MCP transport (JSON-RPC request)
Model Context Protocol endpoint over Streamable HTTP. Send JSON-RPC requests here to list and call varsafe tools. Requires an OAuth 2.1 access token whose granted scopes cover the tool being called; an unauthenticated request answers 401 with a WWW-Authenticate header pointing at the protected-resource metadata.
POST
/mcpResponses
200The JSON-RPC response(s), delivered as a server-sent event stream. The request must `Accept` both `application/json` and `text/event-stream`.
string202Accepted: the message carried only notifications or responses, so no reply.
400The body is not a valid JSON-RPC message, or names an unsupported MCP protocol version.
jsonrpcstringrequirederrorobjectrequiredShow propertiesHide properties
codeintegerrequiredmin -9007199254740991 · max 9007199254740991
messagestringrequireddataanyidstring | nullrequired401No bearer token, or it is invalid, expired or revoked. The `WWW-Authenticate` header names the protected-resource metadata.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequiredRFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstringHuman-readable explanation.
403The token lacks the grant the transport requires.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequiredRFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstringHuman-readable explanation.
406The `Accept` header must allow both `application/json` and `text/event-stream` (`GET` needs `text/event-stream`).
jsonrpcstringrequirederrorobjectrequiredShow propertiesHide properties
codeintegerrequiredmin -9007199254740991 · max 9007199254740991
messagestringrequireddataanyidstring | nullrequired415The request `Content-Type` must be `application/json`.
jsonrpcstringrequirederrorobjectrequiredShow propertiesHide properties
codeintegerrequiredmin -9007199254740991 · max 9007199254740991
messagestringrequireddataanyidstring | nullrequired429Too many rejected authentication attempts.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequiredRFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstringHuman-readable explanation.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequiredStable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequiredHuman-readable explanation. Wording may change.
fieldstringThe offending request field, present on validation failures.
503Token verification is temporarily unavailable. Retry later.
statusCodeintegerrequiredHTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequiredRFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstringHuman-readable explanation.
Request
curl -X POST "https://api.varsafe.dev/mcp"const response = await fetch("https://api.varsafe.dev/mcp", {
method: "POST"
});import requests
response = requests.post(
"https://api.varsafe.dev/mcp",
)Response
"string"Accepted: the message carried only notifications or responses, so no reply.
{
"jsonrpc": "2.0",
"error": {
"code": 0,
"message": "string",
"data": "string"
},
"id": 0
}{
"statusCode": 0,
"error": "string",
"error_description": "string"
}{
"statusCode": 0,
"error": "string",
"error_description": "string"
}{
"jsonrpc": "2.0",
"error": {
"code": 0,
"message": "string",
"data": "string"
},
"id": 0
}{
"jsonrpc": "2.0",
"error": {
"code": 0,
"message": "string",
"data": "string"
},
"id": 0
}{
"statusCode": 0,
"error": "string",
"error_description": "string"
}{
"statusCode": 0,
"code": "string",
"message": "string",
"field": "string"
}{
"statusCode": 0,
"error": "string",
"error_description": "string"
}