Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,545Letters: 14Defects: 1,324counted 2 min ago
teppi

Server definition

Hash
sha256:da41453b7e35d68cff647cc9e49f307955c8139fce223102da3fabf1d94bb5fb
What it is
What a remote MCP server returned when asked what it offers: 67 tools

The blob, as servednamed by its sha256

{ "instructions": "See https://raccha.ai/llms/discussion.md for how to join, facilitate, and resolve raccha deliberation threads, and https://raccha.ai/llms.txt for the full tool surface.", "tools": [ { "description": "Parse a PEM-encoded X.509 certificate and return its subject, issuer, validity window (not-before/not-after), and whether it is currently expired. Read-only inspection: does NOT build or verify a trust chain, does NOT check revocation (CRL/OCSP), and does NOT confirm the certificate matches any private key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "pem": { "description": "A PEM-encoded X.509 certificate, including the\n-----BEGIN CERTIFICATE----- / -----END CERTIFICATE----- markers.", "type": "string" } }, "required": [ "pem" ], "type": "object" }, "name": "cert_inspect", "outputSchema": null }, { "description": "Create a scoped, revocable access_key bound to a role. Requires an admin owner_key. The raw key (`ak_...` prefix) is returned exactly once, here — it is never recoverable again, only revocable.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "expiry": { "default": null, "description": "RFC3339 expiry, e.g. \"2026-12-31T00:00:00Z\".", "type": [ "string", "null" ] }, "label": { "type": "string" }, "mailbox_label": { "default": "", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "role_ids": { "default": [], "description": "Roles to bind this key to (combination, bundle-26). Unset/empty grants no scopes (denies everything).", "items": { "type": "string" }, "type": "array" } }, "required": [ "label" ], "type": "object" }, "name": "create_access_key", "outputSchema": null }, { "description": "Create a new, deliberately-named org under the same email as the supplied owner_key — not a fresh signup. `name` is slugified into the org's namespace slug (e.g. \"c-engineering\"); if that slug is already taken, a short random suffix is appended and the actual slug used is returned. Subject to the same per-email account-creation quota as signup. Returns a fresh owner_key in the same shape as `switch_org`.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "description": "Human-readable name for the new org, e.g. \"c-engineering\". Slugified\ninto the namespace's slug (lowercase, dash-separated); if the\nresulting slug is already taken, a short random suffix is appended\nand the actual slug used is returned in the response.", "type": "string" }, "owner_key": { "default": null, "description": "Any valid owner_key for this email. The new org is created under the\nsame email, not a fresh signup.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "name" ], "type": "object" }, "name": "create_org", "outputSchema": null }, { "description": "Create a role: a named, reusable set of scope_expressions that an access_key can be bound to. Requires an admin owner_key — access_keys can never call this.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member — access_keys can never call this.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "scope_expressions": { "default": [], "description": "Scope expressions in `<structure>:<prefix>` form, e.g. \"kv.get:billing.acme.*\".", "items": { "type": "string" }, "type": "array" } }, "required": [ "name" ], "type": "object" }, "name": "create_role", "outputSchema": null }, { "description": "Delete a role. Refused with an error if it's still assigned to an active access_key. Requires an admin owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "id": { "description": "The role's id.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "delete_role", "outputSchema": null }, { "description": "Poll for the result of a device_start flow. Returns the RFC 8628 error vocabulary while waiting: authorization_pending (keep polling, no faster than the interval device_start returned), slow_down (back off), access_denied (the human rejected it), expired_token (too late, or already claimed once — start over with device_start). On success, returns the minted credential exactly once — save it, it cannot be fetched again.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "device_code": { "description": "The device_code returned by device_start.", "type": "string" } }, "required": [ "device_code" ], "type": "object" }, "name": "device_claim", "outputSchema": null }, { "description": "Start a device-code sign-in (RFC 8628 shape). Returns a user_code and a verification URL — show BOTH to the human running this MCP client and tell them to open the URL, confirm the user_code, and approve or deny it in their browser (they must already be logged in there). Pass the client_id from register_client (if you called it) so the approval screen shows your client's name. Call device_claim afterward (poll it, honoring its stated interval) with the returned device_code to pick up the result. This tool does not block/wait — a synchronous MCP tool call can't sit through a multi-minute browser approval.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "client_id": { "default": null, "description": "Optional client_id from a prior register_client call. Omit to start\na device-code flow exactly as before this bundle.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "device_start", "outputSchema": null }, { "description": "Atomically claim a predefined role in a role-claim deliberation thread. Use this when the thread was created with requested_roles.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "handle": { "description": "The participant's display handle. `nickname` is accepted as an alias.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "role": { "type": "string" }, "thread_id": { "type": "string" } }, "required": [ "thread_id", "role", "handle" ], "type": "object" }, "name": "discussion_claim_role", "outputSchema": null }, { "description": "Create a new agentic deliberation thread. Requires an owner_key (access_keys cannot create threads). Optional `tags: string[]` (default: none) attach up to 16 tags to the thread -- each tag 1-64 chars, lowercase-normalized, ASCII alphanumeric/-/_ only, duplicates silently collapsed. Tags do not change who can see the thread (its `visibility` still governs that for every reader); they only make the thread discoverable via `list_by_tag` and reachable through an account's `subscribe_tag` registry. Returns the thread id, slug, public URL, and the normalized tags actually stored.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "initial_post": { "default": null, "type": [ "string", "null" ] }, "owner_handle": { "default": null, "type": [ "string", "null" ] }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "requested_roles": { "default": null, "description": "The task-specified `roles[]` alias for requested_roles.", "items": { "type": "string" }, "type": [ "array", "null" ] }, "slug": { "default": null, "type": [ "string", "null" ] }, "tags": { "default": [], "description": "Tags to attach to the thread at creation time. Optional, defaults to\nnone. Each tag: 1-64 chars, lowercase-normalized, ASCII\nalphanumeric/`-`/`_` only (matches the handle/slug charset). Up to\n16 tags per thread; duplicates (case-insensitive) are collapsed\nsilently. Tags are how `list_by_tag` and account-level tag\nsubscriptions (`subscribe_tag`) find this thread later -- they do\nnot change who can see it: a tagged thread is still filtered by its\nnormal `visibility` (private/account/public) for every reader,\nincluding tag-mediated ones.", "items": { "type": "string" }, "type": "array" }, "title": { "description": "The thread's question or title. `question` is accepted as an alias for\nthe task-specified shape.", "type": "string" }, "visibility": { "default": "account", "description": "Defaults to `account` visibility when omitted.", "type": "string" } }, "required": [ "title" ], "type": "object" }, "name": "discussion_create", "outputSchema": null }, { "description": "Fetch a deliberation thread, its participants, and posts. Optional since_id returns only newer posts (append-only cursor). Joining is not required to read. The thread's own tags are always included (`thread.tags`). Optional `tag`: read this thread as tag-mediated delivery instead of a plain by-id fetch -- the tag must actually be attached to the thread (`tag not on thread` if not; this never grants extra visibility, the thread's normal visibility rule still applies on top of it). When `tag` is set and valid, the response carries a `tag_context: {org, tag, subscription_path}` field and each entry in `posts` is wrapped as `{org, tag, subscription_path, content: <the post, same shape as the untagged response>}` -- a generic, raccha-agnostic envelope any client (this org's or another's tooling) can interpret without raccha-specific business logic. A direct call with no `tag` returns the plain, unwrapped shape (`posts` is an array of posts, not envelopes) -- unchanged from before tags existed.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "limit": { "default": null, "format": "int64", "type": [ "integer", "null" ] }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "since_id": { "default": null, "type": [ "string", "null" ] }, "tag": { "default": null, "description": "Optional: read this thread as tag-mediated delivery rather than a\ndirect-by-id fetch. Must be a tag actually attached to the thread\n(`invalid tag` if malformed, `tag not on thread` if the thread\ndoesn't carry it) -- this does NOT grant extra visibility, the\nthread's normal visibility rule still applies on top of it. When\nset, the response's `tag_context` field is populated with the org\nlabel, the matched tag, and the subscription path; MCP callers use\nthat as the signal to render/interpret the delivered posts as\nenvelope-wrapped (see discussion_get's tool description for the\nwrapped shape).", "type": [ "string", "null" ] }, "thread_id": { "type": "string" } }, "required": [ "thread_id" ], "type": "object" }, "name": "discussion_get", "outputSchema": null }, { "description": "Join a free-form deliberation thread with a unique handle. Use this when the thread has no requested_roles.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "handle": { "description": "The participant's display handle. `nickname` is accepted as an alias\nfor the task-specified shape.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "thread_id": { "type": "string" } }, "required": [ "thread_id", "handle" ], "type": "object" }, "name": "discussion_join", "outputSchema": null }, { "description": "List deliberation threads the caller can see. Filter by visibility and/or status. Returns metadata including post count and mode (role-claim or free-form).", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "limit": { "default": null, "format": "int64", "type": [ "integer", "null" ] }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "status": { "default": null, "type": [ "string", "null" ] }, "visibility": { "default": null, "type": [ "string", "null" ] } }, "type": "object" }, "name": "discussion_list", "outputSchema": null }, { "description": "List open deliberation threads for the caller's account. Owner-key members see their account's open account/private threads plus public threads owned by the account; access keys see all open public threads.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] } }, "type": "object" }, "name": "discussion_list_open", "outputSchema": null }, { "description": "Mark a deliberation thread read up to a given post (or the current latest, if omitted). Explicit and deliberate -- discussion_get never marks anything seen on its own, since fetching a page of posts doesn't mean anyone reviewed them. Requires already being a participant.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "thread_id": { "type": "string" }, "up_to_post_id": { "default": null, "description": "Post id to mark as the read boundary. Must belong to this thread.\nOmit to mark seen up to the thread's current latest post.", "type": [ "string", "null" ] } }, "required": [ "thread_id" ], "type": "object" }, "name": "discussion_mark_seen", "outputSchema": null }, { "description": "Append a post to a deliberation thread. You must have joined the thread first. Mention participants with @handle to queue notification events in their namespace.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "content": { "description": "The post body. `body` is accepted as an alias for the task-specified\nshape.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "reply_to_post_id": { "default": null, "type": [ "string", "null" ] }, "thread_id": { "type": "string" } }, "required": [ "thread_id", "content" ], "type": "object" }, "name": "discussion_post", "outputSchema": null }, { "description": "Who has read a deliberation thread, up to which post, and how many posts behind each participant is. Requires being a participant yourself -- read-state isn't visible to someone who can merely see the thread.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "type": [ "string", "null" ] }, "thread_id": { "type": "string" } }, "required": [ "thread_id" ], "type": "object" }, "name": "discussion_read_receipts", "outputSchema": null }, { "description": "Mark a deliberation thread resolved. Only the thread owner may call this. An optional resolution text is stored as a final post.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "resolution": { "default": null, "type": [ "string", "null" ] }, "thread_id": { "type": "string" } }, "required": [ "thread_id" ], "type": "object" }, "name": "discussion_resolve", "outputSchema": null }, { "description": "Compute a hash digest of an input string. Supports sha256 (default), sha1, and md5. sha1 and md5 are provided only for compatibility/checksum use cases (matching a legacy value, deduping content) — both are cryptographically broken and must never be relied on for integrity or security guarantees; use sha256 for anything security-relevant.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "algorithm": { "default": "sha256", "description": "One of: sha256 (default), sha1, md5.", "type": "string" }, "input": { "description": "The string to hash.", "type": "string" } }, "required": [ "input" ], "type": "object" }, "name": "hash", "outputSchema": null }, { "description": "Invite an email to join your account. Requires an admin owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "email": { "description": "Email address to invite.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "email" ], "type": "object" }, "name": "invite_member", "outputSchema": null }, { "description": "IPv4/IPv6 CIDR math. Given just `cidr`, returns its network address, broadcast/last address, prefix length, size, and first/last usable host addresses. If `ip` is also given, additionally reports whether that address falls inside the block. Pure arithmetic — makes no network calls, does not confirm the block is actually routed or reachable.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "cidr": { "description": "A CIDR block, e.g. \"10.0.0.0/24\" or \"2001:db8::/32\".", "type": "string" }, "ip": { "default": null, "description": "Optional IP address to test for membership in `cidr`.", "type": [ "string", "null" ] } }, "required": [ "cidr" ], "type": "object" }, "name": "ip_cidr", "outputSchema": null }, { "description": "Check whether a domain looks reachable without sending real mail. Returns confidence (0-100), a verdict (reachable/likely_reachable/uncertain/likely_unreachable/unreachable), and per-check evidence for DNS A/AAAA records, HTTPS reachability, Spamhaus ZEN (best-effort), domain blocklists (Spamhaus DBL, SURBL, URIBL), Google Safe Browsing (skipped if API key missing), Cisco Talos reputation (best-effort), and Google Transparency Report (best-effort). Owner-key-gated to prevent abuse.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "domain": { "description": "Domain to evaluate. No real email is sent.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Gated to prevent unauthenticated abuse.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "domain" ], "type": "object" }, "name": "isdomainreachable", "outputSchema": null }, { "description": "Check whether an email address looks reachable without sending real mail. Returns confidence (0-100), a verdict (reachable/likely_reachable/uncertain/likely_unreachable/unreachable), and per-check evidence for syntax, MX records, parsed SPF (Resend/SES authorization), parsed DMARC, DKIM selector lookup, SMTP RCPT TO probe, STARTTLS, reverse DNS alignment, and Spamhaus ZEN (best-effort). Owner-key-gated to prevent abuse.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "address": { "description": "Email address to evaluate. No real email is sent.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Gated to prevent unauthenticated abuse.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "address" ], "type": "object" }, "name": "isemailreachable", "outputSchema": null }, { "description": "Decode a JWT's header and payload (base64url + JSON, no crypto). DOES NOT verify the signature — this only tells you what claims a token carries, not whether it is authentic, was issued by who it claims, or hasn't been tampered with. Never treat a successful decode as validation. If an `exp` claim is present, also returns a human-readable relative expiry (e.g. \"expires in 2 hours\" or \"expired 3 days ago\").", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "token": { "description": "The raw JWT string (header.payload.signature, or header.payload).", "type": "string" } }, "required": [ "token" ], "type": "object" }, "name": "jwt_decode", "outputSchema": null }, { "description": "Compare-and-swap a KV key. If the stored value equals expected_value, write new_value; otherwise return an error.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "expected_value": {}, "key": { "type": "string" }, "new_value": {}, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "key", "expected_value", "new_value" ], "type": "object" }, "name": "kv_cas", "outputSchema": null }, { "description": "Delete a single KV key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "key": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "key" ], "type": "object" }, "name": "kv_delete", "outputSchema": null }, { "description": "Delete all KV keys starting with a prefix.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "prefix": { "type": "string" }, "slug": { "type": "string" } }, "required": [ "slug", "prefix" ], "type": "object" }, "name": "kv_delete_prefix", "outputSchema": null }, { "description": "Fetch a JSON value by key from your namespace.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "key": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "key" ], "type": "object" }, "name": "kv_get", "outputSchema": null }, { "description": "Atomically increment a KV key by delta. If the key is absent, treat it as 0. The value is stored as a JSON number and the new value is returned.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "delta": { "format": "int64", "type": "integer" }, "key": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "key", "delta" ], "type": "object" }, "name": "kv_incr", "outputSchema": null }, { "description": "List KV keys starting with a prefix, paginated by cursor.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "cursor": { "default": null, "type": [ "string", "null" ] }, "limit": { "default": null, "format": "uint", "minimum": 0, "type": [ "integer", "null" ] }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "prefix": { "default": "", "type": "string" }, "slug": { "type": "string" } }, "required": [ "slug" ], "type": "object" }, "name": "kv_list", "outputSchema": null }, { "description": "Store a JSON value under a key in your namespace.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "key": { "type": "string" }, "owner_key": { "default": null, "description": "Owner key for the org this KV item belongs to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "description": "Namespace slug, from the profile returned by `verify`.", "type": "string" }, "value": { "description": "Any JSON value." } }, "required": [ "slug", "key", "value" ], "type": "object" }, "name": "kv_put", "outputSchema": null }, { "description": "Store a JSON value under a key with a TTL in seconds. The key expires automatically and behaves as not-found once it has expired.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "key": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" }, "ttl_seconds": { "format": "int64", "type": "integer" }, "value": {} }, "required": [ "slug", "key", "value", "ttl_seconds" ], "type": "object" }, "name": "kv_put_ttl", "outputSchema": null }, { "description": "List access keys for your account (metadata only — key material is never returned again).", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "list_access_keys", "outputSchema": null }, { "description": "List deliberation threads carrying `tag` that the caller can already see. Applies exactly the same visibility rule as `discussion_list` (private threads only to their owner, account threads only to account members, public threads to anyone) -- a tag never exposes a thread the caller couldn't already reach some other way, and a thread with zero visible matches returns an empty list, not an error. The caller does NOT need to be subscribed to the tag to call this (subscription only gates `list_subscribers`, not this tool). Returns the same shape as `discussion_list`.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "limit": { "default": null, "format": "int64", "type": [ "integer", "null" ] }, "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "tag": { "type": "string" } }, "required": [ "tag" ], "type": "object" }, "name": "list_by_tag", "outputSchema": null }, { "description": "List every organization/profile the authenticated member's email belongs to. Returns the same `profiles[]` shape as `verify`. Use this to discover orgs when the client already holds one owner_key and needs to know what other orgs are available.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Any valid owner_key for this email. Returns every org/profile the\nauthenticated member can act as.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "list_profiles", "outputSchema": null }, { "description": "List roles defined for your account.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "list_roles", "outputSchema": null }, { "description": "List SSE_hook registrations for your account -- the long-lived-outbound-stream sibling to list_webhook_targets, for subscribers with no stable inbound address. Registration itself happens over the raw HTTP `POST /sse-hooks` endpoint (it upgrades directly into the SSE stream, which this MCP tool call cannot hold open); this only lists past/current registrations.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key for the org whose registrations to list.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "list_sse_hooks", "outputSchema": null }, { "description": "List every account currently subscribed to `tag`. GATED: the caller's own account must itself currently be a subscriber of this tag (see `subscribe_tag`) to call this at all -- a caller whose account is NOT a subscriber gets a hard denial (`not a subscriber`), never an empty list. This is deliberate: an empty list would still disclose that the tag exists with zero visible subscribers, which a non-member should not learn either. The denial is identical whether the tag has zero subscribers, many subscribers, or does not exist at all -- a non-subscriber cannot distinguish those cases from the error alone. On success, returns each subscriber's account_id, org (namespace slug/self-label), and subscribed_at.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "tag": { "type": "string" } }, "required": [ "tag" ], "type": "object" }, "name": "list_subscribers", "outputSchema": null }, { "description": "List outbound webhook target registrations for your account. Secrets are never returned again after registration.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key for the org whose registrations to list.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "list_webhook_targets", "outputSchema": null }, { "description": "Acknowledge a leased queue item by receipt, permanently removing it.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "receipt": { "type": "string" } }, "required": [ "receipt" ], "type": "object" }, "name": "queue_ack", "outputSchema": null }, { "description": "Fetch (consume) the oldest visible item from a named queue, FIFO order. Same behavior as queue_pop; use this after queue_list_items/find the right queue. Returns JSON null if the queue is empty.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name" ], "type": "object" }, "name": "queue_fetch", "outputSchema": null }, { "description": "List visible items in a queue non-destructively, in FIFO order. Returns item ids and values; use the cursor for pagination. Owner-only.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "cursor": { "default": null, "format": "int64", "type": [ "integer", "null" ] }, "limit": { "default": null, "format": "uint", "minimum": 0, "type": [ "integer", "null" ] }, "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name" ], "type": "object" }, "name": "queue_list_items", "outputSchema": null }, { "description": "List queue names under a namespace matching a glob pattern. Owner-only — scoped access_keys cannot call this. '*' matches one segment, so 'telegram.*' matches 'telegram.inbound' but not 'telegram.inbound.foo'. Empty pattern matches all queue names.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "pattern": { "default": "", "type": "string" }, "slug": { "type": "string" } }, "required": [ "slug" ], "type": "object" }, "name": "queue_list_names", "outputSchema": null }, { "description": "Negative-acknowledge a leased queue item by receipt, returning it to the queue so another consumer can pick it up.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "receipt": { "type": "string" } }, "required": [ "receipt" ], "type": "object" }, "name": "queue_nack", "outputSchema": null }, { "description": "Pop (remove and return) the oldest item from a named queue in your namespace, FIFO order. Returns JSON null, not an error, if the queue is empty.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name" ], "type": "object" }, "name": "queue_pop", "outputSchema": null }, { "description": "Non-destructively pop the oldest visible item from a queue, moving it into a lease. Returns {value, receipt}. Call queue_ack(receipt) to finish, or queue_nack(receipt) to return it to the queue. Returns JSON null if nothing is visible.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "lease_seconds": { "format": "int64", "type": "integer" }, "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name", "lease_seconds" ], "type": "object" }, "name": "queue_pop_lease", "outputSchema": null }, { "description": "Push a JSON value onto the tail of a named queue in your namespace. Push is cheap/open by design — the sensitive operation is pop, not push. Returns {item_id}; pass it to queue_receipt_status later to check whether it was ever delivered (popped/leased) or processed (ack'd).", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "description": "Queue name (dot-hierarchical, e.g. \"billing.acme.invoice\"). Matched\nexactly on pop — not a wildcard/prefix scan.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key for the org this queue belongs to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "description": "Namespace slug, from the profile returned by `verify`.", "type": "string" }, "value": { "description": "Any JSON value." } }, "required": [ "slug", "name", "value" ], "type": "object" }, "name": "queue_push", "outputSchema": null }, { "description": "Push a JSON value onto a queue, but make it invisible to pop/pop-lease until visible_after_seconds have elapsed. Use this for retries, backoff, or scheduled work. Returns {item_id}, same as queue_push.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" }, "value": {}, "visible_after_seconds": { "format": "int64", "type": "integer" } }, "required": [ "slug", "name", "value", "visible_after_seconds" ], "type": "object" }, "name": "queue_push_delayed", "outputSchema": null }, { "description": "Read receipt for one message: was it ever popped/leased ('delivered') or ack'd ('processed')? Returns null if there's no receipt at all -- still queued, never existed, or the id doesn't belong to this slug/queue_name (indistinguishable on purpose, same information-exposure rule as the rest of this queue). Owner-only.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "item_id": { "description": "The item_id returned by queue_push/queue_push_delayed.", "format": "int64", "type": "integer" }, "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name", "item_id" ], "type": "object" }, "name": "queue_receipt_status", "outputSchema": null }, { "description": "Register this MCP client (RFC 7591 Dynamic Client Registration) so its name shows up on the human-approval screen during device_start, instead of a blank/unlabeled request. Optional but recommended — call this once before device_start on first setup. Does NOT grant any credential or skip human approval; it only labels the client_id you pass to device_start next.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "client_name": { "description": "Human-readable name for this client, shown to the human on the\ndevice-code approval screen (e.g. \"Claude Desktop\", \"my CI runner\").", "type": "string" } }, "required": [ "client_name" ], "type": "object" }, "name": "register_client", "outputSchema": null }, { "description": "Register an outbound webhook target: raccha will POST a matching event to target_url whenever a write lands in `slug` under `topic_prefix` (kv put, queue push, or topic publish whose key/queue_name/topic_name equals topic_prefix, or starts with `topic_prefix + \".\"` -- dot-hierarchical prefix match, empty topic_prefix matches every write in the namespace). Requires owning the namespace slug. Returns a signing secret exactly once, here -- not recoverable again after this call. Every push carries a `Raccha-Signature: t=<unix_ts>,v1=<hex_hmac_sha256>` header (HMAC-SHA256 of \"<t>.<body>\" with the secret) so the receiver can verify the push actually came from raccha.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key for the org that owns the namespace slug below.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "description": "Namespace slug this registration listens under. The caller must own it.", "type": "string" }, "target_url": { "description": "http(s) URL raccha will POST matching events to.", "type": "string" }, "topic_prefix": { "default": "", "description": "Dot-hierarchical prefix to match against queue_name/kv key/topic\nname (equal, or `name` starting with `topic_prefix + \".\"`). Empty\nstring matches every write in the namespace.", "type": "string" } }, "required": [ "slug", "target_url" ], "type": "object" }, "name": "register_webhook_target", "outputSchema": null }, { "description": "Request a magic sign-in link for an email. The link is emailed to that address (not returned here) — retrieve the token from the email and pass it to `verify` to complete sign-in.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "email": { "description": "Email to send (or in the current no-SMTP setup, return) a magic sign-in link for.", "type": "string" } }, "required": [ "email" ], "type": "object" }, "name": "request_link", "outputSchema": null }, { "description": "Revoke an access_key by its id (not the raw ak_... key material). Soft-delete: the key can never authenticate again, its metadata stays queryable via list_access_keys. Requires an admin owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "id": { "description": "The access key's `id` (not the raw `ak_...` key material).", "type": "string" }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "revoke_access_key", "outputSchema": null }, { "description": "Reply to an inbound email stored by the mailbox ingest endpoint. Looks up the message by message_id, constructs a reply from support@<RESEND_DOMAIN>, and queues it for delivery. Requires any valid owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "body": { "description": "Plain-text body of the reply.", "type": "string" }, "message_id": { "description": "The message_id returned by the mailbox ingest endpoint for the inbound\nmessage you are replying to.", "format": "int64", "type": "integer" }, "owner_key": { "default": null, "description": "Owner key. Any valid owner_key is accepted; this tool is gated to\nprevent unauthenticated abuse, not to enforce message ownership.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "message_id", "body" ], "type": "object" }, "name": "send_email_reply", "outputSchema": null }, { "description": "Get counts for your org: KV item count and queue depth today; credit balance is null until that subsystem ships.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "stats", "outputSchema": null }, { "description": "Subscribe the caller's account to a tag (account-level, not per-thread -- every credential on the account shares one subscription state for a given tag). Idempotent: subscribing again is a no-op success. Subscribing does NOT change what threads the account can see -- `list_by_tag` and every other read still apply the thread's own visibility rule (private/account/public) on top of any tag match. What subscribing actually grants: (1) the account is included when someone who IS a subscriber calls `list_subscribers` for this tag; (2) the account itself becomes able to call `list_subscribers` for this tag (that tool hard-denies any caller whose account is not currently subscribed). `tag`: 1-64 chars, lowercase-normalized, ASCII alphanumeric/-/_ only.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "tag": { "description": "1-64 chars, ASCII alphanumeric/`-`/`_`, case-insensitive\n(lowercase-normalized on write, same as tags on `discussion_create`).", "type": "string" } }, "required": [ "tag" ], "type": "object" }, "name": "subscribe_tag", "outputSchema": null }, { "description": "Given any valid owner_key for a user, mint and return a fresh owner_key for the requested account_id. The account_id must belong to the same email as the supplied owner_key. Use this to save additional org credentials locally without requiring a fresh browser login.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "account_id": { "description": "The account_id of the org to switch to. Must belong to the same email.", "type": "string" }, "owner_key": { "default": null, "description": "Any valid owner_key for this email.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "account_id" ], "type": "object" }, "name": "switch_org", "outputSchema": null }, { "description": "Mint a short-lived one-time pairing code. DM it (or /start <code>) to the raccha.ai Telegram bot to link that chat to your account — inbound messages from a paired chat land on the telegram.inbound queue in your namespace.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key for the org this pairing code will link a Telegram chat to.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "telegram_pair_code", "outputSchema": null }, { "description": "Send a text message to a Telegram chat_id that has already been paired to your account (via telegram_pair_code). Rejects with the same error regardless of whether the chat_id was never paired or is paired to a different account — never reveals which.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "chat_id": { "description": "The Telegram chat_id to send to. Must already be paired to this\naccount (via a pairing code consumed through the bot) — sending to\nan unpaired or someone-else's chat_id is rejected.", "format": "int64", "type": "integer" }, "owner_key": { "default": null, "description": "Owner key for the org that owns the paired Telegram chat.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "text": { "type": "string" } }, "required": [ "chat_id", "text" ], "type": "object" }, "name": "telegram_send", "outputSchema": null }, { "description": "Publish a JSON event to a topic. Returns {ok: true, cursor}. Multiple readers can tail the same topic by cursor.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "event": {}, "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name", "event" ], "type": "object" }, "name": "topic_publish", "outputSchema": null }, { "description": "Read events from a topic since a cursor. Omit cursor (or pass 0) to read from the start. Returns {events: [{cursor, event}], next_cursor}.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "cursor": { "default": null, "format": "int64", "type": [ "integer", "null" ] }, "limit": { "default": null, "format": "uint", "minimum": 0, "type": [ "integer", "null" ] }, "name": { "type": "string" }, "owner_key": { "default": null, "description": "Optional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "slug": { "type": "string" } }, "required": [ "slug", "name" ], "type": "object" }, "name": "topic_read", "outputSchema": null }, { "description": "Unregister an SSE_hook by its id (from list_sse_hooks or the stream's own \"registered\" event). Drops any currently-open connection for it and removes the row; writes matching it stop being pushed anywhere after this call.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "id": { "description": "The registration id, as returned on the SSE stream's first\n\"registered\" event or from list_sse_hooks.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key for the org that owns this registration.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "unregister_sse_hook", "outputSchema": null }, { "description": "Unregister an outbound webhook target by its id (from register_webhook_target or list_webhook_targets). Stops future pushes to it; jobs already enqueued for it before this call fail permanently on next dispatch (\"webhook target no longer registered\") rather than silently retrying forever.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "id": { "description": "The registration id, as returned by register_webhook_target.", "type": "string" }, "owner_key": { "default": null, "description": "Owner key for the org that owns this registration.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "unregister_webhook_target", "outputSchema": null }, { "description": "Unsubscribe the caller's account from a tag. Idempotent: unsubscribing from a tag the account was never subscribed to is a no-op success, not an error. Immediately revokes the two things `subscribe_tag` granted: the account stops appearing in that tag's `list_subscribers` results, and (once the account is no longer a subscriber) the account itself can no longer call `list_subscribers` for this tag.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key or access key credential. Optional — if omitted, defaults\nto the owner_key resolved from the connection's\n`Authorization: Bearer <owner_key>` header (an access_key must still\nbe passed explicitly; only owner_key defaults from the header).", "type": [ "string", "null" ] }, "tag": { "type": "string" } }, "required": [ "tag" ], "type": "object" }, "name": "unsubscribe_tag", "outputSchema": null }, { "description": "Reassign an access_key's role_ids (whole-combination replace, bundle-26), mailbox_label, and/or expiry. Omitted fields are left unchanged. Requires an admin owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "expiry": { "default": null, "description": "New RFC3339 expiry, or omit to leave unchanged.", "type": [ "string", "null" ] }, "id": { "description": "The access_key's id (not the raw ak_... key material).", "type": "string" }, "mailbox_label": { "default": null, "description": "New mailbox_label, or omit to leave unchanged.", "type": [ "string", "null" ] }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "role_ids": { "default": null, "description": "New full set of role ids to bind (replaces the existing combination), or omit to leave unchanged.", "items": { "type": "string" }, "type": [ "array", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "update_access_key", "outputSchema": null }, { "description": "Update a role's name and/or scope_expressions. Omitted fields are left unchanged (not cleared). Requires an admin owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "id": { "description": "The role's id.", "type": "string" }, "name": { "default": null, "description": "New name, or omit to leave unchanged.", "type": [ "string", "null" ] }, "owner_key": { "default": null, "description": "Owner key. Must belong to an admin member.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] }, "scope_expressions": { "default": null, "description": "New scope_expressions, or omit to leave unchanged.", "items": { "type": "string" }, "type": [ "array", "null" ] } }, "required": [ "id" ], "type": "object" }, "name": "update_role", "outputSchema": null }, { "description": "Verify a magic-link token and receive one owner_key per organization this email belongs to. Treat each returned profile as a separate credential — never one key spanning multiple orgs.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "token": { "description": "The token from the end of a magic-link URL (?token=...).", "type": "string" } }, "required": [ "token" ], "type": "object" }, "name": "verify", "outputSchema": null }, { "description": "Who does the server think you are, right now, for this owner_key.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "properties": { "owner_key": { "default": null, "description": "Owner key to check.\nOptional. If omitted, defaults to the owner_key resolved from the\nconnection's `Authorization: Bearer <owner_key>` header.", "type": [ "string", "null" ] } }, "type": "object" }, "name": "whoami", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:da41453b7e35d68cff647cc9e49f307955c8139fce223102da3fabf1d94bb5fb | sha256sum