> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getarbol.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an Agent Knowledge MCP session

> Issues a five-minute, read-only Streamable HTTP MCP capability for an active Agent in the verified Organization. Requires agents:read and knowledge:read. Use the returned token as Authorization: Bearer when calling the returned URL from an MCP client. It searches only the Agent's current assigned documents; it cannot access business tools. Treat the token as a secret. Retrying issues another temporary capability; no persistent session is created.



## OpenAPI

````yaml https://api.getarbol.com/openapi.json post /agents/{agentId}/knowledge-sessions
openapi: 3.1.2
info:
  contact:
    email: support@getarbol.com
    name: Arbol
    url: https://docs.getarbol.com
  description: >-
    Build and operate Arbol's organization-scoped conversational platform
    through one provider-neutral REST contract. Resources cover Agents,
    channels, contacts, conversations, Knowledge, connected accounts, analytics,
    and evaluation runs. Every bearer is verified by Auth0, every request is
    bound to exactly one Organization, and every operation enforces all scopes
    listed in its security requirement.
  title: Arbol API
  version: 1.0.0
servers:
  - description: Production
    url: https://api.getarbol.com/v1
security: []
tags:
  - description: >-
      Create and configure conversational Agents. Provider-specific runtime
      details remain private to Arbol.
    name: Agents
  - description: >-
      Define suites, start durable evaluation runs, inspect trials, and compare
      Agent behavior.
    name: Agent evaluations
  - description: >-
      Read organization-scoped operational aggregates without exposing raw
      provider telemetry.
    name: Analytics
  - description: >-
      Attach and manage provider-neutral voice or messaging endpoints owned by
      an Agent.
    name: Channels
  - description: >-
      Authorize and manage reusable organization accounts whose credentials
      remain in Composio.
    name: Connected accounts
  - description: >-
      Manage people, their routable identities, merged activity timeline, and
      durable CSV imports.
    name: Contacts
  - description: >-
      Start outbound calls and inspect tenant-scoped voice, WhatsApp, and web
      conversations.
    name: Conversations
  - description: >-
      Define revisioned structured fields used to capture organization-specific
      Contact and Conversation facts.
    name: Definitions
  - description: >-
      Call a list of phone numbers with one Agent, a few at a time, with
      optional first-message and prompt overrides.
    name: Outbound batches
  - description: >-
      Read and assert typed values against active Definitions with explicit
      evidence and verification state.
    name: Facts
  - description: >-
      Discover live business-tool capabilities available through Arbol's
      Composio boundary.
    name: Integrations
  - description: >-
      Upload, index, search, download, and lifecycle-manage organization
      Knowledge documents.
    name: Knowledge
  - description: Read and update the current Organization's product-level settings.
    name: Organization
  - description: >-
      Discover provider-neutral synthetic voices that can be assigned to voice
      Agents.
    name: Voices
paths:
  /agents/{agentId}/knowledge-sessions:
    post:
      tags:
        - Agents
        - Knowledge
      summary: Create an Agent Knowledge MCP session
      description: >-
        Issues a five-minute, read-only Streamable HTTP MCP capability for an
        active Agent in the verified Organization. Requires agents:read and
        knowledge:read. Use the returned token as Authorization: Bearer when
        calling the returned URL from an MCP client. It searches only the
        Agent's current assigned documents; it cannot access business tools.
        Treat the token as a secret. Retrying issues another temporary
        capability; no persistent session is created.
      operationId: createAgentKnowledgeSession
      parameters:
        - in: path
          required: true
          name: agentId
          schema:
            $ref: '#/components/schemas/ArbolResourceId'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties: {}
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentKnowledgeSession'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '400':
          description: >-
            Inferable validation failure or a non-inferable malformed transport
            request.
          content:
            application/json:
              schema:
                oneOf:
                  - oneOf:
                      - $ref: '#/components/schemas/BadRequest'
                      - $ref: '#/components/schemas/UndefinedError'
                  - $ref: '#/components/schemas/TransportBadRequestError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '401':
          description: Authentication is required.
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Unauthorized'
                  - $ref: '#/components/schemas/UndefinedError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '403':
          description: The caller is not allowed to perform this operation.
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Forbidden'
                  - $ref: '#/components/schemas/UndefinedError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '404':
          description: Active Agent not found
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/NotFound'
                  - $ref: '#/components/schemas/UndefinedError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '413':
          $ref: '#/components/responses/TransportPayloadTooLarge'
        '415':
          $ref: '#/components/responses/TransportUnsupportedMediaType'
        '429':
          description: '429'
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/TooManyRequests'
                  - $ref: '#/components/schemas/UndefinedError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
        '503':
          description: Knowledge sessions are unavailable
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/ServiceUnavailable2'
                  - $ref: '#/components/schemas/UndefinedError'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
      security:
        - userOAuth:
            - org:use
            - agents:read
            - knowledge:read
        - machineOAuth:
            - agents:read
            - knowledge:read
components:
  schemas:
    ArbolResourceId:
      type: string
      maxLength: 64
      pattern: >-
        ^[a-z][a-z0-9]{1,15}_[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
      description: >-
        Opaque Arbol resource identifier; the endpoint and tenant-scoped lookup
        determine its resource type.
      examples:
        - agt_018f47a2-4f4d-7d61-9e2c-1d7b8e9a0c31
      title: Arbol resource ID
    AgentKnowledgeSession:
      type: object
      properties:
        agentId:
          $ref: '#/components/schemas/ArbolResourceId'
        expiresAt:
          $ref: '#/components/schemas/IsoDatetime'
        token:
          type: string
          minLength: 1
          maxLength: 4096
        transport:
          type: string
          const: streamable-http
        url:
          type: string
          maxLength: 2048
          format: uri
      required:
        - agentId
        - expiresAt
        - token
        - transport
        - url
      additionalProperties: false
      description: >-
        Five-minute read-only MCP bearer capability. Send token in the
        Authorization: Bearer header to url. Keep it secret; it grants only this
        active Agent's current document allowlist, never business tools. Mint a
        new session after expiry.
    BadRequest:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: BAD_REQUEST
        status:
          const: 400
        message:
          type: string
        data:
          type: object
          properties:
            issues:
              maxItems: 20
              type: array
              items:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - custom
                      - invalid_format
                      - invalid_type
                      - invalid_value
                      - too_big
                      - too_small
                      - unrecognized_keys
                  message:
                    type: string
                    maxLength: 500
                  path:
                    maxItems: 16
                    type: array
                    items:
                      anyOf:
                        - type: string
                          maxLength: 120
                        - type: integer
                          minimum: 0
                          maximum: 9007199254740991
                required:
                  - code
                  - message
                additionalProperties: false
            truncated:
              type: boolean
          required:
            - issues
            - truncated
          additionalProperties: false
      required:
        - defined
        - inferable
        - code
        - status
        - message
        - data
    UndefinedError:
      type: object
      properties:
        defined:
          const: false
        inferable:
          type: boolean
        code:
          type: string
        status:
          type: number
        message:
          type: string
        data: {}
      required:
        - defined
        - inferable
        - code
        - status
        - message
    TransportBadRequestError:
      additionalProperties: false
      properties:
        code:
          const: BAD_REQUEST
        data: {}
        defined:
          const: false
        inferable:
          const: false
        message:
          type: string
      required:
        - defined
        - inferable
        - code
        - message
      type: object
    Unauthorized:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: UNAUTHORIZED
        status:
          const: 401
        message:
          type: string
        data: {}
      required:
        - defined
        - inferable
        - code
        - status
        - message
    Forbidden:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: FORBIDDEN
        status:
          const: 403
        message:
          type: string
        data:
          type: object
          properties:
            missingPermissions:
              maxItems: 10
              type: array
              items:
                $ref: '#/components/schemas/AuthPermission'
          required:
            - missingPermissions
          additionalProperties: false
      required:
        - defined
        - inferable
        - code
        - status
        - message
    NotFound:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: NOT_FOUND
        status:
          const: 404
        message:
          type: string
        data: {}
      required:
        - defined
        - inferable
        - code
        - status
        - message
    TooManyRequests:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: TOO_MANY_REQUESTS
        status:
          const: 429
        message:
          type: string
        data:
          type: object
          properties:
            retryAfterSeconds:
              type: integer
              exclusiveMinimum: 0
              maximum: 3600
          required:
            - retryAfterSeconds
          additionalProperties: false
      required:
        - defined
        - inferable
        - code
        - status
        - message
        - data
    ServiceUnavailable2:
      type: object
      properties:
        defined:
          const: true
        inferable:
          type: boolean
        code:
          const: SERVICE_UNAVAILABLE
        status:
          const: 503
        message:
          type: string
        data: {}
      required:
        - defined
        - inferable
        - code
        - status
        - message
    IsoDatetime:
      type: string
      format: date-time
      pattern: >-
        ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
      description: ISO 8601 timestamp with an explicit UTC offset.
      examples:
        - '2026-08-29T14:30:00Z'
      title: ISO timestamp
    AuthPermission:
      type: string
      enum:
        - agent-evaluations:read
        - agent-evaluations:run
        - agent-evaluations:write
        - agents:read
        - agents:write
        - analytics:read
        - arbi:use
        - channels:read
        - channels:write
        - contacts:read
        - contacts:write
        - conversations:read
        - conversations:transcript
        - conversations:write
        - definitions:read
        - definitions:write
        - facts:read
        - facts:write
        - integrations:read
        - integrations:write
        - knowledge:read
        - knowledge:write
        - org:manage
        - org:use
      description: >-
        One permission from the closed Arbol API vocabulary accepted from a
        verified Auth0 token.
      examples:
        - agents:read
      title: API permission
    TransportPayloadTooLargeError:
      additionalProperties: false
      properties:
        code:
          const: PAYLOAD_TOO_LARGE
        data: {}
        defined:
          const: false
        inferable:
          const: false
        message:
          type: string
      required:
        - defined
        - inferable
        - code
        - message
      type: object
    TransportUnsupportedMediaTypeError:
      additionalProperties: false
      properties:
        code:
          const: UNSUPPORTED_MEDIA_TYPE
        data: {}
        defined:
          const: false
        inferable:
          const: false
        message:
          type: string
      required:
        - defined
        - inferable
        - code
        - message
      type: object
  headers:
    RequestId:
      description: >-
        Opaque request correlation identifier. Include it when contacting Arbol
        support.
      schema:
        type: string
        maxLength: 128
  responses:
    TransportPayloadTooLarge:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/TransportPayloadTooLargeError'
      description: The request body exceeds the API transport limit.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
    TransportUnsupportedMediaType:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/TransportUnsupportedMediaTypeError'
      description: The request media type is not supported.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
  securitySchemes:
    userOAuth:
      description: >-
        Organization-scoped Auth0 user access token issued to an approved
        first-party client or exchanged by a trusted OBO resource server.
      flows:
        authorizationCode:
          authorizationUrl: https://auth.getarbol.com/authorize
          scopes:
            agent-evaluations:read: Read Agent evaluation suites, runs, and results.
            agent-evaluations:run: Execute and cancel Agent evaluation runs.
            agent-evaluations:write: Create and update Agent evaluation suites.
            agents:read: Read Agents and their explicitly requested expansions.
            agents:write: Create, update, and delete Agents.
            analytics:read: Read organization analytics.
            arbi:use: Use the personal Arbi workspace.
            channels:read: Read Agent channels.
            channels:write: Create, update, authorize, and delete Agent channels.
            contacts:read: Read Contacts and their explicitly requested expansions.
            contacts:write: Create, update, merge, import, and delete Contacts.
            conversations:read: Read Conversation metadata.
            conversations:transcript: Read Conversation messages and media evidence.
            conversations:write: Create and process Conversations.
            definitions:read: Read Definitions and Definition usage.
            definitions:write: Create, update, and retire Definitions.
            facts:read: Read current and historical Facts.
            facts:write: Assert typed Facts.
            integrations:read: Discover integrations, tools, accounts, and tool-bearing evidence.
            integrations:write: Authorize accounts and assign exact tool access.
            knowledge:read: Read Knowledge documents and search indexed content.
            knowledge:write: Create, index, update, and delete Knowledge documents.
            org:manage: Update the Organization and administer its members.
            org:use: Use Arbol as a member of the selected Auth0 Organization.
          tokenUrl: https://auth.getarbol.com/oauth/token
      type: oauth2
    machineOAuth:
      description: >-
        Organization-bound Auth0 client-credentials token. The client grant must
        contain every operation scope.
      flows:
        clientCredentials:
          scopes:
            agent-evaluations:read: Read Agent evaluation suites, runs, and results.
            agent-evaluations:run: Execute and cancel Agent evaluation runs.
            agent-evaluations:write: Create and update Agent evaluation suites.
            agents:read: Read Agents and their explicitly requested expansions.
            agents:write: Create, update, and delete Agents.
            analytics:read: Read organization analytics.
            channels:read: Read Agent channels.
            channels:write: Create, update, authorize, and delete Agent channels.
            contacts:read: Read Contacts and their explicitly requested expansions.
            contacts:write: Create, update, merge, import, and delete Contacts.
            conversations:read: Read Conversation metadata.
            conversations:transcript: Read Conversation messages and media evidence.
            conversations:write: Create and process Conversations.
            definitions:read: Read Definitions and Definition usage.
            definitions:write: Create, update, and retire Definitions.
            facts:read: Read current and historical Facts.
            facts:write: Assert typed Facts.
            integrations:read: Discover integrations, tools, accounts, and tool-bearing evidence.
            integrations:write: Authorize accounts and assign exact tool access.
            knowledge:read: Read Knowledge documents and search indexed content.
            knowledge:write: Create, index, update, and delete Knowledge documents.
            org:manage: Update the Organization and administer its members.
          tokenUrl: https://auth.getarbol.com/oauth/token
      type: oauth2

````