For AI agents: the complete documentation index is available at /llms.txt, the full documentation bundle is available at /llms-full.txt, and this page is available as Markdown at /automcp/v1/applications.md.

Applications, specifications, and publishing

Availability: The AutoMCP production service is not yet deployed. This page and its examples describe the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.

Register an application, create a draft version, inspect diagnostics and converted tools, configure the prompt and tool permissions, then explicitly publish the reviewed version. Published content is immutable; stopping an app or version blocks new execution, while existing sessions remain pinned to their resolved version.

Supported inputs are OpenAPI 3.0/3.1 JSON or YAML and proto3 source bundles or descriptor sets. JSON request/response and Connect/gRPC unary operations are supported. References and imports must resolve inside the submitted bundle or supported standard types. Swagger 2, customer streaming RPCs, multipart/binary payloads, reflection, arbitrary remote references, private-network targets, and tunnels are unsupported.

Diagnostics identify unsupported operations; unsupported tools must be explicitly excluded or fixed before publishing. AutoMCP never silently drops an operation or changes its meaning. Registered HTTPS destinations are resolved and checked on every connection; redirects, DNS rebinding, loopback, link-local, multicast, metadata, non-HTTPS, and private addresses are rejected.

Tool allowlisting is separate from object/user authorization. User-data tools must bind a customer-user Secret or inject a customer-verified user value into a registered header or argument. Models and browsers cannot overwrite trusted bindings. Only explicitly published read-only tools run automatically; other customer API calls require hosted approval.

Use the AutoMCP section of the shared console to upload OpenAPI JSON/YAML, enter a public HTTPS specification URL, or submit proto3 files/a descriptor. Review every selected tool's target, input/output schemas, safety classification, and data-access classification. Tool names must be unique; automcp_get_run and automcp_cancel_run are reserved. YAML aliases, recursive schemas, and structured URL-parameter serialization are rejected with diagnostics.

Credentials have an explicit safe header and API-key or Bearer scheme. Shared app Secrets and server-injected trusted user values can be configured together. User-owned credentials are written through CustomerSecretService with secrets:write; metadata reads use secrets:read. Values are never returned. Configure an upstream idempotency header only when the upstream actually honors that key. This permits bounded retries without creating another intended action.

The published prompt, tools and model selection remain fixed. Voice requires the published voice model to match the configured price table; a changed model requires a reviewed version and an explicitly configured price table.