Application users, permissions and organizations
On this page
Choose preview or production deliberately. An organization entity is the customer organization; its slug identifies that boundary in supported tool arguments.
Use these tools
- Call the relevant read or status tool first.
- Review the target and required arguments.
- Run one intended action, with explicit human confirmation where required.
- Inspect status or re-read the affected resource afterward.
Inputs below describe the public contract. Your connected server’s current tool list is authoritative. Some tools require a particular host, target, inference mode or plan. Identifiers are values returned by earlier tools; do not invent them.
app_users
The generated app’s users.
Read the returned resource and use its current values when planning the next action.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| all | No | boolean |
Operation: read-only.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
manage_app_user
Invite, update or remove an app user.
User removal or disabling can end access. Review scope and the selected profile before confirming destructive changes.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| action | Yes | invite, update, remove |
| email | No | string; minLength 3; maxLength 254 |
| name | No | string; minLength 1; maxLength 128 |
| role | No | string; minLength 1; maxLength 32 |
| disabled | No | boolean |
| profileId | No | string; minLength 1; maxLength 256 |
| confirm | No | boolean |
Operation: can change state or start work; destructive effects are possible.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
app_permissions
The generated app’s permissions.
Read the returned resource and use its current values when planning the next action.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
Operation: read-only.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
set_app_permission_default
Set a permission’s default holder.
Changes who receives a permission by default. Test an allowed and a denied user afterward.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| permission | Yes | string; minLength 1; maxLength 128 |
| defaultClass | No | none, user, member, owner |
| entityScoped | No | boolean |
Operation: can change state or start work.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
app_grants
Who holds which permission in the generated app.
Read the returned resource and use its current values when planning the next action.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| profileId | No | string; minLength 1; maxLength 256 |
| group | No | string; minLength 1; maxLength 128 |
| entitySlug | No | string; minLength 1; maxLength 63 |
Operation: read-only.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
manage_app_grant
Grant or revoke a permission in the generated app.
Grant or revoke only the intended permission and audience. Use entitySlug for a customer organization boundary.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| action | Yes | assign, revoke |
| permission | Yes | string; minLength 1; maxLength 128 |
| profileId | No | string; minLength 1; maxLength 256 |
| group | No | string; minLength 1; maxLength 128 |
| entitySlug | No | string; minLength 1; maxLength 63 |
| resources | No | array of string |
| mode | No | blanket, resources, all |
Operation: can change state or start work; destructive effects are possible.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
app_organizations
The generated app’s organizations.
Read the returned resource and use its current values when planning the next action.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| entitySlug | No | string; minLength 1; maxLength 63 |
Operation: read-only.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
manage_app_organization
Rename an organization or manage its members.
Manages customer organization titles and membership. Confirm the intended organization entity and user.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| action | Yes | rename, add-member, update-member, remove-member |
| entitySlug | Yes | string; minLength 1; maxLength 63 |
| title | No | string; minLength 1; maxLength 256 |
| email | No | string; minLength 3; maxLength 254 |
| name | No | string; minLength 1; maxLength 128 |
| owner | No | boolean |
| profileId | No | string; minLength 1; maxLength 256 |
| groups | No | array of string |
Operation: can change state or start work; destructive effects are possible.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
app_groups
The groups of an organization in the generated app.
Read the returned resource and use its current values when planning the next action.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| entitySlug | Yes | string; minLength 1; maxLength 63 |
| group | No | string; minLength 1; maxLength 128 |
Operation: read-only.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.
manage_app_group
Create, change or delete a group, or manage its members.
Group membership and permission bundles affect user access. Check the group and scope before changing or deleting it.
| Argument | Required | Type or accepted values |
|---|
| projectId | No | string |
| scope | No | ephemeral, production |
| action | Yes | create, update, delete, add-members, remove-members |
| entitySlug | Yes | string; minLength 1; maxLength 63 |
| group | Yes | string; minLength 1; maxLength 128 |
| title | No | string; minLength 1; maxLength 256 |
| bundles | No | array of object |
| profileIds | No | array of string |
| confirm | No | boolean |
Operation: can change state or start work; destructive effects are possible.
Available setups: stdio, cloud project, cloud inference; stdio, cloud project, delegated inference; stdio, local project, cloud inference; stdio, local project, delegated inference; hosted HTTP.
The machine-readable tool contracts include nested argument schemas.