Skip to main content

Turn an API into MCP tools

Give AI apps controlled access to a REST API that has no MCP server. The gateway turns each API operation into a tool, holds the API key, and checks your access rules on every call before it contacts the API.

Open Settings > AI Gateway > MCP Gateway, click Add MCP server and choose API under Where does this MCP run? The setup has three steps: Connection, Credentials and Tools & access.

Network requirement​

The gateway calls the API from QuilrAI's network, so the base URL (and a spec URL, if you use one) must resolve to a public address. Destinations that resolve to private, loopback, link-local or cloud metadata addresses (and the names localhost, *.localhost and *.internal) are blocked: tool calls fail with Blocked destination, and a spec URL fails at Load spec (upload or paste the spec instead). Tool calls do not follow redirects.

For an internal API, allow QuilrAI's published egress IPs on your firewall so the gateway can reach the API. Get the IP list from your QuilrAI representative.

When to use it​

UseWhen
APIThe service has a REST API but no MCP server, or you want to expose only part of an API.
Remote serverThe service already runs an MCP server. See Adding MCP servers.
Local package (CLI MCP)The MCP must run on the user's own computer. See Local MCP.

Connection​

FieldWhat to enter
NameThe name people see in their AI app.
SlugOptional. Derived from the name when left blank. Forms the gateway URL agents call.
Base URLThe full URL, including https://. Every tool call goes to a path under it. Must resolve to a public address (see Network requirement).
DescriptionOptional. Shown beside the API wherever it is listed.

OpenAPI spec​

With a spec, each operation can become its own tool. Without one, agents get five generic HTTP tools.

SourceHow
URLPaste the spec URL. Click Add fetch header if the spec requires authentication.
UploadSelect a spec file.
PastePaste the spec text.
NoneGeneric mode. No spec is used.

The spec can be Swagger 2.0 or OpenAPI 3.x, JSON or YAML, up to 10 MiB. Click Load spec. The summary shows the Title, Version, Size, Operations (total and how many are supported), Tags and Servers. Nothing is saved yet. A loaded spec stays available for 30 minutes; after that, click Reload spec.

In generic mode agents get these tools, and your access rules decide which paths each call may reach:

ToolWhat it does
api_getGET any path under the base URL, with query parameters
api_postPOST a JSON body to a path
api_putPUT a JSON body to a path
api_patchPATCH a JSON body to a path
api_deleteDELETE a path

API docs for the model​

Optional. Paste Markdown or plain text, up to 1 MiB. This adds an api_docs tool the model can read before it calls anything. In generic mode, write docs so the model knows which paths exist.

Advanced​

SettingDefaultRange
Timeout (seconds)301 to 120
Max response size (KB)64Longer responses are truncated.

Click Continue.

Credentials​

Choose how the gateway signs in to the API. Agents never see the key.

OptionWhen
No authenticationThe API is public, or it trusts the gateway's network.
API keyStore a key at the gateway. Set Authentication scope to Shared by the whole tenant or Each user brings their own.

For an API key, select the Authentication placement (Authorization bearer header, Custom header or Query parameter) and an optional Value prefix such as Bearer. Sent on every call as previews the result, for example Authorization: Bearer ****. With Each user brings their own, the key you enter is your personal key; everyone else adds their own in the user dashboard before the tools work for them.

Under Custom headers and query parameters, add values sent on every call. The model never sees them.

OAuth isn't available for APIs. To change the key later, use General > Upstream authentication in the server's settings.

Tools & access​

Access rules​

Rules decide which operations become tools, and are checked again on every call. Deny wins. If there are allow rules, a request must match one. Inside a rule every field must match; values within a field are alternatives.

Select a starting point from Start from, then click Add allow rule or Add deny rule to adjust it.

PresetRules
EverythingNo rules. Every request is allowed.
No deletesDeny DELETE requests.
Read-onlyAllow only GET and HEAD requests.

Each rule can match Methods (any method when none is selected), a Path, Keywords and, with a spec, Tags.

PatternMatchesExample
*One path segment/contacts/* matches /contacts/123, not /contacts/123/notes
**Any number of segments/contacts/** matches /contacts/123/notes
KeywordA whole segment anywhere in the pathorders matches /v2/orders/1, not /preorders

Paths are relative to the base URL and start with /.

Test a request: enter a method, a path and optional tags, then click Test. The result shows Allowed or Blocked with the rule that decided it, and which operation the request matches. Nothing is sent to the API.

A blocked call fails with the rule's reason and shows in Logs as a failed call. The API is not contacted.

Operations​

With a spec, every operation is listed by tag with N of N selected. Filter by path, tool or summary, or show All, Selected or Not selected. Each row shows why it is or isn't a tool, for example No rule blocks it or Blocked by deny[0].

StateMeaning
AutoFollows the rules.
OnOverrides the rules for this operation and makes it a tool.
OffOverrides the rules for this operation and leaves it out.

Use Set all on a tag to change a whole group. Open a row to set a Tool name, a Description for the model, or Fixed parameters that are sent on every call and hidden from the model.

Turn on Also add generic HTTP tools to add api_get, api_post, api_put, api_patch and api_delete for calls the spec doesn't cover. The access rules still apply.

At least one operation must be selected, or the generic tools added, before you can create the API.

Tools summary​

Agents get N tools lists the tool names agents will see. In OneMCP each name includes this API's prefix. Custom headers, query parameters and fixed parameters are never shown to the model.

Click Create API MCP. The server's settings open so you can choose who can reach it and which tools need confirmation.

After creation​

The API MCP appears under the API tab of the server list. In the server's settings:

SectionWhat you do there
APIReview the base URL, timeout, spec, access rules and the tools each operation became.
ToolsTurn tools on or off and require confirmation. See Tool visibility.
General > Upstream authenticationChange the API key.