> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Resolve a free-form query to an MCP server

> Admin-only, side-effect-free smart resolution for the add-connection flow. Accepts a URL, a bare host, or a product name ("vercel"), matches curated presets, probes bounded well-known endpoint candidates through the SSRF-guarded discovery fetch, and returns the winning URL with its requirements discovery. It performs no client registration, credential write, or connection creation.



## OpenAPI

````yaml /openapi.json post /v1/mcp-connections/resolve
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for API-key-authenticated routes that
    accept organization API keys.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: dev
servers: []
security: []
tags:
  - name: System
    description: Service health and operational routes.
  - name: Organizations
    description: Top-level organization creation and context routes.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: SCIM
    description: Organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Templates
    description: Organization shared template routes.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Admin
    description: Administrative reporting routes.
  - name: Users
    description: Current user and membership routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
paths:
  /v1/mcp-connections/resolve:
    post:
      tags:
        - Authentication
      summary: Resolve a free-form query to an MCP server
      description: >-
        Admin-only, side-effect-free smart resolution for the add-connection
        flow. Accepts a URL, a bare host, or a product name ("vercel"), matches
        curated presets, probes bounded well-known endpoint candidates through
        the SSRF-guarded discovery fetch, and returns the winning URL with its
        requirements discovery. It performs no client registration, credential
        write, or connection creation.
      operationId: postV1McpConnectionsResolve
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExternalMcpResolveInput'
      responses:
        '200':
          description: Resolution result (not_found is a successful outcome).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExternalMcpResolveResult'
        '400':
          description: Invalid request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidRequestError'
        '401':
          description: The caller must be signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Only workspace owners and admins can resolve MCP servers.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
components:
  schemas:
    ExternalMcpResolveInput:
      type: object
      properties:
        query:
          type: string
          minLength: 1
          maxLength: 200
      required:
        - query
    ExternalMcpResolveResult:
      type: object
      properties:
        resolution:
          type: string
          enum:
            - preset
            - discovered
            - not_found
        attempted:
          type: array
          items:
            type: string
        reason:
          type: string
        preset:
          $ref: '#/components/schemas/ExternalMcpPresetResponse'
        match:
          type: object
          properties:
            url:
              type: string
            suggestedName:
              type: string
            discovery:
              $ref: '#/components/schemas/ExternalMcpRequirementsDiscovery'
          required:
            - url
            - suggestedName
            - discovery
      required:
        - resolution
        - attempted
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    ExternalMcpPresetResponse:
      type: object
      properties:
        presetId:
          type: string
        displayName:
          type: string
        description:
          type: string
        url:
          type: string
        authType:
          type: string
          enum:
            - oauth
            - apikey
            - none
        requiresOAuthClient:
          type: boolean
      required:
        - presetId
        - displayName
        - description
        - url
        - authType
    ExternalMcpRequirementsDiscovery:
      type: object
      properties:
        status:
          type: string
          enum:
            - ready
            - manual_action_required
            - unsupported
            - unreachable
        server:
          type: object
          properties:
            url:
              type: string
            protocolVersion:
              type: string
            initialize:
              type: string
              enum:
                - succeeded
                - authentication_required
                - failed
          required:
            - url
            - initialize
        authentication:
          type: object
          properties:
            kind:
              type: string
              enum:
                - none
                - oauth
                - manual_bearer
                - unknown
            resource:
              type: string
            protectedResourceMetadataUrl:
              type: string
            authorizationServers:
              type: array
              items:
                type: object
                properties:
                  issuer:
                    type: string
                  authorizationEndpoint:
                    type: string
                  tokenEndpoint:
                    type: string
                  registrationEndpoint:
                    type: string
                  clientIdMetadataDocumentSupported:
                    type: boolean
                  scopesSupported:
                    type: array
                    items:
                      type: string
                  grantTypesSupported:
                    type: array
                    items:
                      type: string
                  codeChallengeMethodsSupported:
                    type: array
                    items:
                      type: string
                  tokenEndpointAuthMethodsSupported:
                    type: array
                    items:
                      type: string
                required:
                  - issuer
                  - clientIdMetadataDocumentSupported
            requiredScopes:
              type: array
              items:
                type: string
            recommendedScopes:
              type: array
              items:
                type: string
            refreshSupport:
              type: string
              enum:
                - supported
                - not_advertised
                - unknown
            availableRegistrationMethods:
              type: array
              items:
                type: string
                enum:
                  - pre_registered
                  - client_metadata
                  - dynamic
            recommendedRegistrationMethod:
              type: string
              enum:
                - client_metadata
                - dynamic
                - pre_registered
          required:
            - kind
            - authorizationServers
            - requiredScopes
            - recommendedScopes
            - refreshSupport
            - availableRegistrationMethods
            - recommendedRegistrationMethod
        tools:
          type: object
          properties:
            visibility:
              type: string
              enum:
                - available_without_auth
                - requires_auth
                - unavailable
            count:
              type: integer
              minimum: 0
              maximum: 9007199254740991
            items:
              type: array
              items:
                type: object
                properties:
                  name:
                    type: string
                  readOnlyHint:
                    type: boolean
                  destructiveHint:
                    type: boolean
                  openWorldHint:
                    type: boolean
                required:
                  - name
          required:
            - visibility
        manualRequirements:
          type: array
          items:
            type: object
            properties:
              code:
                type: string
              label:
                type: string
              reason:
                type: string
              required:
                type: boolean
            required:
              - code
              - label
              - reason
              - required
        warnings:
          type: array
          items:
            type: object
            properties:
              code:
                type: string
              message:
                type: string
            required:
              - code
              - message
      required:
        - status
        - server
        - authentication
        - tools
        - manualRequirements
        - warnings

````