From 05fac10a758c41c321a1904430b6b3d79ecc4d7e Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Tue, 15 Sep 2026 11:50:49 -0700 Subject: [PATCH] docs(api-server): MCP trust-gate consent surfaces as approval.request on /v1/runs Document that an untrusted-server write-capable MCP tool now parks a run in waiting_for_approval and is resolved through POST /v1/runs/{id}/approval, the same bridge dangerous-command approvals already use. Part of #111526 --- website/docs/user-guide/features/api-server.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/website/docs/user-guide/features/api-server.md b/website/docs/user-guide/features/api-server.md index 4013dc6356..f46c01ad19 100644 --- a/website/docs/user-guide/features/api-server.md +++ b/website/docs/user-guide/features/api-server.md @@ -538,6 +538,8 @@ running. Resolve a pending approval for a run that is waiting on a human decision (for example, a tool call gated behind an approval policy). The body carries the approval decision; the run resumes once the decision is recorded. This endpoint is advertised in `/v1/capabilities` as the `run_approval` feature so external UIs can detect support before surfacing an approval prompt. +MCP trust-gate consent — a write-capable tool on a server configured `trust: untrusted` — surfaces the same way: the run emits an `approval.request` event and parks in `waiting_for_approval` until this endpoint resolves it (`once` runs the tool, `deny` blocks it). + ## Jobs API (background scheduled work) The server exposes a lightweight jobs CRUD surface for managing scheduled / background agent runs from a remote client. All endpoints are gated behind the same bearer auth.