List all versions of a tool
const url = 'https://example.com/v1/tools/example/versions?limit=25&includeTombstoned=false';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/tools/example/versions?limit=25&includeTombstoned=false' \ --header 'Authorization: Bearer <token>'Cursor-paginated list of tool versions. Defaults to active versions only. Pass ?includeTombstoned=true to include soft-tombstoned rows too; tombstoned rows carry unregisteredAt (ISO string), active rows do not.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”ToolId — dotted namespace (acme.lookup-order).
Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
When true, the response includes soft-tombstoned versions in addition to active ones. Tombstoned rows carry an unregisteredAt ISO timestamp; active rows omit the field. Default: false (active-only).
Responses
Section titled “Responses”Page of tool versions.
object
object
ToolId — dotted namespace (e.g. acme.verify-citation).
JSON Schema (Draft 2020-12) for the tool input.
object
JSON Schema (Draft 2020-12) for the tool output.
object
object
object
object
Semantic marker: true when this tool causes observable side effects (writes state, calls external APIs with mutations, sends messages). Read-only tools set false. Absent defaults to true. Consumed by the HITL default classifier — a read-only tool passes straight through, a mutating tool asks on first use.
Isolation posture the runtime enforces around the handler. Optional additive field.
Sandbox-enforced resource caps at dispatch. Optional additive field.
object
Typed discriminated needs (env / secrets / config / capabilities / bindings). Optional additive field.
object
object
object
object
object
object
object
Declarative HTTP-invocation spec. Attached to ToolManifest.spec under the discriminant kind: 'http'. The runtime Tool.handler is synthesized by the ‘http’ spec synthesizer to perform URL-template substitution, secret-ref resolution via ToolContext.resolveSecret, and the outbound fetch. All fields serialize cleanly to JSON.
object
URL template with {param} placeholders substituted from the tool’s input at invoke time.
object
Wall-clock timeout in ms. Default 30000.
When true (default), the response body is parsed as JSON before returning to the invoker.
object
ISO 8601 timestamp — present iff this version has been soft-tombstoned via POST /versions/:v/unregister. Absent on active versions.
Opaque cursor for the next page. Absent when hasMore: false.
Example
{ "data": [ { "effects": [ { "kind": "reads" } ], "transport": "auto", "sandbox": "none", "network": { "kind": "none" }, "codeArtifactRef": { "kind": "oci" }, "spec": { "kind": "http", "method": "GET", "authorization": { "kind": "bearer" }, "requestBody": { "kind": "json-input" } } } ]}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}No tool with that id under this tenant.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}