> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a client

> Edit a client's display name and/or its config. Two ways to change the config: `config` replaces it wholesale, and `set` changes named fields over the config read inside the write transaction — prefer `set`, because a whole-config round-trip composed from a stale read reverts whatever landed in between.

Config edits require `expectedConfigId` and renames require `expectedName`. A stale token is `409 CONFLICT` whose `details` carries the current value: re-read the client and retry. A config edit that resolves to byte-identical settings writes nothing at all.

Guest callers are denied (a write).



## OpenAPI

````yaml /reference/openapi.json patch /projects/{projectId}/clients/{client}
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Clients
    description: >-
      Clients — the named, reusable configurations that define how MCPJam
      connects to and talks to your MCP servers. The original `/hosts` paths
      remain as deprecated, ID-only compatibility aliases with their original
      DTOs and their original (tokenless) write contracts; every alias response
      carries `Deprecation: true`. New integrations should use `/clients`.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and journeys run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Plugins
    description: >-
      Agent Plugins imported into a project — read-only inventory and version
      detail.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: Conformance runs
    description: >-
      Ingest MCP spec-conformance results from the SDK/CLI into project-owned
      history. Distinct from Eval runs (authored LLM cases) and from directory
      readiness.
  - name: Server connections
    description: >-
      Connect an MCP server URL to a project, authorizing in a browser when the
      server requires it.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Scenarios
    description: >-
      Read-only access to the scenarios published from a project: listing,
      settings, attached servers, and share links.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam cloud tunnel` CLI
      flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
  - name: Swarms
    description: >-
      Personas, journeys and swarm containers — the authoring half of Swarms —
      plus the model-backed generation that drafts them.
  - name: Swarm runs
    description: >-
      Launching journeys and reading what they produced. Launching SPENDS — see
      the per-operation notes.
  - name: Swarm insights
    description: >-
      What a swarm run revealed. The scorecard and findings are deterministic
      and free; requesting wave insights runs models and draws on your shared
      daily ledger.
  - name: User testing
    description: >-
      Publishing an environment for real visitors, and controlling who can reach
      it. Several of these NARROW access and take effect immediately.
  - name: Directory readiness
    description: >-
      Grade a saved server against a publisher's listing requirements:
      Anthropic's connector directory or OpenAI's plugin directory. Reported as
      lane status and coverage, never as a numeric score, and excluded from
      `pooledConformanceScore`. Deterministic grading is free; model-backed
      experience observations are an explicit opt-in that consumes MCPJam
      credits and can never decide a verdict.
  - name: Registry
    description: >-
      Search the scraped MCP directories (Claude, ChatGPT, and any future
      source), list curated/org registry cards, and install them into a project.
      Install writes a `servers` row and provenance — it does not open a live
      session. There is no catalog-uninstall route: delete the project server
      instead. Directory reads require a bearer (including minted guest tokens)
      but do not materialize a user. Card/connection reads and all writes are
      authed-non-guest.
paths:
  /projects/{projectId}/clients/{client}:
    patch:
      tags:
        - Clients
      summary: Update a client
      description: >-
        Edit a client's display name and/or its config. Two ways to change the
        config: `config` replaces it wholesale, and `set` changes named fields
        over the config read inside the write transaction — prefer `set`,
        because a whole-config round-trip composed from a stale read reverts
        whatever landed in between.


        Config edits require `expectedConfigId` and renames require
        `expectedName`. A stale token is `409 CONFLICT` whose `details` carries
        the current value: re-read the client and retry. A config edit that
        resolves to byte-identical settings writes nothing at all.


        Guest callers are denied (a write).
      operationId: updateClient
      parameters:
        - $ref: '#/components/parameters/projectId'
        - $ref: '#/components/parameters/client'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ClientUpdateRequest'
            example:
              expectedConfigId: hc_01J8…
              set:
                temperature: 0.2
      responses:
        '200':
          description: The updated client settings.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientDetail'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
        '502':
          $ref: '#/components/responses/ServerUnreachable'
components:
  parameters:
    projectId:
      name: projectId
      in: path
      required: true
      description: ID of the hosted project that contains the server.
      schema:
        type: string
    client:
      name: client
      in: path
      required: true
      description: >-
        Client **name or ID**. A name is matched case-insensitively and must be
        unique in the project; an ambiguous name is refused with `409 CONFLICT`
        listing the candidate ids rather than resolved to one of them.
      schema:
        type: string
  schemas:
    ClientUpdateRequest:
      type: object
      description: >-
        Edit a client. Provide at least one of `name`, `config` (whole-config
        replacement) or `set` (named fields); `config` and `set` are mutually
        exclusive. Config edits require `expectedConfigId` and renames require
        `expectedName`, so a concurrent edit is rejected rather than
        overwritten.
      properties:
        name:
          type: string
          minLength: 1
          description: New display name.
        expectedName:
          type: string
          minLength: 1
          description: >-
            The `name` you last read for this client. REQUIRED whenever the
            request sends `name`: a rename does not rotate the config, so
            `expectedConfigId` cannot detect a concurrent one. A mismatch is
            `409 CONFLICT` carrying `details.currentName`.
        expectedConfigId:
          type: string
          minLength: 1
          description: >-
            The `configId` you last read for this client. REQUIRED whenever the
            request changes the config (`config` or `set`): without it a write
            composed from a stale read silently reverts whatever landed in
            between. A mismatch is `409 CONFLICT` carrying
            `details.currentConfigId`.
        expectedImpact:
          allOf:
            - $ref: '#/components/schemas/ClientImpact'
          description: >-
            The `impact` you last read for this client. Optional, and checked
            transactionally when sent — a consumer added or removed since you
            read it makes the write conflict (`details.currentImpact`) instead
            of quietly affecting more than you were told it would.
        config:
          type: object
          additionalProperties: true
          minProperties: 1
          description: >-
            Replacement client config v2. Replaces the config wholesale; use
            `set` to change named fields instead.
        set:
          $ref: '#/components/schemas/ClientFieldSet'
      anyOf:
        - required:
            - name
        - required:
            - config
        - required:
            - set
      additionalProperties: false
    ClientDetail:
      type: object
      description: >-
        A client plus its resolved config (model, capabilities, host context,
        MCP profile) and the read-backs an editor needs.
      required:
        - id
        - name
        - config
        - ownerScope
      properties:
        id:
          type: string
        name:
          type: string
        configId:
          type: string
          description: The concurrency token — see `Client.configId`.
        config:
          type: object
          additionalProperties: true
          description: >-
            Client config v2 DTO. Opaque object; shape mirrors the inspector's
            client editor.
        ownerScope:
          type:
            - object
            - 'null'
          additionalProperties: true
        hasComputer:
          type: boolean
        createdAt:
          type: number
          description: Unix epoch milliseconds.
        updatedAt:
          type: number
          description: Unix epoch milliseconds.
        impact:
          $ref: '#/components/schemas/ClientImpact'
    ClientImpact:
      type: object
      description: >-
        What a config edit to this client would follow. These are the DURABLE
        consumers that re-resolve the client's current config; past runs,
        per-turn traces and pinned eval-suite snapshots hold a config id and are
        unaffected. Direct playground and client-chat use follows the edit too
        and has no row to count.
      required:
        - liveEnvironmentCount
        - scenarioAttachmentCount
        - activeLegacyJourneyCount
      properties:
        liveEnvironmentCount:
          type: integer
          description: Non-archived project environments selecting this client.
        scenarioAttachmentCount:
          type: integer
          description: Scenario attachments re-materialized inside the edit transaction.
        activeLegacyJourneyCount:
          type: integer
          description: Active journeys with no environments that pin this client.
    ClientFieldSet:
      type: object
      description: >-
        Named fields to change, applied over the client's current config INSIDE
        the write transaction. Absent always means keep. `null` means "make it
        go away", and what that means depends on the field: a required field
        resets to its documented default, an optional one clears to absent.
        Object-valued fields are whole-object replacements, not merges — to
        change a deep knob, read the client, overlay the sub-object, and send it
        back whole. `hostStyle`, `clientCapabilities`, `hostContext` and server
        membership are deliberately not settable here (use a whole-`config`
        replacement, or the servers operation).
      minProperties: 1
      additionalProperties: false
      properties:
        modelId:
          type: string
          minLength: 1
          pattern: .*\S.*
          description: >-
            Model id the client pins. Value only — there is no `null`, and a
            blank string is refused: a client that pins a model cannot be edited
            into one that does not.
        systemPrompt:
          type:
            - string
            - 'null'
          description: >-
            Send `null` to reset this field to its canonical default. Default:
            `""`.
        temperature:
          type:
            - number
            - 'null'
          description: >-
            Send `null` to reset this field to its canonical default. Default:
            `0.7`.
        requireToolApproval:
          type:
            - boolean
            - 'null'
          description: >-
            Send `null` to reset this field to its canonical default. Default:
            `false`.
        connectionDefaults:
          type:
            - object
            - 'null'
          additionalProperties: false
          required:
            - headers
            - requestTimeout
          properties:
            headers:
              type: object
              additionalProperties:
                type: string
            requestTimeout:
              type: number
          description: >-
            Send `null` to reset this field to its canonical default. Default:
            empty headers and the platform's default request timeout.
        respectToolVisibility:
          type:
            - boolean
            - 'null'
          description: Send `null` to clear this field back to absent.
        progressiveToolDiscovery:
          type:
            - boolean
            - 'null'
          description: Send `null` to clear this field back to absent.
        harness:
          type:
            - string
            - 'null'
          enum:
            - claude-code
            - codex
            - null
          description: >-
            Execution runtime selector. Send `null` to clear this field back to
            absent. Setting one requires the matching feature flag; clearing
            never does.
        computer:
          type:
            - object
            - 'null'
          additionalProperties: false
          required:
            - kind
          properties:
            kind:
              type: string
              enum:
                - personal
            toolset:
              type: string
              enum:
                - bash
            workdir:
              type: string
          description: >-
            Send `null` to clear this field back to absent. Attaching one
            requires the computers feature flag; detaching never does.
        builtInToolIds:
          type:
            - array
            - 'null'
          items:
            type: string
          description: Send `null` to clear this field back to absent.
        skillSelection:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: >-
            `{ mode: "all-visible" }` or `{ mode: "explicit", skillIds: [...]
            }`. Send `null` to clear this field back to absent.
        modelVisibleMcpToolResults:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: Send `null` to clear this field back to absent.
        mcpToolResultImageRendering:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: Send `null` to clear this field back to absent.
        mcpProfile:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: Send `null` to clear this field back to absent.
        hostCapabilitiesOverride:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: Send `null` to clear this field back to absent.
        chatUiOverride:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: Send `null` to clear this field back to absent.
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
  responses:
    ValidationError:
      description: Malformed body or parameters.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: VALIDATION_ERROR
            message: Invalid JSON body
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    Forbidden:
      description: Key is valid but not allowed to do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FORBIDDEN
            message: You do not have access to this project
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    Conflict:
      description: >-
        The resource is not in a state that accepts this write — a stale
        `expectedRevision`, a duplicate name, or an environment that cannot
        currently be launched. The request was well-formed; re-read the resource
        and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: CONFLICT
            message: >-
              Environment changed since you loaded it (expected revision 3,
              current 5). Reload and retry.
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
    ServerUnreachable:
      description: Could not connect to the target MCP server.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: SERVER_UNREACHABLE
            message: Failed to connect to server
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````