Server definition
- Hash
- sha256:f814c0b40eae841ac748fdd6bdb1d314eb39a4d81d46c0ae0220497a6d6e3598
- What it is
- What a remote MCP server returned when asked what it offers: 21 tools
The blob, as servednamed by its sha256
{
"instructions": "WebRun drives a real Chrome browser in the cloud. Use browser_task for one-off tasks (creates a session, runs, auto-terminates). For multi-step interactive work: create_session, then send_task per task, then terminate_session. To run or TEST a saved workflow, always use trigger_workflow — never browser_task or create_session: only a workflow run carries the workflow's rules, tracking and memory. When the user says \"run it\", \"run it once\", \"test it\" or \"try it\" about a workflow that exists or was just created, that means trigger_workflow — \"one-off\" only ever means a task with no saved workflow behind it. After starting a task, poll get_task_status; if it reports awaiting_input, answer with guardrail_response. screenshot inspects a live session. When a result carries a liveViewURL, that is the watch-it-live page and the only URL in the response you may give the user — never hand out webRTCURL or webViewURL, which are machine endpoints that fail to open in a browser. list_sessions and list_environments show what is available. Docs: https://docs.webrun.ai\n\nWorkflows & scheduled agents — authoring posture: most users are NOT technical, so never interrogate them with configuration questions. Ask only two things, in plain words: what the automation should do, and (if it should repeat) when. Everything else you decide yourself with sensible defaults and simply state afterwards. Write CONCRETE values (group names, URLs, numbers) directly into the workflow prompt — do NOT introduce {{variables}} unless the user explicitly asks for a reusable template whose inputs change run to run. Workflows and standalone agents are created in this connection's environment automatically: never ask the user which environment to use, whether something is \"logged in\", or about dedup/polling/schema details — pick a sensible default, create the thing, and mention what you chose in one sentence. If a run then hits a login wall, WebRun reports it and the user connects the site once from the dashboard.\n\nThe TASK INTERVIEW — when to ask MORE before creating. \"What should it do\" is complete only when the runbook could be executed by a human in a browser with no follow-up questions. When a request moves data between platforms per record or per person (send/forward/resend/sync/notify — e.g. \"resend my customers the reconciled invoices\"), five facts ARE the what; collect the missing ones from the user in ONE compact round of plain-language questions, and never re-ask anything they already said: (1) SOURCE — the exact website that holds the data (\"my books\" is not enough: QuickBooks? Zoho Books? Xero?). (2) SELECTION — which records count (reconciled since when? every customer or a subset?). (3) FIELDS — what to capture per record (customer name, invoice number, amount, the invoice PDF itself?). (4) DESTINATION — the exact platform and form of delivery (a WhatsApp message per customer? one email summary to the user?). (5) THE LINK — the matching rule connecting each source record to its destination recipient: which identifier exists on BOTH sides (the customer name exactly as written in the source matched against the contact name? a phone number printed on the invoice?), and the no-match behavior (skip it and report it — NEVER deliver to a similarly-named near-match). Worked example — \"resend my customers their latest reconciled invoices\": ask which platform the invoices live in, which invoices count as ready, what each customer should receive, where to send it, and how to find each customer there (exact name from the invoice, or a phone/email on it?). Then write the answers into the prompt as concrete stages. These are business facts only the user knows — asking them is REQUIRED; asking about environments, variables, or technical settings remains forbidden.\n\nTracking (\"handle each new item once\" — new messages, don't repeat, forward once): author memoryContract, never prompt it. Its three plain-English fields, each written FOR the agent: groundRules (standing rules for every turn — what it must never do, what counts as proof a step succeeded, pacing limits), memoryInstruction (when one item counts as done, what to do when it cannot tell, and what happens to leftovers), itemIdentity (what tells one item apart from another, using only what is visible on screen, written the same way every time). The platform wires the tracking itself — create_workflow REJECTS handle-once tasks that omit the contract. Do NOT write \"check memory\" / \"record in memory\" steps into the prompt; the prompt describes only the browsing actions.\n\nThe three channels in one line: promptTemplate = what to do each run; memoryContract = how to behave and what counts as handled; memory = durable facts the agent must know or has learned (its private notebook, shown to it every run and updated automatically after each run). Good memory entries are short one-line facts — the exact description of a target picture, a user preference, a known starting state — never task steps, never tracking rules. Seed memory at create time when the task depends on a fact the first run cannot discover by itself (e.g. \"Target picture: red Hermès Birkin 25, gold hardware, handle tag\"); otherwise leave it empty and the agent maintains it. Replacing memory later via update_workflow keeps the previous version as a one-step undo.\n\nProxy country — the one setting you SHOULD raise (it is business, not config): when the automation touches a social or messaging platform (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok), tell the user in plain words that these sites tend to refuse a login or log the session out again and again when the browser looks like it is in a different country from them, recommend matching the proxy to the country they are in right now, and ask which country that is. Apply their answer as proxy {source:\"WebRun\", country:\"<2-letter code>\"} everywhere that automation runs — the session (browser_task / create_session), the workflow, and a standalone scheduled agent (create_agent in workflow mode inherits the workflow proxy instead) — and keep that country stable so every later run looks like the same place. The browser clock follows the proxy country automatically (e.g. \"de\" → Europe/Berlin) — only set timezone when the user wants a different zone. If the user declines or does not know, continue without one and say so.",
"tools": [
{
"description": "Execute a browser automation task in a real Chrome browser running in a WebRun cloud environment (docs.webrun.ai). Creates a session, runs the task, and auto-terminates. Best for simple one-off tasks that no saved workflow covers. May navigate, fill forms, and submit data on third-party websites as the task requires. Do NOT use this to run or test a saved workflow — use trigger_workflow instead: only a workflow run carries the workflow's own rules, tracking and memory, so a session run will behave differently. If the user says \"run it\", \"run it once\", \"test it\" or \"try it\" about a workflow, that means trigger_workflow, not this tool.",
"inputSchema": {
"properties": {
"debugC": {
"description": "Enable debug mode on the instance (default: false)",
"type": "boolean"
},
"environmentId": {
"description": "Environment ID for persistent profile session. Use list_environments to find available IDs. Without this, a disposable instance is used.",
"type": "string"
},
"files": {
"description": "Optional file IDs to attach: ids returned by POST /files/upload, or any file already in one of the user's environment catalogs (GET /environments/:id/files). Max 5 files.",
"items": {
"type": "string"
},
"type": "array"
},
"maxDuration": {
"description": "Max duration in minutes (default: 20, max: 60)",
"type": "number"
},
"model": {
"description": "Optional model name or profile key (from global config). Falls back to the configured default.",
"type": "string"
},
"outputSchema": {
"description": "JSON Schema for structured output (required if outputType is structured_json)",
"type": "object"
},
"outputType": {
"description": "Response format (default: text)",
"enum": [
"text",
"structured_json",
"structured_csv"
],
"type": "string"
},
"policyId": {
"description": "Policy ID to apply automation guardrails (domain restrictions, capability controls, LLM role). Optional.",
"type": "string"
},
"prompt": {
"description": "Task description in natural language",
"type": "string"
},
"proxy": {
"description": "Proxy configuration. WebRun-managed: { source: \"WebRun\", country: \"GB\" }. Custom: { source: \"custom\", type: \"http\"|\"socks\", host, port, username?, password? }. Omit for no proxy. Social/messaging automation (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok): prefer country = the country the user is in right now — recommend it and confirm the country with them first; a mismatch is the usual cause of refused logins and sessions that log out repeatedly.",
"properties": {
"country": {
"description": "ISO country code for WebRun proxy (e.g. \"GB\", \"US\") or \"random\" for a random country with good connectivity",
"type": "string"
},
"host": {
"description": "Custom proxy host",
"type": "string"
},
"level": {
"description": "Proxy level. \"chrome\" (default) applies proxy via browser extension (instant, no swap). \"system\" launches Chrome with --proxy-server flag (requires instance swap).",
"enum": [
"system",
"chrome"
],
"type": "string"
},
"password": {
"description": "Custom proxy password (optional)",
"type": "string"
},
"port": {
"description": "Custom proxy port",
"type": "number"
},
"source": {
"description": "Proxy provider",
"enum": [
"WebRun",
"custom"
],
"type": "string"
},
"type": {
"description": "Custom proxy type",
"enum": [
"http",
"socks"
],
"type": "string"
},
"username": {
"description": "Custom proxy username (optional)",
"type": "string"
}
},
"type": "object"
},
"reach_out_mode": {
"description": "Controls proactive chat-platform messages (Telegram/WhatsApp/Slack/Discord/Teams) to bot users on the same environment. Default: \"off\" — no messages are sent unless this is set explicitly. \"guardrail_only\" forwards guardrail prompts (CAPTCHA/2FA/verification) to chat when the API caller is offline. \"full\" also forwards the task result on completion. Each bot user additionally filters by their own reachOutMode preference.",
"enum": [
"off",
"guardrail_only",
"full"
],
"type": "string"
},
"secrets": {
"description": "Domain-matched secrets [{match, fields}] passed to instance (not stored)",
"items": {
"type": "object"
},
"type": "array"
},
"startingUrl": {
"description": "Optional starting URL",
"type": "string"
},
"timezone": {
"description": "IANA timezone name for the session, e.g. \"America/New_York\", \"Europe/London\", \"Asia/Tokyo\". Date/time-sensitive instructions (e.g. \"tomorrow morning\", \"today\", \"in 2 hours\") are interpreted in this timezone. When omitted, follows the WebRun proxy country if one is set (e.g. country \"de\" → Europe/Berlin); otherwise the browser default.",
"type": "string"
},
"webhook": {
"description": "Webhook configuration for task completion notification",
"properties": {
"auth": {
"description": "Authorization header value",
"type": "string"
},
"name": {
"description": "Webhook identifier",
"type": "string"
},
"submittedData": {
"description": "Payload type",
"enum": [
"full_response",
"structured_output",
"just_ping"
],
"type": "string"
},
"url": {
"description": "HTTPS URL to receive webhook",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"prompt"
],
"type": "object"
},
"name": "browser_task",
"outputSchema": {
"additionalProperties": true,
"description": "Task outcome envelope: a completion (success/type/data), a pending marker (poll get_task_status), or an awaiting_input guardrail. `data` is the task output; its shape is task-defined (freeform text or the caller-supplied structured schema).",
"properties": {
"data": {
"additionalProperties": true,
"description": "Task output payload (instance-authored shape)",
"type": "object"
},
"environment": {
"properties": {
"environmentId": {
"type": "string"
},
"name": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"error": {
"type": "string"
},
"liveViewURL": {
"description": "Page for watching the run live, present while it is still running or awaiting input. The only URL here that is safe to show a user or open in a browser.",
"type": "string"
},
"message": {
"type": "string"
},
"pending": {
"description": "True when the task is still running — poll get_task_status",
"type": "boolean"
},
"sessionId": {
"type": "string"
},
"status": {
"description": "Present on guardrail results: 'awaiting_input'",
"type": "string"
},
"success": {
"type": "boolean"
},
"taskId": {
"type": [
"string",
"null"
]
},
"type": {
"description": "Result type, e.g. 'task_completed', 'task_failed', 'guardrail_trigger'",
"type": "string"
}
},
"type": "object"
}
},
{
"description": "Create a scheduled agent — a recurring or one-time automation that runs on a timer in a real Chrome browser. Two modes. WORKFLOW MODE: pass workflowId plus a schedule — the platform copies everything else (prompt, starting URL, output contract, model, proxy, policy, files) from the workflow and bakes your variables into the prompt; results and memory stay centralised on the workflow. STANDALONE MODE: omit workflowId and provide name, prompt (a Goal / Ground rules / Stages / Output browsing runbook — see the prompt field description), and a schedule; the connection's environment is used automatically. Ask the user only what it should do and when it should run, in plain language — pick sensible defaults for everything else and state them; never ask about environments or technical settings. Results are delivered to your connected chat and appear in session history.",
"inputSchema": {
"description": "Two modes: pass workflowId to deploy a workflow (everything else about the run is copied from it), or omit workflowId and provide name + prompt for a standalone agent. schedule is required in both.",
"properties": {
"environmentId": {
"description": "STANDALONE MODE, rarely needed — OMIT it: the connection-bound environment (or your only one) is applied automatically; never ask the user to choose. Workflow mode always uses the workflow's deployed environment.",
"type": "string"
},
"expiresAt": {
"description": "ISO 8601 date-time after which the agent auto-pauses (recurring schedules).",
"type": "string"
},
"memory": {
"description": "STANDALONE MODE: the agent's private notebook, shown to it every run and updated automatically after each run. Seed ONLY durable facts the next run must know (target descriptions, preferences, known state) — one short line each. Task steps belong in prompt, not here. Usually best left empty.",
"maxLength": 10000,
"type": "string"
},
"name": {
"description": "Agent name. Required standalone; defaults to the workflow title in workflow mode.",
"maxLength": 100,
"type": "string"
},
"outputSchema": {
"description": "STANDALONE MODE: JSON Schema object (structured) or column-name array (structured_csv).",
"type": [
"object",
"array"
]
},
"outputType": {
"description": "STANDALONE MODE: output contract (same rules as create_workflow).",
"enum": [
"text",
"structured",
"structured_csv"
],
"type": "string"
},
"prompt": {
"description": "STANDALONE MODE (required there): The task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):` — bullet invariants when the task needs them, e.g. work one item at a time — never batch; only record a figure you can read on screen this turn — if it is not shown record it as \"not stated\", never estimate; keep a running tally and restate it every turn (\"captured C items · written R rows\"). Then `Stage N — <Site name> (<https://url>)` — one section per website or phase, listing the concrete steps to take in the browser (open/navigate, click, read, capture, compare, flag) in the order a person would do them, each stage ending with `Done when: <verifiable completion condition>`. Finish with `Output —` stating exactly what to produce or deliver once the final tally is met, including what to say when there is no data (never fabricate a row). When a stage delivers per-recipient (message/email each customer), state the MATCHING RULE in that stage — the identifier shared by the source record and the destination recipient (e.g. the customer name exactly as written in the source, matched against the contact name) — and the no-match branch: skip it and report it, never deliver to a similarly-named near-match. Write the user's CONCRETE values (group names, URLs, numbers) directly into the text; use {{variables}} ONLY when the user explicitly wants a reusable template whose inputs change per run. A short single-site task can be just a Goal plus its steps. PURE TASK ONLY — never write memory bookkeeping into the prompt (no \"check memory\", \"record in memory\", \"store in memory\" steps): tracking is authored in memoryContract and WebRun applies it to every run automatically.",
"maxLength": 5000,
"type": "string"
},
"proxy": {
"description": "STANDALONE MODE (workflow mode inherits the workflow proxy instead): Proxy for runs. {source:\"WebRun\", country?} or {source:\"custom\", type:\"http\"|\"socks\", host, port, username?, password?}. Custom passwords are encrypted at rest and never returned. Social/messaging workflows (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok): set country to the country the user is in right now — recommend it and confirm the country with them first; a mismatch is the usual cause of refused logins and sessions that log out repeatedly, and a scheduled workflow re-hits it every run, so keep the country stable once set.",
"properties": {
"country": {
"description": "2-letter ISO code or \"random\" (WebRun).",
"type": "string"
},
"host": {
"type": "string"
},
"level": {
"enum": [
"system",
"chrome"
],
"type": "string"
},
"password": {
"type": "string"
},
"port": {
"type": "number"
},
"source": {
"enum": [
"WebRun",
"custom"
],
"type": "string"
},
"type": {
"enum": [
"http",
"socks"
],
"type": "string"
},
"username": {
"type": "string"
}
},
"type": "object"
},
"schedule": {
"description": "When the agent fires. Required.",
"properties": {
"at": {
"description": "ISO 8601 date-time (type \"at\").",
"type": "string"
},
"cron": {
"description": "5-field cron expression (type \"cron\").",
"type": "string"
},
"interval": {
"description": "Repeat interval in ms, min 60000 (type \"every\").",
"type": "number"
},
"timezone": {
"description": "IANA timezone for the schedule (drives fire times AND the browser session). Default UTC.",
"type": "string"
},
"type": {
"description": "'at' = once at a specific time; 'every' = fixed interval; 'cron' = cron expression.",
"enum": [
"at",
"every",
"cron"
],
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
},
"startingUrl": {
"description": "STANDALONE MODE: page Chrome opens at the start of each run.",
"type": "string"
},
"variables": {
"additionalProperties": {
"type": "string"
},
"description": "WORKFLOW MODE, and only when the workflow's prompt actually contains {{variables}}: values for them, BAKED IN at deploy and reused every run (stored variableValues defaults fill gaps). Every template variable must be covered — an unattended agent cannot ask later. Workflows with concrete prompts need nothing here.",
"type": "object"
},
"workflowId": {
"description": "WORKFLOW MODE: 24-hex id of the workflow to deploy (from list_workflows). The prompt, starting URL, output contract, model, proxy, policy, and files are all copied from it.",
"type": "string"
}
},
"required": [
"schedule"
],
"type": "object"
},
"name": "create_agent",
"outputSchema": {
"properties": {
"agentId": {
"type": "string"
},
"mode": {
"enum": [
"workflow",
"standalone"
],
"type": "string"
},
"name": {
"type": "string"
},
"nextRunAt": {
"description": "ISO 8601 timestamp of the first fire",
"type": [
"string",
"null"
]
},
"notes": {
"items": {
"type": "string"
},
"type": "array"
},
"schedule": {
"description": "Humanized schedule",
"type": "string"
},
"success": {
"type": "boolean"
},
"timezone": {
"type": "string"
},
"workflow": {
"description": "Present in workflow mode: the workflow this agent was deployed from",
"properties": {
"title": {
"type": "string"
},
"workflowId": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"success",
"agentId",
"name",
"mode"
],
"type": "object"
}
},
{
"description": "Create a persistent session in a real Chrome browser running in a WebRun cloud environment (docs.webrun.ai), for multi-step interactive work. Returns a sessionId for subsequent commands. With an initial task the browser may act on third-party websites immediately. Do NOT use this to run or test a saved workflow — use trigger_workflow instead: only a workflow run carries the workflow's own rules, tracking and memory, so a session run will behave differently.",
"inputSchema": {
"properties": {
"debugC": {
"description": "Enable debug mode on the instance (default: false)",
"type": "boolean"
},
"environmentId": {
"description": "Environment ID for persistent profile session. Use list_environments to find available IDs. Without this, a disposable instance is used.",
"type": "string"
},
"mode": {
"description": "Session mode (default: default)",
"type": "string"
},
"model": {
"description": "Optional model name or profile key (from global config). Falls back to the configured default.",
"type": "string"
},
"policyId": {
"description": "Policy ID to apply automation guardrails (domain restrictions, capability controls, LLM role). Optional.",
"type": "string"
},
"proxy": {
"description": "Proxy configuration. WebRun-managed: { source: \"WebRun\", country: \"GB\" }. Custom: { source: \"custom\", type: \"http\"|\"socks\", host, port, username?, password? }. Omit for no proxy. Social/messaging automation (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok): prefer country = the country the user is in right now — recommend it and confirm the country with them first; a mismatch is the usual cause of refused logins and sessions that log out repeatedly.",
"properties": {
"country": {
"description": "ISO country code for WebRun proxy (e.g. \"GB\", \"US\") or \"random\" for a random country with good connectivity",
"type": "string"
},
"host": {
"description": "Custom proxy host",
"type": "string"
},
"level": {
"description": "Proxy level. \"chrome\" (default) applies proxy via browser extension (instant, no swap). \"system\" launches Chrome with --proxy-server flag (requires instance swap).",
"enum": [
"system",
"chrome"
],
"type": "string"
},
"password": {
"description": "Custom proxy password (optional)",
"type": "string"
},
"port": {
"description": "Custom proxy port",
"type": "number"
},
"source": {
"description": "Proxy provider",
"enum": [
"WebRun",
"custom"
],
"type": "string"
},
"type": {
"description": "Custom proxy type",
"enum": [
"http",
"socks"
],
"type": "string"
},
"username": {
"description": "Custom proxy username (optional)",
"type": "string"
}
},
"type": "object"
},
"reach_out_mode": {
"description": "Controls proactive chat-platform messages (Telegram/WhatsApp/Slack/Discord/Teams) to bot users on the same environment. Default: \"off\" — no messages are sent unless this is set explicitly. \"guardrail_only\" forwards guardrail prompts (CAPTCHA/2FA/verification) to chat when the API caller is offline. \"full\" also forwards the task result on completion. Each bot user additionally filters by their own reachOutMode preference.",
"enum": [
"off",
"guardrail_only",
"full"
],
"type": "string"
},
"task": {
"description": "Initial task configuration",
"properties": {
"files": {
"description": "Optional file IDs to attach: ids returned by POST /files/upload, or any file already in one of the user's environment catalogs (GET /environments/:id/files). Max 5 files.",
"items": {
"type": "string"
},
"type": "array"
},
"maxDuration": {
"description": "Max duration in minutes",
"type": "number"
},
"outputSchema": {
"description": "JSON Schema for structured output (required if outputType is structured_json)",
"type": "object"
},
"outputType": {
"description": "Response format",
"enum": [
"text",
"structured_json",
"structured_csv"
],
"type": "string"
},
"prompt": {
"description": "Task description",
"type": "string"
},
"secrets": {
"description": "Domain-matched secrets [{match, fields}] (not stored)",
"items": {
"type": "object"
},
"type": "array"
},
"startingUrl": {
"description": "Starting URL",
"type": "string"
},
"terminateOnCompletion": {
"description": "Auto-terminate after task",
"type": "boolean"
},
"webhook": {
"description": "Webhook configuration",
"type": "object"
}
},
"type": "object"
},
"timezone": {
"description": "IANA timezone name for the session, e.g. \"America/New_York\", \"Europe/London\", \"Asia/Tokyo\". Date/time-sensitive instructions (e.g. \"tomorrow morning\", \"today\", \"in 2 hours\") are interpreted in this timezone. When omitted, follows the WebRun proxy country if one is set (e.g. country \"de\" → Europe/Berlin); otherwise the browser default.",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "create_session",
"outputSchema": {
"properties": {
"environment": {
"description": "Environment this session is bound to, when one was requested",
"properties": {
"environmentId": {
"type": "string"
},
"name": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"message": {
"type": "string"
},
"sessionId": {
"description": "Session ID for subsequent commands",
"type": "string"
},
"streaming": {
"description": "Endpoints for watching the running browser. Only liveViewURL is a web page — the other two are machine endpoints on a non-standard port.",
"properties": {
"dimensions": {
"properties": {
"height": {
"type": "number"
},
"width": {
"type": "number"
}
},
"type": "object"
},
"liveViewURL": {
"description": "The live-view page. This is the ONLY URL to show a user or open in a browser. Null when the stream is unavailable — say live view is unavailable rather than offering another field.",
"type": [
"string",
"null"
]
},
"webRTCURL": {
"description": "WHEP signaling endpoint for a programmatic WebRTC client. POST-only: a browser GET returns HTTP 405. Never show this to a user.",
"type": [
"string",
"null"
]
},
"webViewURL": {
"description": "Direct MediaMTX player on the streaming host (port 2096), unbranded and often firewall-blocked. Debugging fallback only — prefer liveViewURL.",
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"taskId": {
"description": "Task ID when an initial task was provided",
"type": [
"string",
"null"
]
}
},
"required": [
"sessionId"
],
"type": "object"
}
},
{
"description": "Create a new saved workflow. READINESS BAR: if you could not execute the prompt yourself as a human in a browser — which site, which records, which fields, delivered where, matched to each recipient how — it is not ready; first collect the missing business facts from the user (see the TASK INTERVIEW in the server instructions), then create. Requires title and promptTemplate — write the prompt as a browsing runbook following the Goal / Ground rules / Stages / Output contract in the promptTemplate field description. For tasks that must handle each new item exactly once (new messages, forward once, skip seen), memoryContract is REQUIRED — three plain-English fields addressed to the agent: groundRules, memoryInstruction and itemIdentity (see the field descriptions); the platform wires the tracking itself — never write memory or tracking steps into the prompt. Created in the connection's environment automatically — omit environmentId and never ask the user to choose one. Write the user's concrete values (names, URLs, numbers) directly into the prompt; use {{variables}} ONLY when the user explicitly wants a reusable template with per-run inputs. Everything else is optional and defaults sensibly — do not quiz the user about settings. A supplied schedule is stored as a setting only — the workflow does not run on a timer until deployed via create_agent. To run or TEST the workflow, use trigger_workflow ONLY — never browser_task or create_session.",
"inputSchema": {
"properties": {
"compatibleTools": {
"description": "Sites/tools the workflow uses: [{ name, loginUrl, domain, role }].",
"items": {
"properties": {
"domain": {
"type": "string"
},
"loginUrl": {
"type": "string"
},
"name": {
"type": "string"
},
"role": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"conciergeNotify": {
"description": "Where the concierge announces results (e.g. 'Telegram', 'Slack', 'WhatsApp', 'Microsoft Teams', 'concierge').",
"maxLength": 50,
"type": "string"
},
"department": {
"description": "Free-text department label (e.g. \"inventory\").",
"maxLength": 100,
"type": "string"
},
"deployedPolicyId": {
"description": "Policy id to run under (must be owned by you).",
"maxLength": 24,
"type": "string"
},
"destination": {
"description": "Result destination chip: { type, sub, description }. Types seen: 'custom-api', 'slack', 'sheets', 'email', 'messaging', 'telegram', 'crm'.",
"properties": {
"description": {
"type": "string"
},
"sub": {
"type": [
"string",
"null"
]
},
"type": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"environmentId": {
"description": "Rarely needed — OMIT it: the connection's bound environment (or your only environment) is applied automatically. Pass only when the user explicitly names a different environment. Never ask the user to choose.",
"type": "string"
},
"fileDeferred": {
"description": "Dashboard flag: file selection deferred to run time.",
"type": "boolean"
},
"flow": {
"description": "Dashboard flow diagram: { trigger: {kind, phrase}, steps: [{ primary: {label, domain}, verb }] }.",
"type": "object"
},
"listType": {
"description": "Advanced — defaults automatically ('monitor' when memoryContract is supplied); leave unset.",
"enum": [
"static",
"dynamic",
"monitor"
],
"type": "string"
},
"memory": {
"description": "The agent's private notebook: shown to it at the start of every run, updated automatically after each run. Seed it ONLY with durable facts the next run must already know — the exact description of a target item (e.g. the specific picture to match), user preferences, known starting state — one short line per fact. Do NOT put task steps here (promptTemplate) or tracking rules here (memoryContract). Most workflows need no seed at all: the agent builds its own notebook as it runs.",
"maxLength": 10000,
"type": "string"
},
"memoryContract": {
"description": "How this workflow should behave and what it must remember between runs. REQUIRED whenever the task handles each thing once — new messages, forward once, skip anything already done. Write all three fields in plain English, addressed to the agent; the platform wires the tracking itself. Never write any of this into the prompt: the prompt says what to do, this says how to do it consistently. To explicitly disable tracking for a task that looks like it needs it, pass {mode:'none'}.",
"properties": {
"groundRules": {
"description": "Standing rules the agent follows on every turn of every run: what it must never do, what counts as proof a step actually succeeded, what to do when something looks ambiguous, and any pacing or volume limits. Short bullets.",
"maxLength": 1500,
"type": "string"
},
"itemIdentity": {
"description": "What tells one item apart from another, and stays the same the next time the agent sees it. Use only details visible on screen — for example where it came from, who it is from, when it appeared, and its opening words — and say how to write it the same way every time.",
"maxLength": 300,
"type": "string"
},
"memoryInstruction": {
"description": "When a single item counts as finished, and what happens to everything else. State plainly what must be true before an item is considered done, what to do when the agent cannot tell whether a past item was done, and what happens to items left over at the end of a run.",
"maxLength": 1500,
"type": "string"
}
},
"type": "object"
},
"memoryEnabled": {
"description": "Persist per-workflow agent memory across runs (default true).",
"type": "boolean"
},
"model": {
"description": "Model profile key. Omit for the account default.",
"maxLength": 60,
"type": "string"
},
"orchestrateFirst": {
"description": "Discovery mode: one run gathers the WHOLE work list up front, later runs claim one item each.",
"type": "boolean"
},
"outputSchema": {
"description": "JSON Schema object (outputType \"structured\") or array of column-name strings (outputType \"structured_csv\").",
"type": [
"object",
"array"
]
},
"outputType": {
"description": "Output contract: 'text' (default), 'structured' (JSON matching outputSchema), 'structured_csv' (rows for the outputSchema column names).",
"enum": [
"text",
"structured",
"structured_csv"
],
"type": "string"
},
"policyOptedOut": {
"description": "Opt this workflow out of the environment's default policy.",
"type": "boolean"
},
"promptTemplate": {
"description": "The task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):` — bullet invariants when the task needs them, e.g. work one item at a time — never batch; only record a figure you can read on screen this turn — if it is not shown record it as \"not stated\", never estimate; keep a running tally and restate it every turn (\"captured C items · written R rows\"). Then `Stage N — <Site name> (<https://url>)` — one section per website or phase, listing the concrete steps to take in the browser (open/navigate, click, read, capture, compare, flag) in the order a person would do them, each stage ending with `Done when: <verifiable completion condition>`. Finish with `Output —` stating exactly what to produce or deliver once the final tally is met, including what to say when there is no data (never fabricate a row). When a stage delivers per-recipient (message/email each customer), state the MATCHING RULE in that stage — the identifier shared by the source record and the destination recipient (e.g. the customer name exactly as written in the source, matched against the contact name) — and the no-match branch: skip it and report it, never deliver to a similarly-named near-match. Write the user's CONCRETE values (group names, URLs, numbers) directly into the text; use {{variables}} ONLY when the user explicitly wants a reusable template whose inputs change per run. A short single-site task can be just a Goal plus its steps. PURE TASK ONLY — never write memory bookkeeping into the prompt (no \"check memory\", \"record in memory\", \"store in memory\" steps): tracking is authored in memoryContract and WebRun applies it to every run automatically.",
"maxLength": 5000,
"type": "string"
},
"proxy": {
"description": "Proxy for runs. {source:\"WebRun\", country?} or {source:\"custom\", type:\"http\"|\"socks\", host, port, username?, password?}. Custom passwords are encrypted at rest and never returned. Social/messaging workflows (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok): set country to the country the user is in right now — recommend it and confirm the country with them first; a mismatch is the usual cause of refused logins and sessions that log out repeatedly, and a scheduled workflow re-hits it every run, so keep the country stable once set.",
"properties": {
"country": {
"description": "2-letter ISO code or \"random\" (WebRun).",
"type": "string"
},
"host": {
"type": "string"
},
"level": {
"enum": [
"system",
"chrome"
],
"type": "string"
},
"password": {
"type": "string"
},
"port": {
"type": "number"
},
"source": {
"enum": [
"WebRun",
"custom"
],
"type": "string"
},
"type": {
"enum": [
"http",
"socks"
],
"type": "string"
},
"username": {
"type": "string"
}
},
"type": "object"
},
"publicDraftId": {
"description": "Dashboard public-draft correlation id.",
"maxLength": 64,
"type": "string"
},
"reachOutMode": {
"description": "Proactive-chat policy for runs: 'off', 'guardrail_only', or 'full'. Omit (or pass null) to inherit the account default (MCP-initiated runs treat inherit as 'off').",
"enum": [
"off",
"guardrail_only",
"full",
null
],
"type": [
"string",
"null"
]
},
"refineMessages": {
"description": "Dashboard builder refinement thread rows: [{ role, content }].",
"items": {
"properties": {
"content": {
"type": "string"
},
"role": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"requiredFiles": {
"description": "Files attached to every run (downloaded before the agent starts). Each fileId must already be in the workflow's own environment (GET /environments/:id/files) — a workflow only uses files from its own environment. originalName and size are filled from that catalog.",
"items": {
"properties": {
"environmentId": {
"description": "Optional. If given, must be the workflow's own environment (24-hex).",
"type": "string"
},
"fileId": {
"type": "string"
},
"originalName": {
"type": "string"
},
"size": {
"type": "number"
}
},
"required": [
"fileId"
],
"type": "object"
},
"type": "array"
},
"roiHourlyRate": {
"description": "Hourly rate for the ROI card.",
"type": [
"number",
"null"
]
},
"roiMinutesPerTask": {
"description": "Minutes saved per run (dashboard ROI card).",
"type": [
"number",
"null"
]
},
"schedule": {
"description": "Saved schedule setting. NOTE: record-only — the workflow does NOT run on a timer until deployed as a scheduled agent (dashboard or Telegram bot).",
"properties": {
"at": {
"description": "ISO 8601 date-time (type \"at\").",
"type": "string"
},
"cron": {
"description": "5-field cron expression (type \"cron\").",
"type": "string"
},
"interval": {
"description": "Repeat interval in ms, min 60000 (type \"every\").",
"type": "number"
},
"timezone": {
"description": "IANA timezone for the schedule. Default UTC.",
"type": "string"
},
"type": {
"enum": [
"at",
"every",
"cron",
null
],
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"shortDescription": {
"description": "One-line summary shown in workflow lists.",
"maxLength": 500,
"type": "string"
},
"skills": {
"description": "Workflow-scoped skill entries (dashboard shape).",
"items": {
"type": "object"
},
"type": "array"
},
"startingUrl": {
"description": "Page Chrome opens at the start of each run. Omit to let the prompt decide.",
"maxLength": 2000,
"type": "string"
},
"templateVariables": {
"description": "ONLY for explicitly dynamic workflows (the user asked for a reusable template): metadata for the {{variables}} used in promptTemplate (drives the dashboard fill-in UI). Omit entirely when the prompt carries concrete values.",
"items": {
"properties": {
"kind": {
"description": "e.g. 'config'",
"type": "string"
},
"label": {
"type": "string"
},
"name": {
"description": "Must match a {{name}} in promptTemplate ([a-zA-Z0-9_]).",
"type": "string"
},
"prompt": {
"description": "Question to ask the user for this value.",
"type": "string"
},
"required": {
"type": "boolean"
},
"sampleValue": {
"type": "string"
},
"type": {
"description": "e.g. 'text', 'keywords'",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"type": "array"
},
"timezone": {
"description": "IANA timezone for runs of this workflow (e.g. \"America/New_York\"). Leave unset to follow the proxy country.",
"maxLength": 60,
"type": "string"
},
"title": {
"description": "Workflow title (shown on the dashboard).",
"maxLength": 120,
"type": "string"
},
"trigger": {
"description": "How the workflow is meant to be invoked (informational — see notes). Defaults to {type:'manual', source:'manual'}.",
"properties": {
"source": {
"description": "e.g. 'cron', 'manual', 'gmail', 'webhook', 'hubspot'",
"maxLength": 50,
"type": "string"
},
"type": {
"enum": [
"cron",
"external",
"manual"
],
"type": "string"
},
"via": {
"description": "e.g. 'direct', 'n8n'",
"maxLength": 50,
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"triggerPhrase": {
"description": "Natural-language phrase that invokes this workflow in chat.",
"maxLength": 200,
"type": "string"
},
"useCaseTags": {
"description": "Categorisation tags.",
"items": {
"maxLength": 60,
"type": "string"
},
"type": "array"
},
"variableValues": {
"additionalProperties": {
"type": "string"
},
"description": "ONLY for explicitly dynamic workflows: default values for {{variables}}, keyed by variable name. NOTE: applied only when triggering via MCP trigger_workflow (merged under caller-supplied variables); REST /trigger and bot triggers ignore this field.",
"type": "object"
},
"wizardPreset": {
"description": "Dashboard wizard preset: { technology, useCases[], destination, destinationSub }.",
"type": "object"
},
"workListEnabled": {
"description": "Advanced — set automatically when memoryContract is supplied; leave unset.",
"type": "boolean"
}
},
"required": [
"title",
"promptTemplate"
],
"type": "object"
},
"name": "create_workflow",
"outputSchema": {
"properties": {
"environment": {
"properties": {
"environmentId": {
"type": "string"
},
"name": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"memoryContract": {
"description": "Echo of the stored tracking contract (the three authored fields) — absent when the workflow has none",
"properties": {
"groundRules": {
"type": [
"string",
"null"
]
},
"itemIdentity": {
"type": [
"string",
"null"
]
},
"memoryInstruction": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"nextStep": {
"description": "How to run or test this workflow (always trigger_workflow)",
"type": "string"
},
"notes": {
"description": "Caveats the caller should relay (e.g. the schedule is record-only)",
"items": {
"type": "string"
},
"type": "array"
},
"slug": {
"type": "string"
},
"success": {
"type": "boolean"
},
"title": {
"type": "string"
},
"workflowId": {
"type": "string"
}
},
"required": [
"success",
"workflowId",
"slug",
"title"
],
"type": "object"
}
},
{
"description": "Check the status of a task previously started in a browser session. Use to poll for completion or detect guardrails. Read-only: reports on the task without affecting it.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
},
"taskId": {
"description": "Task ID to check",
"type": "string"
}
},
"required": [
"sessionId",
"taskId"
],
"type": "object"
},
"name": "get_task_status",
"outputSchema": {
"additionalProperties": true,
"properties": {
"data": {
"additionalProperties": true,
"description": "Task output payload when completed (instance-authored shape)",
"type": "object"
},
"liveViewURL": {
"description": "Page for watching the run live, present while it is still running or awaiting input. The only URL here that is safe to show a user or open in a browser.",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"status": {
"description": "Task/session state: 'completed', 'failed', 'awaiting_input', 'pending', 'active', 'paused', 'orphaned', or 'not_found'",
"type": "string"
},
"taskId": {
"type": "string"
},
"type": {
"description": "Raw result type when the task finished",
"type": "string"
}
},
"required": [
"status"
],
"type": "object"
}
},
{
"description": "Full detail of one workflow: prompt template, {{variables}} and their defaults, trigger + schedule, run settings (starting URL, timezone, model, proxy, output contract, files), memory state, and any pending logins. Identify by workflowId or exact title. Read-only; proxy credentials are masked.",
"inputSchema": {
"properties": {
"title": {
"description": "Exact workflow title (case-insensitive) — alternative to workflowId",
"type": "string"
},
"workflowId": {
"description": "24-hex workflow id (from list_workflows or create_workflow)",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "get_workflow",
"outputSchema": {
"additionalProperties": true,
"properties": {
"environmentId": {
"type": [
"string",
"null"
]
},
"notes": {
"items": {
"type": "string"
},
"type": "array"
},
"outputType": {
"type": "string"
},
"promptTemplate": {
"type": "string"
},
"schedule": {
"type": [
"object",
"null"
]
},
"scheduleDescription": {
"type": [
"string",
"null"
]
},
"slug": {
"type": "string"
},
"title": {
"type": "string"
},
"totalTriggers": {
"type": "number"
},
"trigger": {
"type": [
"object",
"null"
]
},
"variables": {
"items": {
"type": "string"
},
"type": "array"
},
"workflowId": {
"type": "string"
}
},
"required": [
"workflowId",
"slug",
"title",
"promptTemplate"
],
"type": "object"
}
},
{
"description": "Respond to a guardrail trigger when the browser agent needs human input (credentials, clarification, approval). The response is handed to the live agent, which continues acting on it.",
"inputSchema": {
"properties": {
"files": {
"description": "Optional file IDs to attach: ids returned by POST /files/upload, or any file already in one of the user's environment catalogs (GET /environments/:id/files). Max 5 files.",
"items": {
"type": "string"
},
"type": "array"
},
"newState": {
"description": "How to continue: 'resume' (default) provides the requested input and continues the task; 'deny' declines the request (response text optional).",
"enum": [
"resume",
"deny"
],
"type": "string"
},
"response": {
"description": "Your response/instructions to the agent. Required when newState is 'resume'.",
"type": "string"
},
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "guardrail_response",
"outputSchema": {
"additionalProperties": true,
"properties": {
"message": {
"description": "What happened and what to do next (poll get_task_status)",
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
},
"taskId": {
"type": [
"string",
"null"
]
}
},
"required": [
"success"
],
"type": "object"
}
},
{
"description": "List the account's scheduled agents (cron deployments): schedule, status, next/last run, and whether each is standalone or deployed from a workflow. Scoped to the bound environment when this connection has one; pass scope \"all\" for every environment. Read-only.",
"inputSchema": {
"properties": {
"scope": {
"description": "'environment' (default when bound) lists agents in the bound environment; 'all' lists every agent on the account.",
"enum": [
"environment",
"all"
],
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "list_agents",
"outputSchema": {
"properties": {
"agents": {
"items": {
"properties": {
"agentId": {
"type": "string"
},
"deliveryMode": {
"type": "string"
},
"environmentId": {
"type": [
"string",
"null"
]
},
"expiresAt": {
"type": [
"string",
"null"
]
},
"lastRunAt": {
"type": [
"string",
"null"
]
},
"name": {
"type": "string"
},
"nextRunAt": {
"type": [
"string",
"null"
]
},
"pausedReason": {
"description": "Why a paused agent stopped: 'manual', 'login_wall', 'expired', 'list_complete'",
"type": "string"
},
"promptPreview": {
"type": [
"string",
"null"
]
},
"schedule": {
"description": "Humanized schedule",
"type": [
"string",
"null"
]
},
"standalone": {
"description": "True when the agent carries its own prompt (not deployed from a workflow)",
"type": "boolean"
},
"status": {
"description": "'active' | 'paused' | 'completed' | 'failed'",
"type": "string"
},
"timezone": {
"type": "string"
},
"totalRuns": {
"type": "number"
},
"workflow": {
"description": "Present when deployed from a workflow",
"properties": {
"title": {
"type": [
"string",
"null"
]
},
"workflowId": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"agentId",
"name",
"status",
"standalone"
],
"type": "object"
},
"type": "array"
},
"count": {
"type": "number"
},
"scope": {
"enum": [
"environment",
"all"
],
"type": "string"
}
},
"required": [
"agents",
"count",
"scope"
],
"type": "object"
}
},
{
"description": "List available browser environments (persistent profiles) for this account. Returns environment IDs needed for persistent sessions in browser_task or create_session. Read-only. NOTE: workflows and agents use the connection's environment automatically — you rarely need this tool for those, and should not ask the user to choose an environment.",
"inputSchema": {
"properties": {},
"required": [],
"type": "object"
},
"name": "list_environments",
"outputSchema": {
"properties": {
"boundEnvironment": {
"properties": {
"environmentId": {
"type": "string"
},
"name": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"count": {
"type": "number"
},
"environments": {
"items": {
"properties": {
"bound": {
"description": "True for the environment this MCP connection is bound to",
"type": "boolean"
},
"createdAt": {
"description": "ISO 8601 timestamp",
"type": "string"
},
"description": {
"type": [
"string",
"null"
]
},
"environmentId": {
"type": "string"
},
"hasMemory": {
"type": "boolean"
},
"name": {
"type": [
"string",
"null"
]
}
},
"required": [
"environmentId"
],
"type": "object"
},
"type": "array"
},
"hint": {
"type": "string"
}
},
"required": [
"environments",
"count"
],
"type": "object"
}
},
{
"description": "List all active browser sessions for this account. Read-only.",
"inputSchema": {
"properties": {},
"required": [],
"type": "object"
},
"name": "list_sessions",
"outputSchema": {
"properties": {
"count": {
"type": "number"
},
"sessions": {
"items": {
"properties": {
"createdAt": {
"description": "ISO 8601 timestamp",
"type": "string"
},
"sessionId": {
"type": "string"
},
"status": {
"type": "string"
},
"task": {
"description": "Prompt of the most recent task, if any",
"type": [
"string",
"null"
]
}
},
"required": [
"sessionId",
"status"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"sessions",
"count"
],
"type": "object"
}
},
{
"description": "List the user's saved workflows (prompt-templated browser automations, docs.webrun.ai). Shows each workflow's title, schedule, {{variables}}, and run stats. Scoped to the bound environment when this connection has one; pass scope \"all\" for every environment. Read-only.",
"inputSchema": {
"properties": {
"scope": {
"description": "'environment' (default when this connection is bound to one) lists workflows deployed to the bound environment; 'all' lists every workflow on the account.",
"enum": [
"environment",
"all"
],
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "list_workflows",
"outputSchema": {
"properties": {
"count": {
"type": "number"
},
"scope": {
"enum": [
"environment",
"all"
],
"type": "string"
},
"workflows": {
"items": {
"properties": {
"environmentId": {
"type": [
"string",
"null"
]
},
"lastTriggeredAt": {
"description": "ISO 8601 timestamp",
"type": [
"string",
"null"
]
},
"schedule": {
"description": "Humanized saved schedule (record-only — runs on a timer only when deployed as a scheduled agent)",
"type": [
"string",
"null"
]
},
"shortDescription": {
"type": "string"
},
"slug": {
"type": "string"
},
"title": {
"type": "string"
},
"totalTriggers": {
"type": "number"
},
"triggerType": {
"description": "'cron' | 'external' | 'manual'",
"type": "string"
},
"variables": {
"description": "{{variable}} names the promptTemplate expects",
"items": {
"type": "string"
},
"type": "array"
},
"workflowId": {
"type": "string"
}
},
"required": [
"workflowId",
"title",
"slug"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"workflows",
"count",
"scope"
],
"type": "object"
}
},
{
"description": "Pause an active scheduled agent — it stops firing until resumed. Get agentId from list_agents.",
"inputSchema": {
"properties": {
"agentId": {
"description": "24-hex agent id (from list_agents or create_agent)",
"type": "string"
}
},
"required": [
"agentId"
],
"type": "object"
},
"name": "pause_agent",
"outputSchema": {
"properties": {
"agentId": {
"type": "string"
},
"message": {
"type": "string"
},
"name": {
"type": "string"
},
"status": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"agentId",
"status"
],
"type": "object"
}
},
{
"description": "Pause the task currently running in a browser session. Resume it later with resume_session_task.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "pause_session_task",
"outputSchema": {
"properties": {
"action": {
"description": "The control action that was applied",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"sessionId",
"action",
"message"
],
"type": "object"
}
},
{
"description": "Resume a paused scheduled agent — recomputes its next run and reactivates it. A completed work-list agent restarts with a fresh full pass. Refuses if the agent's expiry has passed (extend it on the dashboard first).",
"inputSchema": {
"properties": {
"agentId": {
"description": "24-hex agent id (from list_agents)",
"type": "string"
}
},
"required": [
"agentId"
],
"type": "object"
},
"name": "resume_agent",
"outputSchema": {
"properties": {
"agentId": {
"type": "string"
},
"message": {
"type": "string"
},
"name": {
"type": "string"
},
"nextRunAt": {
"type": [
"string",
"null"
]
},
"status": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"agentId",
"status"
],
"type": "object"
}
},
{
"description": "Resume a previously paused task in a browser session.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "resume_session_task",
"outputSchema": {
"properties": {
"action": {
"description": "The control action that was applied",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"sessionId",
"action",
"message"
],
"type": "object"
}
},
{
"description": "Capture a screenshot of the current browser page in an active session. Returns the screenshot as an inline image. Read-only.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "screenshot",
"outputSchema": {
"additionalProperties": true,
"description": "Capture confirmation — the screenshot itself is returned as inline image content alongside this.",
"properties": {
"error": {
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"type": "object"
}
},
{
"description": "Send a new task to an existing browser session (from create_session). The real Chrome browser may navigate, fill forms, and submit data on third-party websites as the task requires.",
"inputSchema": {
"properties": {
"files": {
"description": "Optional file IDs to attach: ids returned by POST /files/upload, or any file already in one of the user's environment catalogs (GET /environments/:id/files). Max 5 files.",
"items": {
"type": "string"
},
"type": "array"
},
"maxDuration": {
"description": "Max duration for this task in minutes (3-60). Defaults to the value the session was created with.",
"type": "number"
},
"maxInputTokens": {
"description": "Max input tokens for this task (100-3000000). Defaults to the value the session was created with.",
"type": "number"
},
"maxOutputTokens": {
"description": "Max output tokens for this task (100-1000000). Defaults to the value the session was created with.",
"type": "number"
},
"outputSchema": {
"description": "JSON Schema for structured output (required if outputType is structured_json)",
"type": "object"
},
"outputType": {
"description": "Response format",
"enum": [
"text",
"structured_json",
"structured_csv"
],
"type": "string"
},
"prompt": {
"description": "Task description",
"type": "string"
},
"secrets": {
"description": "Domain-matched secrets [{match, fields}] (not stored)",
"items": {
"type": "object"
},
"type": "array"
},
"sessionId": {
"description": "Session ID from create_session",
"type": "string"
},
"startingUrl": {
"description": "URL to navigate to before starting this task (optional)",
"type": "string"
},
"terminateOnCompletion": {
"description": "Auto-terminate after task (default: false)",
"type": "boolean"
},
"webhook": {
"description": "Webhook configuration",
"type": "object"
}
},
"required": [
"sessionId",
"prompt"
],
"type": "object"
},
"name": "send_task",
"outputSchema": {
"additionalProperties": true,
"description": "Task outcome envelope: a completion (success/type/data), a pending marker (poll get_task_status), or an awaiting_input guardrail. `data` is the task output; its shape is task-defined (freeform text or the caller-supplied structured schema).",
"properties": {
"data": {
"additionalProperties": true,
"description": "Task output payload (instance-authored shape)",
"type": "object"
},
"environment": {
"properties": {
"environmentId": {
"type": "string"
},
"name": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"error": {
"type": "string"
},
"liveViewURL": {
"description": "Page for watching the run live, present while it is still running or awaiting input. The only URL here that is safe to show a user or open in a browser.",
"type": "string"
},
"message": {
"type": "string"
},
"pending": {
"description": "True when the task is still running — poll get_task_status",
"type": "boolean"
},
"sessionId": {
"type": "string"
},
"status": {
"description": "Present on guardrail results: 'awaiting_input'",
"type": "string"
},
"success": {
"type": "boolean"
},
"taskId": {
"type": [
"string",
"null"
]
},
"type": {
"description": "Result type, e.g. 'task_completed', 'task_failed', 'guardrail_trigger'",
"type": "string"
}
},
"type": "object"
}
},
{
"description": "Cancel the task currently running in a browser session, keeping the session alive for new tasks.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "stop_session_task",
"outputSchema": {
"properties": {
"action": {
"description": "The control action that was applied",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"sessionId",
"action",
"message"
],
"type": "object"
}
},
{
"description": "End a browser session and free its resources. The session and any running task cannot be resumed afterwards.",
"inputSchema": {
"properties": {
"sessionId": {
"description": "Session ID",
"type": "string"
}
},
"required": [
"sessionId"
],
"type": "object"
},
"name": "terminate_session",
"outputSchema": {
"properties": {
"action": {
"description": "The control action that was applied",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"type": "string"
},
"success": {
"type": "boolean"
}
},
"required": [
"success",
"sessionId",
"action",
"message"
],
"type": "object"
}
},
{
"description": "Run a workflow now in its deployed environment. This is the ONLY correct way to run or TEST a saved workflow — a run started here carries the workflow's rules, tracking and memory; browser_task/create_session runs do not. When the user says \"run it\", \"run it once\", \"test it\" or \"try it\" about a workflow, this is the tool they mean. Drives a real Chrome browser: the run may navigate, fill forms, and submit data on third-party websites as the workflow's prompt requires. Pass values for the workflow's {{variables}} in `variables` (stored variableValues defaults fill any gaps). Returns a sessionId — poll get_task_status for the result.",
"inputSchema": {
"properties": {
"force": {
"description": "Work-list workflows only: when the list reports complete, re-open it for a fresh full pass.",
"type": "boolean"
},
"title": {
"description": "Exact workflow title (case-insensitive) — alternative to workflowId",
"type": "string"
},
"variables": {
"additionalProperties": {
"type": "string"
},
"description": "Values for the workflow's {{variables}}, keyed by exact variable name. Merged over the workflow's stored variableValues defaults.",
"type": "object"
},
"workflowId": {
"description": "24-hex workflow id",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "trigger_workflow",
"outputSchema": {
"properties": {
"listComplete": {
"description": "Work-list workflows: every item has been visited (no run started)",
"type": "boolean"
},
"liveViewURL": {
"description": "Page for watching the run live, present when a run started. The only URL here that is safe to show a user or open in a browser.",
"type": "string"
},
"message": {
"type": "string"
},
"sessionId": {
"description": "Poll get_task_status with this id",
"type": "string"
},
"success": {
"type": "boolean"
},
"taskId": {
"type": [
"string",
"null"
]
},
"workflowId": {
"type": "string"
}
},
"required": [
"success",
"workflowId"
],
"type": "object"
}
},
{
"description": "Update an existing workflow. Supply workflowId plus only the fields to change: prompt, trigger, schedule, run settings, variables, presentation. Object and array fields are replaced whole; pass null to clear an optional field. Renaming via title keeps the slug stable. The stored schedule stays a saved setting — scheduled agents already deployed from this workflow keep their own timing. promptTemplate follows the same Goal / Ground rules / Stages / Output runbook contract as create_workflow (see that field's description). memoryContract is the exception to whole-replace: supplying its three fields updates them while platform tracking details are preserved.",
"inputSchema": {
"description": "Supply only the fields to change. Object/array fields are replaced whole. Pass null to clear an optional field. Renaming via title does not change the slug.",
"properties": {
"compatibleTools": {
"description": "Sites/tools the workflow uses: [{ name, loginUrl, domain, role }].",
"items": {
"properties": {
"domain": {
"type": "string"
},
"loginUrl": {
"type": "string"
},
"name": {
"type": "string"
},
"role": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"conciergeNotify": {
"description": "Where the concierge announces results (e.g. 'Telegram', 'Slack', 'WhatsApp', 'Microsoft Teams', 'concierge').",
"maxLength": 50,
"type": "string"
},
"department": {
"description": "Free-text department label (e.g. \"inventory\").",
"maxLength": 100,
"type": "string"
},
"deployedPolicyId": {
"description": "Policy id to run under (must be owned by you).",
"maxLength": 24,
"type": "string"
},
"destination": {
"description": "Result destination chip: { type, sub, description }. Types seen: 'custom-api', 'slack', 'sheets', 'email', 'messaging', 'telegram', 'crm'.",
"properties": {
"description": {
"type": "string"
},
"sub": {
"type": [
"string",
"null"
]
},
"type": {
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"environmentId": {
"description": "Move the workflow to a different environment you own. Refused while that would leave attached files or scheduled agents behind: pass requiredFiles (files in the new environment, or []) in the same update, and remove its scheduled agents first.",
"type": "string"
},
"fileDeferred": {
"description": "Dashboard flag: file selection deferred to run time.",
"type": "boolean"
},
"flow": {
"description": "Dashboard flow diagram: { trigger: {kind, phrase}, steps: [{ primary: {label, domain}, verb }] }.",
"type": "object"
},
"listType": {
"description": "Advanced — defaults automatically ('monitor' when memoryContract is supplied); leave unset.",
"enum": [
"static",
"dynamic",
"monitor"
],
"type": "string"
},
"memory": {
"description": "The agent's private notebook: shown to it at the start of every run, updated automatically after each run. Seed it ONLY with durable facts the next run must already know — the exact description of a target item (e.g. the specific picture to match), user preferences, known starting state — one short line per fact. Do NOT put task steps here (promptTemplate) or tracking rules here (memoryContract). Most workflows need no seed at all: the agent builds its own notebook as it runs.",
"maxLength": 10000,
"type": "string"
},
"memoryContract": {
"description": "How this workflow should behave and what it must remember between runs. REQUIRED whenever the task handles each thing once — new messages, forward once, skip anything already done. Write all three fields in plain English, addressed to the agent; the platform wires the tracking itself. Never write any of this into the prompt: the prompt says what to do, this says how to do it consistently. To explicitly disable tracking for a task that looks like it needs it, pass {mode:'none'}.",
"properties": {
"groundRules": {
"description": "Standing rules the agent follows on every turn of every run: what it must never do, what counts as proof a step actually succeeded, what to do when something looks ambiguous, and any pacing or volume limits. Short bullets.",
"maxLength": 1500,
"type": "string"
},
"itemIdentity": {
"description": "What tells one item apart from another, and stays the same the next time the agent sees it. Use only details visible on screen — for example where it came from, who it is from, when it appeared, and its opening words — and say how to write it the same way every time.",
"maxLength": 300,
"type": "string"
},
"memoryInstruction": {
"description": "When a single item counts as finished, and what happens to everything else. State plainly what must be true before an item is considered done, what to do when the agent cannot tell whether a past item was done, and what happens to items left over at the end of a run.",
"maxLength": 1500,
"type": "string"
}
},
"type": "object"
},
"memoryEnabled": {
"description": "Persist per-workflow agent memory across runs (default true).",
"type": "boolean"
},
"model": {
"description": "Model profile key. Omit for the account default.",
"maxLength": 60,
"type": "string"
},
"orchestrateFirst": {
"description": "Discovery mode: one run gathers the WHOLE work list up front, later runs claim one item each.",
"type": "boolean"
},
"outputSchema": {
"description": "JSON Schema object (outputType \"structured\") or array of column-name strings (outputType \"structured_csv\").",
"type": [
"object",
"array"
]
},
"outputType": {
"description": "Output contract: 'text' (default), 'structured' (JSON matching outputSchema), 'structured_csv' (rows for the outputSchema column names).",
"enum": [
"text",
"structured",
"structured_csv"
],
"type": "string"
},
"policyOptedOut": {
"description": "Opt this workflow out of the environment's default policy.",
"type": "boolean"
},
"promptTemplate": {
"description": "The task the browser agent runs, written as a BROWSING RUNBOOK. Structure it as: `Goal:` — one sentence naming the outcome. `Ground rules (every stage, every turn):` — bullet invariants when the task needs them, e.g. work one item at a time — never batch; only record a figure you can read on screen this turn — if it is not shown record it as \"not stated\", never estimate; keep a running tally and restate it every turn (\"captured C items · written R rows\"). Then `Stage N — <Site name> (<https://url>)` — one section per website or phase, listing the concrete steps to take in the browser (open/navigate, click, read, capture, compare, flag) in the order a person would do them, each stage ending with `Done when: <verifiable completion condition>`. Finish with `Output —` stating exactly what to produce or deliver once the final tally is met, including what to say when there is no data (never fabricate a row). When a stage delivers per-recipient (message/email each customer), state the MATCHING RULE in that stage — the identifier shared by the source record and the destination recipient (e.g. the customer name exactly as written in the source, matched against the contact name) — and the no-match branch: skip it and report it, never deliver to a similarly-named near-match. Write the user's CONCRETE values (group names, URLs, numbers) directly into the text; use {{variables}} ONLY when the user explicitly wants a reusable template whose inputs change per run. A short single-site task can be just a Goal plus its steps. PURE TASK ONLY — never write memory bookkeeping into the prompt (no \"check memory\", \"record in memory\", \"store in memory\" steps): tracking is authored in memoryContract and WebRun applies it to every run automatically.",
"maxLength": 5000,
"type": "string"
},
"proxy": {
"description": "Proxy for runs. {source:\"WebRun\", country?} or {source:\"custom\", type:\"http\"|\"socks\", host, port, username?, password?}. Custom passwords are encrypted at rest and never returned. Social/messaging workflows (WhatsApp, Telegram, Instagram, Facebook, X, LinkedIn, TikTok): set country to the country the user is in right now — recommend it and confirm the country with them first; a mismatch is the usual cause of refused logins and sessions that log out repeatedly, and a scheduled workflow re-hits it every run, so keep the country stable once set.",
"properties": {
"country": {
"description": "2-letter ISO code or \"random\" (WebRun).",
"type": "string"
},
"host": {
"type": "string"
},
"level": {
"enum": [
"system",
"chrome"
],
"type": "string"
},
"password": {
"type": "string"
},
"port": {
"type": "number"
},
"source": {
"enum": [
"WebRun",
"custom"
],
"type": "string"
},
"type": {
"enum": [
"http",
"socks"
],
"type": "string"
},
"username": {
"type": "string"
}
},
"type": "object"
},
"publicDraftId": {
"description": "Dashboard public-draft correlation id.",
"maxLength": 64,
"type": "string"
},
"reachOutMode": {
"description": "Proactive-chat policy for runs: 'off', 'guardrail_only', or 'full'. Omit (or pass null) to inherit the account default (MCP-initiated runs treat inherit as 'off').",
"enum": [
"off",
"guardrail_only",
"full",
null
],
"type": [
"string",
"null"
]
},
"refineMessages": {
"description": "Dashboard builder refinement thread rows: [{ role, content }].",
"items": {
"properties": {
"content": {
"type": "string"
},
"role": {
"type": "string"
}
},
"type": "object"
},
"type": "array"
},
"requiredFiles": {
"description": "Files attached to every run (downloaded before the agent starts). Each fileId must already be in the workflow's own environment (GET /environments/:id/files) — a workflow only uses files from its own environment. originalName and size are filled from that catalog.",
"items": {
"properties": {
"environmentId": {
"description": "Optional. If given, must be the workflow's own environment (24-hex).",
"type": "string"
},
"fileId": {
"type": "string"
},
"originalName": {
"type": "string"
},
"size": {
"type": "number"
}
},
"required": [
"fileId"
],
"type": "object"
},
"type": "array"
},
"roiHourlyRate": {
"description": "Hourly rate for the ROI card.",
"type": [
"number",
"null"
]
},
"roiMinutesPerTask": {
"description": "Minutes saved per run (dashboard ROI card).",
"type": [
"number",
"null"
]
},
"schedule": {
"description": "Saved schedule setting. NOTE: record-only — the workflow does NOT run on a timer until deployed as a scheduled agent (dashboard or Telegram bot).",
"properties": {
"at": {
"description": "ISO 8601 date-time (type \"at\").",
"type": "string"
},
"cron": {
"description": "5-field cron expression (type \"cron\").",
"type": "string"
},
"interval": {
"description": "Repeat interval in ms, min 60000 (type \"every\").",
"type": "number"
},
"timezone": {
"description": "IANA timezone for the schedule. Default UTC.",
"type": "string"
},
"type": {
"enum": [
"at",
"every",
"cron",
null
],
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"shortDescription": {
"description": "One-line summary shown in workflow lists.",
"maxLength": 500,
"type": "string"
},
"skills": {
"description": "Workflow-scoped skill entries (dashboard shape).",
"items": {
"type": "object"
},
"type": "array"
},
"startingUrl": {
"description": "Page Chrome opens at the start of each run. Omit to let the prompt decide.",
"maxLength": 2000,
"type": "string"
},
"templateVariables": {
"description": "ONLY for explicitly dynamic workflows (the user asked for a reusable template): metadata for the {{variables}} used in promptTemplate (drives the dashboard fill-in UI). Omit entirely when the prompt carries concrete values.",
"items": {
"properties": {
"kind": {
"description": "e.g. 'config'",
"type": "string"
},
"label": {
"type": "string"
},
"name": {
"description": "Must match a {{name}} in promptTemplate ([a-zA-Z0-9_]).",
"type": "string"
},
"prompt": {
"description": "Question to ask the user for this value.",
"type": "string"
},
"required": {
"type": "boolean"
},
"sampleValue": {
"type": "string"
},
"type": {
"description": "e.g. 'text', 'keywords'",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"type": "array"
},
"timezone": {
"description": "IANA timezone for runs of this workflow (e.g. \"America/New_York\"). Leave unset to follow the proxy country.",
"maxLength": 60,
"type": "string"
},
"title": {
"description": "Workflow title (shown on the dashboard).",
"maxLength": 120,
"type": "string"
},
"trigger": {
"description": "How the workflow is meant to be invoked (informational — see notes). Defaults to {type:'manual', source:'manual'}.",
"properties": {
"source": {
"description": "e.g. 'cron', 'manual', 'gmail', 'webhook', 'hubspot'",
"maxLength": 50,
"type": "string"
},
"type": {
"enum": [
"cron",
"external",
"manual"
],
"type": "string"
},
"via": {
"description": "e.g. 'direct', 'n8n'",
"maxLength": 50,
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"triggerPhrase": {
"description": "Natural-language phrase that invokes this workflow in chat.",
"maxLength": 200,
"type": "string"
},
"useCaseTags": {
"description": "Categorisation tags.",
"items": {
"maxLength": 60,
"type": "string"
},
"type": "array"
},
"variableValues": {
"additionalProperties": {
"type": "string"
},
"description": "ONLY for explicitly dynamic workflows: default values for {{variables}}, keyed by variable name. NOTE: applied only when triggering via MCP trigger_workflow (merged under caller-supplied variables); REST /trigger and bot triggers ignore this field.",
"type": "object"
},
"wizardPreset": {
"description": "Dashboard wizard preset: { technology, useCases[], destination, destinationSub }.",
"type": "object"
},
"workListEnabled": {
"description": "Advanced — set automatically when memoryContract is supplied; leave unset.",
"type": "boolean"
},
"workflowId": {
"description": "24-hex id of the workflow to update (from list_workflows or create_workflow). Required — the title property here is the NEW title for renames, never an identifier.",
"type": "string"
}
},
"required": [
"workflowId"
],
"type": "object"
},
"name": "update_workflow",
"outputSchema": {
"properties": {
"changes": {
"description": "Human-readable field: old → new summaries of what was applied (empty when everything supplied matched the current values)",
"items": {
"type": "string"
},
"type": "array"
},
"notes": {
"description": "Caveats to relay (record-only schedule, linked scheduled agents, prompt-structure advice)",
"items": {
"type": "string"
},
"type": "array"
},
"slug": {
"type": "string"
},
"success": {
"type": "boolean"
},
"title": {
"type": "string"
},
"workflowId": {
"type": "string"
}
},
"required": [
"success",
"workflowId",
"changes"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:f814c0b40eae841ac748fdd6bdb1d314eb39a4d81d46c0ae0220497a6d6e3598 | sha256sum