curl --request POST \
--url https://api.checkfu.com/v1/tool-sources \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"name": "<string>",
"provider": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": true
},
"description": "<string>",
"default_enabled": true
}
'import requests
url = "https://api.checkfu.com/v1/tool-sources"
payload = {
"name": "<string>",
"provider": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": True
},
"description": "<string>",
"default_enabled": True
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: '<string>',
provider: '<string>',
source: {kind: 'mcp', url: '<string>', authenticated: true},
description: '<string>',
default_enabled: true
})
};
fetch('https://api.checkfu.com/v1/tool-sources', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/tool-sources",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'provider' => '<string>',
'source' => [
'kind' => 'mcp',
'url' => '<string>',
'authenticated' => true
],
'description' => '<string>',
'default_enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/tool-sources"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/tool-sources")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/tool-sources")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"name": "<string>",
"provider": "<string>",
"description": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": true
},
"status": "pending",
"default_enabled": true,
"default_permission": "always_ask",
"tool_count": 1,
"last_sync_at": "<string>",
"last_sync_error_code": "<string>",
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Register a Tool Source
Register an MCP server, an OpenAPI document, or an inline API manifest as a ToolSource and run first discovery. The logical name and provider identity are immutable, and the provider is what a Connection’s provider resolves to. Hosted discovery accepts only credential-free HTTPS URLs on public DNS hostnames and never follows redirects, so a private API must supply inline tool definitions. Set default_enabled: false for default-off subsetting: every tool this source discovers — now and on every later sync — arrives disabled until enabled by name through patchTool, so a tool that appears upstream later cannot reach an agent unreviewed. Omitting it keeps the admitting default. The posture is fixed at creation, like the source’s name and provider. Accepts an Idempotency-Key.
Checkfu support posture: alpha; hosted. Required evidence journey: capability-catalog. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
curl --request POST \
--url https://api.checkfu.com/v1/tool-sources \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"name": "<string>",
"provider": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": true
},
"description": "<string>",
"default_enabled": true
}
'import requests
url = "https://api.checkfu.com/v1/tool-sources"
payload = {
"name": "<string>",
"provider": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": True
},
"description": "<string>",
"default_enabled": True
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: '<string>',
provider: '<string>',
source: {kind: 'mcp', url: '<string>', authenticated: true},
description: '<string>',
default_enabled: true
})
};
fetch('https://api.checkfu.com/v1/tool-sources', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/tool-sources",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'provider' => '<string>',
'source' => [
'kind' => 'mcp',
'url' => '<string>',
'authenticated' => true
],
'description' => '<string>',
'default_enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/tool-sources"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/tool-sources")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/tool-sources")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"provider\": \"<string>\",\n \"source\": {\n \"kind\": \"mcp\",\n \"url\": \"<string>\",\n \"authenticated\": true\n },\n \"description\": \"<string>\",\n \"default_enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"name": "<string>",
"provider": "<string>",
"description": "<string>",
"source": {
"kind": "mcp",
"url": "<string>",
"authenticated": true
},
"status": "pending",
"default_enabled": true,
"default_permission": "always_ask",
"tool_count": 1,
"last_sync_at": "<string>",
"last_sync_error_code": "<string>",
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-27 255Body
Response
Success
^ts_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$^[a-z0-9](?:[a-z0-9._-]{0,93})$^[a-z0-9](?:[a-z0-9._-]{0,93})$16384- Option 1
- Option 2
- Option 3
- Option 4
- Option 5
Show child attributes
Show child attributes
pending, healthy, sync_failed always_ask, always_allow x >= 01 - 8192x > 0