curl --request GET \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"status": "ok",
"items": [
{
"name": "<string>",
"canonical_name": "<string>",
"description": "<string>",
"inputSchema": {},
"annotations": {}
}
],
"error": "<string>"
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}List the tools an attached MCP server exposes
Runs the server’s tools/list and returns each advertised tool with
the canonical_name the model calls it by (the name a
tool_permissions rule must target to reach that tool), plus its
inputSchema and annotations exactly as published. canonical_name
is computed by the runtime’s own naming helper: consume it, never
derive it.
Always 200 once the entry is resolved. status says whether the
list could be fetched (ok), whether the caller has to connect to an
OAuth-gated server first (auth_required, empty items), or whether
the server did not answer (unavailable, empty items, error).
Only mcp entries have capabilities: any other type is a 400. The
list is served from the same per-server cache the runtime uses, with
the same rule: never cached for auth-bearing catalog entries.
curl --request GET \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/tools/{toolId}/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"status": "ok",
"items": [
{
"name": "<string>",
"canonical_name": "<string>",
"description": "<string>",
"inputSchema": {},
"annotations": {}
}
],
"error": "<string>"
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Authorizations
User-bound credential carrying an identity: either a session JWT
or a user access token (at:*) generated from the user settings UI.
Send as Authorization: Bearer <token>.
Org API keys (iak_*) are not accepted here - they carry
no user identity. Use the x-prismeai-api-key header instead
(see OrgApiKeyAuth).
Path Parameters
64128Response
Server tools, or the reason they could not be listed.
Tools an MCP server attached to an agent exposes, as returned by
GET /v1/agents/{agentId}/tools/{toolId}/capabilities.
ok: items is the server's list. auth_required: OAuth-gated
server the caller is not connected to; items is empty.
unavailable: the handshake or tools/list failed; items is
empty and error carries the message.
ok, auth_required, unavailable Hide child attributes
Hide child attributes
Tool name exactly as the server advertises it (what tools/call receives).
<parent>__<child> name the model calls the tool by, and the value
a tool_permissions.tools[].tool rule must carry to target this
tool. Both segments sanitised to [A-Za-z0-9_-], the pair trimmed
to 64 characters. Computed by the runtime; never derive it.
^[a-zA-Z0-9_-]{1,64}$JSON Schema of the tool's arguments, as published. A
properties.action.enum is the Prisme schema convention for
several operations behind one tool; a rule may target one of them
with conditions: {action: "<value>"}.
MCP tool annotations as published (readOnlyHint,
destructiveHint, …), null when the server publishes none.
Forwarded raw; nothing is derived from them.
Transport or JSON-RPC error message when status is unavailable.
Was this page helpful?