> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Save a server into a project

> Creates a saved MCP server and responds `201` with its detail. This is the provisioning entry point: every eval, host and environment route addresses servers that were created here. Names are unique per workspace, so a clash responds `409` rather than silently returning the existing row. Secret-bearing fields (`env`, `headers`, `clientSecret`) are encrypted at rest and never returned by any read.



## OpenAPI

````yaml /reference/openapi.json post /projects/{projectId}/servers
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Hosts
    description: >-
      Project hosts: named model + capability profiles you run chats and eval
      suites against.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and journeys run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Chatboxes
    description: >-
      Read-only access to the chatboxes published from a project: listing,
      settings, attached servers, and share links.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam tunnel` CLI flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
paths:
  /projects/{projectId}/servers:
    post:
      tags:
        - Servers
      summary: Save a server into a project
      description: >-
        Creates a saved MCP server and responds `201` with its detail. This is
        the provisioning entry point: every eval, host and environment route
        addresses servers that were created here. Names are unique per
        workspace, so a clash responds `409` rather than silently returning the
        existing row. Secret-bearing fields (`env`, `headers`, `clientSecret`)
        are encrypted at rest and never returned by any read.
      operationId: createProjectServer
      parameters:
        - $ref: '#/components/parameters/projectId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProjectServerCreateRequest'
            example:
              name: learn
              enabled: true
              transportType: http
              url: https://learn.mcpjam.com/mcp
      responses:
        '201':
          description: The server was created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProjectServer'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
        '502':
          $ref: '#/components/responses/ServerUnreachable'
components:
  parameters:
    projectId:
      name: projectId
      in: path
      required: true
      description: ID of the hosted project that contains the server.
      schema:
        type: string
  schemas:
    ProjectServerCreateRequest:
      type: object
      description: >-
        Creates a saved server in the project. Server names are unique per
        workspace — a clash responds `409`. Scope comes from the path:
        `projectId`, `serverId` and `workspaceId` are rejected in the body.
      required:
        - name
        - enabled
        - transportType
      additionalProperties: false
      properties:
        name:
          type: string
          minLength: 1
        enabled:
          type: boolean
        transportType:
          type: string
          enum:
            - stdio
            - http
        command:
          type: string
          description: stdio transport only.
        args:
          type: array
          items:
            type: string
        env:
          type: object
          additionalProperties:
            type: string
          description: Stored encrypted; never returned by any read.
        url:
          type: string
          format: uri
          description: http transport only.
        headers:
          type: object
          additionalProperties:
            type: string
          description: Stored encrypted; never returned by any read.
        hasBearerToken:
          type: boolean
        timeout:
          type: number
          exclusiveMinimum: 0
        clientCapabilities:
          description: Opaque MCP client capabilities bag.
        useOAuth:
          type: boolean
        oauthScopes:
          type: array
          items:
            type: string
        clientId:
          type: string
        oauthResourceUrl:
          type: string
        oauthProtocolMode:
          type: string
        oauthProtocolVersion:
          type: string
        oauthRegistrationStrategy:
          type: string
        xaaAuthzIssuer:
          type: string
        xaaAllowPathScopedIssuer:
          type: boolean
        oauthAllowPathScopedIssuer:
          type: boolean
        useXaa:
          type: boolean
        authServerMode:
          type: string
          enum:
            - mcpjam
            - own
        xaaSubject:
          type: string
        xaaEmail:
          type: string
        xaaIdentityAssertionFormat:
          type: string
        xaaClientAuth:
          type: string
        authMethod:
          type: string
        registrationMode:
          type: string
        clientSecret:
          type: string
          description: >-
            Stored encrypted; never returned. Reads expose only
            `hasClientSecret`.
    ProjectServer:
      type: object
      description: >-
        A saved MCP server, projected toward the hosted (HTTP) shape. STDIO
        command/args/env and raw headers are never exposed.
      required:
        - id
        - name
        - enabled
        - transportType
        - useOAuth
        - hasClientSecret
      properties:
        id:
          type: string
        projectId:
          type:
            - string
            - 'null'
        name:
          type: string
        enabled:
          type: boolean
        transportType:
          type: string
        url:
          type:
            - string
            - 'null'
          description: Endpoint for HTTP-transport servers; `null` for stdio.
        useOAuth:
          type: boolean
        hasClientSecret:
          type: boolean
        oauthScopes:
          type: array
          items:
            type: string
        createdAt:
          type:
            - number
            - 'null'
          description: Epoch milliseconds.
        updatedAt:
          type:
            - number
            - 'null'
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
  responses:
    ValidationError:
      description: Malformed body or parameters.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: VALIDATION_ERROR
            message: Invalid JSON body
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    Forbidden:
      description: Key is valid but not allowed to do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FORBIDDEN
            message: You do not have access to this project
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    Conflict:
      description: >-
        The resource is not in a state that accepts this write — a stale
        `expectedRevision`, a duplicate name, or an environment that cannot
        currently be launched. The request was well-formed; re-read the resource
        and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: CONFLICT
            message: >-
              Environment changed since you loaded it (expected revision 3,
              current 5). Reload and retry.
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
    ServerUnreachable:
      description: Could not connect to the target MCP server.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: SERVER_UNREACHABLE
            message: Failed to connect to server
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````