Documentation menu

Application users, permissions and organizations

On this page

Choose preview or production deliberately. An organization entity is the customer organization; its slug identifies that boundary in supported tool arguments.

Use these tools

  1. Call the relevant read or status tool first.
  2. Review the target and required arguments.
  3. Run one intended action, with explicit human confirmation where required.
  4. Inspect status or re-read the affected resource afterward.

Inputs below describe the public contract. Your connected server’s current tool list is authoritative. Some tools require a particular host, target, inference mode or plan. Identifiers are values returned by earlier tools; do not invent them.

app_users

The generated app’s users.

Read the returned resource and use its current values when planning the next action.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| all | No | boolean |

Operation: read-only.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

manage_app_user

Invite, update or remove an app user.

User removal or disabling can end access. Review scope and the selected profile before confirming destructive changes.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| action | Yes | invite, update, remove |

| email | No | string; minLength 3; maxLength 254 |

| name | No | string; minLength 1; maxLength 128 |

| role | No | string; minLength 1; maxLength 32 |

| disabled | No | boolean |

| profileId | No | string; minLength 1; maxLength 256 |

| confirm | No | boolean |

Operation: can change state or start work; destructive effects are possible.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

app_permissions

The generated app’s permissions.

Read the returned resource and use its current values when planning the next action.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

Operation: read-only.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

set_app_permission_default

Set a permission’s default holder.

Changes who receives a permission by default. Test an allowed and a denied user afterward.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| permission | Yes | string; minLength 1; maxLength 128 |

| defaultClass | No | none, user, member, owner |

| entityScoped | No | boolean |

Operation: can change state or start work.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

app_grants

Who holds which permission in the generated app.

Read the returned resource and use its current values when planning the next action.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| profileId | No | string; minLength 1; maxLength 256 |

| group | No | string; minLength 1; maxLength 128 |

| entitySlug | No | string; minLength 1; maxLength 63 |

Operation: read-only.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

manage_app_grant

Grant or revoke a permission in the generated app.

Grant or revoke only the intended permission and audience. Use entitySlug for a customer organization boundary.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| action | Yes | assign, revoke |

| permission | Yes | string; minLength 1; maxLength 128 |

| profileId | No | string; minLength 1; maxLength 256 |

| group | No | string; minLength 1; maxLength 128 |

| entitySlug | No | string; minLength 1; maxLength 63 |

| resources | No | array of string |

| mode | No | blanket, resources, all |

Operation: can change state or start work; destructive effects are possible.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

app_organizations

The generated app’s organizations.

Read the returned resource and use its current values when planning the next action.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| entitySlug | No | string; minLength 1; maxLength 63 |

Operation: read-only.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

manage_app_organization

Rename an organization or manage its members.

Manages customer organization titles and membership. Confirm the intended organization entity and user.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| action | Yes | rename, add-member, update-member, remove-member |

| entitySlug | Yes | string; minLength 1; maxLength 63 |

| title | No | string; minLength 1; maxLength 256 |

| email | No | string; minLength 3; maxLength 254 |

| name | No | string; minLength 1; maxLength 128 |

| owner | No | boolean |

| profileId | No | string; minLength 1; maxLength 256 |

| groups | No | array of string |

Operation: can change state or start work; destructive effects are possible.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

app_groups

The groups of an organization in the generated app.

Read the returned resource and use its current values when planning the next action.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| entitySlug | Yes | string; minLength 1; maxLength 63 |

| group | No | string; minLength 1; maxLength 128 |

Operation: read-only.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

manage_app_group

Create, change or delete a group, or manage its members.

Group membership and permission bundles affect user access. Check the group and scope before changing or deleting it.

ArgumentRequiredType or accepted values

| projectId | No | string |

| scope | No | ephemeral, production |

| action | Yes | create, update, delete, add-members, remove-members |

| entitySlug | Yes | string; minLength 1; maxLength 63 |

| group | Yes | string; minLength 1; maxLength 128 |

| title | No | string; minLength 1; maxLength 256 |

| bundles | No | array of object |

| profileIds | No | array of string |

| confirm | No | boolean |

Operation: can change state or start work; destructive effects are possible.

Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.

The machine-readable tool contracts include nested argument schemas.

MCP home · Recovery workflow · Costs