curl --request POST \
--url https://mcp.echozero.app/mcp \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-03-26",
"capabilities": {},
"clientInfo": {
"name": "swagger",
"version": "1.0.0"
}
}
}
'MCP JSON-RPC over Streamable HTTP
Requires Authorize (x-api-key) and a JSON-RPC body. Use Accept: application/json, text/event-stream and Content-Type: application/json. First call is usually initialize; response includes mcp-session-id — send it on later requests as header mcp-session-id.
curl --request POST \
--url https://mcp.echozero.app/mcp \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-03-26",
"capabilities": {},
"clientInfo": {
"name": "swagger",
"version": "1.0.0"
}
}
}
'Authorizations
User JWT access token issued by POST /api/auth/verify or POST /api/auth/social/verify. Routes that accept both auth modes declare api-key and bearer-jwt security schemes.
Headers
Must list both application/json and text/event-stream (MCP Streamable HTTP).
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
Single JSON-RPC request or batch array.
- object
- object[]
The body is of type object.
Response
JSON or SSE per MCP transport. Response headers may include mcp-session-id (after initialize) and X-Mcp-Instance-Id (which replica served the request; use with load balancer sticky sessions). See MCP_DEPLOYMENT_SCALING.md.