Server definition
- Hash
- sha256:429edf5dc310604463c785e40b1c157a0dc53c4c7a26865b5a40cb676b720218
- What it is
- What a remote MCP server returned when asked what it offers: 10 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "Apply the Workbench profile to a target: clone the repo and install missing components (OpenCode CLI, Node/pnpm, MCP servers, skills, plugins, optional Docker). It OVERWRITES `<home>/.config/opencode/opencode.json`, copies `AGENTS.md`, resets an existing profile repo to `origin/main`, and runs global installs that need write permission (plus SSH for `mode:ssh`) and can take minutes. Writes a names-only `~/.env.workbench` (mode 600); never secret values. Consent-gated and idempotent: without `confirm:true` it returns the plan and changes nothing. Parameter semantics: `components` defaults to required+core; `workspace` defaults to `~/opencode-workbench`; `skipRepo` skips the clone/update; `profileUrl` overrides the git remote; `dryRun` returns the plan. To preview only, use plan_clone.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"components": {
"description": "Component ids to include; defaults to required+core.",
"items": {
"type": "string"
},
"type": "array"
},
"confirm": {
"description": "Set true to actually install. When absent, the call returns a plan and makes no changes.",
"type": "boolean"
},
"dryRun": {
"description": "Report only; make no changes.",
"type": "boolean"
},
"profileUrl": {
"description": "Override profile git URL.",
"type": "string"
},
"skipRepo": {
"description": "Do not clone/update the profile repo on the target.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Target directory for the profile repo.",
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "apply_clone",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"configPath": {
"description": "Path of the written opencode.json.",
"type": "string"
},
"degraded": {
"description": "Capabilities disabled because required credentials are absent; fill the named env vars to enable them.",
"items": {
"additionalProperties": false,
"properties": {
"id": {
"type": "string"
},
"reason": {
"type": "string"
}
},
"required": [
"id",
"reason"
],
"type": "object"
},
"type": "array"
},
"dryRun": {
"description": "True when the run made no changes.",
"type": "boolean"
},
"envPath": {
"description": "Path of the written ~/.env.workbench template.",
"type": "string"
},
"envVars": {
"description": "Environment variable names listed in the env template.",
"items": {
"type": "string"
},
"type": "array"
},
"installed": {
"description": "Components installed, with exit codes and output.",
"items": {
"additionalProperties": false,
"properties": {
"code": {
"description": "Exit code of the install step.",
"type": "number"
},
"id": {
"description": "Component id installed.",
"type": "string"
},
"output": {
"description": "Captured install output (truncated).",
"type": "string"
}
},
"required": [
"id",
"code",
"output"
],
"type": "object"
},
"type": "array"
},
"model": {
"description": "Default model selected for the target (DeepSeek when its key is present, else the OpenCode Zen free floor).",
"type": "string"
},
"plan": {
"additionalProperties": false,
"description": "Presented when confirmation is required.",
"properties": {
"commands": {
"description": "Privileged command preview per component.",
"items": {
"additionalProperties": false,
"properties": {
"command": {
"type": "string"
},
"id": {
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"type": "array"
},
"toInstall": {
"description": "Component ids that would be installed.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"toInstall",
"commands"
],
"type": "object"
},
"providerMode": {
"description": "Which provider the model resolves to.",
"enum": [
"deepseek",
"zen",
"degraded"
],
"type": "string"
},
"requiresConfirmation": {
"description": "True when the call returned a plan without applying; re-call with confirm:true to install.",
"type": "boolean"
},
"skipped": {
"description": "Component ids skipped (already present or manual).",
"items": {
"type": "string"
},
"type": "array"
},
"target": {
"description": "Label of the target.",
"type": "string"
},
"workspace": {
"description": "Directory where the profile repo was cloned.",
"type": "string"
}
},
"required": [
"target",
"workspace",
"configPath",
"envPath",
"installed",
"skipped",
"envVars",
"dryRun",
"model",
"providerMode",
"degraded"
],
"type": "object"
}
},
{
"description": "Describe this MCP server from its bundled profile without contacting any target or making a network call: repository URL, the default component set, components grouped by tier (required/core/optional), and optional MCP add-ons. It takes no parameters, is always safe, and returns instantly. Use it first to resolve a component id for install_component/remove_component/update_component or to see available add-ons; use inspect_target for a machine's live state.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "describe_workbench",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"components": {
"description": "Every component with id, tier and description.",
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "What the component provides.",
"type": "string"
},
"id": {
"description": "Component identifier — pass this to install_component.",
"type": "string"
},
"manual": {
"description": "True when the step cannot be fully automated.",
"type": "boolean"
},
"tier": {
"description": "Component tier.",
"enum": [
"required",
"core",
"optional"
],
"type": "string"
},
"title": {
"description": "Human-readable component name.",
"type": "string"
}
},
"required": [
"id",
"title",
"tier",
"description",
"manual"
],
"type": "object"
},
"type": "array"
},
"defaultComponents": {
"description": "Component ids installed by default.",
"items": {
"type": "string"
},
"type": "array"
},
"optionalMcp": {
"description": "Optional MCP add-on ids available in the profile.",
"items": {
"type": "string"
},
"type": "array"
},
"packageRoot": {
"description": "Filesystem path of the installed package.",
"type": "string"
},
"repo": {
"description": "Web URL of the workbench repository.",
"type": "string"
},
"repoGit": {
"description": "Git clone URL of the workbench repository.",
"type": "string"
}
},
"required": [
"repo",
"repoGit",
"packageRoot",
"defaultComponents",
"optionalMcp",
"components"
],
"type": "object"
}
},
{
"description": "Probe one Linux machine — this host (`local`) or a remote host over SSH (`ssh`) — and report its OS, kernel, architecture, package manager, Node/npm, OpenCode, Docker, and per-tool detection flags, plus the names (never values) of credentials present. Read-only: it runs one shell probe as the target user (over SSH when `mode:ssh`), installs nothing, writes nothing, contacts no external service, and can take a few seconds per hop. Parameter semantics: `target.mode` selects local vs ssh (default `local`); `target.host` is required only for ssh; `target.user` defaults to the ssh config/current user; `target.cwd` sets the directory for relative checks; `target.port`/`identityFile` pass straight to ssh. Use it to see what a clone would touch, then plan_clone to turn that into an ordered plan and apply_clone to perform it.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "inspect_target",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"arch": {
"description": "CPU architecture (e.g. x86_64, aarch64).",
"type": "string"
},
"configDir": {
"description": "OpenCode config directory on the target.",
"type": "string"
},
"dockerRunning": {
"description": "Whether the Docker daemon is reachable.",
"type": "boolean"
},
"envPresent": {
"description": "Space-separated names of credentials present on the target (values are never read).",
"type": "string"
},
"has": {
"additionalProperties": {
"type": "boolean"
},
"description": "Detection flags for git, curl, node, npm, corepack, pnpm, docker, uv, gh, opencode, sudo.",
"propertyNames": {
"type": "string"
},
"type": "object"
},
"home": {
"description": "Home directory on the target.",
"type": "string"
},
"kernel": {
"description": "Kernel name and release.",
"type": "string"
},
"nodeVersion": {
"description": "Installed Node.js version, if any.",
"type": "string"
},
"npmModules": {
"description": "npm global modules directory.",
"type": "string"
},
"opencodeBin": {
"description": "Path to the opencode binary, if installed.",
"type": "string"
},
"osId": {
"description": "OS identifier (e.g. ubuntu, debian, rhel).",
"type": "string"
},
"osName": {
"description": "Human-readable OS name.",
"type": "string"
},
"osVersion": {
"description": "OS version string.",
"type": "string"
},
"packageManager": {
"description": "Detected package manager (apt-get, dnf, yum, apk, pacman, zypper, or none).",
"type": "string"
},
"user": {
"description": "Detected user on the target.",
"type": "string"
},
"workspaceDefault": {
"description": "Default directory where the profile repo will be cloned.",
"type": "string"
}
},
"required": [
"user",
"home",
"workspaceDefault",
"configDir",
"has"
],
"type": "object"
}
},
{
"description": "Install a single Workbench component by id (e.g. `node`, `opencode`, `npm-mcps`, `skills`) on a target; `component` must be an id from describe_workbench. Overwrites that component's files when present (e.g. `skills`/`plugins` replace the copies under `<home>/.config/opencode`); global installs need write permission and can take minutes. Idempotent and consent-gated: without `confirm:true` it returns the plan. Parameter semantics: `component` is required; `workspace` defaults to `~/opencode-workbench`; `confirm` defaults to false (plan only). Use it for one targeted component; use apply_clone to install the full default set.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"component": {
"description": "Component id from describe_workbench.",
"type": "string"
},
"confirm": {
"description": "Set true to actually install. When absent, the call returns a plan and makes no changes.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Target directory for the profile repo.",
"type": "string"
}
},
"required": [
"target",
"component"
],
"type": "object"
},
"name": "install_component",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"configPath": {
"description": "Path of the written opencode.json.",
"type": "string"
},
"degraded": {
"description": "Capabilities disabled because required credentials are absent; fill the named env vars to enable them.",
"items": {
"additionalProperties": false,
"properties": {
"id": {
"type": "string"
},
"reason": {
"type": "string"
}
},
"required": [
"id",
"reason"
],
"type": "object"
},
"type": "array"
},
"dryRun": {
"description": "True when the run made no changes.",
"type": "boolean"
},
"envPath": {
"description": "Path of the written ~/.env.workbench template.",
"type": "string"
},
"envVars": {
"description": "Environment variable names listed in the env template.",
"items": {
"type": "string"
},
"type": "array"
},
"installed": {
"description": "Components installed, with exit codes and output.",
"items": {
"additionalProperties": false,
"properties": {
"code": {
"description": "Exit code of the install step.",
"type": "number"
},
"id": {
"description": "Component id installed.",
"type": "string"
},
"output": {
"description": "Captured install output (truncated).",
"type": "string"
}
},
"required": [
"id",
"code",
"output"
],
"type": "object"
},
"type": "array"
},
"model": {
"description": "Default model selected for the target (DeepSeek when its key is present, else the OpenCode Zen free floor).",
"type": "string"
},
"plan": {
"additionalProperties": false,
"description": "Presented when confirmation is required.",
"properties": {
"commands": {
"description": "Privileged command preview per component.",
"items": {
"additionalProperties": false,
"properties": {
"command": {
"type": "string"
},
"id": {
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"type": "array"
},
"toInstall": {
"description": "Component ids that would be installed.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"toInstall",
"commands"
],
"type": "object"
},
"providerMode": {
"description": "Which provider the model resolves to.",
"enum": [
"deepseek",
"zen",
"degraded"
],
"type": "string"
},
"requiresConfirmation": {
"description": "True when the call returned a plan without applying; re-call with confirm:true to install.",
"type": "boolean"
},
"skipped": {
"description": "Component ids skipped (already present or manual).",
"items": {
"type": "string"
},
"type": "array"
},
"target": {
"description": "Label of the target.",
"type": "string"
},
"workspace": {
"description": "Directory where the profile repo was cloned.",
"type": "string"
}
},
"required": [
"target",
"workspace",
"configPath",
"envPath",
"installed",
"skipped",
"envVars",
"dryRun",
"model",
"providerMode",
"degraded"
],
"type": "object"
}
},
{
"description": "List the credentials the profile references, which the target already provides, and how to acquire each missing one. Value-blind: it reads only whether each env var is set — no values, no network, no writes — via one read-only probe. Parameter semantics: `target` selects the machine (`local` or SSH) and its `home` sets the returned `template` path and the env file the presence check reads; there are no other parameters. Returns `present`/`missing` var-name arrays plus one guidance record per credential (`var`, `purpose`, `url`, `method`, `command`). Use it after plan_clone to see what would degrade; act on one credential with run_auth_flow.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "list_required_credentials",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"credentials": {
"description": "Every credential the profile references with its acquisition guidance.",
"items": {
"additionalProperties": false,
"properties": {
"command": {
"description": "Exact non-interactive command, when one exists.",
"type": "string"
},
"label": {
"description": "Human-readable name.",
"type": "string"
},
"method": {
"description": "Recommended acquisition method.",
"enum": [
"paste",
"oauth",
"cli",
"instruction"
],
"type": "string"
},
"optional": {
"description": "True when only a subset of tools degrades without it.",
"type": "boolean"
},
"present": {
"description": "Whether the target already provides it (value never read).",
"type": "boolean"
},
"purpose": {
"description": "What uses it.",
"type": "string"
},
"url": {
"description": "Where to create/obtain the key.",
"type": "string"
},
"var": {
"description": "Environment variable name.",
"type": "string"
}
},
"required": [
"var",
"label",
"purpose",
"method",
"present"
],
"type": "object"
},
"type": "array"
},
"missing": {
"description": "Credential names not present.",
"items": {
"type": "string"
},
"type": "array"
},
"present": {
"description": "Credential names already present on the target.",
"items": {
"type": "string"
},
"type": "array"
},
"target": {
"description": "Label of the inspected target.",
"type": "string"
},
"template": {
"description": "Path of the env file to fill in.",
"type": "string"
}
},
"required": [
"target",
"present",
"missing",
"template",
"credentials"
],
"type": "object"
}
},
{
"description": "Return a read-only plan for a target: compare it against the Workbench profile and list each component as `install`, `present`, or `manual`, with the commands that would run. It still runs a detection probe on the target (same access as inspect_target) but clones nothing and writes nothing. Parameter semantics: `components` restricts the diff to those ids (default: required+core); `workspace` sets the expected profile path on the target (default `~/opencode-workbench`); `profileUrl` overrides the git remote. Use it to preview before apply_clone, which performs the changes.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"components": {
"description": "Component ids to include; defaults to required+core.",
"items": {
"type": "string"
},
"type": "array"
},
"dryRun": {
"description": "Report only; make no changes.",
"type": "boolean"
},
"profileUrl": {
"description": "Override profile git URL.",
"type": "string"
},
"skipRepo": {
"description": "Do not clone/update the profile repo on the target.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Target directory for the profile repo.",
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "plan_clone",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"inspect": {
"additionalProperties": false,
"description": "Full inspection of the target.",
"properties": {
"arch": {
"description": "CPU architecture (e.g. x86_64, aarch64).",
"type": "string"
},
"configDir": {
"description": "OpenCode config directory on the target.",
"type": "string"
},
"dockerRunning": {
"description": "Whether the Docker daemon is reachable.",
"type": "boolean"
},
"envPresent": {
"description": "Space-separated names of credentials present on the target (values are never read).",
"type": "string"
},
"has": {
"additionalProperties": {
"type": "boolean"
},
"description": "Detection flags for git, curl, node, npm, corepack, pnpm, docker, uv, gh, opencode, sudo.",
"propertyNames": {
"type": "string"
},
"type": "object"
},
"home": {
"description": "Home directory on the target.",
"type": "string"
},
"kernel": {
"description": "Kernel name and release.",
"type": "string"
},
"nodeVersion": {
"description": "Installed Node.js version, if any.",
"type": "string"
},
"npmModules": {
"description": "npm global modules directory.",
"type": "string"
},
"opencodeBin": {
"description": "Path to the opencode binary, if installed.",
"type": "string"
},
"osId": {
"description": "OS identifier (e.g. ubuntu, debian, rhel).",
"type": "string"
},
"osName": {
"description": "Human-readable OS name.",
"type": "string"
},
"osVersion": {
"description": "OS version string.",
"type": "string"
},
"packageManager": {
"description": "Detected package manager (apt-get, dnf, yum, apk, pacman, zypper, or none).",
"type": "string"
},
"user": {
"description": "Detected user on the target.",
"type": "string"
},
"workspaceDefault": {
"description": "Default directory where the profile repo will be cloned.",
"type": "string"
}
},
"required": [
"user",
"home",
"workspaceDefault",
"configDir",
"has"
],
"type": "object"
},
"steps": {
"description": "Per-component plan.",
"items": {
"additionalProperties": false,
"properties": {
"action": {
"description": "Planned action: install, already present, or manual step.",
"enum": [
"install",
"present",
"manual"
],
"type": "string"
},
"command": {
"description": "Preview of the privileged command that would run, for consent.",
"type": "string"
},
"description": {
"description": "What the component provides.",
"type": "string"
},
"id": {
"description": "Component id.",
"type": "string"
},
"tier": {
"description": "Component tier.",
"enum": [
"required",
"core",
"optional"
],
"type": "string"
},
"title": {
"description": "Component name.",
"type": "string"
}
},
"required": [
"id",
"title",
"tier",
"action",
"description"
],
"type": "object"
},
"type": "array"
},
"target": {
"description": "Label of the inspected target.",
"type": "string"
},
"toInstall": {
"description": "Component ids that will be installed.",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"target",
"inspect",
"steps",
"toInstall"
],
"type": "object"
}
},
{
"description": "Uninstall one Workbench component by id from a target — the inverse of install_component — for a bounded, documented subset with an automated uninstall (e.g. `opencode`, `pnpm`, `npm-mcps`, `skills`, `docker-containers`); `component` must be an id from describe_workbench. Idempotent: an already-absent component reports `absent`; a component with no automated uninstall (system packages such as git/curl/node) reports `manual`. Destructive and consent-gated: without `confirm:true` it returns a preview and changes nothing, and it deletes only that component's files — never `opencode.json` or the profile repo. Parameter semantics: `workspace` sets the profile path some removals need; `dryRun` reports without changing. Use it to tear down one component; for several, call it per id.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"component": {
"description": "Component id from describe_workbench.",
"type": "string"
},
"confirm": {
"description": "Set true to actually remove. When absent, the call returns a preview and makes no changes.",
"type": "boolean"
},
"dryRun": {
"description": "Report the action without changing anything.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Profile repo directory (used by components whose removal needs it).",
"type": "string"
}
},
"required": [
"target",
"component"
],
"type": "object"
},
"name": "remove_component",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"action": {
"description": "What happened: removed, updated, already absent, or manual (no automated uninstall).",
"enum": [
"removed",
"updated",
"absent",
"manual"
],
"type": "string"
},
"code": {
"description": "Exit code of the action.",
"type": "number"
},
"id": {
"description": "Component id acted on.",
"type": "string"
},
"output": {
"description": "Captured output (truncated).",
"type": "string"
},
"requiresConfirmation": {
"description": "True when the call returned a preview without acting; re-call with confirm:true.",
"type": "boolean"
},
"target": {
"description": "Label of the target.",
"type": "string"
}
},
"required": [
"target",
"id",
"action",
"code",
"output"
],
"type": "object"
}
},
{
"description": "Return the acquisition plan for one credential on a target: the provider URL, the exact non-interactive command when one exists (e.g. `opencode auth login`, `opencode mcp auth vercel`, `gh auth login`), and whether it is already present. Read-only and value-blind: it emits guidance and re-checks presence with one read-only probe; it does not run the commands or handle secret values. Parameter semantics: `var` must be an env var name returned by list_required_credentials (unknown names error); `target` selects the machine and its `home` is where the value should be written. Use it for a single credential; it does not replace that listing.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"var": {
"description": "Credential env var name from list_required_credentials (e.g. OPENCODE_API_KEY).",
"type": "string"
}
},
"required": [
"target",
"var"
],
"type": "object"
},
"name": "run_auth_flow",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"command": {
"description": "Command for the agent/user to run.",
"type": "string"
},
"method": {
"description": "Acquisition method.",
"enum": [
"paste",
"oauth",
"cli",
"instruction"
],
"type": "string"
},
"next": {
"description": "What to do next.",
"type": "string"
},
"present": {
"description": "Whether the credential is present now.",
"type": "boolean"
},
"target": {
"description": "Label of the target.",
"type": "string"
},
"url": {
"description": "Provider URL to open.",
"type": "string"
},
"var": {
"description": "Credential being acquired.",
"type": "string"
},
"verified": {
"description": "True when the credential is present and ready.",
"type": "boolean"
}
},
"required": [
"target",
"var",
"method",
"present",
"verified",
"next"
],
"type": "object"
}
},
{
"description": "Update one Workbench component in place by id: re-run its install script to fetch the current version (e.g. `opencode` re-runs the official installer; `npm-mcps` reinstalls the latest globals). It OVERWRITES the component's files, needs write permission, and can take minutes for global installs; the resolved version may change. Parameter semantics: `component` must be an id from describe_workbench; `workspace` defaults to `~/opencode-workbench`; `dryRun` previews; `confirm` defaults to false — set `confirm:true` to apply. For the whole profile use apply_clone.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"component": {
"description": "Component id from describe_workbench.",
"type": "string"
},
"confirm": {
"description": "Set true to actually update. When absent, the call returns a preview and makes no changes.",
"type": "boolean"
},
"dryRun": {
"description": "Report the action without changing anything.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Profile repo directory (used by components whose update needs it).",
"type": "string"
}
},
"required": [
"target",
"component"
],
"type": "object"
},
"name": "update_component",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"action": {
"description": "What happened: removed, updated, already absent, or manual (no automated uninstall).",
"enum": [
"removed",
"updated",
"absent",
"manual"
],
"type": "string"
},
"code": {
"description": "Exit code of the action.",
"type": "number"
},
"id": {
"description": "Component id acted on.",
"type": "string"
},
"output": {
"description": "Captured output (truncated).",
"type": "string"
},
"requiresConfirmation": {
"description": "True when the call returned a preview without acting; re-call with confirm:true.",
"type": "boolean"
},
"target": {
"description": "Label of the target.",
"type": "string"
}
},
"required": [
"target",
"id",
"action",
"code",
"output"
],
"type": "object"
}
},
{
"description": "Re-check a target after a clone: return a per-component `present`/`missing` list plus whether `opencode.json` and `~/.env.workbench` exist. Read-only and idempotent: it runs a detection probe (SSH or local) and checks files, writing nothing. `target` selects the machine (`local` or SSH) and its `home` is where the `opencode.json` and `~/.env.workbench` checks run; `components` restricts the check to those ids (omit it to check every component, the default); `workspace` sets the profile path used by component checks. Use it after apply_clone and after component changes; for a pre-clone preview use plan_clone.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"components": {
"description": "Component ids to include; defaults to required+core.",
"items": {
"type": "string"
},
"type": "array"
},
"dryRun": {
"description": "Report only; make no changes.",
"type": "boolean"
},
"profileUrl": {
"description": "Override profile git URL.",
"type": "string"
},
"skipRepo": {
"description": "Do not clone/update the profile repo on the target.",
"type": "boolean"
},
"target": {
"description": "The machine to operate on: this host (local) or a remote host over SSH (ssh).",
"properties": {
"cwd": {
"description": "Working directory on the target.",
"type": "string"
},
"host": {
"description": "SSH host (required when mode=ssh).",
"type": "string"
},
"identityFile": {
"description": "SSH private key path.",
"type": "string"
},
"mode": {
"description": "Run on this machine (local) or a remote host (ssh).",
"enum": [
"local",
"ssh"
],
"type": "string"
},
"port": {
"description": "SSH port.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
},
"user": {
"description": "SSH user (defaults to ssh config / current user).",
"type": "string"
}
},
"required": [
"mode"
],
"type": "object"
},
"workspace": {
"description": "Target directory for the profile repo.",
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "verify_clone",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"components": {
"description": "Per-component presence detection.",
"items": {
"additionalProperties": false,
"properties": {
"id": {
"description": "Component id.",
"type": "string"
},
"present": {
"description": "Whether the component is detected as present.",
"type": "boolean"
}
},
"required": [
"id",
"present"
],
"type": "object"
},
"type": "array"
},
"configExists": {
"description": "Whether opencode.json exists on the target.",
"type": "boolean"
},
"envExists": {
"description": "Whether ~/.env.workbench exists on the target.",
"type": "boolean"
},
"missing": {
"description": "Component ids detected as missing.",
"items": {
"type": "string"
},
"type": "array"
},
"target": {
"description": "Label of the target.",
"type": "string"
}
},
"required": [
"target",
"configExists",
"envExists",
"components",
"missing"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:429edf5dc310604463c785e40b1c157a0dc53c4c7a26865b5a40cb676b720218 | sha256sum