Documentation

Tool scoping

Each endpoint has an enabled_tools allowlist with allow-by-default semantics: an empty list permits every tool (including tools added later), and a non-empty list narrows to exactly the tools named in it. The same predicate governs what tools/list shows and what tools/call accepts, so the two cannot disagree. A disabled tool is hidden from the list AND rejected at call time, reported identically to an unknown tool — and that rejection is audited.

New tokens are read-only by default

The console defaults a new endpoint to the read-only tools, so a fresh token cannot mutate anything until someone deliberately grants a write tool.

See the Tools overview for which tools are read-only and which mutate state.

Last modified on