> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update MCP config

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes how the app's MCP server authenticates clients, which tools it serves, or both. The app needs an MCP server first, which the builder sets up when you ask it to in chat.

Send only the keys you want to change. `tools` replaces the stored `tools` object whole, so read the current one with [Get MCP config](/api-reference/get-mcp-config), change it, and send all of it back.

Changes reach AI clients once you [deploy the app](/api-reference/deploy-an-app). The response shows the config as saved, and each tool's `published` tells you whether the live server already matches it.

Switching to `none` needs the app to be open to visitors without logging in. A workspace can also turn MCP off for its apps, or require `oauth`.

This is limited to 60 requests a minute for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json patch /api/apps/platform/{app_id}/mcp/config
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/platform/{app_id}/mcp/config:
    patch:
      summary: Update MCP config
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Changes how the app's MCP server authenticates clients, which tools it
        serves, or both. The app needs an MCP server first, which the builder
        sets up when you ask it to in chat.


        Send only the keys you want to change. `tools` replaces the stored
        `tools` object whole, so read the current one with [Get MCP
        config](/api-reference/get-mcp-config), change it, and send all of it
        back.


        Changes reach AI clients once you [deploy the
        app](/api-reference/deploy-an-app). The response shows the config as
        saved, and each tool's `published` tells you whether the live server
        already matches it.


        Switching to `none` needs the app to be open to visitors without logging
        in. A workspace can also turn MCP off for its apps, or require `oauth`.


        This is limited to 60 requests a minute for each app. Some workspaces
        have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: patch_app_mcp_config_api_apps_platform__app_id__mcp_config_patch
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppMcpConfigPatch'
      responses:
        '200':
          description: The config as saved, and its tools.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AppMcpConfigResponse'
        '400':
          description: The resulting config isn't valid. The detail lists each problem.
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, it doesn't exist, or your
            API key is read-only. Also returned when the app's workspace has
            turned MCP off, or requires `oauth` and the config uses `none`.
        '404':
          description: >-
            App not found, or it's outside the workspace your credential is
            scoped to.
        '409':
          description: >-
            The app has no MCP server yet, or you're switching to `none` and the
            app requires visitors to log in.
        '422':
          description: >-
            The body isn't a JSON object, `auth` isn't `none` or `oauth`, or
            `tools` isn't an object.
        '429':
          description: Too many MCP config updates for this app in the last minute.
components:
  schemas:
    AppMcpConfigPatch:
      properties:
        auth:
          anyOf:
            - type: string
              enum:
                - none
                - oauth
            - type: 'null'
          title: Auth
          description: >-
            How clients authenticate. Either `"oauth"`, where clients sign in,
            or `"none"`, where anyone can call the entity read tools without
            signing in. Leave it out to keep the current mode.
          example: oauth
        tools:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Tools
          description: >-
            The whole `tools` object, which replaces the stored one.
            `excluded_agents` lists agents to hold back. `entity_overrides` maps
            an entity name to the `operations` to serve, where an empty list
            holds the entity back. `functions` lists the custom tools, and one
            with `disabled` set to `true` is held back. Leave it out to keep the
            current tools.
          example:
            entity_overrides:
              Invoice:
                operations: []
            excluded_agents:
              - support_bot
            functions: []
      type: object
      title: AppMcpConfigPatch
      description: The MCP config keys to change.
    AppMcpConfigResponse:
      properties:
        config:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Config
          description: >-
            The editable config, or `null` when the app has no MCP server. It
            has `auth`, `login_path`, `consent_path`, and the `tools` object
            that [Update MCP config](/api-reference/update-mcp-config) replaces.
          example:
            auth: oauth
            tools:
              entity_overrides:
                Invoice:
                  operations: []
              excluded_agents:
                - support_bot
              functions: []
        tools:
          items:
            $ref: '#/components/schemas/AppMcpToolRow'
          type: array
          title: Tools
          description: Every tool the config can serve, and whether it does.
          default: []
        pending_removal:
          items:
            $ref: '#/components/schemas/AppMcpLiveToolRow'
          type: array
          title: Pending Removal
          description: >-
            Tools the live server still serves that the config no longer
            produces. The next publish removes them.
          default: []
      type: object
      title: AppMcpConfigResponse
      description: The app's editable MCP config and the tools it resolves to.
    AppMcpToolRow:
      properties:
        key:
          type: string
          title: Key
          description: >-
            Stable ID of the row. Two rows can share a `name`, but never a
            `key`.
          example: 'entity:Task:read:'
        name:
          type: string
          title: Name
          description: Name AI clients call the tool by.
          example: query_task
        kind:
          type: string
          enum:
            - entity
            - agent
            - function
          title: Kind
          description: >-
            Where the tool comes from. Either `"entity"`, `"agent"`, or
            `"function"` for a custom tool.
          example: entity
        source:
          type: string
          title: Source
          description: >-
            Entity, agent, or custom tool in the config that this row belongs
            to.
          example: Task
        operation:
          anyOf:
            - type: string
            - type: 'null'
          title: Operation
          description: >-
            Entity operation the tool performs, or `null` for agent and custom
            tools. One of `read`, `create`, `update`, or `delete`.
          example: read
        handler:
          anyOf:
            - type: string
            - type: 'null'
          title: Handler
          description: Backend function a custom tool runs, or `null` for other tools.
          example: sendInvoice
        title:
          anyOf:
            - type: string
            - type: 'null'
          title: Title
          description: Display title of the tool, or `null` when it has none.
          example: Query tasks
        description:
          type: string
          title: Description
          description: What the tool does, as AI clients see it.
          default: ''
          example: Find Task records by ID or filter.
        read_only_hint:
          type: boolean
          title: Read Only Hint
          description: Whether the tool is marked as only reading data.
          default: false
          example: true
        exposed:
          type: boolean
          title: Exposed
          description: Whether the config serves the tool.
          example: true
        published:
          type: boolean
          title: Published
          description: >-
            Whether the live server already matches `exposed`. It's `false`
            while a change waits for a publish.
          example: true
      type: object
      required:
        - key
        - name
        - kind
        - source
        - exposed
        - published
      title: AppMcpToolRow
      description: A tool the config serves or holds back.
    AppMcpLiveToolRow:
      properties:
        name:
          type: string
          title: Name
          description: Name AI clients call the tool by.
          example: query_invoice
        kind:
          type: string
          enum:
            - entity
            - agent
            - function
          title: Kind
          description: >-
            Where the tool comes from. Either `"entity"`, `"agent"`, or
            `"function"` for a custom tool.
          example: entity
        title:
          anyOf:
            - type: string
            - type: 'null'
          title: Title
          description: Display title of the tool, or `null` when it has none.
          example: Query invoices
        description:
          type: string
          title: Description
          description: What the tool does, as AI clients see it.
          default: ''
          example: Find Invoice records by ID or filter.
        read_only_hint:
          type: boolean
          title: Read Only Hint
          description: Whether the tool is marked as only reading data.
          default: false
          example: true
      type: object
      required:
        - name
        - kind
      title: AppMcpLiveToolRow
      description: A tool only the live server still has.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````