Documentation
Tool scoping
Each endpoint has an enabled_tools allowlist with allow-by-default semantics: an empty
list permits every tool (including tools added later), and a non-empty list narrows to
exactly the tools named in it. The same predicate governs what tools/list shows and what
tools/call accepts, so the two cannot disagree. A disabled tool is hidden from the list AND
rejected at call time, reported identically to an unknown tool — and that rejection is audited.
New tokens are read-only by default
The console defaults a new endpoint to the read-only tools, so a fresh token cannot mutate anything until someone deliberately grants a write tool.
See the Tools overview for which tools are read-only and which mutate state.
Last modified on