# Update MCP configuration

Update MCP configuration

`PATCH /api/mcp/servers/{id}`

Required permission: `mcpServer:update`.

## Parameters

| Name | In | Type | Required | Description |

| --- | --- | --- | --- | --- |

| `id` | path | `string` | Yes | — |

| `Idempotency-Key` | header | `string` | No | Required for writes authenticated by a service credential and for service-account lifecycle writes. Other session writes may opt in. Reuse the key and payload for retries. Settled keys remain reserved for at least seven days; a transient 4xx releases its key. Changed payloads return 409. Match any legacy clientOperationId/clientMessageId in the body. |

## Request body

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `projectId` | `string \| null` | No | — | — |
| `name` | `string` | No | min length 1 | — |
| `config` | `object` | No | — | — |
| `config.auth` | `object` | No | — | — |
| `config.auth.Option 1` | `object` | No | — | — |
| `config.auth.Option 1.kind` | `string` | Yes | constant "oauth2" | — |
| `config.auth.Option 1.grantType` | `string` | Yes | constant "client_credentials" | — |
| `config.auth.Option 1.clientId` | `string` | Yes | min length 1 | — |
| `config.auth.Option 1.clientSecret` | `string` | Yes | min length 1 | — |
| `config.auth.Option 1.clientName` | `string` | No | min length 1 | — |
| `config.auth.Option 1.scope` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens` | `object` | No | — | — |
| `config.auth.Option 1.tokens.accessToken` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.access_token` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.expiresIn` | `number` | No | — | — |
| `config.auth.Option 1.tokens.expires_in` | `number` | No | — | — |
| `config.auth.Option 1.tokens.idToken` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.id_token` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.refreshToken` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.refresh_token` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.scope` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.tokenType` | `string` | No | min length 1 | — |
| `config.auth.Option 1.tokens.token_type` | `string` | No | min length 1 | — |
| `config.auth.Option 2` | `object` | No | — | — |
| `config.auth.Option 2.kind` | `string` | Yes | constant "oauth2" | — |
| `config.auth.Option 2.grantType` | `string` | Yes | constant "authorization_code" | — |
| `config.auth.Option 2.clientId` | `string` | No | min length 1 | — |
| `config.auth.Option 2.clientSecret` | `string` | No | min length 1 | — |
| `config.auth.Option 2.clientInformation` | `object` | No | — | — |
| `config.auth.Option 2.clientInformation.client_id` | `string` | Yes | min length 1 | — |
| `config.auth.Option 2.clientInformation.client_secret` | `string` | No | min length 1 | — |
| `config.auth.Option 2.clientInformation.client_id_issued_at` | `number` | No | — | — |
| `config.auth.Option 2.clientInformation.client_secret_expires_at` | `number` | No | — | — |
| `config.auth.Option 2.clientName` | `string` | No | min length 1 | — |
| `config.auth.Option 2.codeVerifier` | `string` | No | min length 1 | — |
| `config.auth.Option 2.discoveryState` | `object` | No | — | — |
| `config.auth.Option 2.discoveryState.[key]` | `updateMcpServerRequestschema0` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 1` | `string` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 2` | `number` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 3` | `boolean` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 4` | `null` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 5` | `updateMcpServerRequestschema0[]` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 5.Recursive value` | `updateMcpServerRequestschema0` | No | — | Recursive schema; see /docs/openapi.json. |
| `config.auth.Option 2.discoveryState.[key].Option 6` | `object` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 6.[key]` | `updateMcpServerRequestschema0` | No | — | — |
| `config.auth.Option 2.discoveryState.[key].Option 6.[key].Recursive value` | `updateMcpServerRequestschema0` | No | — | Recursive schema; see /docs/openapi.json. |
| `config.auth.Option 2.redirectUrl` | `string<uri>` | No | — | — |
| `config.auth.Option 2.scope` | `string` | No | min length 1 | — |
| `config.auth.Option 2.state` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens` | `object` | No | — | — |
| `config.auth.Option 2.tokens.accessToken` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.access_token` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.expiresIn` | `number` | No | — | — |
| `config.auth.Option 2.tokens.expires_in` | `number` | No | — | — |
| `config.auth.Option 2.tokens.idToken` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.id_token` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.refreshToken` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.refresh_token` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.scope` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.tokenType` | `string` | No | min length 1 | — |
| `config.auth.Option 2.tokens.token_type` | `string` | No | min length 1 | — |
| `config.args` | `string[]` | No | — | — |
| `config.args.[item]` | `string` | No | — | — |
| `config.command` | `string` | No | min length 1 | — |
| `config.cwd` | `string` | No | — | — |
| `config.description` | `string` | No | max length 500 | — |
| `config.env` | `object` | No | — | — |
| `config.env.[key]` | `string` | No | — | — |
| `config.headers` | `object` | No | — | — |
| `config.headers.[key]` | `string` | No | — | — |
| `config.needsAuth` | `boolean` | No | — | — |
| `config.transport` | `string` | No | http · sse · stdio | — |
| `config.url` | `string<uri>` | No | — | — |
| `replaceConfig` | `boolean` | No | — | — |
| `enabled` | `boolean` | No | — | — |
| `clientOperationId` | `string` | No | min length 1, max length 64 | — |

```json
{
  "enabled": false
}
```

## Example request

```bash
curl --request PATCH \
  --url https://api.hoplite.sh/api/mcp/servers/id \
  --header "X-Api-Key: $HOPLITE_API_KEY" \
  --header "Idempotency-Key: $HOPLITE_OPERATION_ID" \
  --header 'Content-Type: application/json' \
  --data '{
  "enabled": false
}'
```

## 200 response

Successful response

Content type: `application/json`. Response type: `object`.

| Field | Type | Required | Constraints | Description |
| --- | --- | --- | --- | --- |
| `ok` | `boolean` | Yes | constant true | — |
| `server` | `object` | Yes | — | — |
| `server.id` | `string` | Yes | — | — |
| `server.projectId` | `string \| null` | No | — | — |
| `server.name` | `string` | Yes | — | — |
| `server.config` | `object` | No | — | — |
| `server.config.[key]` | `updateMcpServerResponseschema0` | No | — | — |
| `server.config.[key].Option 1` | `string` | No | — | — |
| `server.config.[key].Option 2` | `number` | No | — | — |
| `server.config.[key].Option 3` | `boolean` | No | — | — |
| `server.config.[key].Option 4` | `null` | No | — | — |
| `server.config.[key].Option 5` | `updateMcpServerResponseschema0[]` | No | — | — |
| `server.config.[key].Option 5.Recursive value` | `updateMcpServerResponseschema0` | No | — | Recursive schema; see /docs/openapi.json. |
| `server.config.[key].Option 6` | `object` | No | — | — |
| `server.config.[key].Option 6.[key]` | `updateMcpServerResponseschema0` | No | — | — |
| `server.config.[key].Option 6.[key].Recursive value` | `updateMcpServerResponseschema0` | No | — | Recursive schema; see /docs/openapi.json. |
| `server.enabled` | `boolean` | No | — | — |
| `server.createdAt` | `string` | No | — | — |
| `server.updatedAt` | `string` | No | — | — |

```json

```

## Response headers

| Header | Type | Statuses | Description |

| --- | --- | --- | --- |

| `RateLimit` | `string` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Current ingress policy, remaining requests, and seconds until reset, for example `"ingress";r=599;t=60`. |

| `RateLimit-Policy` | `string` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Ingress quota and window, for example `"ingress";q=600;qu="requests";w=60`. |

| `X-RateLimit-Limit` | `integer` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Maximum requests allowed in the current rolling window. |

| `X-RateLimit-Remaining` | `integer` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Requests remaining in the current rolling window. |

| `X-RateLimit-Reset` | `integer` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Unix timestamp when the current rolling window resets. |

| `x-request-id` | `string` | `200`, `400`, `401`, `402`, `403`, `404`, `409`, `410`, `429`, `500`, `501`, `503` | Request correlation ID. |

| `Retry-After` | `integer` | `429`, `503` | Seconds until another request should be attempted. |

| `X-Retry-After` | `integer` | `429`, `503` | Legacy retry delay in seconds. |

## Status codes

- `200` — Successful response

- `400` — Invalid request. Validation responses include field paths.

- `401` — The API key is missing, invalid, or lacks the operation's permission.

- `402` — The organization does not have access to the requested product capability.

- `403` — The key's current user no longer has the required organization membership or role.

- `404` — The resource is not available in the authenticated scope.

- `409` — The request conflicts with a retry receipt or current resource state.

- `410` — The event cursor has expired; capture a fresh head and resource snapshot.

- `429` — The API-key rate limit has been exceeded.

- `500` — The API encountered an unexpected failure.

- `501` — The deployment has not configured the requested capability.

- `503` — A required API dependency, including the rate limiter, is unavailable.