Metadata discovery

Review the metadata endpoints and response formats that API consumers and MCP Clients use to discover MCP-enabled endpoints.

Discovering MCP-enabled endpoints

API consumers and MCP Clients can discover available MCP servers through the metadata API.

Use this request to list MCP-enabled operations:

GET /ionapi/metadata/v1/{tenant}/operations?includemcp=true

Response format

Each MCP endpoint in the operations response includes:

{
        "swaggerOperationId": "{proxyEndpointName}",
        "infoTitle": "{suiteContext}-{proxyEndpointName}",
        "logicalIdPrefix": "non-infor.{lid}",
        "method": "OPTIONS",
        "infoDescription": "{targetEndpointDescription}",
        "suiteContext": "{suiteContext}",
        "operationSummary": "{targetEndpointDescription}",
        "proxyPath": "{tenant}/{suiteContext}/{proxyContext}",
        "productName": "{productName}"
        }

The operationSummary field contains the Target Endpoint Description. Infor GenAI displays this value as the tool name during agent creation and tool association.

Protected resource metadata

Each MCP endpoint exposes a .well-known/oauth-protected-resource document that MCP Clients use for OAuth discovery, as defined in RFC 9728.

GET /.well-known/oauth-protected-resource/{mcp-endpoint-path}

The request returns:

{
        "resource": "https://{gateway-host}/ionapi/{tenant}/{suiteContext}/{proxyContext}",
        "authorization_servers": ["https://sts.infor.com"],
        "scopes_supported": ["mcp:tools", "mcp:resources"],
        "bearer_methods_supported": ["header"]
        }

This endpoint is publicly accessible and does not require authentication. It enables MCP Clients to complete the OAuth 2.1 discovery handshake automatically.