> ## Documentation Index
> Fetch the complete documentation index at: https://docs.custral.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List MCP tools

> The exact `tools/list` an MCP client (Claude, Cursor, …) sees when it connects to `POST /mcp` with this key — the read surface always, plus each write action the key's scopes authorise (`applications:manage`, `webhooks:manage`). Lets a UI or script verify the MCP surface without performing the JSON-RPC handshake. **Requires scope:** `mcp:read`.



## OpenAPI

````yaml /openapi-v1.json get /v1/mcp/tools
openapi: 3.1.0
info:
  title: Custral API
  version: v1
  description: >-
    The curated, versioned, API-key-authenticated public REST surface (`/v1`).
    Every endpoint here is what the official SDKs (`@custral/sdk`) and the MCP
    server are built on. Authenticate with a secret API key (`sk_…`) created in
    **Settings → Applications**.
  contact:
    name: Custral Support
    email: hello@custral.com
    url: https://custral.com
  license:
    name: Proprietary
    url: https://custral.com
servers:
  - url: https://api.custral.com
    description: Production
security:
  - ApiKey: []
tags:
  - name: Identity
    description: Introspect the calling API key.
  - name: Records
    description: Create, list, retrieve, and update records on any object.
  - name: Objects
    description: Read the object (table) schema of your workspace.
  - name: Conversations
    description: View, manage, and ingest conversations and their messages.
  - name: MCP
    description: Introspect the Model Context Protocol tool surface for a key.
  - name: Documents
    description: Read record notes / page documents as markdown.
paths:
  /v1/mcp/tools:
    get:
      tags:
        - MCP
      summary: List MCP tools
      description: >-
        The exact `tools/list` an MCP client (Claude, Cursor, …) sees when it
        connects to `POST /mcp` with this key — the read surface always, plus
        each write action the key's scopes authorise (`applications:manage`,
        `webhooks:manage`). Lets a UI or script verify the MCP surface without
        performing the JSON-RPC handshake. **Requires scope:** `mcp:read`.
      operationId: listMcpTools
      responses:
        '200':
          description: The MCP tool manifest for this key.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/McpTools'
                  reqId:
                    $ref: '#/components/schemas/RequestId'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  schemas:
    McpTools:
      type: object
      description: The `GET /v1/mcp/tools` payload.
      properties:
        endpoint:
          type: string
          example: https://api.custral.com/mcp
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/ApiKeyScope'
        count:
          type: integer
          example: 6
        tools:
          type: array
          items:
            $ref: '#/components/schemas/McpTool'
      required:
        - endpoint
        - count
        - tools
    RequestId:
      type: string
      description: >-
        A per-request id (`req_…`). Quote it to support when reporting a
        problem.
      example: req_2a1f9c8e7b6d5
    ApiKeyScope:
      type: string
      description: A permission a key can hold.
      enum:
        - records:read
        - records:write
        - objects:read
        - documents:read
        - conversations:read
        - conversations:write
        - property_agents:read
        - property_agents:write
        - tasks:read
        - usage:read
        - usage:write
        - webhooks:manage
        - mcp:read
        - mcp:write
    McpTool:
      type: object
      additionalProperties: true
      properties:
        name:
          type: string
          example: list_records
        description:
          type: string
        inputSchema:
          type: object
          additionalProperties: true
      required:
        - name
    Error:
      type: object
      description: >-
        The failure envelope. Every error carries a machine-readable `code` and
        the `reqId` of the failing request.
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              example: insufficient_scope
          required:
            - code
        reqId:
          $ref: '#/components/schemas/RequestId'
      required:
        - error
  responses:
    Unauthorized:
      description: >-
        The API key is missing, unknown, inactive, or expired (`code:
        invalid_api_key`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: invalid_api_key
            reqId: req_2a1f9c8e7b6d5
    Forbidden:
      description: >-
        The key lacks the scope this endpoint requires (`code:
        insufficient_scope`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: insufficient_scope
            reqId: req_2a1f9c8e7b6d5
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: sk_...
      description: >-
        A Custral **secret** API key (`sk_…`), created in Settings →
        Applications. Sent as `Authorization: Bearer sk_…`. The `X-Api-Key:
        sk_…` header is also accepted and takes precedence. Never expose a
        secret key in a browser.

````

## Related topics

- [MCP Server](/dev/mcp/overview.md)
- [MCP Connections](/ai/mcp-connections.md)
- [CLI](/dev/cli/overview.md)
- [Managing subscriptions](/dev/webhooks/managing.md)
- [Provider Tools](/ai/provider-tools.md)
