Register a tool manifest
const url = 'https://example.com/v1/tools';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"id":"example","description":"example","version":"example","input":{},"output":{},"needs":[{"name":"example","optional":true}],"effects":[{"kind":"reads","resource":"example","notes":"example"}],"transport":"auto","mcpEndpoint":"example","metadata":{},"mutating":true,"sandbox":"none","limits":{"memMB":1,"cpuMs":1},"network":{"kind":"none"},"needsSpec":{"env":{"additionalProperty":{}},"secrets":{"additionalProperty":{}},"config":{"additionalProperty":{}},"capabilities":["example"],"bindings":["example"]},"codeArtifactRef":{"kind":"oci","imageRef":"example","modulePath":"example","artifactVersion":"example"},"spec":{"kind":"http","method":"GET","urlTemplate":"example","headers":[{"name":"example","value":"example"}],"authorization":{"kind":"bearer","secretRef":{"envName":"example","name":"example"}},"requestBody":{"kind":"json-input"},"timeoutMs":1,"parseJson":true,"successStatus":{"min":1,"max":1}},"projectId":"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/tools \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "id": "example", "description": "example", "version": "example", "input": {}, "output": {}, "needs": [ { "name": "example", "optional": true } ], "effects": [ { "kind": "reads", "resource": "example", "notes": "example" } ], "transport": "auto", "mcpEndpoint": "example", "metadata": {}, "mutating": true, "sandbox": "none", "limits": { "memMB": 1, "cpuMs": 1 }, "network": { "kind": "none" }, "needsSpec": { "env": { "additionalProperty": {} }, "secrets": { "additionalProperty": {} }, "config": { "additionalProperty": {} }, "capabilities": [ "example" ], "bindings": [ "example" ] }, "codeArtifactRef": { "kind": "oci", "imageRef": "example", "modulePath": "example", "artifactVersion": "example" }, "spec": { "kind": "http", "method": "GET", "urlTemplate": "example", "headers": [ { "name": "example", "value": "example" } ], "authorization": { "kind": "bearer", "secretRef": { "envName": "example", "name": "example" } }, "requestBody": { "kind": "json-input" }, "timeoutMs": 1, "parseJson": true, "successStatus": { "min": 1, "max": 1 } }, "projectId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0" }'Body is a ToolManifest (Tool minus its runtime handler). Server validates via @kindgi/tools.validateToolManifest. Metadata only: the handler is not uploaded through this route and must already be available to the runtime.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”Caller-supplied idempotency key. Retries with the same key return the original response byte-identical (per docs/API-ROUTE-CONVENTIONS.md §3.1).
Request Bodyrequired
Section titled “Request Bodyrequired”ToolManifest — Tool minus its runtime handler. Validated server-side via @kindgi/tools.validateToolManifest. Metadata-only registration: the handler is not uploaded and must already be available to the runtime.
object
ToolId — dotted namespace (e.g. acme.verify-citation).
JSON Schema (Draft 2020-12) for the tool input.
object
JSON Schema (Draft 2020-12) for the tool output.
object
object
object
object
Semantic marker: true when this tool causes observable side effects (writes state, calls external APIs with mutations, sends messages). Read-only tools set false. Absent defaults to true. Consumed by the HITL default classifier — a read-only tool passes straight through, a mutating tool asks on first use.
Isolation posture the runtime enforces around the handler. Optional additive field.
Sandbox-enforced resource caps at dispatch. Optional additive field.
object
Typed discriminated needs (env / secrets / config / capabilities / bindings). Optional additive field.
object
object
object
object
object
object
object
Declarative HTTP-invocation spec. Attached to ToolManifest.spec under the discriminant kind: 'http'. The runtime Tool.handler is synthesized by the ‘http’ spec synthesizer to perform URL-template substitution, secret-ref resolution via ToolContext.resolveSecret, and the outbound fetch. All fields serialize cleanly to JSON.
object
URL template with {param} placeholders substituted from the tool’s input at invoke time.
object
Wall-clock timeout in ms. Default 30000.
When true (default), the response body is parsed as JSON before returning to the invoker.
object
Project this belongs to (its content scope). Required: missing, or not a project in the caller’s tenant → 400 bad-input.
Responses
Section titled “Responses”Tool registered.
object
Examplegenerated
{ "toolId": "example"}Validation failed (see details.issues).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Tool already registered at that id.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Server error (unmapped domain code or framework crash).
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}