API documentation
Use MCP to connect an AI client to your Rapid Test account. The web API also provides public health and authorization discovery endpoints.
MCP API
MCP Server Card — public discovery metadata using the requested SEP-1649 draft format. Supports tools; resources and prompts are not available. Discovery does not replace OAuth or MCP initialization.
Endpoint: https://mcp.rapidtest.uz/mcp
OpenAPI transport specification · OAuth resource metadata
- Configure an MCP client with the endpoint above and OAuth authentication.
- Discover the authorization server, use S256 PKCE, and sign in to Rapid Test. The user approves the requested scopes.
- Initialize the MCP connection and call
tools/listfor current tools and input schemas. Usetools/callto execute an authorized operation.
The transport is stateless Streamable HTTP with JSON responses. Send both application/json and text/event-stream in Accept, and the negotiated MCP protocol version after initialization. An MCP SDK handles these details.
Permissions
- banks:read / banks:write
- Read your question banks and answer keys; create, edit and archive banks and questions, and manage temporary previews.
- assets:read / assets:write
- Read and upload question images.
- exams:read / exams:write
- Read quizzes and get their links and QR images; create and edit drafts, publish and close quizzes. Source-bank operations also require banks:read.
- groups:read / groups:write
- Read your groups and members; create or rename groups and assign completed quiz participants.
- groups:notify
- Queue a quiz link for delivery to your group through Telegram. Preview recipients first and obtain user intent to send. Members must start the bot; delivery status is asynchronous.
- results:read
- Read results and statistics for your own quizzes and generate private reports.
Author operations require an active Free/RT2 plan and verified phone. Access remains restricted to the authorized owner and tenant. Read current revisions before editing; reuse an idempotency key only for the same request. Temporary preview links include answers: share them only as intended. Private report downloads require the owner's web session.
Access tokens are valid only for this MCP resource. Never send a Telegram bot token as an API credential. Manage or revoke grants in ChatGPT connections. Existing grants do not gain new scopes automatically.
Web API
Base path: https://rapidtest.uz/api/
OpenAPI public discovery specification
- GET /api/health/live — process liveness.
- GET /api/health/ready — database, storage and attempt service readiness; HTTP 503 when unavailable.
- GET /api/auth/status — Telegram login availability.
- GET /.well-known/oauth-authorization-server — authorization server metadata.
This specification covers public discovery endpoints. The first-party application also uses authenticated session-based endpoints, which are not a general-purpose bearer-token REST API. Use MCP for automated content, group and quiz management. Protected web operations continue to require a valid session and applicable CSRF, ownership and plan checks.