> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create or replace an External MCP Connection by stable key

> Admin-only declarative upsert. Creates a connection when the organization has not used the key, otherwise replaces the keyed connection without changing its stable identity.



## OpenAPI

````yaml /openapi.json put /v1/mcp-connections/by-key/{externalKey}
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: dev
servers:
  - url: http://api.den.local
security: []
tags:
  - name: System
    description: Service health and operational routes.
  - name: Organizations
    description: Top-level organization creation and context routes.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: SCIM
    description: Organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Templates
    description: Organization shared template routes.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Admin
    description: Administrative reporting routes.
  - name: Users
    description: Current user and membership routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
paths:
  /v1/mcp-connections/by-key/{externalKey}:
    put:
      tags:
        - Capability Sources
      summary: Create or replace an External MCP Connection by stable key
      description: >-
        Admin-only declarative upsert. Creates a connection when the
        organization has not used the key, otherwise replaces the keyed
        connection without changing its stable identity.
      operationId: putV1McpConnectionsByKeyByExternalKey
      parameters:
        - name: If-Match
          in: header
          required: false
          description: >-
            Existing connection updatedAt timestamp required by the caller for
            conditional replacement.
          schema:
            type: string
            format: date-time
        - in: path
          name: externalKey
          schema:
            type: string
            pattern: ^[a-z0-9][a-z0-9._-]{0,127}$
          required: true
          description: Client-chosen stable identifier, unique per organization. Immutable.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExternalMcpConnectionByKeyUpsertInput'
      responses:
        '200':
          description: Connection updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExternalMcpConnectionUpdatedResponse'
        '201':
          description: Connection created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExternalMcpConnectionCreatedResponse'
        '400':
          description: Invalid request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidRequestError'
        '401':
          description: The caller must be signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Only workspace owners and admins can upsert MCP connections.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
        '409':
          description: The edit is stale or changes marketplace-owned identity fields.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExternalMcpConnectionUpdateConflictError'
        '502':
          description: The proposed connection could not be validated.
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/ExternalMcpConnectionValidationFailedError
components:
  schemas:
    ExternalMcpConnectionByKeyUpsertInput:
      type: object
      properties:
        kind:
          type: string
          const: external_mcp
        name:
          type: string
          minLength: 1
          maxLength: 255
        url:
          type: string
          maxLength: 2048
          format: uri
        authType:
          type: string
          enum:
            - oauth
            - apikey
            - none
        credentialMode:
          default: shared
          type: string
          enum:
            - shared
            - per_member
        exposeDirectly:
          default: false
          type: boolean
        apiKey:
          type: string
          minLength: 1
          maxLength: 4096
        oauthClient:
          type: object
          properties:
            clientId:
              type: string
              minLength: 1
              maxLength: 512
            clientSecret:
              type: string
              minLength: 1
              maxLength: 4096
            tokenEndpointAuthMethod:
              type: string
              enum:
                - client_secret_basic
                - client_secret_post
          required:
            - clientId
        authorizationServerIssuer:
          anyOf:
            - type: string
              maxLength: 2048
              format: uri
            - type: 'null'
        requestedScopes:
          maxItems: 100
          type: array
          items:
            type: string
            minLength: 1
            maxLength: 255
        access:
          $ref: '#/components/schemas/ExternalMcpConnectionAccessInput'
      required:
        - name
        - url
        - authType
    ExternalMcpConnectionUpdatedResponse:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        externalKey:
          anyOf:
            - type: string
            - type: 'null'
        url:
          type: string
        authType:
          type: string
          enum:
            - oauth
            - apikey
            - none
        credentialMode:
          type: string
          enum:
            - shared
            - per_member
        exposeDirectly:
          type: boolean
        connected:
          type: boolean
        connectedAt:
          anyOf:
            - type: string
            - type: 'null'
        createdByName:
          anyOf:
            - type: string
            - type: 'null'
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        connectedForMe:
          type: boolean
        needsReconnect:
          type: boolean
        credentialHealth:
          type: string
          enum:
            - unknown
            - ready
            - reconnect_required
        credentialHealthReason:
          anyOf:
            - type: string
              enum:
                - authorization_rejected
                - credential_expired
                - post_authorization_validation_failed
            - type: 'null'
        credentialHealthCheckedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        issuerReviewRequired:
          type: boolean
        reconnectActionOwner:
          anyOf:
            - type: string
              enum:
                - member
                - organization_admin
            - type: 'null'
        missingFeatures:
          type: array
          items:
            type: string
        externalAccountId:
          anyOf:
            - type: string
            - type: 'null'
        grantedScopes:
          type: array
          items:
            type: string
        tenantId:
          anyOf:
            - type: string
            - type: 'null'
        requiredBy:
          type: array
          items:
            $ref: '#/components/schemas/ExternalMcpConnectionRequiredBy'
        identityManagedBy:
          type: array
          items:
            $ref: '#/components/schemas/ExternalMcpConnectionRequiredBy'
        requiredAuthType:
          anyOf:
            - type: string
              enum:
                - oauth
                - apikey
                - none
            - type: 'null'
        authPolicyConfirmed:
          type: boolean
        authTypeMismatch:
          type: boolean
        oauthClientConfigured:
          type: boolean
        oauthClientRequired:
          type: boolean
        setupRequired:
          type: boolean
        access:
          anyOf:
            - $ref: '#/components/schemas/ExternalMcpConnectionAccessSummary'
            - type: 'null'
        oauthClientId:
          anyOf:
            - type: string
            - type: 'null'
        oauthCallbackUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthSharedCallbackUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthClientMetadataUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthCallbackMode:
          anyOf:
            - type: string
              enum:
                - shared-v1
                - isolated-v1
                - legacy-v1
            - type: 'null'
        oauthRegistrationSource:
          anyOf:
            - type: string
              enum:
                - pre-registered
                - client-metadata
                - dynamic
            - type: 'null'
        authorizationServerIssuer:
          anyOf:
            - type: string
            - type: 'null'
        requestedScopes:
          type: array
          items:
            type: string
        identityChanged:
          type: boolean
        reconnectionRequired:
          type: boolean
      required:
        - id
        - name
        - externalKey
        - url
        - authType
        - credentialMode
        - exposeDirectly
        - connected
        - connectedAt
        - updatedAt
        - connectedForMe
        - requiredBy
        - identityManagedBy
        - access
        - identityChanged
        - reconnectionRequired
    ExternalMcpConnectionCreatedResponse:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        externalKey:
          anyOf:
            - type: string
            - type: 'null'
        url:
          type: string
        authType:
          type: string
          enum:
            - oauth
            - apikey
            - none
        credentialMode:
          type: string
          enum:
            - shared
            - per_member
        exposeDirectly:
          type: boolean
        connected:
          type: boolean
        connectedAt:
          anyOf:
            - type: string
            - type: 'null'
        createdByName:
          anyOf:
            - type: string
            - type: 'null'
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        connectedForMe:
          type: boolean
        needsReconnect:
          type: boolean
        credentialHealth:
          type: string
          enum:
            - unknown
            - ready
            - reconnect_required
        credentialHealthReason:
          anyOf:
            - type: string
              enum:
                - authorization_rejected
                - credential_expired
                - post_authorization_validation_failed
            - type: 'null'
        credentialHealthCheckedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        issuerReviewRequired:
          type: boolean
        reconnectActionOwner:
          anyOf:
            - type: string
              enum:
                - member
                - organization_admin
            - type: 'null'
        missingFeatures:
          type: array
          items:
            type: string
        externalAccountId:
          anyOf:
            - type: string
            - type: 'null'
        grantedScopes:
          type: array
          items:
            type: string
        tenantId:
          anyOf:
            - type: string
            - type: 'null'
        requiredBy:
          type: array
          items:
            $ref: '#/components/schemas/ExternalMcpConnectionRequiredBy'
        identityManagedBy:
          type: array
          items:
            $ref: '#/components/schemas/ExternalMcpConnectionRequiredBy'
        requiredAuthType:
          anyOf:
            - type: string
              enum:
                - oauth
                - apikey
                - none
            - type: 'null'
        authPolicyConfirmed:
          type: boolean
        authTypeMismatch:
          type: boolean
        oauthClientConfigured:
          type: boolean
        oauthClientRequired:
          type: boolean
        setupRequired:
          type: boolean
        access:
          anyOf:
            - $ref: '#/components/schemas/ExternalMcpConnectionAccessSummary'
            - type: 'null'
        oauthClientId:
          anyOf:
            - type: string
            - type: 'null'
        oauthCallbackUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthSharedCallbackUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthClientMetadataUrl:
          anyOf:
            - type: string
            - type: 'null'
        oauthCallbackMode:
          anyOf:
            - type: string
              enum:
                - shared-v1
                - isolated-v1
                - legacy-v1
            - type: 'null'
        oauthRegistrationSource:
          anyOf:
            - type: string
              enum:
                - pre-registered
                - client-metadata
                - dynamic
            - type: 'null'
        authorizationServerIssuer:
          anyOf:
            - type: string
            - type: 'null'
        requestedScopes:
          type: array
          items:
            type: string
        links:
          type: object
          properties:
            yourConnections:
              type: string
            oauthCallback:
              type: string
          required:
            - yourConnections
            - oauthCallback
      required:
        - id
        - name
        - externalKey
        - url
        - authType
        - credentialMode
        - exposeDirectly
        - connected
        - connectedAt
        - connectedForMe
        - requiredBy
        - access
        - links
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    ExternalMcpConnectionUpdateConflictError:
      anyOf:
        - $ref: '#/components/schemas/ExternalMcpConnectionConflictError'
        - $ref: '#/components/schemas/ExternalMcpConnectionMarketplaceManagedError'
    ExternalMcpConnectionValidationFailedError:
      type: object
      properties:
        error:
          type: string
          const: connection_validation_failed
        message:
          type: string
        diagnostic:
          $ref: '#/components/schemas/ExternalMcpDiagnostic'
      required:
        - error
        - message
        - diagnostic
    ExternalMcpConnectionAccessInput:
      type: object
      properties:
        orgWide:
          default: false
          type: boolean
        memberIds:
          default: []
          maxItems: 200
          type: array
          items:
            type: string
            minLength: 1
        teamIds:
          default: []
          maxItems: 200
          type: array
          items:
            type: string
            minLength: 1
    ExternalMcpConnectionRequiredBy:
      type: object
      properties:
        pluginId:
          type: string
        name:
          type: string
      required:
        - pluginId
        - name
    ExternalMcpConnectionAccessSummary:
      type: object
      properties:
        orgWide:
          type: boolean
        memberIds:
          type: array
          items:
            type: string
        teamIds:
          type: array
          items:
            type: string
      required:
        - orgWide
        - memberIds
        - teamIds
    ExternalMcpConnectionConflictError:
      type: object
      properties:
        error:
          type: string
          const: connection_conflict
        message:
          type: string
      required:
        - error
        - message
    ExternalMcpConnectionMarketplaceManagedError:
      type: object
      properties:
        error:
          type: string
          const: marketplace_managed
        message:
          type: string
      required:
        - error
        - message
    ExternalMcpDiagnostic:
      type: object
      properties:
        referenceId:
          type: string
        phase:
          type: string
          enum:
            - CONFIGURATION
            - NETWORK_DNS
            - NETWORK_TCP
            - NETWORK_TLS
            - HTTP_ROUTING
            - AUTH_RESOURCE_DISCOVERY
            - AUTH_ISSUER_DISCOVERY
            - AUTH_CLIENT_REGISTRATION
            - AUTH_USER_OR_WORKLOAD
            - AUTH_TOKEN_ACQUISITION
            - AUTH_RESOURCE_VALIDATION
            - MCP_TRANSPORT
            - MCP_VERSION
            - MCP_INITIALIZE
            - MCP_INITIALIZED
            - MCP_TOOL_DISCOVERY
            - MCP_TOOL_EXECUTION
            - PROVIDER_AUTHORIZATION
            - PROVIDER_EXECUTION
            - CONTINUITY_REFRESH
            - CONTINUITY_SESSION
            - SHUTDOWN
        category:
          type: string
        code:
          type: string
        highestPassed:
          type: string
          enum:
            - configured
            - reachable
            - authorized
            - protocol_ready
            - catalog_ready
            - operation_ready
        retryable:
          type: boolean
        actionOwner:
          type: string
          enum:
            - openwork
            - network_admin
            - provider_admin
            - organization_admin
            - member
        operatorAction:
          type: string
        message:
          type: string
        httpStatus:
          type: integer
          minimum: 100
          maximum: 599
        operationPhase:
          type: string
          enum:
            - CONFIGURATION
            - NETWORK_DNS
            - NETWORK_TCP
            - NETWORK_TLS
            - HTTP_ROUTING
            - AUTH_RESOURCE_DISCOVERY
            - AUTH_ISSUER_DISCOVERY
            - AUTH_CLIENT_REGISTRATION
            - AUTH_USER_OR_WORKLOAD
            - AUTH_TOKEN_ACQUISITION
            - AUTH_RESOURCE_VALIDATION
            - MCP_TRANSPORT
            - MCP_VERSION
            - MCP_INITIALIZE
            - MCP_INITIALIZED
            - MCP_TOOL_DISCOVERY
            - MCP_TOOL_EXECUTION
            - PROVIDER_AUTHORIZATION
            - PROVIDER_EXECUTION
            - CONTINUITY_REFRESH
            - CONTINUITY_SESSION
            - SHUTDOWN
        outbound:
          type: object
          properties:
            origin:
              type: string
            pathHash:
              type: string
          required:
            - origin
            - pathHash
        providerRequestId:
          type: string
        providerStatus:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        providerCode:
          type: string
        payloadBytes:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        jsonRpcCode:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        connectUrl:
          type: string
          format: uri
      required:
        - referenceId
        - phase
        - category
        - code
        - highestPassed
        - retryable
        - actionOwner
        - operatorAction
        - message

````