Skip to content
Get an API key

Get started

Muse (MCP)

Publish your app in Muse as a hosted MCP server. Nodium runs the server and OAuth, and calls your API directly.

An app is your software as Muse sees it: a name, a list of tools, and the address of your API. Every account already has one. With mcpEnabled: true, Nodium serves it at https://nodium.io/api/v1/apps/{id}/mcp — the URL your users paste into Muse. You write no server code: each tool is an operation of your own API, described by your OpenAPI document.

Describe your API and pick the tools

Shell

# 1. Your account already has an app. Point it at your API (admin key)curl -X PATCH https://nodium.io/api/v1/apps/<app id> \ -H "Authorization: Bearer $NODIUM_KEY" \ -H "Content-Type: application/json" \ -d '{ "apiBaseUrl": "https://api.example.com", "mcpEnabled": true }'# 2. Derive its tools from your OpenAPI 3 documentcurl https://nodium.io/api/v1/apps/<app id>/tools/import \ -H "Authorization: Bearer $NODIUM_KEY" \ -H "Content-Type: application/json" \ -d '{ "url": "https://api.example.com/openapi.json", "dryRun": true }'# 3. The URL your users paste into Muse# https://nodium.io/api/v1/apps/<app id>/mcp
  • POST /apps/{id}/tools/import derives one tool per operation of an OpenAPI 3 document (JSON), by url or inline document. mode: "merge" keeps the tools you already have; dryRun: true shows the result without saving. GET and HEAD operations come enabled; every other operation comes disabled until you enable it.
  • PATCH /apps/{id}/tools/{name} enables or disables one tool. Or set mcpTools yourself with PATCH /apps/{id}: a name, a description, an inputSchema (JSON Schema of type object), an operation ({ method, path }), optionally scope (read or write) and enabled.
  • PATCH /apps/{id} also sets apiBaseUrl (https), status (active or paused) and how your users sign in to your API: authType api_key, oauth2 (your provider, PKCE — register https://nodium.io/api/oauth/callback as redirect URI) or none. The import pre-fills it from your OpenAPI security scheme.

Test a tool

POST /apps/{id}/tools/{name}/test calls one tool for real with a test credential of yours (testCredential in PATCH /apps/{id}, write-only) and returns your API's answer. Test calls are marked as such in the journal and never billed.

What Nodium runs

  • The MCP endpoint, Streamable HTTP: POST /api/v1/apps/{id}/mcp carries JSON-RPC (initialize, tools/list, tools/call); GET answers 405; DELETE ends the session.
  • OAuth 2.1 for Muse: discovery at /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource/api/v1/apps/{id}/mcp, dynamic client registration (POST /api/oauth/register), authorization with PKCE S256 and a consent screen (/api/oauth/authorize), tokens (POST /api/oauth/token), revocation (POST /api/oauth/revoke).
  • A call without a Nodium token gets 401 with WWW-Authenticate pointing to that discovery document: the client starts the flow on its own.
  • Only enabled tools are offered to assistants. Each tools/call counts against your quota; past it on a plan that blocks, the tool answers with an error result instead of calling your API.

What your API receives

HTTP

# Muse asks "where is order 1042?": Nodium calls your API, as your OpenAPI describes it,# with that user's own token at your service.GET https://api.example.com/orders/1042Authorization: Bearer <the user's token at your service>Accept: application/json
  • The call is the operation the tool stands for, on apiBaseUrl, with the user's own credential at your service — placed as your authConfig says (Authorization: Bearer with OAuth). The assistant never has more rights than that user.
  • Nodium refreshes an expired OAuth token; a connection that cannot be refreshed makes the tool ask the user to sign in again.
  • Answer JSON: Nodium turns it into the MCP result. A non-2xx answer becomes an error result. The call times out after 30 seconds and the body is capped at 1 MB. Private addresses are refused, like for webhooks.
  • Every call lands in GET /apps/{id}/invocations; GET /apps/{id}/stats sums them up, GET /apps/{id}/connections lists who is connected, and DELETE /apps/{id}/connections/{connId} cuts one off.
  • GET /apps/{id}/review-kit (format=markdown for a file) generates the file for Muse's directory review: listing, checklist and MCP address.