> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Send feedback to the MCPJam team

> Tell the MCPJam team about MCPJam itself (a bug, a missing capability, something confusing, or a docs gap) at the moment you hit it. THE TEXT IS SENT TO THE MCPJAM TEAM, outside your organization, and kept for 180 days. It is stored in MCPJam's own database and never published. Summarize: never include secrets, tokens, or raw tool output. When a call failed, include its `requestId` (the failing response's `x-request-id`) so the report can be joined to our logs.

A `201` means the report is stored; notifying the team happens afterwards and cannot fail it. An identical report from you in the last 24 hours is answered with the existing report's id and `duplicate: true` instead of being filed again. Requires a signed-in account: guest tokens get `401`. Rate-limited per user (`429` with `Retry-After`); duplicates and key replays do not count.



## OpenAPI

````yaml /reference/openapi.json post /feedback
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Agent browsers
    description: >-
      Isolated cloud browser sessions for coding agents. Requires authenticated
      project membership and a configured desktop runtime.
  - name: Clients
    description: >-
      Clients — the named, reusable configurations that define how MCPJam
      connects to and talks to your MCP servers. The original `/hosts` paths
      remain as deprecated, ID-only compatibility aliases with their original
      DTOs and their original (tokenless) write contracts; every alias response
      carries `Deprecation: true`. New integrations should use `/clients`.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and goals run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Plugins
    description: >-
      Agent Plugins imported into a project — read-only inventory and version
      detail.
  - name: Skills
    description: >-
      Cloud Skills: authored SKILL.md files stored in a project. Read-only here.
      Environments pin skills by id (`skillSelection.skillIds`) and eval runs
      pin them with `--compose-skill`, so this surface exists to give an
      unattended caller those ids; authoring is an app flow behind a beta gate.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: Conformance runs
    description: >-
      Ingest MCP spec-conformance results from the SDK/CLI into project-owned
      history. Distinct from Eval runs (authored LLM cases) and from directory
      readiness.
  - name: Server connections
    description: >-
      Connect an MCP server URL to a project, authorizing in a browser when the
      server requires it.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Studies
    description: >-
      Publish a project environment as a **study** for people outside the
      project to talk to, read what they did, and control who can reach it.
      Several of these NARROW access and take effect immediately.


      The pre-rename paths — `/projects/{projectId}/scenarios`,
      `/projects/{projectId}/scenarios/{scenarioId}`,
      `/projects/{projectId}/environments/{environmentId}/scenario` and
      `/projects/{projectId}/user-testing/scenarios/{scenarioId}/…` — keep
      working and are deliberately not documented here. They return their
      original bodies, which spell the owning id `scenarioId` and whose detail
      read carries no execution settings, and every response answers with
      `Deprecation: true` and a `Link` header naming its successor. They are
      removed at general availability; a new integration should use the paths on
      this page.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam cloud tunnel` CLI
      flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
  - name: Swarms
    description: >-
      Personas, journeys and swarm containers — the authoring half of Swarms —
      plus the model-backed generation that drafts them.
  - name: Swarm runs
    description: >-
      Launching journeys and reading what they produced. Launching SPENDS — see
      the per-operation notes.
  - name: Swarm insights
    description: >-
      What a swarm run revealed. The scorecard and findings are deterministic
      and free; requesting wave insights runs models and draws on your shared
      daily ledger.
  - name: Directory readiness
    description: >-
      Grade a saved server against a publisher's listing requirements:
      Anthropic's connector directory or OpenAI's plugin directory. Reported as
      lane status and coverage, never as a numeric score, and excluded from
      `pooledConformanceScore`. Deterministic grading is free; model-backed
      experience observations are an explicit opt-in whose model cost is on
      MCPJam — no credits are consumed — and they can never decide a verdict.
  - name: Registry
    description: >-
      Search the scraped MCP directories (Claude, ChatGPT, and any future
      source), list curated/org registry cards, and install them into a project.
      Install writes a `servers` row and provenance — it does not open a live
      session. There is no catalog-uninstall route: delete the project server
      instead. Directory reads require a bearer (including minted guest tokens)
      but do not materialize a user. Card/connection reads and all writes are
      authed-non-guest.
  - name: Feedback
    description: >-
      Feedback about MCPJam itself (bugs, missing capabilities, confusing
      behavior), sent to the MCPJam team and kept for 180 days. The
      `send_feedback` MCP tool calls the same endpoint.
paths:
  /feedback:
    post:
      tags:
        - Feedback
      summary: Send feedback to the MCPJam team
      description: >-
        Tell the MCPJam team about MCPJam itself (a bug, a missing capability,
        something confusing, or a docs gap) at the moment you hit it. THE TEXT
        IS SENT TO THE MCPJAM TEAM, outside your organization, and kept for 180
        days. It is stored in MCPJam's own database and never published.
        Summarize: never include secrets, tokens, or raw tool output. When a
        call failed, include its `requestId` (the failing response's
        `x-request-id`) so the report can be joined to our logs.


        A `201` means the report is stored; notifying the team happens
        afterwards and cannot fail it. An identical report from you in the last
        24 hours is answered with the existing report's id and `duplicate: true`
        instead of being filed again. Requires a signed-in account: guest tokens
        get `401`. Rate-limited per user (`429` with `Retry-After`); duplicates
        and key replays do not count.
      operationId: sendFeedback
      parameters:
        - name: Idempotency-Key
          in: header
          required: false
          description: >-
            Retry-safe report key, validated STRICTLY. Replaying the SAME key
            with the SAME report returns the original receipt; reusing it for
            DIFFERENT content is a `409`. A header that is present but empty, or
            longer than 256 characters, is a `400`, never silently ignored.
            `x-mcpjam-idempotency-key` is accepted as an alternative spelling;
            sending both with different values is a `400`.
          schema:
            type: string
            minLength: 1
            maxLength: 256
        - $ref: '#/components/parameters/launcherHeader'
      requestBody:
        required: true
        description: The report.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FeedbackRequest'
      responses:
        '201':
          description: >-
            The report is stored. `duplicate: true` means an identical report
            from you was already recorded.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FeedbackReceipt'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    launcherHeader:
      name: x-mcpjam-launcher
      in: header
      required: false
      description: >-
        The launching process's own DECLARED identity, as compact JSON:
        `{"kind":"cli"|"mcp"|"github_action","client":"…","version":"…"}`.
        Stored on the run as `launcher` and used only as a display label —
        `source` stays `api` and the audit trail reads the platform-minted
        `attribution` instead.


        A header rather than a body field so that sending it never breaks
        against an older deployment: both eval-run bodies reject unknown
        properties, while an unknown header is ignored everywhere. For the same
        reason a malformed value, or a `kind` outside the three above, is
        DROPPED rather than rejected — a label must never fail a launch. Max 512
        bytes.
      schema:
        type: string
      example: '{"kind":"github_action","client":"mcpjam-cli","version":"8.2.0"}'
  schemas:
    FeedbackRequest:
      type: object
      additionalProperties: false
      required:
        - kind
        - summary
      properties:
        kind:
          type: string
          enum:
            - bug
            - missing_capability
            - confusing
            - docs
            - other
          description: What sort of problem this is.
        summary:
          type: string
          minLength: 1
          maxLength: 200
          description: >-
            One line: what went wrong or what is missing. Trimmed. Appears in
            the team's notification.
        details:
          type: string
          maxLength: 8000
          description: >-
            What you were trying to accomplish, what you expected, and what
            blocked you. For a missing capability, name the task and any
            workaround you tried; there may be no request id. Summarize; never
            paste secrets, tokens, or raw tool output. Stored only in MCPJam's
            database, never emailed, and deleted after 180 days.
        operation:
          type: string
          maxLength: 120
          description: The tool, CLI command or app page in use.
        requestId:
          type: string
          maxLength: 128
          description: The failing call's `x-request-id`, when there is one.
        errorCode:
          type: string
          maxLength: 64
          description: The failing call's error code, e.g. `INTERNAL_ERROR`.
        projectId:
          type: string
          description: >-
            A project you can see, when the report is about one; anything else
            is a `404`. Omit it otherwise: no project is assumed.
    FeedbackReceipt:
      type: object
      required:
        - id
        - receivedAt
        - duplicate
      properties:
        id:
          type: string
          description: The stored report's id.
        receivedAt:
          type: number
          description: When the report was received, in epoch milliseconds.
        duplicate:
          type: boolean
          description: >-
            True when an identical report from you was already recorded in the
            last 24 hours; `id` is that report.
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
  responses:
    ValidationError:
      description: Malformed body or parameters.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: VALIDATION_ERROR
            message: Invalid JSON body
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    Conflict:
      description: >-
        The resource is not in a state that accepts this write — a stale
        `expectedRevision`, a duplicate name, or an environment that cannot
        currently be launched. The request was well-formed; re-read the resource
        and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: CONFLICT
            message: >-
              Environment changed since you loaded it (expected revision 3,
              current 5). Reload and retry.
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````