> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Update an MCP gateway

> Updates mutable fields of an existing MCP gateway. Omitted optional fields keep their current values.

<Note>
  **Related guide**: MCP gateways guide. See the [MCP gateways guide](/ai-gateway/mcp-portal/mcp-gateways) for a walkthrough with examples.
</Note>


## OpenAPI

````yaml patch /v2/mcp-gateways/{id}
openapi: 3.1.0
info:
  title: orq.ai API
  version: '2.0'
  description: orq.ai API documentation
servers:
  - url: https://my.orq.ai
security:
  - ApiKey: []
tags:
  - name: Chunking
    description: Split text into smaller chunks for retrieval and generation workflows.
  - name: File Systems
    description: >-
      Create and manage persistent file systems that agents and MCP clients read
      from and write to.
  - name: Knowledge Bases
    description: Create and manage knowledge bases used by agents and retrieval workflows.
  - name: Memory Stores
    description: Create and manage memory stores, memories, and memory documents.
  - name: Evals
    description: Run an evaluator against a conversation and its result
  - name: Logs
    description: >-
      OpenTelemetry log query API. Search, filter, aggregate, and facet log
      records ingested via OTLP.
  - name: Reporting
    description: >-
      GenAI reporting API over canonical analytics rollups. Accepts a metric
      name, time range, grain, group-by, and filters; returns a typed time
      series and optional totals.
  - name: Traces
    description: >-
      Query and inspect ingested trace data: search trace summaries, aggregate
      metrics, and read individual traces and their spans.
  - description: List models available through the AI Router.
    name: Models
  - name: Policies
  - name: Alerts
    description: >-
      Alerts evaluate a Reporting API metric on a fixed interval and fire
      notifications through notifiers when the value breaches a threshold. Each
      breach opens a trigger that tracks the incident until the value recovers.
  - name: Annotation Queues
    description: Annotation queues collect spans for human review.
  - name: API keys
    description: >-
      API keys authenticate programmatic access to the workspace. They expose
      opaque tokens, per-domain access grants, and budget and rate-limit
      constraints.
  - name: Audit Logs
    description: Audit logs record workspace entity changes and access-relevant events.
  - name: Budgets
    description: >-
      Budgets govern spend, token usage, and request rate across six scopes:
      workspace, project, identity, API key, provider, and model. Every
      applicable budget is enforced, and the most restrictive limit applies per
      dimension.
  - name: Files
    description: File upload and retrieval operations.
  - name: Guardrail Rules
    description: >-
      Guardrail Rules conditionally enforce evaluators and plugins for AI
      Gateway traffic. Rules may be scoped to a project or the whole workspace.
  - name: Hub
    description: Hub items are reusable templates available to a workspace.
  - name: Identities
    description: >-
      Identities represent end users from your system for usage and engagement
      tracking.
  - name: Management keys
    description: >-
      Management keys are workspace-scoped credentials that authenticate
      programmatic access to workspace administration surfaces (API keys,
      budgets). Unlike project-scoped API keys, a management key always operates
      at the workspace level.
  - name: MCP Gateway
    description: >-
      Register upstream MCP servers, discover and sync their tools, and assemble
      gateways that expose a curated tool surface to MCP clients.
  - name: Model Catalog
    description: >-
      Browse the orq.ai model catalog: every model orq offers, across every
      provider, with pricing, capabilities and benchmark data. List endpoints
      only return models that are not deprecated. This API is public, requires
      no authentication, and is rate limited to 120 requests per minute per IP.
      Responses carry a 5-minute cache-control max-age.
  - name: Notifiers
    description: Notifier destinations used to send delivery and workflow notifications.
  - name: Projects
    description: Projects organize resources within a workspace
  - name: Routing Rules
    description: >-
      Routing Rules conditionally select models and enforce request plugins for
      AI Gateway traffic. Rules are evaluated by ascending priority and may be
      scoped to a project or the whole workspace.
  - name: Threads
    description: Threads group related trace invocations and their aggregate usage
  - name: Skills
    description: >-
      Skills are modular instructions you can use to codify processes and
      conventions
  - name: Smart Routers
    description: >-
      Create and manage workspace Smart Routers. A Smart Router selects a model
      from an eligible pool for each request according to a quality, balanced,
      or cost profile.
  - name: Webhooks
    description: >-
      Create and manage webhooks that deliver workspace events to external HTTPS
      endpoints.
  - name: Workspaces
    description: >-
      A workspace is the tenant. Create is called from a user session during
      onboarding; Get, List, and Update are the public management surface.
  - name: Workspace Security
    description: >-
      Workspace-level domain verification and IP allowlist controls. These
      operations are restricted to workspace administrators.
  - name: Workspace Settings
    description: >-
      Workspace-level settings managed with a workspace credential. A workspace
      is the tenant, so these settings are a singleton — there is nothing to
      create or delete, only read and update.
  - name: Responses
  - description: Run agents on a cron cadence. Minimum firing interval is 1 hour.
    name: Agent Schedules
  - name: Embeddings
  - name: Telemetry
    description: >-
      Unified query envelope for traces, metrics, and logs. One request shape,
      one filter dialect, and one response shape per source, validated by a
      per-source registry.
  - description: Beta. Run typed classification questions against a classify model.
    name: Classify
  - description: Search Gateway with managed credits or BYOK.
    name: Web Search
externalDocs:
  url: https://docs.orq.ai
  description: orq.ai Documentation
paths:
  /v2/mcp-gateways/{id}:
    patch:
      tags:
        - MCP Gateway
      summary: Update an MCP gateway
      description: >-
        Updates mutable fields of an existing MCP gateway. Omitted optional
        fields keep their current values.
      operationId: McpGatewayUpdate
      parameters:
        - name: id
          in: path
          description: Unique identifier of the MCP gateway.
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateMcpGatewayRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateMcpGatewayResponse'
      x-code-samples:
        - lang: curl
          label: Core - Narrow the tools a gateway exposes
          source: |
            curl --request PATCH \
              --url 'https://my.orq.ai/v2/mcp-gateways/01JQ0M8W4T5YB2Q7N1F6K3PZRC' \
              --header "Authorization: Bearer $ORQ_API_KEY" \
              --header 'Content-Type: application/json' \
              --data '{
                "server_links": [
                  {
                    "mcp_server_id": "01JQ0K5R8N2ZC7X4M9T3V6HWBD",
                    "alias": "github",
                    "enabled": true,
                    "tool_exposure": {
                      "mode": "MCP_TOOL_EXPOSURE_MODE_SELECTED",
                      "tool_ids": [
                        "01JQ0KA2M7VD9E4R6T8Y1U3XSB",
                        "01JQ0KB5P9WF2G7H4J6K8L1NQD"
                      ]
                    }
                  }
                ]
              }'
        - lang: curl
          label: Core - Disable a gateway
          source: |
            curl --request PATCH \
              --url 'https://my.orq.ai/v2/mcp-gateways/01JQ0M8W4T5YB2Q7N1F6K3PZRC' \
              --header "Authorization: Bearer $ORQ_API_KEY" \
              --header 'Content-Type: application/json' \
              --data '{ "status": "MCP_GATEWAY_STATUS_DISABLED" }'
        - lang: python
          label: Python - Narrow the tools a gateway exposes
          source: >
            import os

            from orq_ai_sdk import Orq


            client = Orq(api_key=os.environ["ORQ_API_KEY"])


            # tool_ids come from McpTool.id. A tool renamed upstream gets a new
            id

            # on the next sync, which drops it from this allowlist.

            result = client.mcp_gateways.update(
                id="01JQ0M8W4T5YB2Q7N1F6K3PZRC",
                server_links=[
                    {
                        "mcp_server_id": "01JQ0K5R8N2ZC7X4M9T3V6HWBD",
                        "alias": "github",
                        "enabled": True,
                        "tool_exposure": {
                            "mode": "MCP_TOOL_EXPOSURE_MODE_SELECTED",
                            "tool_ids": [
                                "01JQ0KA2M7VD9E4R6T8Y1U3XSB",
                                "01JQ0KB5P9WF2G7H4J6K8L1NQD",
                            ],
                        },
                    },
                ],
            )


            print(result.mcp_gateway.exposed_tools_count)
        - lang: typescript
          label: Node.js - Narrow the tools a gateway exposes
          source: >
            import { Orq } from '@orq-ai/node';


            const client = new Orq({
              apiKey: process.env.ORQ_API_KEY,
            });


            // toolIds come from McpTool.id. A tool renamed upstream gets a new
            id

            // on the next sync, which drops it from this allowlist.

            const result = await client.mcpGateways.update({
              id: '01JQ0M8W4T5YB2Q7N1F6K3PZRC',
              serverLinks: [
                {
                  mcpServerId: '01JQ0K5R8N2ZC7X4M9T3V6HWBD',
                  alias: 'github',
                  enabled: true,
                  toolExposure: {
                    mode: 'MCP_TOOL_EXPOSURE_MODE_SELECTED',
                    toolIds: [
                      '01JQ0KA2M7VD9E4R6T8Y1U3XSB',
                      '01JQ0KB5P9WF2G7H4J6K8L1NQD',
                    ],
                  },
                },
              ],
            });


            console.log(result.mcpGateway.exposedToolsCount);
components:
  schemas:
    UpdateMcpGatewayRequest:
      required: []
      type: object
      properties:
        key:
          type: string
          description: >-
            Rejected with INVALID_ARGUMENT: the key backs the gateway's public
            MCP URL
             and is immutable after creation. Retained so callers get an error rather
             than a silently ignored field.
        display_name:
          type: string
          description: Human readable name shown in the workspace.
        description:
          type: string
          description: Free-form note about what this gateway is for.
        server_links:
          type: array
          items:
            $ref: '#/components/schemas/McpGatewayServerLink'
          description: >-
            Replaces the current links. An empty array is treated as no change;
            use `clear_server_links` to remove them all.
        tool_naming:
          $ref: '#/components/schemas/McpToolNaming'
          description: How upstream tool names are namespaced before they are exposed.
        status:
          $ref: '#/components/schemas/McpGatewayStatus'
          description: >-
            ACTIVE serves MCP traffic; DISABLED rejects it while keeping the
            configuration.
        mode:
          $ref: '#/components/schemas/McpGatewayMode'
          description: 'Shape of the tool surface presented to MCP clients: CODE or DIRECT.'
        sharing:
          allOf:
            - $ref: '#/components/schemas/Sharing'
          description: >-
            Which projects in the workspace may use this gateway. Defaults to
            every project.
        clear_server_links:
          type: boolean
          description: >-
            Set true to remove every link; cannot be combined with
            `server_links`.
        plugins:
          type: array
          items:
            $ref: '#/components/schemas/McpGatewayPlugin'
          description: Plugins run on every tool call this gateway serves.
    UpdateMcpGatewayResponse:
      type: object
      properties:
        mcp_gateway:
          $ref: '#/components/schemas/McpGateway'
    McpGatewayServerLink:
      required:
        - mcp_server_id
        - alias
        - tool_exposure
      type: object
      properties:
        mcp_server_id:
          type: string
          description: Upstream MCP server this gateway aggregates.
        alias:
          type: string
          description: >-
            Prefix used instead of the server key when namespacing this server's
            tool names. Must be unique within the gateway.
        enabled:
          type: boolean
          description: Whether this link contributes tools to the gateway.
        tool_exposure:
          allOf:
            - $ref: '#/components/schemas/McpToolExposure'
          description: Narrows which of the server's tools this gateway exposes.
    McpToolNaming:
      type: string
      enum:
        - MCP_TOOL_NAMING_UNSPECIFIED
        - MCP_TOOL_NAMING_PREFIX_WITH_SERVER_KEY
        - MCP_TOOL_NAMING_PREFIX_ON_COLLISION
    McpGatewayStatus:
      type: string
      enum:
        - MCP_GATEWAY_STATUS_UNSPECIFIED
        - MCP_GATEWAY_STATUS_ACTIVE
        - MCP_GATEWAY_STATUS_DISABLED
    McpGatewayMode:
      type: string
      enum:
        - MCP_GATEWAY_MODE_UNSPECIFIED
        - MCP_GATEWAY_MODE_CODE
        - MCP_GATEWAY_MODE_DIRECT
    Sharing:
      type: object
      properties:
        all_projects:
          allOf:
            - $ref: '#/components/schemas/SharingAllProjects'
          description: Visible to every project in the workspace.
        selected:
          allOf:
            - $ref: '#/components/schemas/SharingSelectedProjects'
          description: Visible to the listed projects only.
        allow_version_pin:
          type: boolean
          description: |-
            Consuming projects may pin a specific version instead of tracking
             the latest version.
        allow_fork:
          type: boolean
          description: |-
            Projects may duplicate this entity into a detached project-owned
             copy.
        auto_grant_new_projects:
          type: boolean
          description: |-
            New projects created after this sharing config is applied should
             receive access automatically.
      description: |-
        Sharing controls which projects in the workspace may use this entity and
         what they may do with it.
    McpGatewayPlugin:
      type: object
      properties:
        id:
          type: string
          description: Plugin discriminator.
        language:
          type: string
        entities:
          type: array
          items:
            type: string
        on_failure:
          type: string
        threshold:
          type: number
          format: double
        mask:
          type: array
          items:
            type: string
    McpGateway:
      type: object
      properties:
        id:
          type: string
          description: Unique identifier of the MCP gateway.
        key:
          type: string
          description: >-
            Lowercase slug of letters, digits, hyphens and underscores, max 64
            characters, unique per workspace; backs the gateway's public MCP
            URL.
        display_name:
          type: string
          description: Human readable name shown in the workspace.
        description:
          type: string
          description: Free-form note about what this gateway is for.
        server_links:
          type: array
          items:
            $ref: '#/components/schemas/McpGatewayServerLink'
          description: Upstream servers this gateway aggregates.
        tool_naming:
          $ref: '#/components/schemas/McpToolNaming'
          description: How upstream tool names are namespaced before they are exposed.
        status:
          $ref: '#/components/schemas/McpGatewayStatus'
          description: >-
            ACTIVE serves MCP traffic; DISABLED rejects it while keeping the
            configuration.
        public_url:
          type: string
          description: >-
            Endpoint MCP clients connect to; relative when the deployment has no
            public base URL configured.
        created:
          type: string
          description: ISO 8601 timestamp of when the gateway was created.
        updated:
          type: string
          description: ISO 8601 timestamp of the most recent change to the gateway.
        exposed_tools_count:
          type: integer
          description: Number of tools currently exposed across all enabled links.
          format: int32
        mode:
          $ref: '#/components/schemas/McpGatewayMode'
          description: 'Shape of the tool surface presented to MCP clients: CODE or DIRECT.'
        sharing:
          allOf:
            - $ref: '#/components/schemas/Sharing'
          description: Which projects in the workspace may use this gateway.
        plugins:
          type: array
          items:
            $ref: '#/components/schemas/McpGatewayPlugin'
          description: Plugins run on every tool call this gateway serves.
    McpToolExposure:
      required:
        - mode
      type: object
      properties:
        mode:
          $ref: '#/components/schemas/McpToolExposureMode'
          description: 'Selection strategy: ALL, SELECTED or NONE.'
        read_only:
          type: boolean
          description: Keeps only the tools the upstream annotates as read-only.
        tool_ids:
          type: array
          items:
            type: string
          description: >-
            `McpTool.id` values to expose when mode is SELECTED; a tool renamed
            upstream gets a new id on the next sync.
    SharingAllProjects:
      type: object
      properties: {}
    SharingSelectedProjects:
      type: object
      properties:
        project_ids:
          type: array
          items:
            type: string
          description: >-
            Projects allowed to use the entity. An empty list shares it with no
            project.
    McpToolExposureMode:
      type: string
      enum:
        - MCP_TOOL_EXPOSURE_MODE_UNSPECIFIED
        - MCP_TOOL_EXPOSURE_MODE_ALL
        - MCP_TOOL_EXPOSURE_MODE_SELECTED
        - MCP_TOOL_EXPOSURE_MODE_NONE
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.