Header Policies — MCP Tools
Header policies on org, project and spec level. This page documents the Header Policies group of the Routebase MCP server, with the scope and the parameters of each tool.
A session that stages its tools advertises this group once the agent calls enable_toolset with the slug header-policies. Full-access keys, scoped keys and OAuth sessions see every tool they are allowed to call without that step.
delete_header_policy
Delete a header policy at spec or project level. Check get_header_policy with includeImpact first to see what stops receiving the headers. Requires project context.
Required scope: specs:delete
| Parameter | Type | Required | Description |
|---|---|---|---|
policyId |
string | Yes | Public ID (GUID) of the header policy |
level |
string | Yes | Which level the policy lives at: 'spec' or 'project' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'spec' |
get_header_policy
Get one header policy with its scopes, assigned header components and rowVersion. Level 'spec' (needs specId) or 'project'. Set includeImpact to also see which endpoints and responses it touches and which policies conflict with it — spec level only. Requires project context. Use this for spec or project level; for the organization level use get_org_header_policy.
Required scope: specs:read
| Parameter | Type | Required | Description |
|---|---|---|---|
policyId |
string | Yes | Public ID (GUID) of the header policy |
level |
string | Yes | Which level to read: 'spec' or 'project' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'spec' |
includeImpact |
boolean | No (default false) |
Also report affected endpoints and conflicting policies — spec level only (default false) |
get_org_header_policy
Get one organization-wide header policy with its scopes, header components and rowVersion. Use this for the organization level; for spec or project level use get_header_policy. Requires organization context.
Required scope: org:manage-governance
| Parameter | Type | Required | Description |
|---|---|---|---|
policyId |
string | Yes | Public ID (GUID) of the header policy |
get_resolved_headers
Get the headers that actually apply to one endpoint response after the full cascade — organization, project and spec policies, local overrides and exclusions — each with where it came from. get_header_policies does the same for a whole endpoint, grouped by status code. Requires project context.
Required scope: specs:read
| Parameter | Type | Required | Description |
|---|---|---|---|
specId |
string | Yes | Public ID (GUID) of the API specification |
responseId |
string | Yes | Public ID (GUID) of the endpoint response |
list_header_exclusions
List the headers excluded from the policy cascade. Level 'response' (needs specId and responseId) covers one endpoint response, 'project' the whole project. Requires project context. Use this to see what is excluded from the cascade; to add or drop an exclusion use manage_header_exclusion.
Required scope: specs:read
| Parameter | Type | Required | Description |
|---|---|---|---|
level |
string | Yes | Which level to read: 'response' or 'project' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'response' |
responseId |
string | No | Public ID (GUID) of the endpoint response — required for level 'response' |
list_header_policies
List the header policies defined at one level: 'spec' (needs specId) or 'project'. Returns the ids, priorities and rowVersions needed to change them. This lists the policy objects — for the resolved header cascade on an endpoint use get_header_policies, for one response get_resolved_headers. Requires project context.
Required scope: specs:read
| Parameter | Type | Required | Description |
|---|---|---|---|
level |
string | Yes | Which level to read: 'spec' or 'project' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'spec' |
list_org_header_policies
List the organization-wide header policies — the ones every project and spec inherits. Use this for the organization level; for spec or project level use list_header_policies. Requires organization context.
Required scope: org:manage-governance
No parameters.
manage_header_exclusion
Exclude a policy header from one endpoint response ('response', needs specId and responseId) or from a whole project ('project'), or remove such an exclusion again. 'exclude' needs headerComponentId, 'remove' needs exclusionId from list_header_exclusions. Requires project context.
Required scope: specs:write
| Parameter | Type | Required | Description |
|---|---|---|---|
level |
string | Yes | Which level to write: 'response' or 'project' |
action |
string | Yes | What to do: 'exclude' or 'remove' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'response' |
responseId |
string | No | Public ID (GUID) of the endpoint response — required for level 'response' |
headerComponentId |
string | No | Public ID (GUID) of the header component to exclude — required for 'exclude' |
reason |
string | No | Optional note why the header is excluded |
exclusionId |
string | No | Public ID (GUID) of the exclusion — required for 'remove' |
manage_header_policy
Create, update, enable/disable or reorder header policies at spec or project level. 'create' needs name and scopes; 'update' needs policyId and rowVersion and REPLACES the policy — omitted fields, including scopes and headerComponentIds, are carried over from the current state; 'toggle' needs policyId and isEnabled; 'reorder' needs policyIds, every policy of that level in the wanted order (lower position wins on conflicts). Deleting is delete_header_policy. Requires project context.
Required scope: specs:write
| Parameter | Type | Required | Description |
|---|---|---|---|
level |
string | Yes | Which level to write: 'spec' or 'project' |
action |
string | Yes | What to do: 'create', 'update', 'toggle' or 'reorder' |
specId |
string | No | Public ID (GUID) of the API specification — required for level 'spec' |
policyId |
string | No | Public ID (GUID) of the policy — required for 'update' and 'toggle' |
rowVersion |
string | No | Base64-encoded row version from list_header_policies — required for 'update' |
name |
string | No | Policy name — required for 'create' |
description |
string | No | Optional description |
scopes |
string | No | Which responses the policy applies to, comma-separated: 'all', a range ('2xx', '4xx', '5xx') or an exact status code (e.g. '404') — required for 'create', e.g. '2xx,404' |
headerComponentIds |
string | No | Header component IDs (GUIDs) the policy applies, comma-separated and in the wanted order. They must live at the same level as the policy. |
isEnabled |
boolean | No | Whether the policy is active — required for 'toggle' |
policyIds |
string | No | Policy IDs (GUIDs) in the wanted order — required for 'reorder' |
manage_org_header_policy
Create, update, delete, enable/disable or reorder organization-wide header policies. 'create' needs name and scopes; 'update' needs policyId and rowVersion and REPLACES the policy, omitted fields are carried over; 'delete' and 'toggle' need policyId ('toggle' also isEnabled); 'reorder' needs policyIds. These apply to every project in the organization. Use this for the organization level; for spec or project level use manage_header_policy. Requires organization context.
Required scope: org:manage-governance
| Parameter | Type | Required | Description |
|---|---|---|---|
action |
string | Yes | What to do: 'create', 'update', 'delete', 'toggle' or 'reorder' |
policyId |
string | No | Public ID (GUID) of the policy — required for 'update', 'delete' and 'toggle' |
rowVersion |
string | No | Base64-encoded row version from list_org_header_policies — required for 'update' |
name |
string | No | Policy name — required for 'create' |
description |
string | No | Optional description |
scopes |
string | No | Which responses the policy applies to, comma-separated: 'all', a range ('2xx', '4xx', '5xx') or an exact status code — required for 'create' |
headerComponentIds |
string | No | Header component IDs (GUIDs) the policy applies, comma-separated and in the wanted order. They must be organization-level components. |
isEnabled |
boolean | No | Whether the policy is active — required for 'toggle' |
policyIds |
string | No | Policy IDs (GUIDs) in the wanted order — required for 'reorder' |