Import one
In Browse apps, choose Import from OpenAPI (it is also offered inside Add custom), then either:- By address — paste the spec URL. Passport reads it and can re-read it later.
- Paste the spec — paste the document itself.
How tools are derived
- Name — the operation’s
operationId, lowercased and reduced toa-z 0-9 _ -; otherwise<method>_<path>. Duplicates get a numeric suffix. - Description —
summarythendescription, trimmed to 2,000 characters. - Arguments — one JSON Schema object per tool. Path, query, and non-credential header parameters become top-level properties; a JSON request body is nested under
body(orrequestBodyif a parameter already uses that name). Required parameters and a required body are marked required. - Action class — from the HTTP method:
GET/HEADare read,POST/PUT/PATCHare write,DELETEis destructive. An operation may carryx-passport-riskofwriteordestructiveto raise its class; a spec can never lower one, so labelling aDELETEas read has no effect. - Address —
servers[0]. Every imported tool is pinned to that origin; a tool argument cannot move a call to another host or path.
example, examples, vendor x- extensions, and the regular-expression keywords (pattern, patternProperties)
are removed from imported schemas. Passport compiles reviewed schemas to validate arguments, and it will not compile a
regular expression that arrived in a document.Bounds
An import fails with a clear message rather than partially succeeding:
An operation Passport cannot import — a remote
$ref, a recursive schema, no application/json body, a path placeholder with no declared parameter — is skipped and listed in the warnings. If nothing is left, the import fails.
Imported definitions pass the same bounded admission and definition-security scan as every other tool catalog, so a spec carrying an injected tool description is refused before the app exists.
Sign-in
The spec’s security schemes decide the choices, and the choice decides the app’s sign-in mode:- No sign-in — nothing is attached. Passes, guardrails, and the audit trail still apply.
- Company credential — one workspace credential, stored encrypted, attached on every call as
Authorization: Bearer …, as a named API-key header, or as an API-key query parameter, exactly as the scheme declares. Query-parameter keys are attached at call time and never logged. - Per person — for an
oauth2scheme with anauthorizationCodeflow. Passport uses its standard OAuth broker; an admin supplies the provider’s client ID and secret, and each person then connects their own account.
Private networks and SSRF
Reading a spec address and calling an imported API both go through Passport’s single outbound choke point:- Passport Cloud (
passportmcp.com) reaches public HTTPS addresses only. Private, loopback, link-local, and cloud-metadata addresses are refused, and every redirect hop is re-checked. - A self-hosted Passport may reach its own private network, which is what makes internal services importable. Cloud-metadata addresses stay refused in every environment.
Refresh
An app imported by address can be re-read from Refresh tools on the app. Passport fetches the spec again, re-derives the inventory under the same checks, keeps the reviewed sign-in, and reports what was added, removed, and changed — the same drift record and alerts as an MCP refresh, sonewToolsDefault: off still holds new tools and changes that aren’t low risk until you approve them. An app imported from a pasted spec has no address to re-read; import it again to update it.