Fetch a tool manifest (latest active version)
const url = 'https://example.com/v1/tools/example';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/v1/tools/example \ --header 'Authorization: Bearer <token>'Returns the latest active version of the tool. When all versions are unregistered (retired), the head row still exists but has no active version — the response is 410 tool-gone with the id, distinct from 404 tool-not-found (never registered).
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”ToolId — dotted namespace (acme.lookup-order).
Responses
Section titled “Responses”Tool manifest.
object
ToolId — dotted namespace (e.g. acme.verify-citation).
JSON Schema (Draft 2020-12) for the tool input.
object
JSON Schema (Draft 2020-12) for the tool output.
object
object
object
object
Semantic marker: true when this tool causes observable side effects (writes state, calls external APIs with mutations, sends messages). Read-only tools set false. Absent defaults to true. Consumed by the HITL default classifier — a read-only tool passes straight through, a mutating tool asks on first use.
Isolation posture the runtime enforces around the handler. Optional additive field.
Sandbox-enforced resource caps at dispatch. Optional additive field.
object
Typed discriminated needs (env / secrets / config / capabilities / bindings). Optional additive field.
object
object
object
object
object
object
object
Declarative HTTP-invocation spec. Attached to ToolManifest.spec under the discriminant kind: 'http'. The runtime Tool.handler is synthesized by the ‘http’ spec synthesizer to perform URL-template substitution, secret-ref resolution via ToolContext.resolveSecret, and the outbound fetch. All fields serialize cleanly to JSON.
object
URL template with {param} placeholders substituted from the tool’s input at invoke time.
object
Wall-clock timeout in ms. Default 30000.
When true (default), the response body is parsed as JSON before returning to the invoker.
object
Example
{ "effects": [ { "kind": "reads" } ], "transport": "auto", "sandbox": "none", "network": { "kind": "none" }, "codeArtifactRef": { "kind": "oci" }, "spec": { "kind": "http", "method": "GET", "authorization": { "kind": "bearer" }, "requestBody": { "kind": "json-input" } }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}No tool with that id under this tenant.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Tool retired (all versions unregistered).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}