Transport (OpenAPI)
OpenAPI documents the HTTP transport, not each tool’s parameters:GET /api/mcp returns 405 — use POST with a JSON-RPC body.
Per-tool input and output JSON Schemas are returned only from tools/list (outputSchema uses JSON Schema draft 2020-12 for validating structuredContent from tools/call). Tool descriptors also include OAuth securitySchemes for ChatGPT linking. They are intentionally not duplicated in OpenAPI.
V1 tools (readonly)
Scopes on the bearer token must allow the data each tool reads.
Test locally
Frompackages/external, run the API (for example bun run dev), then use MCP Inspector:
http://localhost:<port>/api/mcp and set:
OAuth for ChatGPT and Claude
Discovery URLs:GET /.well-known/oauth-protected-resourceGET /api/.well-known/oauth-protected-resource/mcpGET /.well-known/oauth-authorization-server(includesoffline_accessfor refresh tokens)GET /.well-known/openid-configuration
/api):
GET /.well-known/openai-apps-challenge
GET /api/oauth/authorize on the external host, which forwards to Supabase after removing offline_access. Token exchange and refresh use Supabase’s token_endpoint directly.
After updating OAuth discovery, delete and recreate the ChatGPT connector so cached metadata is refreshed (OpenAI connector OAuth guidance).
Shared AI connectors use known_mcp OAuth clients provisioned from the Vings server package; register redirect URIs per the OpenAI Apps SDK auth guide.