MCP Server - API Usage & Reference
API Endpoints
Call a Tool
Endpoint:POST {OMURL}/mcp
Sample Request (Search Metadata):
Get a Prompt
Endpoint:POST {OMURL}/mcp
Sample Request:
Error Handling
Protocol-Level Errors
Authentication Error
A request with a missing or invalid/expired bearer token fails at the transport level: the server responds with HTTP status401 Unauthorized (plus a WWW-Authenticate header identifying the OAuth authorization server) and a JSON-RPC 2.0 error body:
message is "Invalid or expired bearer token" instead. Check the HTTP status code first: a 401 response means your client must (re-)authenticate before retrying, rather than treating the call as a normal JSON-RPC tool error.
Invalid Tool Error
Validation Error
Tool Execution Errors
A tool that runs but fails (a bad argument, a missing entity, an authorization denial, or a backend fault) does not return a JSON-RPC protocol-level error object. Instead, the server returns a normal JSON-RPC success response whoseresult.isError field is true. The failure details are a JSON string inside result.content[0].text, and the same object is also available as result.structuredContent for clients that support it.
Sample Response (entity not found):
Always check
result.isError on a successful JSON-RPC response before assuming the tool call succeeded. A 200-shaped response isn’t proof the operation worked.
Best Practices
- Always authenticate: Include the JWT token in every request
- Handle errors gracefully: Check for error responses and handle them appropriately
- Use appropriate limits: Don’t request too many results at once to avoid performance issues
- Cache server capabilities: Store the results of the initialize call to avoid repeated requests
- Use specific entity types: When possible, specify entityType to get more relevant results
Security Considerations
- JWT tokens should be kept secure and not logged
- Use HTTPS for all communications
- Implement token refresh logic for long-running connections
- Follow your organization’s security policies for API access