nv_sess_… token) that expires and can be revoked at any time. The session’s tool list is
the fused native + third-party toolset, filtered by that user’s
Account Kit. See
Architecture → Sessions.
Tools
Creating a Session
The token travels in theAuthorization header — never in the URL. The returned
mcp.url + mcp.headers are everything an MCP client needs to connect.
Parameters
The MCP connection is bound to the session’s tenant user: multi-tenant tools
(connections, vault, logs) default to that user, and execution stays gated by the user’s
Account Kit. Revoke a session and the connection is rejected immediately.
Listing & Revoking
active, expired (past its TTL), or revoked.