Turn an API into MCP tools
Give AI apps controlled access to a REST API that has no MCP server. The gateway turns each API operation into a tool, holds the API key, and checks your access rules on every call before it contacts the API.
Open Settings > AI Gateway > MCP Gateway, click Add MCP server and choose API under Where does this MCP run? The setup has three steps: Connection, Credentials and Tools & access.
Network requirement
The gateway calls the API from QuilrAI's network, so the base URL (and a spec URL, if you use one) must resolve to a public address. Destinations that resolve to private, loopback, link-local or cloud metadata addresses (and the names localhost, *.localhost and *.internal) are blocked: tool calls fail with Blocked destination, and a spec URL fails at Load spec (upload or paste the spec instead). Tool calls do not follow redirects.
For an internal API, allow QuilrAI's published egress IPs on your firewall so the gateway can reach the API. Get the IP list from your QuilrAI representative.
When to use it
Connection
OpenAPI spec
With a spec, each operation can become its own tool. Without one, agents get five generic HTTP tools.
The spec can be Swagger 2.0 or OpenAPI 3.x, JSON or YAML, up to 10 MiB. Click Load spec. The summary shows the Title, Version, Size, Operations (total and how many are supported), Tags and Servers. Nothing is saved yet. A loaded spec stays available for 30 minutes; after that, click Reload spec.
In generic mode agents get these tools, and your access rules decide which paths each call may reach:
API docs for the model
Optional. Paste Markdown or plain text, up to 1 MiB. This adds an api_docs tool the model can read before it calls anything. In generic mode, write docs so the model knows which paths exist.
Advanced
Click Continue.
Credentials
Choose how the gateway signs in to the API. Agents never see the key.
For an API key, select the Authentication placement (Authorization bearer header, Custom header or Query parameter) and an optional Value prefix such as Bearer. Sent on every call as previews the result, for example Authorization: Bearer ****. With Each user brings their own, the key you enter is your personal key; everyone else adds their own in the user dashboard before the tools work for them.
Under Custom headers and query parameters, add values sent on every call. The model never sees them.
OAuth isn't available for APIs. To change the key later, use General > Upstream authentication in the server's settings.
Tools & access
Access rules
Rules decide which operations become tools, and are checked again on every call. Deny wins. If there are allow rules, a request must match one. Inside a rule every field must match; values within a field are alternatives.
Select a starting point from Start from, then click Add allow rule or Add deny rule to adjust it.
Each rule can match Methods (any method when none is selected), a Path, Keywords and, with a spec, Tags.
Paths are relative to the base URL and start with /.
Test a request: enter a method, a path and optional tags, then click Test. The result shows Allowed or Blocked with the rule that decided it, and which operation the request matches. Nothing is sent to the API.
A blocked call fails with the rule's reason and shows in Logs as a failed call. The API is not contacted.
Operations
With a spec, every operation is listed by tag with N of N selected. Filter by path, tool or summary, or show All, Selected or Not selected. Each row shows why it is or isn't a tool, for example No rule blocks it or Blocked by deny[0].
Use Set all on a tag to change a whole group. Open a row to set a Tool name, a Description for the model, or Fixed parameters that are sent on every call and hidden from the model.
Turn on Also add generic HTTP tools to add api_get, api_post, api_put, api_patch and api_delete for calls the spec doesn't cover. The access rules still apply.
At least one operation must be selected, or the generic tools added, before you can create the API.
Tools summary
Agents get N tools lists the tool names agents will see. In OneMCP each name includes this API's prefix. Custom headers, query parameters and fixed parameters are never shown to the model.
Click Create API MCP. The server's settings open so you can choose who can reach it and which tools need confirmation.
After creation
The API MCP appears under the API tab of the server list. In the server's settings:
Related
- Human approval - ask the user before a write call runs.
- Security guardrails - scan tool inputs and API responses.
- OneMCP - one endpoint for every MCP, including APIs.