tools it resolves to.
The editable config, or null when the app has no MCP server. It has auth, login_path, consent_path, and the tools object that Update MCP config replaces.
{
"auth": "oauth",
"tools": {
"entity_overrides": { "Invoice": { "operations": [] } },
"excluded_agents": ["support_bot"],
"functions": []
}
}
Every tool the config can serve, and whether it does.
Show child attributes
Show child attributes
Tools the live server still serves that the config no longer produces. The next publish removes them.
Show child attributes
Show child attributes
Was this page helpful?