Get started
Muse (MCP)
Publish your app in Muse as a hosted MCP server. Nodium runs the server and OAuth, and calls your API directly.
An app is your software as Muse sees it: a name, a list of tools, and the address of your API. Every account already has one. With mcpEnabled: true, Nodium serves it at https://nodium.io/api/v1/apps/{id}/mcp — the URL your users paste into Muse. You write no server code: each tool is an operation of your own API, described by your OpenAPI document.
Describe your API and pick the tools
# 1. Your account already has an app. Point it at your API (admin key)curl -X PATCH https://nodium.io/api/v1/apps/<app id> \ -H "Authorization: Bearer $NODIUM_KEY" \ -H "Content-Type: application/json" \ -d '{ "apiBaseUrl": "https://api.example.com", "mcpEnabled": true }'# 2. Derive its tools from your OpenAPI 3 documentcurl https://nodium.io/api/v1/apps/<app id>/tools/import \ -H "Authorization: Bearer $NODIUM_KEY" \ -H "Content-Type: application/json" \ -d '{ "url": "https://api.example.com/openapi.json", "dryRun": true }'# 3. The URL your users paste into Muse# https://nodium.io/api/v1/apps/<app id>/mcpPOST /apps/{id}/tools/importderives one tool per operation of an OpenAPI 3 document (JSON), byurlor inlinedocument.mode: "merge"keeps the tools you already have;dryRun: trueshows the result without saving.GETandHEADoperations come enabled; every other operation comes disabled until you enable it.PATCH /apps/{id}/tools/{name}enables or disables one tool. Or setmcpToolsyourself withPATCH /apps/{id}: aname, adescription, aninputSchema(JSON Schema of typeobject), anoperation({ method, path }), optionallyscope(readorwrite) andenabled.PATCH /apps/{id}also setsapiBaseUrl(https),status(activeorpaused) and how your users sign in to your API:authTypeapi_key,oauth2(your provider, PKCE — registerhttps://nodium.io/api/oauth/callbackas redirect URI) ornone. The import pre-fills it from your OpenAPI security scheme.
Test a tool
POST /apps/{id}/tools/{name}/test calls one tool for real with a test credential of yours (testCredential in PATCH /apps/{id}, write-only) and returns your API's answer. Test calls are marked as such in the journal and never billed.
What Nodium runs
- The MCP endpoint, Streamable HTTP:
POST /api/v1/apps/{id}/mcpcarries JSON-RPC (initialize,tools/list,tools/call);GETanswers 405;DELETEends the session. - OAuth 2.1 for Muse: discovery at
/.well-known/oauth-authorization-serverand/.well-known/oauth-protected-resource/api/v1/apps/{id}/mcp, dynamic client registration (POST /api/oauth/register), authorization with PKCE S256 and a consent screen (/api/oauth/authorize), tokens (POST /api/oauth/token), revocation (POST /api/oauth/revoke). - A call without a Nodium token gets
401withWWW-Authenticatepointing to that discovery document: the client starts the flow on its own. - Only enabled tools are offered to assistants. Each
tools/callcounts against your quota; past it on a plan that blocks, the tool answers with an error result instead of calling your API.
What your API receives
# Muse asks "where is order 1042?": Nodium calls your API, as your OpenAPI describes it,# with that user's own token at your service.GET https://api.example.com/orders/1042Authorization: Bearer <the user's token at your service>Accept: application/json- The call is the operation the tool stands for, on
apiBaseUrl, with the user's own credential at your service — placed as yourauthConfigsays (Authorization: Bearerwith OAuth). The assistant never has more rights than that user. - Nodium refreshes an expired OAuth token; a connection that cannot be refreshed makes the tool ask the user to sign in again.
- Answer JSON: Nodium turns it into the MCP result. A non-
2xxanswer becomes an error result. The call times out after 30 seconds and the body is capped at 1 MB. Private addresses are refused, like for webhooks. - Every call lands in
GET /apps/{id}/invocations;GET /apps/{id}/statssums them up,GET /apps/{id}/connectionslists who is connected, andDELETE /apps/{id}/connections/{connId}cuts one off. GET /apps/{id}/review-kit(format=markdownfor a file) generates the file for Muse's directory review: listing, checklist and MCP address.