Send an MCP message
POST/mcp
A Model Context Protocol server (streamable HTTP transport, JSON
responses, protocol version 2025-06-18; 2025-03-26 and
2024-11-05 are also accepted), authenticated with the same bearer
keys. Secret keys and OAuth tokens only. The body is one JSON-RPC 2.0
message; batches are not supported.
Methods: initialize, ping, tools/list and tools/call. A
notification (a message with no id) is acknowledged with 202 and
no body. Protocol errors use JSON-RPC error codes (-32700 parse
error, -32600 invalid request, -32601 unknown method, -32602
unknown tool) inside a 200 response. A tool that refuses (a
validation failure, a missing record) answers with a result whose
isError is true, so the model can read the reason and correct
itself.
Tools, each listed only when the key has its scope:
| Tool | Scope | What it does |
|---|---|---|
search_vehicles | vehicles:read | Lists vehicles, filtered by status, make, model or registration. |
get_vehicle | vehicles:read | One vehicle with its full details and photos. |
update_vehicle_price | vehicles:write | Sets the asking price in minor units, or marks it price on application. |
stock_summary | vehicles:read | How many vehicles are in each status, and the asking value of stock on sale. |
list_enquiries | enquiries:read | Lists enquiries, filtered by status. |
get_enquiry | enquiries:read | One enquiry with its notes. |
create_enquiry | enquiries:write | Records a lead; takes the POST /enquiries body. |
search_customers | customers:read | Finds customers by email or phone. |
list_appointments | appointments:read | Appointments, optionally between two dates. |
list_deals | sales:read | Sales deals. |
request_website_theme | website_themes:write | Starts a website theme build from a brief, or a revision of the last one. It does not go live by itself. |
get_theme_generation | website_themes:read | A theme build's status, with a preview link once it has succeeded. |
Request
Responses
- 200
- 202
- 401
- 403
- 429
A JSON-RPC 2.0 response, carrying either result or error.
Response Headers
This request's id. Quote it to support.
Requests allowed per minute for this key.
Requests left in the current minute.
A notification was received. No body.
Response Headers
This request's id. Quote it to support.
No key, or one that cannot be used. Codes: missing_api_key,
invalid_api_key, api_key_revoked, api_key_expired,
key_owner_inactive.
Response Headers
This request's id. Quote it to support.
Bearer.
The key may not do this. Codes: insufficient_scope,
scope_not_permitted_for_owner, plan_not_entitled,
secret_key_required, publishable_key_required,
secret_key_in_browser, origin_not_allowed, ip_not_allowed,
branch_move_not_permitted, plan_stock_cap_reached,
sandbox_stock_cap_reached, not_available_in_sandbox,
theme_builder_not_enabled.
Response Headers
This request's id. Quote it to support.
Too many requests. Code rate_limited; wait Retry-After seconds. On POST /theme-generations, also theme_generation_quota_exceeded, when the dealer's monthly theme generations are used up (no Retry-After).
Response Headers
This request's id. Quote it to support.
Requests allowed per minute for this key.
Requests left in the current minute.
Seconds to wait before retrying.