List per-user access
curl --request GET \
--url https://api.devic.ai/v1/tool-servers/{toolServerId}/users \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.devic.ai/v1/tool-servers/{toolServerId}/users"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.devic.ai/v1/tool-servers/{toolServerId}/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devic.ai/v1/tool-servers/{toolServerId}/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.devic.ai/v1/tool-servers/{toolServerId}/users"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.devic.ai/v1/tool-servers/{toolServerId}/users")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devic.ai/v1/tool-servers/{toolServerId}/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"_id": "<string>",
"toolServerId": "<string>",
"userUID": "<string>",
"allowed": true,
"profileId": "<string>",
"userHiddenToolNames": [
"<string>"
],
"creationTimestampMs": 123,
"lastEditTimestampMs": 123
}
]MCP Gateway
List per-user access
Who can reach the gateway and what each one sees: the access gate, the profile assigned to them and any per-user override on top of it.
GET
/
v1
/
tool-servers
/
{toolServerId}
/
users
List per-user access
curl --request GET \
--url https://api.devic.ai/v1/tool-servers/{toolServerId}/users \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.devic.ai/v1/tool-servers/{toolServerId}/users"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.devic.ai/v1/tool-servers/{toolServerId}/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devic.ai/v1/tool-servers/{toolServerId}/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.devic.ai/v1/tool-servers/{toolServerId}/users"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.devic.ai/v1/tool-servers/{toolServerId}/users")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devic.ai/v1/tool-servers/{toolServerId}/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"_id": "<string>",
"toolServerId": "<string>",
"userUID": "<string>",
"allowed": true,
"profileId": "<string>",
"userHiddenToolNames": [
"<string>"
],
"creationTimestampMs": 123,
"lastEditTimestampMs": 123
}
]Authorizations
An API key from your Devic console, sent as Authorization: Bearer <key>. An embedded front end sends a tenant-session token instead, so no API key reaches the browser, and an OAuth integration sends its access token. Missing, invalid or expired credentials get a 401. See Authentication.
Path Parameters
Id of the MCP Gateway tool server
Response
Access rows of the gateway
Whether the user can use the gateway at all
Visibility profile assigned to the user
Extra tools hidden for this user, on top of the profile