API reference
Tools
Tools endpoints.
| Method | Path | Summary |
|---|---|---|
GET | /v1/account/tool-catalog | Tool servers the platform offers this account, with their approved tools |
POST | /v1/account/tool-catalog/{serverId}/connect | Turn on a managed server, or connect this account to a catalog server: with no sign-in, an API key, or an OAuth sign-in URL |
GET | /v1/account/tool-servers | The account's MCP tool servers, with how many tools wait for review |
POST | /v1/account/tool-servers | Add a tool server. No sign-in: saved and discovered. API key: saved once the key works. OAuth: saved as pending, with a sign-in URL |
POST | /v1/account/tool-servers/probe | Find out whether a server needs no sign-in, an API key, or OAuth |
PATCH | /v1/account/tool-servers/{serverId} | Rename a tool server |
DELETE | /v1/account/tool-servers/{serverId} | Remove a tool server, its tools and its credential |
POST | /v1/account/tool-servers/{serverId}/discover | List the tools on the server now: new ones wait for review, changed ones stop until reviewed |
POST | /v1/account/tool-servers/{serverId}/reconnect | Sign in to a server again: a new API key, or a new OAuth sign-in. Probes first, so a server that changed how it signs in is handled |
GET | /v1/account/tools | The tools the account's servers offer, and where each one stands |
GET | /v1/account/tools/usage | Calls per tool, error rate, p95 latency, last use, and the playbooks that bind it. Visibility, not billing: tool calls are included |
GET | /v1/account/tools/{toolId} | One tool: its definition, any waiting change, and what the review should look at |
POST | /v1/account/tools/{toolId}/approve | Approve the definition you reviewed, with the description our model will read and what the tool does |
POST | /v1/account/tools/{toolId}/reject | Decide a tool is not to be used |
POST | /v1/account/tools/{toolId}/try | Run an approved tool with sample arguments. A tool that changes something needs confirm: true, because it acts on the real system |
Tool servers the platform offers this account, with their approved tools#
GET /v1/account/tool-catalog
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
servers | array<CatalogServer> | Yes | — |
servers[].auth | enum | Yes | One of: "none", "api_key", "oauth". |
servers[].connectionId | string (tcn_… ID) | null | Yes | — |
servers[].connectorTemplate | map | null | Yes | — |
servers[].connectorTemplate.{key} | any | No | Any key. |
servers[].id | string (pts_… ID) | Yes | ID (pts_…) |
servers[].name | string | Yes | — |
servers[].summary | string | null | Yes | — |
servers[].tier | enum | Yes | One of: "managed", "catalog". |
servers[].tools | array<object> | Yes | — |
servers[].tools[].description | string | Yes | — |
servers[].tools[].effect | enum | Yes | One of: "read", "write". |
servers[].tools[].name | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X GET "$ANSWERSTACK_API_URL/v1/account/tool-catalog" \
-H "Authorization: Bearer $ACCESS_TOKEN"Turn on a managed server, or connect this account to a catalog server: with no sign-in, an API key, or an OAuth sign-in URL#
POST /v1/account/tool-catalog/{serverId}/connect
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (pts_… ID) | Yes | ID (pts_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
apiKey | object | No | — |
apiKey.header | string | Yes | Pattern: ^[A-Za-z0-9-]\{1,64\}$. |
apiKey.key | string | Yes | 1–4000 characters. |
Response 201
| Field | Type | Required | Description |
|---|---|---|---|
authorizationUrl | string | null | Yes | — |
server | ToolServer | Yes | — |
server.apiKeyHeader | string | null | Yes | — |
server.auth | enum | Yes | One of: "none", "api_key", "oauth". |
server.authenticatedAt | string (date-time) | null | Yes | — |
server.authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
server.circuitOpenedAt | string (date-time) | null | Yes | — |
server.createdAt | string (date-time) | Yes | — |
server.hasCredential | boolean | Yes | — |
server.id | string (tcn_… ID) | Yes | ID (tcn_…) |
server.lastCheckedAt | string (date-time) | null | Yes | — |
server.lastError | string | null | Yes | — |
server.name | string | Yes | — |
server.platformServerId | string (pts_… ID) | null | Yes | — |
server.status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
server.tools | object | Yes | — |
server.tools.approved | integer | Yes | — |
server.tools.changed | integer | Yes | — |
server.tools.pending | integer | Yes | — |
server.tools.rejected | integer | Yes | — |
server.tools.withdrawn | integer | Yes | — |
server.url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tool-catalog/{serverId}/connect" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'The account's MCP tool servers, with how many tools wait for review#
GET /v1/account/tool-servers
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
servers | array<ToolServer> | Yes | — |
servers[].apiKeyHeader | string | null | Yes | — |
servers[].auth | enum | Yes | One of: "none", "api_key", "oauth". |
servers[].authenticatedAt | string (date-time) | null | Yes | — |
servers[].authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
servers[].circuitOpenedAt | string (date-time) | null | Yes | — |
servers[].createdAt | string (date-time) | Yes | — |
servers[].hasCredential | boolean | Yes | — |
servers[].id | string (tcn_… ID) | Yes | ID (tcn_…) |
servers[].lastCheckedAt | string (date-time) | null | Yes | — |
servers[].lastError | string | null | Yes | — |
servers[].name | string | Yes | — |
servers[].platformServerId | string (pts_… ID) | null | Yes | — |
servers[].status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
servers[].tools | object | Yes | — |
servers[].tools.approved | integer | Yes | — |
servers[].tools.changed | integer | Yes | — |
servers[].tools.pending | integer | Yes | — |
servers[].tools.rejected | integer | Yes | — |
servers[].tools.withdrawn | integer | Yes | — |
servers[].url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X GET "$ANSWERSTACK_API_URL/v1/account/tool-servers" \
-H "Authorization: Bearer $ACCESS_TOKEN"Add a tool server. No sign-in: saved and discovered. API key: saved once the key works. OAuth: saved as pending, with a sign-in URL#
POST /v1/account/tool-servers
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
apiKey | object | No | — |
apiKey.header | string | Yes | Pattern: ^[A-Za-z0-9-]\{1,64\}$. |
apiKey.key | string | Yes | 1–4000 characters. |
name | string | Yes | 1–80 characters. |
url | string | Yes | Up to 2048 characters. |
Response 201
| Field | Type | Required | Description |
|---|---|---|---|
authorizationUrl | string | null | Yes | — |
server | ToolServer | Yes | — |
server.apiKeyHeader | string | null | Yes | — |
server.auth | enum | Yes | One of: "none", "api_key", "oauth". |
server.authenticatedAt | string (date-time) | null | Yes | — |
server.authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
server.circuitOpenedAt | string (date-time) | null | Yes | — |
server.createdAt | string (date-time) | Yes | — |
server.hasCredential | boolean | Yes | — |
server.id | string (tcn_… ID) | Yes | ID (tcn_…) |
server.lastCheckedAt | string (date-time) | null | Yes | — |
server.lastError | string | null | Yes | — |
server.name | string | Yes | — |
server.platformServerId | string (pts_… ID) | null | Yes | — |
server.status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
server.tools | object | Yes | — |
server.tools.approved | integer | Yes | — |
server.tools.changed | integer | Yes | — |
server.tools.pending | integer | Yes | — |
server.tools.rejected | integer | Yes | — |
server.tools.withdrawn | integer | Yes | — |
server.url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tool-servers" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "string",
"url": "string"
}'Find out whether a server needs no sign-in, an API key, or OAuth#
POST /v1/account/tool-servers/probe
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
url | string | Yes | Up to 2048 characters. |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
auth | enum | Yes | One of: "none", "api_key", "oauth". |
url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tool-servers/probe" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "string"
}'Rename a tool server#
PATCH /v1/account/tool-servers/{serverId}
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | 1–80 characters. |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
server | ToolServer | Yes | — |
server.apiKeyHeader | string | null | Yes | — |
server.auth | enum | Yes | One of: "none", "api_key", "oauth". |
server.authenticatedAt | string (date-time) | null | Yes | — |
server.authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
server.circuitOpenedAt | string (date-time) | null | Yes | — |
server.createdAt | string (date-time) | Yes | — |
server.hasCredential | boolean | Yes | — |
server.id | string (tcn_… ID) | Yes | ID (tcn_…) |
server.lastCheckedAt | string (date-time) | null | Yes | — |
server.lastError | string | null | Yes | — |
server.name | string | Yes | — |
server.platformServerId | string (pts_… ID) | null | Yes | — |
server.status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
server.tools | object | Yes | — |
server.tools.approved | integer | Yes | — |
server.tools.changed | integer | Yes | — |
server.tools.pending | integer | Yes | — |
server.tools.rejected | integer | Yes | — |
server.tools.withdrawn | integer | Yes | — |
server.url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X PATCH "$ANSWERSTACK_API_URL/v1/account/tool-servers/{serverId}" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "string"
}'Remove a tool server, its tools and its credential#
DELETE /v1/account/tool-servers/{serverId}
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
deleted | enum | Yes | One of: true. |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X DELETE "$ANSWERSTACK_API_URL/v1/account/tool-servers/{serverId}" \
-H "Authorization: Bearer $ACCESS_TOKEN"List the tools on the server now: new ones wait for review, changed ones stop until reviewed#
POST /v1/account/tool-servers/{serverId}/discover
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
message | string | null | Yes | — |
ok | boolean | Yes | — |
server | ToolServer | Yes | — |
server.apiKeyHeader | string | null | Yes | — |
server.auth | enum | Yes | One of: "none", "api_key", "oauth". |
server.authenticatedAt | string (date-time) | null | Yes | — |
server.authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
server.circuitOpenedAt | string (date-time) | null | Yes | — |
server.createdAt | string (date-time) | Yes | — |
server.hasCredential | boolean | Yes | — |
server.id | string (tcn_… ID) | Yes | ID (tcn_…) |
server.lastCheckedAt | string (date-time) | null | Yes | — |
server.lastError | string | null | Yes | — |
server.name | string | Yes | — |
server.platformServerId | string (pts_… ID) | null | Yes | — |
server.status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
server.tools | object | Yes | — |
server.tools.approved | integer | Yes | — |
server.tools.changed | integer | Yes | — |
server.tools.pending | integer | Yes | — |
server.tools.rejected | integer | Yes | — |
server.tools.withdrawn | integer | Yes | — |
server.url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tool-servers/{serverId}/discover" \
-H "Authorization: Bearer $ACCESS_TOKEN"Sign in to a server again: a new API key, or a new OAuth sign-in. Probes first, so a server that changed how it signs in is handled#
POST /v1/account/tool-servers/{serverId}/reconnect
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
apiKey | object | No | — |
apiKey.header | string | Yes | Pattern: ^[A-Za-z0-9-]\{1,64\}$. |
apiKey.key | string | Yes | 1–4000 characters. |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
authorizationUrl | string | null | Yes | — |
server | ToolServer | Yes | — |
server.apiKeyHeader | string | null | Yes | — |
server.auth | enum | Yes | One of: "none", "api_key", "oauth". |
server.authenticatedAt | string (date-time) | null | Yes | — |
server.authenticatedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
server.circuitOpenedAt | string (date-time) | null | Yes | — |
server.createdAt | string (date-time) | Yes | — |
server.hasCredential | boolean | Yes | — |
server.id | string (tcn_… ID) | Yes | ID (tcn_…) |
server.lastCheckedAt | string (date-time) | null | Yes | — |
server.lastError | string | null | Yes | — |
server.name | string | Yes | — |
server.platformServerId | string (pts_… ID) | null | Yes | — |
server.status | enum | Yes | One of: "pending", "active", "needs_reauth", "failing". |
server.tools | object | Yes | — |
server.tools.approved | integer | Yes | — |
server.tools.changed | integer | Yes | — |
server.tools.pending | integer | Yes | — |
server.tools.rejected | integer | Yes | — |
server.tools.withdrawn | integer | Yes | — |
server.url | string | Yes | — |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tool-servers/{serverId}/reconnect" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'The tools the account's servers offer, and where each one stands#
GET /v1/account/tools
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
serverId | string (tcn_… ID) | No | ID (tcn_…) |
status | enum | No | One of: "pending", "approved", "rejected", "changed", "withdrawn". |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
tools | array<AccountTool> | Yes | — |
tools[].definition | map | Yes | — |
tools[].definition.{key} | any | No | Any key. |
tools[].definitionHash | string | Yes | — |
tools[].description | string | null | Yes | — |
tools[].effect | enum | null | Yes | One of: "read", "write". |
tools[].fromPlatform | boolean | Yes | — |
tools[].id | string (atl_… ID) | Yes | ID (atl_…) |
tools[].idempotencyArgument | string | null | Yes | — |
tools[].lastSeenAt | string (date-time) | Yes | — |
tools[].latestDefinition | map | null | Yes | — |
tools[].latestDefinition.{key} | any | No | Any key. |
tools[].name | string | Yes | — |
tools[].review | object | Yes | — |
tools[].review.argumentNames | array<string> | Yes | — |
tools[].review.flags | array<object> | Yes | — |
tools[].review.flags[].kind | enum | Yes | One of: "instruction", "url", "hidden_text", "long". |
tools[].review.flags[].match | string | Yes | — |
tools[].review.flags[].where | string | Yes | — |
tools[].review.hash | string | Yes | — |
tools[].review.problems | array<object> | Yes | — |
tools[].review.problems[].message | string | Yes | — |
tools[].review.problems[].where | enum | Yes | One of: "inputSchema", "outputSchema". |
tools[].review.suggestedEffect | enum | Yes | One of: "read", "write". |
tools[].reviewNote | string | null | Yes | — |
tools[].reviewedAt | string (date-time) | null | Yes | — |
tools[].reviewedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
tools[].serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
tools[].status | enum | Yes | One of: "pending", "approved", "rejected", "changed", "withdrawn". |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X GET "$ANSWERSTACK_API_URL/v1/account/tools" \
-H "Authorization: Bearer $ACCESS_TOKEN"Calls per tool, error rate, p95 latency, last use, and the playbooks that bind it. Visibility, not billing: tool calls are included#
GET /v1/account/tools/usage
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
days | integer | No | Between 1 and 90. Default: 30. |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
tools | array<object> | Yes | — |
tools[].calls | integer | Yes | — |
tools[].errors | integer | Yes | — |
tools[].lastUsedAt | string (date-time) | null | Yes | — |
tools[].p95Ms | integer | null | Yes | — |
tools[].playbooks | array<object> | Yes | — |
tools[].playbooks[].id | string (pb_… ID) | Yes | ID (pb_…) |
tools[].playbooks[].name | string | Yes | — |
tools[].toolId | string (atl_… ID) | Yes | ID (atl_…) |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X GET "$ANSWERSTACK_API_URL/v1/account/tools/usage" \
-H "Authorization: Bearer $ACCESS_TOKEN"One tool: its definition, any waiting change, and what the review should look at#
GET /v1/account/tools/{toolId}
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
toolId | string (atl_… ID) | Yes | ID (atl_…) |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
tool | AccountTool | Yes | — |
tool.definition | map | Yes | — |
tool.definition.{key} | any | No | Any key. |
tool.definitionHash | string | Yes | — |
tool.description | string | null | Yes | — |
tool.effect | enum | null | Yes | One of: "read", "write". |
tool.fromPlatform | boolean | Yes | — |
tool.id | string (atl_… ID) | Yes | ID (atl_…) |
tool.idempotencyArgument | string | null | Yes | — |
tool.lastSeenAt | string (date-time) | Yes | — |
tool.latestDefinition | map | null | Yes | — |
tool.latestDefinition.{key} | any | No | Any key. |
tool.name | string | Yes | — |
tool.review | object | Yes | — |
tool.review.argumentNames | array<string> | Yes | — |
tool.review.flags | array<object> | Yes | — |
tool.review.flags[].kind | enum | Yes | One of: "instruction", "url", "hidden_text", "long". |
tool.review.flags[].match | string | Yes | — |
tool.review.flags[].where | string | Yes | — |
tool.review.hash | string | Yes | — |
tool.review.problems | array<object> | Yes | — |
tool.review.problems[].message | string | Yes | — |
tool.review.problems[].where | enum | Yes | One of: "inputSchema", "outputSchema". |
tool.review.suggestedEffect | enum | Yes | One of: "read", "write". |
tool.reviewNote | string | null | Yes | — |
tool.reviewedAt | string (date-time) | null | Yes | — |
tool.reviewedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
tool.serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
tool.status | enum | Yes | One of: "pending", "approved", "rejected", "changed", "withdrawn". |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X GET "$ANSWERSTACK_API_URL/v1/account/tools/{toolId}" \
-H "Authorization: Bearer $ACCESS_TOKEN"Approve the definition you reviewed, with the description our model will read and what the tool does#
POST /v1/account/tools/{toolId}/approve
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
toolId | string (atl_… ID) | Yes | ID (atl_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
description | string | Yes | 1–1000 characters. |
effect | enum | Yes | One of: "read", "write". |
idempotencyArgument | string | null | No | 1–128 characters. |
reviewedHash | string | Yes | — |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
tool | AccountTool | Yes | — |
tool.definition | map | Yes | — |
tool.definition.{key} | any | No | Any key. |
tool.definitionHash | string | Yes | — |
tool.description | string | null | Yes | — |
tool.effect | enum | null | Yes | One of: "read", "write". |
tool.fromPlatform | boolean | Yes | — |
tool.id | string (atl_… ID) | Yes | ID (atl_…) |
tool.idempotencyArgument | string | null | Yes | — |
tool.lastSeenAt | string (date-time) | Yes | — |
tool.latestDefinition | map | null | Yes | — |
tool.latestDefinition.{key} | any | No | Any key. |
tool.name | string | Yes | — |
tool.review | object | Yes | — |
tool.review.argumentNames | array<string> | Yes | — |
tool.review.flags | array<object> | Yes | — |
tool.review.flags[].kind | enum | Yes | One of: "instruction", "url", "hidden_text", "long". |
tool.review.flags[].match | string | Yes | — |
tool.review.flags[].where | string | Yes | — |
tool.review.hash | string | Yes | — |
tool.review.problems | array<object> | Yes | — |
tool.review.problems[].message | string | Yes | — |
tool.review.problems[].where | enum | Yes | One of: "inputSchema", "outputSchema". |
tool.review.suggestedEffect | enum | Yes | One of: "read", "write". |
tool.reviewNote | string | null | Yes | — |
tool.reviewedAt | string (date-time) | null | Yes | — |
tool.reviewedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
tool.serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
tool.status | enum | Yes | One of: "pending", "approved", "rejected", "changed", "withdrawn". |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tools/{toolId}/approve" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"reviewedHash": "string",
"description": "string",
"effect": "read"
}'Decide a tool is not to be used#
POST /v1/account/tools/{toolId}/reject
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
toolId | string (atl_… ID) | Yes | ID (atl_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
note | string | No | Up to 500 characters. |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
tool | AccountTool | Yes | — |
tool.definition | map | Yes | — |
tool.definition.{key} | any | No | Any key. |
tool.definitionHash | string | Yes | — |
tool.description | string | null | Yes | — |
tool.effect | enum | null | Yes | One of: "read", "write". |
tool.fromPlatform | boolean | Yes | — |
tool.id | string (atl_… ID) | Yes | ID (atl_…) |
tool.idempotencyArgument | string | null | Yes | — |
tool.lastSeenAt | string (date-time) | Yes | — |
tool.latestDefinition | map | null | Yes | — |
tool.latestDefinition.{key} | any | No | Any key. |
tool.name | string | Yes | — |
tool.review | object | Yes | — |
tool.review.argumentNames | array<string> | Yes | — |
tool.review.flags | array<object> | Yes | — |
tool.review.flags[].kind | enum | Yes | One of: "instruction", "url", "hidden_text", "long". |
tool.review.flags[].match | string | Yes | — |
tool.review.flags[].where | string | Yes | — |
tool.review.hash | string | Yes | — |
tool.review.problems | array<object> | Yes | — |
tool.review.problems[].message | string | Yes | — |
tool.review.problems[].where | enum | Yes | One of: "inputSchema", "outputSchema". |
tool.review.suggestedEffect | enum | Yes | One of: "read", "write". |
tool.reviewNote | string | null | Yes | — |
tool.reviewedAt | string (date-time) | null | Yes | — |
tool.reviewedBy | string (usr_… ID) | string (svc_… ID) | null | Yes | — |
tool.serverId | string (tcn_… ID) | Yes | ID (tcn_…) |
tool.status | enum | Yes | One of: "pending", "approved", "rejected", "changed", "withdrawn". |
Errors: 400, 401, 403, 404, 409, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tools/{toolId}/reject" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'Run an approved tool with sample arguments. A tool that changes something needs confirm: true, because it acts on the real system#
POST /v1/account/tools/{toolId}/try
Authentication: Bearer token: Authorization: Bearer <token> (Supabase access token).
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
toolId | string (atl_… ID) | Yes | ID (atl_…) |
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
arguments | map | No | Default: \{\}. |
arguments.{key} | any | No | Any key. |
confirm | boolean | No | — |
retry | object | No | — |
retry.inputResponses | map | Yes | — |
retry.inputResponses.{key} | any | No | Any key. |
retry.requestState | string | null | No | — |
Response 200
| Field | Type | Required | Description |
|---|---|---|---|
outcome | object | object | Yes | — |
outcome.isError | boolean | Yes | (variant 1) |
outcome.kind | enum | Yes | (variant 1) One of: "complete". |
outcome.structuredContent | any | No | (variant 1) |
outcome.text | string | Yes | (variant 1) |
outcome.inputRequests | map | Yes | (variant 2) |
outcome.inputRequests.{key} | any | No | (variant 2) Any key. |
outcome.kind | enum | Yes | (variant 2) One of: "input_required". |
outcome.requestState | string | null | Yes | (variant 2) |
Errors: 400, 401, 403, 404, 409, 422, 429, 500, with an ErrorBody body.
Example
curl -X POST "$ANSWERSTACK_API_URL/v1/account/tools/{toolId}/try" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"arguments": {},
"confirm": true,
"retry": {
"inputResponses": {}
}
}'