RouterMCP
API Reference

MCP Skills

Import and expose reviewed skills from compatible upstream MCP servers.

MCP Skills

RouterMCP can expose skills from a project's configured MCP servers through the MCP Skills extension. Project managers choose which upstream skills the project exposes. Imported skills remain disabled until a manager enables them.

Compatibility and setup

The gateway implements the stateless MCP protocol version 2026-07-28 and advertises the io.modelcontextprotocol/skills extension when Skills policy storage is available. The upstream server must declare both a resources capability and the Skills extension in server/discover. RouterMCP checks that declaration before sending skills/list, skills/get, or resources/read to an upstream.

Skills use the same authenticated project endpoint as other MCP requests: POST /v1/mcp/:projectId/request, where projectId is the project UUID. See MCP Protocol for endpoint authentication and request headers.

Apply database migration 0031_mcp_skills to the database used by the dashboard and gateway. It creates the project skill-policy storage and the version snapshot column. If policy storage is unavailable, the dashboard reports that the migration is pending and the gateway does not advertise Skills.

Manage project skills

Open a project and choose Skills. Select a configured source server and choose Refresh skills to explicitly fetch its catalog. Discovery uses the current viewer's access to that source. The dashboard does not fetch upstream catalogs just by opening the project server list.

Project managers can import a listed skill or validate a known skill URI directly. Importing creates a project policy with exposure disabled. A manager can then preview the instructions and manifest files, and enable the policy when the project should expose it. Disabling a policy removes the skill from the project's MCP catalog and remains available while the source server is disconnected. Members without management access can inspect skills available through their current source connection, but cannot import or change project policies.

Previewing reads the requested instruction or manifest file. It does not activate the skill in an AI client. The AI client decides whether to use an exposed skill.

Source credentials

Skills do not have separate credentials. Dashboard discovery and preview use the selected project's existing server configuration and credential resolver. Gateway requests use the credentials available for the caller's project principal. Missing, stale, or revoked source credentials prevent the upstream request; connect or repair that source server using its normal authentication flow.

Upstream resources/read responses are limited to 36 MiB before JSON parsing, including JSON and Base64 overhead. Each decoded content item is limited to 16 MiB. Text with extensive JSON escaping can reach the response limit before the decoded-content limit. With a legacy direct per-user OAuth connection, a normal token refresh requires the user to approve Chat skills again. Connected-account credentials retain their approval across normal token refreshes.

The gateway caps each skills/list page and skills/get response at 8 MiB including its JSON-RPC envelope. The enabled catalog has a 16 MiB aggregate metadata limit; a catalog beyond that limit returns a safe 413 error.

Servers configured for session_login are not supported as Skills sources. Use a source server with a supported configured credential mode.

MCP methods and mapped URIs

The gateway returns only enabled project policies from skills/list. It discovers the current upstream catalog and matches entries to those policies. skills/get fetches an enabled skill from its source. resources/read rechecks the current source and policy before reading a skill resource. Static manifest resources are checked against their declared digest and size.

RouterMCP wraps skill and manifest resource URIs in a server-scoped URI such as:

routermcp-skill://<server-id>/<opaque-origin>/<skill-name>/<resource-path>

Use the complete URIs returned by skills/list and skills/get; do not construct or edit them. The wrapper lets RouterMCP route a read to the correct source server and verify that the policy is still enabled. The upstream URI and server origin stay scoped to that source.

RouterMCP does not rewrite absolute links embedded in skill instructions. For gateway clients, only URIs returned in a skill's manifest are wrapped for reads. A URI with another scheme or a network-path reference (//host/path) cannot be treated as a relative resource in the current skill directory. Resolve supported relative references against the source SKILL.md and use a resource URI from the returned manifest.

RouterMCP Chat has a separate activation boundary: it requires explicit approval for the current session and holds the verified skill entry and source context. Chat may resolve an absolute file reference only when that file belongs to the same held source manifest. References to another source or external host are not available through that activation. External MCP clients control their own activation and reference handling; RouterMCP's Chat behavior does not apply to them.

An upstream may return a dynamic manifest instead of a static file list. RouterMCP can relay that declaration, but dynamic resources have no static digest manifest and are marked unverified when read. Reads remain scoped to the source skill directory.

Unsupported behavior

  • RouterMCP does not advertise directoryRead and does not provide arbitrary directory reads.
  • Dynamic skill activation is not implemented. Exposing a policy makes the skill available to an MCP client. RouterMCP Chat separately requires explicit user approval to activate a static skill for a session.
  • RouterMCP returns skill instructions and files but does not execute scripts or run code from a skill.
  • session_login source servers cannot be used for Skills discovery or reads.

Availability and verification

This page describes the implementation in source. Local tests cover protocol handling, policy enforcement, credential checks, URI mapping, and dashboard workflows. They do not prove that migration 0031_mcp_skills is applied to a production database, that a production gateway deployment contains the implementation, or that a particular upstream accepts Skills requests. Verify those conditions in the target environment before relying on production availability.

On this page