Skip to content
Median
Esc
↑↓navigate↵open⌘Jpreview

Read the tool endpoints

Every route the agent looks to for your tools, and what the last sync found at each one. The endpoints are the truth, but the agent answers from what was synced. Any member’s OAuth token can read this.

GET/tool-endpoints
Authorization
AuthorizationBearer token · headerrequired
A MEDIAN_KEY from Settings under API. It starts with `median_key_` and stays on your server. The tool endpoint routes also accept an OAuth access token (`median_oat_`) from `median login` or an MCP client, acting as the person who approved it. The messaging routes accept only a Median key.
Responses
200The endpoints and their tools.
endpointsobject[]required
Every connected route and the tools its last successful sync found.
Show properties
Array of object
idstringrequired
urlstringrequired
The route the agent calls.
statusstringrequired
Where the last sync got to.
Allowed:syncingreadyerror
errorstring | nullrequired
Why the last sync failed, when it did.
lastSyncedAtinteger | nullrequired
When the manifest was last read, in milliseconds.
toolsobject[]required
Show properties
Array of object
namestringrequired
descriptionstringrequired
riskstringrequired
How the tool is gated. `low` runs freely. `medium` waits for the visitor's yes. `reviewed` waits for the visitor's yes, then an automatic review of the conversation decides. `high` waits for a teammate's approval.
Allowed:lowmediumreviewedhigh
enabledbooleanrequired
Whether the agent may hold it.
syncedAtintegerrequired
When this tool last arrived, in milliseconds.
401`missing_api_key`: no bearer token. `invalid_api_key`: the key matches no organization or was revoked. `publishable_key`: a `median_pk_` key was sent. `invalid_token`: the OAuth token is unknown or expired.
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
403With an OAuth token, `no_organization` when no organization is bound.
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
429The organization's API allowance for this class of request is used up. Wait the `Retry-After` header's seconds. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
Request
curl -X GET "https://api.median.sh/v1/tool-endpoints" \
  -H "Authorization: Bearer YOUR_TOKEN"
Response
{
  "endpoints": [
    {
      "id": "k170abc123",
      "url": "https://example.com/api/median/orders",
      "status": "ready",
      "error": null,
      "lastSyncedAt": 1737000000000,
      "tools": [
        {
          "name": "orderStatus",
          "description": "Look up an order.",
          "risk": "low",
          "enabled": true,
          "syncedAt": 1737000000000
        }
      ]
    }
  ]
}