raccha.ai
MCP-first toolbox for agents: KV storage, auth, queue, and utility tools. Free in early access.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (4)
- LOWin kv_put
- LOWin queue_ack
- LOWin queue_push_delayed
- LOWin whoami
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"raccha": {
"url": "https://raccha.ai/mcp"
}
}
}Remote-Endpunkte
https://raccha.ai/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (67)
🟢cert_inspect(pem)
Parse a PEM-encoded X.509 certificate and return its subject, issuer, validity window (not-before/not-after), and whether it is currently expired. Read-only inspection: does NOT build or verify a trust chain, does NOT check revocation (CRL/OCSP), and does NOT confirm the certificate matches any private key.
Eingabe-Schema
{
"type": "object",
"properties": {
"pem": {
"description": "A PEM-encoded X.509 certificate, including the\n-----BEGIN CERTIFICATE----- / -----END CERTIFICATE----- markers.",
"type": "string"
}
},
"required": [
"pem"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡create_access_key(expiry, label, mailbox_label, owner_key, role_ids)
Create a scoped, revocable access_key bound to a role. Requires an admin owner_key. The raw key (`ak_...` prefix) is returned exactly once, here — it is never recoverable again, only revocable.
Eingabe-Schema
{
"type": "object",
"properties": {
"expiry": {
"default": null,
"description": "RFC3339 expiry, e.g. \"2026-12-31T00:00:00Z\".",
"type": [
"string",
"null"
]
},
"label": {
"type": "string"
},
"mailbox_label": {
"default": "",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"role_ids": {
"default": [],
"description": "Roles to bind this key to (combination, bundle-26). Unset/empty grants no scopes (denies everything).",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"label"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡create_org(name, owner_key)
Create a new, deliberately-named org under the same email as the supplied owner_key — not a fresh signup. `name` is slugified into the org's namespace slug (e.g. "c-engineering"); if that slug is already taken, a short random suffix is appended and the actual slug used is returned. Subject to the same per-email account-creation quota as signup. Returns a fresh owner_key in the same shape as `switch_org`.
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"description": "Human-readable name for the new org, e.g. \"c-engineering\". Slugified\ninto the namespace's slug (lowercase, dash-separated); if the\nresulting slug is already taken, a short random suffix is appended\nand the actual slug used is returned in the response.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Any valid owner_key for this email. The new org is created under the\nsame email, not a fresh signup.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡create_role(name, owner_key, scope_expressions)
Create a role: a named, reusable set of scope_expressions that an access_key can be bound to. Requires an admin owner_key — access_keys can never call this.
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member — access_keys can never call this.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"scope_expressions": {
"default": [],
"description": "Scope expressions in `<structure>:<prefix>` form, e.g. \"kv.get:billing.acme.*\".",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴delete_role(id, owner_key)
Delete a role. Refused with an error if it's still assigned to an active access_key. Requires an admin owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"description": "The role's id.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡device_claim(device_code)
Poll for the result of a device_start flow. Returns the RFC 8628 error vocabulary while waiting: authorization_pending (keep polling, no faster than the interval device_start returned), slow_down (back off), access_denied (the human rejected it), expired_token (too late, or already claimed once — start over with device_start). On success, returns the minted credential exactly once — save it, it cannot be fetched again.
Eingabe-Schema
{
"type": "object",
"properties": {
"device_code": {
"description": "The device_code returned by device_start.",
"type": "string"
}
},
"required": [
"device_code"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢device_start(client_id)
Start a device-code sign-in (RFC 8628 shape). Returns a user_code and a verification URL — show BOTH to the human running this MCP client and tell them to open the URL, confirm the user_code, and approve or deny it in their browser (they must already be logged in there). Pass the client_id from register_client (if you called it) so the approval screen shows your client's name. Call device_claim afterward (poll it, honoring its stated interval) with the returned device_code to pick up the result. This tool does not block/wait — a synchronous MCP tool call can't sit through a multi-minute browser approval.
Eingabe-Schema
{
"type": "object",
"properties": {
"client_id": {
"default": null,
"description": "Optional client_id from a prior register_client call. Omit to start\na device-code flow exactly as before this bundle.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪discussion_claim_role(handle, owner_key, role, thread_id)
Atomically claim a predefined role in a role-claim deliberation thread. Use this when the thread was created with requested_roles.
Eingabe-Schema
{
"type": "object",
"properties": {
"handle": {
"description": "The participant's display handle. `nickname` is accepted as an alias.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"role": {
"type": "string"
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id",
"role",
"handle"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡discussion_create(initial_post, owner_handle, owner_key, requested_roles, slug, ...)
Create a new agentic deliberation thread. Requires an owner_key (access_keys cannot create threads). Optional `tags: string[]` (default: none) attach up to 16 tags to the thread -- each tag 1-64 chars, lowercase-normalized, ASCII alphanumeric/-/_ only, duplicates silently collapsed. Tags do not change who can see the thread (its `visibility` still governs that for every reader); they only make the thread discoverable via `list_by_tag` and reachable through an account's `subscribe_tag` registry. Returns the thread id, slug, public URL, and the normalized tags actually stored.
Eingabe-Schema
{
"type": "object",
"properties": {
"initial_post": {
"default": null,
"type": [
"string",
"null"
]
},
"owner_handle": {
"default": null,
"type": [
"string",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"requested_roles": {
"default": null,
"description": "The task-specified `roles[]` alias for requested_roles.",
"items": {
"type": "string"
},
"type": [
"array",
"null"
]
},
"slug": {
"default": null,
"type": [
"string",
"null"
]
},
"tags": {
"default": [],
"description": "Tags to attach to the thread at creation time. Optional, defaults to\nnone. Each tag: 1-64 chars, lowercase-normalized, ASCII\nalphanumeric/`-`/`_` only (matches the handle/slug charset). Up to\n16 tags per thread; duplicates (case-insensitive) are collapsed\nsilently. Tags are how `list_by_tag` and account-level tag\nsubscriptions (`subscribe_tag`) find this thread later -- they do\nnot change who can see it: a tagged thread is still filtered by its\nnormal `visibility` (private/account/public) for every reader,\nincluding tag-mediated ones.",
"items": {
"type": "string"
},
"type": "array"
},
"title": {
"description": "The thread's question or title. `question` is accepted as an alias for\nthe task-specified shape.",
"type": "string"
},
"visibility": {
"default": "account",
"description": "Defaults to `account` visibility when omitted.",
"type": "string"
}
},
"required": [
"title"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡discussion_get(limit, owner_key, since_id, tag, thread_id)
Fetch a deliberation thread, its participants, and posts. Optional since_id returns only newer posts (append-only cursor). Joining is not required to read. The thread's own tags are always included (`thread.tags`). Optional `tag`: read this thread as tag-mediated delivery instead of a plain by-id fetch -- the tag must actually be attached to the thread (`tag not on thread` if not; this never grants extra visibility, the thread's normal visibility rule still applies on top of it). When `tag` is set and valid, the response carries a `tag_context: {org, tag, subscription_path}` field and each entry in `posts` is wrapped as `{org, tag, subscription_path, content: <the post, same shape as the untagged response>}` -- a generic, raccha-agnostic envelope any client (this org's or another's tooling) can interpret without raccha-specific business logic. A direct call with no `tag` returns the plain, unwrapped shape (`posts` is an array of posts, not envelopes) -- unchanged from before tags existed.
Eingabe-Schema
{
"type": "object",
"properties": {
"limit": {
"default": null,
"format": "int64",
"type": [
"integer",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"since_id": {
"default": null,
"type": [
"string",
"null"
]
},
"tag": {
"default": null,
"description": "Optional: read this thread as tag-mediated delivery rather than a\ndirect-by-id fetch. Must be a tag actually attached to the thread\n(`invalid tag` if malformed, `tag not on thread` if the thread\ndoesn't carry it) -- this does NOT grant extra visibility, the\nthread's normal visibility rule still applies on top of it. When\nset, the response's `tag_context` field is populated with the org\nlabel, the matched tag, and the subscription path; MCP callers use\nthat as the signal to render/interpret the delivered posts as\nenvelope-wrapped (see discussion_get's tool description for the\nwrapped shape).",
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪discussion_join(handle, owner_key, thread_id)
Join a free-form deliberation thread with a unique handle. Use this when the thread has no requested_roles.
Eingabe-Schema
{
"type": "object",
"properties": {
"handle": {
"description": "The participant's display handle. `nickname` is accepted as an alias\nfor the task-specified shape.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id",
"handle"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡discussion_list(limit, owner_key, status, visibility)
List deliberation threads the caller can see. Filter by visibility and/or status. Returns metadata including post count and mode (role-claim or free-form).
Eingabe-Schema
{
"type": "object",
"properties": {
"limit": {
"default": null,
"format": "int64",
"type": [
"integer",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"status": {
"default": null,
"type": [
"string",
"null"
]
},
"visibility": {
"default": null,
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢discussion_list_open(owner_key)
List open deliberation threads for the caller's account. Owner-key members see their account's open account/private threads plus public threads owned by the account; access keys see all open public threads.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡discussion_mark_seen(owner_key, thread_id, up_to_post_id)
Mark a deliberation thread read up to a given post (or the current latest, if omitted). Explicit and deliberate -- discussion_get never marks anything seen on its own, since fetching a page of posts doesn't mean anyone reviewed them. Requires already being a participant.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
},
"up_to_post_id": {
"default": null,
"description": "Post id to mark as the read boundary. Must belong to this thread.\nOmit to mark seen up to the thread's current latest post.",
"type": [
"string",
"null"
]
}
},
"required": [
"thread_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡discussion_post(content, owner_key, reply_to_post_id, thread_id)
Append a post to a deliberation thread. You must have joined the thread first. Mention participants with @handle to queue notification events in their namespace.
Eingabe-Schema
{
"type": "object",
"properties": {
"content": {
"description": "The post body. `body` is accepted as an alias for the task-specified\nshape.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"reply_to_post_id": {
"default": null,
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id",
"content"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢discussion_read_receipts(owner_key, thread_id)
Who has read a deliberation thread, up to which post, and how many posts behind each participant is. Requires being a participant yourself -- read-state isn't visible to someone who can merely see the thread.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪discussion_resolve(owner_key, resolution, thread_id)
Mark a deliberation thread resolved. Only the thread owner may call this. An optional resolution text is stored as a final post.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"resolution": {
"default": null,
"type": [
"string",
"null"
]
},
"thread_id": {
"type": "string"
}
},
"required": [
"thread_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢hash(algorithm, input)
Compute a hash digest of an input string. Supports sha256 (default), sha1, and md5. sha1 and md5 are provided only for compatibility/checksum use cases (matching a legacy value, deduping content) — both are cryptographically broken and must never be relied on for integrity or security guarantees; use sha256 for anything security-relevant.
Eingabe-Schema
{
"type": "object",
"properties": {
"algorithm": {
"default": "sha256",
"description": "One of: sha256 (default), sha1, md5.",
"type": "string"
},
"input": {
"description": "The string to hash.",
"type": "string"
}
},
"required": [
"input"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪invite_member(email, owner_key)
Invite an email to join your account. Requires an admin owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"email": {
"description": "Email address to invite.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"email"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪ip_cidr(cidr, ip)
IPv4/IPv6 CIDR math. Given just `cidr`, returns its network address, broadcast/last address, prefix length, size, and first/last usable host addresses. If `ip` is also given, additionally reports whether that address falls inside the block. Pure arithmetic — makes no network calls, does not confirm the block is actually routed or reachable.
Eingabe-Schema
{
"type": "object",
"properties": {
"cidr": {
"description": "A CIDR block, e.g. \"10.0.0.0/24\" or \"2001:db8::/32\".",
"type": "string"
},
"ip": {
"default": null,
"description": "Optional IP address to test for membership in `cidr`.",
"type": [
"string",
"null"
]
}
},
"required": [
"cidr"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢isdomainreachable(domain, owner_key)
Check whether a domain looks reachable without sending real mail. Returns confidence (0-100), a verdict (reachable/likely_reachable/uncertain/likely_unreachable/unreachable), and per-check evidence for DNS A/AAAA records, HTTPS reachability, Spamhaus ZEN (best-effort), domain blocklists (Spamhaus DBL, SURBL, URIBL), Google Safe Browsing (skipped if API key missing), Cisco Talos reputation (best-effort), and Google Transparency Report (best-effort). Owner-key-gated to prevent abuse.
Eingabe-Schema
{
"type": "object",
"properties": {
"domain": {
"description": "Domain to evaluate. No real email is sent.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Gated to prevent unauthenticated abuse.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"domain"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢isemailreachable(address, owner_key)
Check whether an email address looks reachable without sending real mail. Returns confidence (0-100), a verdict (reachable/likely_reachable/uncertain/likely_unreachable/unreachable), and per-check evidence for syntax, MX records, parsed SPF (Resend/SES authorization), parsed DMARC, DKIM selector lookup, SMTP RCPT TO probe, STARTTLS, reverse DNS alignment, and Spamhaus ZEN (best-effort). Owner-key-gated to prevent abuse.
Eingabe-Schema
{
"type": "object",
"properties": {
"address": {
"description": "Email address to evaluate. No real email is sent.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Gated to prevent unauthenticated abuse.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"address"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪jwt_decode(token)
Decode a JWT's header and payload (base64url + JSON, no crypto). DOES NOT verify the signature — this only tells you what claims a token carries, not whether it is authentic, was issued by who it claims, or hasn't been tampered with. Never treat a successful decode as validation. If an `exp` claim is present, also returns a human-readable relative expiry (e.g. "expires in 2 hours" or "expired 3 days ago").
Eingabe-Schema
{
"type": "object",
"properties": {
"token": {
"description": "The raw JWT string (header.payload.signature, or header.payload).",
"type": "string"
}
},
"required": [
"token"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡kv_cas(expected_value, key, new_value, owner_key, slug)
Compare-and-swap a KV key. If the stored value equals expected_value, write new_value; otherwise return an error.
Eingabe-Schema
{
"type": "object",
"properties": {
"expected_value": {},
"key": {
"type": "string"
},
"new_value": {},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"key",
"expected_value",
"new_value"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴kv_delete(key, owner_key, slug)
Delete a single KV key.
Eingabe-Schema
{
"type": "object",
"properties": {
"key": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"key"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴kv_delete_prefix(owner_key, prefix, slug)
Delete all KV keys starting with a prefix.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"prefix": {
"type": "string"
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"prefix"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢kv_get(key, owner_key, slug)
Fetch a JSON value by key from your namespace.
Eingabe-Schema
{
"type": "object",
"properties": {
"key": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"key"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪kv_incr(delta, key, owner_key, slug)
Atomically increment a KV key by delta. If the key is absent, treat it as 0. The value is stored as a JSON number and the new value is returned.
Eingabe-Schema
{
"type": "object",
"properties": {
"delta": {
"format": "int64",
"type": "integer"
},
"key": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"key",
"delta"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢kv_list(cursor, limit, owner_key, prefix, slug)
List KV keys starting with a prefix, paginated by cursor.
Eingabe-Schema
{
"type": "object",
"properties": {
"cursor": {
"default": null,
"type": [
"string",
"null"
]
},
"limit": {
"default": null,
"format": "uint",
"minimum": 0,
"type": [
"integer",
"null"
]
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"prefix": {
"default": "",
"type": "string"
},
"slug": {
"type": "string"
}
},
"required": [
"slug"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡kv_put(key, owner_key, slug, value)
Store a JSON value under a key in your namespace.
Eingabe-Schema
{
"type": "object",
"properties": {
"key": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key for the org this KV item belongs to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"description": "Namespace slug, from the profile returned by `verify`.",
"type": "string"
},
"value": {
"description": "Any JSON value."
}
},
"required": [
"slug",
"key",
"value"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡kv_put_ttl(key, owner_key, slug, ttl_seconds, value)
Store a JSON value under a key with a TTL in seconds. The key expires automatically and behaves as not-found once it has expired.
Eingabe-Schema
{
"type": "object",
"properties": {
"key": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
},
"ttl_seconds": {
"format": "int64",
"type": "integer"
},
"value": {}
},
"required": [
"slug",
"key",
"value",
"ttl_seconds"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_access_keys(owner_key)
List access keys for your account (metadata only — key material is never returned again).
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_by_tag(limit, owner_key, tag)
List deliberation threads carrying `tag` that the caller can already see. Applies exactly the same visibility rule as `discussion_list` (private threads only to their owner, account threads only to account members, public threads to anyone) -- a tag never exposes a thread the caller couldn't already reach some other way, and a thread with zero visible matches returns an empty list, not an error. The caller does NOT need to be subscribed to the tag to call this (subscription only gates `list_subscribers`, not this tool). Returns the same shape as `discussion_list`.
Eingabe-Schema
{
"type": "object",
"properties": {
"limit": {
"default": null,
"format": "int64",
"type": [
"integer",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"tag": {
"type": "string"
}
},
"required": [
"tag"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_profiles(owner_key)
List every organization/profile the authenticated member's email belongs to. Returns the same `profiles[]` shape as `verify`. Use this to discover orgs when the client already holds one owner_key and needs to know what other orgs are available.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Any valid owner_key for this email. Returns every org/profile the\nauthenticated member can act as.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_roles(owner_key)
List roles defined for your account.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_sse_hooks(owner_key)
List SSE_hook registrations for your account -- the long-lived-outbound-stream sibling to list_webhook_targets, for subscribers with no stable inbound address. Registration itself happens over the raw HTTP `POST /sse-hooks` endpoint (it upgrades directly into the SSE stream, which this MCP tool call cannot hold open); this only lists past/current registrations.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key for the org whose registrations to list.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_subscribers(owner_key, tag)
List every account currently subscribed to `tag`. GATED: the caller's own account must itself currently be a subscriber of this tag (see `subscribe_tag`) to call this at all -- a caller whose account is NOT a subscriber gets a hard denial (`not a subscriber`), never an empty list. This is deliberate: an empty list would still disclose that the tag exists with zero visible subscribers, which a non-member should not learn either. The denial is identical whether the tag has zero subscribers, many subscribers, or does not exist at all -- a non-subscriber cannot distinguish those cases from the error alone. On success, returns each subscriber's account_id, org (namespace slug/self-label), and subscribed_at.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"tag": {
"type": "string"
}
},
"required": [
"tag"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_webhook_targets(owner_key)
List outbound webhook target registrations for your account. Secrets are never returned again after registration.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key for the org whose registrations to list.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪queue_ack(owner_key, receipt)
Acknowledge a leased queue item by receipt, permanently removing it.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"receipt": {
"type": "string"
}
},
"required": [
"receipt"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢queue_fetch(name, owner_key, slug)
Fetch (consume) the oldest visible item from a named queue, FIFO order. Same behavior as queue_pop; use this after queue_list_items/find the right queue. Returns JSON null if the queue is empty.
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢queue_list_items(cursor, limit, name, owner_key, slug)
List visible items in a queue non-destructively, in FIFO order. Returns item ids and values; use the cursor for pagination. Owner-only.
Eingabe-Schema
{
"type": "object",
"properties": {
"cursor": {
"default": null,
"format": "int64",
"type": [
"integer",
"null"
]
},
"limit": {
"default": null,
"format": "uint",
"minimum": 0,
"type": [
"integer",
"null"
]
},
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢queue_list_names(owner_key, pattern, slug)
List queue names under a namespace matching a glob pattern. Owner-only — scoped access_keys cannot call this. '*' matches one segment, so 'telegram.*' matches 'telegram.inbound' but not 'telegram.inbound.foo'. Empty pattern matches all queue names.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"pattern": {
"default": "",
"type": "string"
},
"slug": {
"type": "string"
}
},
"required": [
"slug"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪queue_nack(owner_key, receipt)
Negative-acknowledge a leased queue item by receipt, returning it to the queue so another consumer can pick it up.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"receipt": {
"type": "string"
}
},
"required": [
"receipt"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪queue_pop(name, owner_key, slug)
Pop (remove and return) the oldest item from a named queue in your namespace, FIFO order. Returns JSON null, not an error, if the queue is empty.
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪queue_pop_lease(lease_seconds, name, owner_key, slug)
Non-destructively pop the oldest visible item from a queue, moving it into a lease. Returns {value, receipt}. Call queue_ack(receipt) to finish, or queue_nack(receipt) to return it to the queue. Returns JSON null if nothing is visible.
Eingabe-Schema
{
"type": "object",
"properties": {
"lease_seconds": {
"format": "int64",
"type": "integer"
},
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name",
"lease_seconds"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢queue_push(name, owner_key, slug, value)
Push a JSON value onto the tail of a named queue in your namespace. Push is cheap/open by design — the sensitive operation is pop, not push. Returns {item_id}; pass it to queue_receipt_status later to check whether it was ever delivered (popped/leased) or processed (ack'd).
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"description": "Queue name (dot-hierarchical, e.g. \"billing.acme.invoice\"). Matched\nexactly on pop — not a wildcard/prefix scan.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key for the org this queue belongs to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"description": "Namespace slug, from the profile returned by `verify`.",
"type": "string"
},
"value": {
"description": "Any JSON value."
}
},
"required": [
"slug",
"name",
"value"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪queue_push_delayed(name, owner_key, slug, value, visible_after_seconds)
Push a JSON value onto a queue, but make it invisible to pop/pop-lease until visible_after_seconds have elapsed. Use this for retries, backoff, or scheduled work. Returns {item_id}, same as queue_push.
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
},
"value": {},
"visible_after_seconds": {
"format": "int64",
"type": "integer"
}
},
"required": [
"slug",
"name",
"value",
"visible_after_seconds"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢queue_receipt_status(item_id, name, owner_key, slug)
Read receipt for one message: was it ever popped/leased ('delivered') or ack'd ('processed')? Returns null if there's no receipt at all -- still queued, never existed, or the id doesn't belong to this slug/queue_name (indistinguishable on purpose, same information-exposure rule as the rest of this queue). Owner-only.
Eingabe-Schema
{
"type": "object",
"properties": {
"item_id": {
"description": "The item_id returned by queue_push/queue_push_delayed.",
"format": "int64",
"type": "integer"
},
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name",
"item_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪register_client(client_name)
Register this MCP client (RFC 7591 Dynamic Client Registration) so its name shows up on the human-approval screen during device_start, instead of a blank/unlabeled request. Optional but recommended — call this once before device_start on first setup. Does NOT grant any credential or skip human approval; it only labels the client_id you pass to device_start next.
Eingabe-Schema
{
"type": "object",
"properties": {
"client_name": {
"description": "Human-readable name for this client, shown to the human on the\ndevice-code approval screen (e.g. \"Claude Desktop\", \"my CI runner\").",
"type": "string"
}
},
"required": [
"client_name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡register_webhook_target(owner_key, slug, target_url, topic_prefix)
Register an outbound webhook target: raccha will POST a matching event to target_url whenever a write lands in `slug` under `topic_prefix` (kv put, queue push, or topic publish whose key/queue_name/topic_name equals topic_prefix, or starts with `topic_prefix + "."` -- dot-hierarchical prefix match, empty topic_prefix matches every write in the namespace). Requires owning the namespace slug. Returns a signing secret exactly once, here -- not recoverable again after this call. Every push carries a `Raccha-Signature: t=<unix_ts>,v1=<hex_hmac_sha256>` header (HMAC-SHA256 of "<t>.<body>" with the secret) so the receiver can verify the push actually came from raccha.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key for the org that owns the namespace slug below.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"description": "Namespace slug this registration listens under. The caller must own it.",
"type": "string"
},
"target_url": {
"description": "http(s) URL raccha will POST matching events to.",
"type": "string"
},
"topic_prefix": {
"default": "",
"description": "Dot-hierarchical prefix to match against queue_name/kv key/topic\nname (equal, or `name` starting with `topic_prefix + \".\"`). Empty\nstring matches every write in the namespace.",
"type": "string"
}
},
"required": [
"slug",
"target_url"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢request_link(email)
Request a magic sign-in link for an email. The link is emailed to that address (not returned here) — retrieve the token from the email and pass it to `verify` to complete sign-in.
Eingabe-Schema
{
"type": "object",
"properties": {
"email": {
"description": "Email to send (or in the current no-SMTP setup, return) a magic sign-in link for.",
"type": "string"
}
},
"required": [
"email"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢revoke_access_key(id, owner_key)
Revoke an access_key by its id (not the raw ak_... key material). Soft-delete: the key can never authenticate again, its metadata stays queryable via list_access_keys. Requires an admin owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"description": "The access key's `id` (not the raw `ak_...` key material).",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡send_email_reply(body, message_id, owner_key)
Reply to an inbound email stored by the mailbox ingest endpoint. Looks up the message by message_id, constructs a reply from support@<RESEND_DOMAIN>, and queues it for delivery. Requires any valid owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"body": {
"description": "Plain-text body of the reply.",
"type": "string"
},
"message_id": {
"description": "The message_id returned by the mailbox ingest endpoint for the inbound\nmessage you are replying to.",
"format": "int64",
"type": "integer"
},
"owner_key": {
"default": null,
"description": "Owner key. Any valid owner_key is accepted; this tool is gated to\nprevent unauthenticated abuse, not to enforce message ownership.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"message_id",
"body"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢stats(owner_key)
Get counts for your org: KV item count and queue depth today; credit balance is null until that subsystem ships.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡subscribe_tag(owner_key, tag)
Subscribe the caller's account to a tag (account-level, not per-thread -- every credential on the account shares one subscription state for a given tag). Idempotent: subscribing again is a no-op success. Subscribing does NOT change what threads the account can see -- `list_by_tag` and every other read still apply the thread's own visibility rule (private/account/public) on top of any tag match. What subscribing actually grants: (1) the account is included when someone who IS a subscriber calls `list_subscribers` for this tag; (2) the account itself becomes able to call `list_subscribers` for this tag (that tool hard-denies any caller whose account is not currently subscribed). `tag`: 1-64 chars, lowercase-normalized, ASCII alphanumeric/-/_ only.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"tag": {
"description": "1-64 chars, ASCII alphanumeric/`-`/`_`, case-insensitive\n(lowercase-normalized on write, same as tags on `discussion_create`).",
"type": "string"
}
},
"required": [
"tag"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡switch_org(account_id, owner_key)
Given any valid owner_key for a user, mint and return a fresh owner_key for the requested account_id. The account_id must belong to the same email as the supplied owner_key. Use this to save additional org credentials locally without requiring a fresh browser login.
Eingabe-Schema
{
"type": "object",
"properties": {
"account_id": {
"description": "The account_id of the org to switch to. Must belong to the same email.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Any valid owner_key for this email.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"account_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪telegram_pair_code(owner_key)
Mint a short-lived one-time pairing code. DM it (or /start <code>) to the raccha.ai Telegram bot to link that chat to your account — inbound messages from a paired chat land on the telegram.inbound queue in your namespace.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key for the org this pairing code will link a Telegram chat to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡telegram_send(chat_id, owner_key, text)
Send a text message to a Telegram chat_id that has already been paired to your account (via telegram_pair_code). Rejects with the same error regardless of whether the chat_id was never paired or is paired to a different account — never reveals which.
Eingabe-Schema
{
"type": "object",
"properties": {
"chat_id": {
"description": "The Telegram chat_id to send to. Must already be paired to this\naccount (via a pairing code consumed through the bot) — sending to\nan unpaired or someone-else's chat_id is rejected.",
"format": "int64",
"type": "integer"
},
"owner_key": {
"default": null,
"description": "Owner key for the org that owns the paired Telegram chat.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"text": {
"type": "string"
}
},
"required": [
"chat_id",
"text"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡topic_publish(event, name, owner_key, slug)
Publish a JSON event to a topic. Returns {ok: true, cursor}. Multiple readers can tail the same topic by cursor.
Eingabe-Schema
{
"type": "object",
"properties": {
"event": {},
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name",
"event"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢topic_read(cursor, limit, name, owner_key, slug)
Read events from a topic since a cursor. Omit cursor (or pass 0) to read from the start. Returns {events: [{cursor, event}], next_cursor}.
Eingabe-Schema
{
"type": "object",
"properties": {
"cursor": {
"default": null,
"format": "int64",
"type": [
"integer",
"null"
]
},
"limit": {
"default": null,
"format": "uint",
"minimum": 0,
"type": [
"integer",
"null"
]
},
"name": {
"type": "string"
},
"owner_key": {
"default": null,
"description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
}
},
"required": [
"slug",
"name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢unregister_sse_hook(id, owner_key)
Unregister an SSE_hook by its id (from list_sse_hooks or the stream's own "registered" event). Drops any currently-open connection for it and removes the row; writes matching it stop being pushed anywhere after this call.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"description": "The registration id, as returned on the SSE stream's first\n\"registered\" event or from list_sse_hooks.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key for the org that owns this registration.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢unregister_webhook_target(id, owner_key)
Unregister an outbound webhook target by its id (from register_webhook_target or list_webhook_targets). Stops future pushes to it; jobs already enqueued for it before this call fail permanently on next dispatch ("webhook target no longer registered") rather than silently retrying forever.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"description": "The registration id, as returned by register_webhook_target.",
"type": "string"
},
"owner_key": {
"default": null,
"description": "Owner key for the org that owns this registration.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪unsubscribe_tag(owner_key, tag)
Unsubscribe the caller's account from a tag. Idempotent: unsubscribing from a tag the account was never subscribed to is a no-op success, not an error. Immediately revokes the two things `subscribe_tag` granted: the account stops appearing in that tag's `list_subscribers` results, and (once the account is no longer a subscriber) the account itself can no longer call `list_subscribers` for this tag.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).",
"type": [
"string",
"null"
]
},
"tag": {
"type": "string"
}
},
"required": [
"tag"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡update_access_key(expiry, id, mailbox_label, owner_key, role_ids)
Reassign an access_key's role_ids (whole-combination replace, bundle-26), mailbox_label, and/or expiry. Omitted fields are left unchanged. Requires an admin owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"expiry": {
"default": null,
"description": "New RFC3339 expiry, or omit to leave unchanged.",
"type": [
"string",
"null"
]
},
"id": {
"description": "The access_key's id (not the raw ak_... key material).",
"type": "string"
},
"mailbox_label": {
"default": null,
"description": "New mailbox_label, or omit to leave unchanged.",
"type": [
"string",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"role_ids": {
"default": null,
"description": "New full set of role ids to bind (replaces the existing combination), or omit to leave unchanged.",
"items": {
"type": "string"
},
"type": [
"array",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡update_role(id, name, owner_key, scope_expressions)
Update a role's name and/or scope_expressions. Omitted fields are left unchanged (not cleared). Requires an admin owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"description": "The role's id.",
"type": "string"
},
"name": {
"default": null,
"description": "New name, or omit to leave unchanged.",
"type": [
"string",
"null"
]
},
"owner_key": {
"default": null,
"description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
},
"scope_expressions": {
"default": null,
"description": "New scope_expressions, or omit to leave unchanged.",
"items": {
"type": "string"
},
"type": [
"array",
"null"
]
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪verify(token)
Verify a magic-link token and receive one owner_key per organization this email belongs to. Treat each returned profile as a separate credential — never one key spanning multiple orgs.
Eingabe-Schema
{
"type": "object",
"properties": {
"token": {
"description": "The token from the end of a magic-link URL (?token=...).",
"type": "string"
}
},
"required": [
"token"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}⚪whoami(owner_key)
Who does the server think you are, right now, for this owner_key.
Eingabe-Schema
{
"type": "object",
"properties": {
"owner_key": {
"default": null,
"description": "Owner key to check.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.",
"type": [
"string",
"null"
]
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}Community
Nachweis