Tool groups and managed HTTP API tools
Tool groups are managed objects in the administration API, not YAML configuration. A group owns the shared HTTPS base URL, static headers or OAuth 2.0 client_credentials, JWT required scopes, and request timeout for its tools. Header values and OAuth client secrets are encrypted in the selected database; the API exposes only configured/not-configured markers. Group scope checks retain the same all-of semantics as backend scopes; optional group-local tool rules can add scopes to selected tools.
A group may contain hand-authored HTTP tools and multiple OpenAPI 3.0 or 3.1 imports. OpenAPI imports can be inspected before they are saved. Both kinds are MCP capabilities: they are listed and invoked only through the configured /mcp Streamable HTTP endpoint. MCPHub does not expose a raw HTTP proxy or an arbitrary method/path passthrough route.
The stable management paths are:
| Operation | Path |
|---|---|
| List/create groups | GET/POST /api/v1/tool-groups |
| Read/update/delete a group; probe it | GET/PUT/DELETE /api/v1/tool-groups/{groupID}, POST .../{groupID}/probe |
| List/create or read/update/delete manual tools | GET/POST .../{groupID}/tools, GET/PUT/DELETE .../{groupID}/tools/{toolName} |
| Inspect, list/create, or read/update/delete OpenAPI imports | POST .../{groupID}/imports/inspect, GET/POST .../{groupID}/imports, GET/PUT/DELETE .../{groupID}/imports/{importID} |
| Refresh an OpenAPI import | POST .../{groupID}/imports/{importID}/refresh |
Group, manual-tool, and import resources return an ETag. Updates and deletes require the matching If-Match; a stale revision returns 409 revision_conflict. These resources are persisted and changed only through the admin API and the selected database; there is intentionally no tool_groups (or equivalent) YAML schema and SIGHUP does not import one.
Group base URLs and OpenAPI source URLs must use HTTPS; group HTTP requests and source fetches do not follow redirects. A source fetched from another origin never receives the group's static headers or OAuth secret. OpenAPI documents are capped at 5 MiB, requests carrying a document at 6 MiB, and HTTP-tool responses at 1 MiB by default; the response limit is configurable from 64 KiB through 16 MiB. A URL-backed import refreshes automatically every 15 minutes by default (allowed range 1 minute to 24 hours); a failed refresh keeps the last-known-good document/tools and retries with backoff.