# REST API & MCP tools

**Category:** [Session Replay](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/session-replay)
**Updated:** 2026-10-04

## REST API

All endpoints use Bearer-token auth and are documented in the OpenAPI spec (`/api/v1/openapi.json`). Highlights:

- `GET /api/v1/session-replay/sessions` — list sessions.
- `GET /api/v1/session-replay/search?q=...` — semantic search.
- `GET /api/v1/session-replay/investigations` — list AI investigations.
- `POST /api/v1/session-replay/investigations` — start an investigation (returns `running`; poll until `complete`).
- `GET /api/v1/session-replay/investigations/{uid}` — fetch a finding.

## MCP tools

For AI assistants, the MCP server exposes `session_replay_list_sessions`, `session_replay_search_sessions`, `session_replay_investigate`, `session_replay_list_investigations`, and `session_replay_get_investigation` — all tenant-scoped. Running an investigation from the API or MCP consumes AI Units just like the in-app button.

---

## Related Articles

- [Getting started: install the recorder](https://help.totalctrl.app/en-US/articles/session-replay-getting-started)
- [Install the recording SDK](https://help.totalctrl.app/en-US/articles/install-the-sdk)
- [Restrict recording to your sites with Allowed origins](https://help.totalctrl.app/en-US/articles/session-replay-allowed-origins)
- [Find and replay a session](https://help.totalctrl.app/en-US/articles/replay-a-session)
- [Frustration signals: rage clicks, dead clicks, errors & struggle score](https://help.totalctrl.app/en-US/articles/session-replay-signals)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)