Read the tool endpoints
Every route the agent looks to for your tools, and what the last sync found at each one. The endpoints are the truth, but the agent answers from what was synced. Any member’s OAuth token can read this.
GET
/tool-endpointsAuthorization
AuthorizationBearer token · headerrequiredA MEDIAN_KEY from Settings under API. It starts with `median_key_` and stays on your server. The tool endpoint routes also accept an OAuth access token (`median_oat_`) from `median login` or an MCP client, acting as the person who approved it. The messaging routes accept only a Median key.
Responses
200The endpoints and their tools.
endpointsobject[]requiredEvery connected route and the tools its last successful sync found.
Show propertiesHide properties
Array of
objectidstringrequiredurlstringrequiredThe route the agent calls.
statusstringrequiredWhere the last sync got to.
Allowed:
syncingreadyerrorerrorstring | nullrequiredWhy the last sync failed, when it did.
lastSyncedAtinteger | nullrequiredWhen the manifest was last read, in milliseconds.
toolsobject[]requiredShow propertiesHide properties
Array of
objectnamestringrequireddescriptionstringrequiredriskstringrequiredHow the tool is gated. `low` runs freely. `medium` waits for the visitor's yes. `reviewed` waits for the visitor's yes, then an automatic review of the conversation decides. `high` waits for a teammate's approval.
Allowed:
lowmediumreviewedhighenabledbooleanrequiredWhether the agent may hold it.
syncedAtintegerrequiredWhen this tool last arrived, in milliseconds.
401`missing_api_key`: no bearer token. `invalid_api_key`: the key matches no organization or was revoked. `publishable_key`: a `median_pk_` key was sent. `invalid_token`: the OAuth token is unknown or expired.
errorobjectrequiredShow propertiesHide properties
codestringrequiredBranch on this rather than on the message.
messagestringrequired403With an OAuth token, `no_organization` when no organization is bound.
errorobjectrequiredShow propertiesHide properties
codestringrequiredBranch on this rather than on the message.
messagestringrequired429The organization's API allowance for this class of request is used up. Wait the `Retry-After` header's seconds. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectrequiredShow propertiesHide properties
codestringrequiredBranch on this rather than on the message.
messagestringrequiredRequest
curl -X GET "https://api.median.sh/v1/tool-endpoints" \
-H "Authorization: Bearer YOUR_TOKEN"const response = await fetch("https://api.median.sh/v1/tool-endpoints", {
method: "GET",
headers: {
"Authorization": "Bearer YOUR_TOKEN"
}
});Response
{
"endpoints": [
{
"id": "k170abc123",
"url": "https://example.com/api/median/orders",
"status": "ready",
"error": null,
"lastSyncedAt": 1737000000000,
"tools": [
{
"name": "orderStatus",
"description": "Look up an order.",
"risk": "low",
"enabled": true,
"syncedAt": 1737000000000
}
]
}
]
}{
"error": {
"code": "invalid_api_key",
"message": "That Median key does not match any organization. Copy the median_key_ key again from Settings under API."
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "rate_limited",
"message": "Your organization's API allowance is temporarily full. Please retry shortly."
}
}