> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Send one agent Playground message

> Send one message to a project's MCP servers and get the model's reply plus the telemetry a participant in the conversation could not see: which tools ran, with what arguments, what each returned, per-call latency, and token usage.

**Spends model credits per call.** `idempotencyKey` is required and must be STABLE for the triggering intent — a fresh key per HTTP attempt deduplicates nothing, so a timeout-and-retry would run and bill the turn twice. With a stable key, a retry replays the completed turn.

Omit `sessionId` to start a session; pass the one this returns to continue it. Configuration (`modelId`, target, `systemPrompt`, `toolMode`) pins on the FIRST turn — a continuation that resends any of it is refused with `details.reason: "CONFIG_ON_CONTINUATION"`.

Only sessions created through this endpoint may be continued through it (`CONTINUATION_NOT_ALLOWED`): appending to a human's live Playground session would interleave two writers on one transcript.

`toolMode` defaults to `read_only`, which advertises only tools the server annotated `readOnlyHint: true`. That hint is server-asserted, so `read_only` is a policy this host applies, not a guarantee it can verify. `auto` advertises everything and **may cause real external side effects** through arbitrary third-party tools.



## OpenAPI

````yaml /reference/openapi.json post /chat-sessions/messages
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Hosts
    description: >-
      Project hosts: named model + capability profiles you run chats and eval
      suites against.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and journeys run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Plugins
    description: >-
      Agent Plugins imported into a project — read-only inventory and version
      detail.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: Conformance runs
    description: >-
      Ingest MCP spec-conformance results from the SDK/CLI into project-owned
      history. Distinct from Eval runs (authored LLM cases) and from directory
      readiness.
  - name: Server connections
    description: >-
      Connect an MCP server URL to a project, authorizing in a browser when the
      server requires it.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Scenarios
    description: >-
      Read-only access to the scenarios published from a project: listing,
      settings, attached servers, and share links.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam cloud tunnel` CLI
      flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
  - name: Swarms
    description: >-
      Personas, journeys and swarm containers — the authoring half of Swarms —
      plus the model-backed generation that drafts them.
  - name: Swarm runs
    description: >-
      Launching journeys and reading what they produced. Launching SPENDS — see
      the per-operation notes.
  - name: Swarm insights
    description: >-
      What a swarm run revealed. The scorecard and findings are deterministic
      and free; requesting wave insights runs models and draws on your shared
      daily ledger.
  - name: User testing
    description: >-
      Publishing an environment for real visitors, and controlling who can reach
      it. Several of these NARROW access and take effect immediately.
  - name: Directory readiness
    description: >-
      Grade a saved server against a publisher's listing requirements:
      Anthropic's connector directory or OpenAI's plugin directory. Reported as
      lane status and coverage, never as a numeric score, and excluded from
      `pooledConformanceScore`. Deterministic grading is free; model-backed
      experience observations are an explicit opt-in that consumes MCPJam
      credits and can never decide a verdict.
  - name: Registry
    description: >-
      Search the scraped MCP directories (Claude, ChatGPT, and any future
      source), list curated/org registry cards, and install them into a project.
      Install writes a `servers` row and provenance — it does not open a live
      session. There is no catalog-uninstall route: delete the project server
      instead. Directory reads require a bearer (including minted guest tokens)
      but do not materialize a user. Card/connection reads and all writes are
      authed-non-guest.
paths:
  /chat-sessions/messages:
    post:
      tags:
        - Chat sessions
      summary: Send one agent Playground message
      description: >-
        Send one message to a project's MCP servers and get the model's reply
        plus the telemetry a participant in the conversation could not see:
        which tools ran, with what arguments, what each returned, per-call
        latency, and token usage.


        **Spends model credits per call.** `idempotencyKey` is required and must
        be STABLE for the triggering intent — a fresh key per HTTP attempt
        deduplicates nothing, so a timeout-and-retry would run and bill the turn
        twice. With a stable key, a retry replays the completed turn.


        Omit `sessionId` to start a session; pass the one this returns to
        continue it. Configuration (`modelId`, target, `systemPrompt`,
        `toolMode`) pins on the FIRST turn — a continuation that resends any of
        it is refused with `details.reason: "CONFIG_ON_CONTINUATION"`.


        Only sessions created through this endpoint may be continued through it
        (`CONTINUATION_NOT_ALLOWED`): appending to a human's live Playground
        session would interleave two writers on one transcript.


        `toolMode` defaults to `read_only`, which advertises only tools the
        server annotated `readOnlyHint: true`. That hint is server-asserted, so
        `read_only` is a policy this host applies, not a guarantee it can
        verify. `auto` advertises everything and **may cause real external side
        effects** through arbitrary third-party tools.
      operationId: sendChatMessage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SendChatMessageRequest'
      responses:
        '200':
          description: >-
            The turn ran. `persisted.outcome` reports whether the transcript
            landed — a turn that ran but failed to persist still spent, so this
            is a 200 with an honest `persisted` block rather than an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChatTurn'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: >-
            `details.reason` is one of `TURN_IN_PROGRESS` (another turn holds
            this session's lease; retry after `details.retryAfterMs`),
            `CONTINUATION_NOT_ALLOWED`, or `SESSION_VERSION_CONFLICT`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          $ref: '#/components/responses/FeatureNotSupported'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
        '502':
          $ref: '#/components/responses/ServerUnreachable'
        '504':
          $ref: '#/components/responses/Timeout'
components:
  schemas:
    SendChatMessageRequest:
      type: object
      required:
        - idempotencyKey
        - message
      additionalProperties: false
      properties:
        idempotencyKey:
          type: string
          minLength: 1
          maxLength: 200
          description: >-
            STABLE identity for this turn's intent — reuse it when retrying. A
            fresh key per attempt deduplicates nothing and will bill the turn
            twice. Printable ASCII only.
        message:
          type: string
          minLength: 1
          maxLength: 8000
          description: The message to send, as the user.
        projectId:
          type: string
          description: Required to START a session; ignored when continuing one.
        sessionId:
          type: string
          description: Continue this session. Omit to start a new one.
        modelId:
          type: string
          description: >-
            Provider-prefixed model id, e.g. `anthropic/claude-sonnet-5`.
            Required on a first turn. A BARE id is rejected with
            `details.reason: "MODEL_AMBIGUOUS"` rather than guessed — an
            unprefixed id is indistinguishable from a local Ollama model, and
            guessing would spend on the wrong rail.
        environmentId:
          type: string
          description: >-
            Target this environment's servers. Mutually exclusive with
            `serverIds`. First turn only.
        serverIds:
          type: array
          maxItems: 20
          items:
            type: string
          description: >-
            Target these project servers. Mutually exclusive with
            `environmentId`. First turn only. Server CONFIGS are never accepted
            — only ids the project already holds.
        systemPrompt:
          type: string
          maxLength: 8000
          description: First turn only.
        temperature:
          type: number
          minimum: 0
          maximum: 2
          description: >-
            First turn only — pinned to the session and reused on every
            continuation.
        maxSteps:
          type: integer
          minimum: 1
          maximum: 16
        toolMode:
          type: string
          enum:
            - read_only
            - auto
          default: read_only
          description: >-
            `read_only` advertises only tools annotated `readOnlyHint: true`.
            `auto` advertises everything and MAY CAUSE REAL EXTERNAL SIDE
            EFFECTS. First turn only.
        allowedServerIds:
          type: array
          maxItems: 20
          items:
            type: string
          description: >-
            Narrow THIS TURN to a subset of the target's servers. An empty array
            narrows to none and is rejected — omit the field to use the whole
            target. Per-turn, not pinned.
        allowedTools:
          type: array
          maxItems: 100
          items:
            type: string
          description: >-
            Advertise only these tool names, for THIS TURN. An empty array
            advertises no tools at all — the same request as `maxToolCalls: 0`.
            Per-turn, not pinned.
        maxToolCalls:
          type: integer
          minimum: 0
          maximum: 16
          description: >-
            Cap the tool calls this turn may make, enforced at DISPATCH rather
            than by bounding steps (one step can emit several parallel calls).
            `0` advertises no tools at all.
    ChatTurn:
      type: object
      required:
        - sessionId
        - turnId
        - persisted
        - origin
      properties:
        sessionId:
          type:
            - string
            - 'null'
          description: >-
            The one public session id. Pass it back to continue, and to the
            trace/detail reads. NULL only when the turn ran but its transcript
            did not persist — which `persisted.outcome` reports, and which must
            not be read as "nothing happened": the turn already spent.
        turnId:
          type: string
          description: >-
            Minted by the turn lease and used by the ingest dedupe, so it names
            the same turn in both.
        reply:
          type: string
        finishReason:
          type:
            - string
            - 'null'
        toolCalls:
          type: array
          items:
            $ref: '#/components/schemas/ChatTurnToolCall'
        trace:
          type: object
          description: This turn's spans, inline.
          properties:
            turnId:
              type: string
            spanCount:
              type: integer
            spans:
              type: array
              items:
                type: object
        usage:
          $ref: '#/components/schemas/TurnUsage'
        model:
          type: object
          properties:
            id:
              type: string
            provider:
              type: string
        toolMode:
          type: string
          enum:
            - read_only
            - auto
        advertisedToolCount:
          type: integer
          description: Tools the model could see this turn.
        excludedToolCount:
          type: integer
          description: Tools the tool policy withheld.
        persisted:
          type: object
          properties:
            outcome:
              type: string
            version:
              type: integer
        origin:
          type: string
          enum:
            - api
        replay:
          type: boolean
          description: >-
            Set when this idempotencyKey replayed an already-completed turn.
            Nothing was spent.
        message:
          type: string
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
    ChatTurnToolCall:
      type: object
      required:
        - toolCallId
        - toolName
        - input
        - status
      properties:
        toolCallId:
          type: string
        toolName:
          type: string
        input:
          description: >-
            The raw arguments sent, scrubbed of protocol annotations (`_meta`,
            `$`-prefixed keys) and bounded.
        status:
          type: string
          enum:
            - ok
            - error
        output:
          description: >-
            The raw result, scrubbed and bounded. Absent when no result was
            recorded.
        errorMessage:
          type: string
        truncated:
          type: boolean
          description: >-
            The payload was clipped. Always announced — a silently shortened
            result an agent believes is complete sends it debugging the wrong
            thing.
    TurnUsage:
      type: object
      properties:
        inputTokens:
          type: integer
        outputTokens:
          type: integer
        totalTokens:
          type: integer
  responses:
    ValidationError:
      description: Malformed body or parameters.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: VALIDATION_ERROR
            message: Invalid JSON body
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    Forbidden:
      description: Key is valid but not allowed to do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FORBIDDEN
            message: You do not have access to this project
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    FeatureNotSupported:
      description: The target server doesn't support this MCP capability.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FEATURE_NOT_SUPPORTED
            message: Server does not support resources
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
    ServerUnreachable:
      description: Could not connect to the target MCP server.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: SERVER_UNREACHABLE
            message: Failed to connect to server
    Timeout:
      description: The target MCP server connected but didn't respond in time.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: TIMEOUT
            message: Request to server timed out
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````