{"_id":"@axonity-ai/mcp","_rev":"13-331e994a61b4e1cb9d8d43e49d13024e","name":"@axonity-ai/mcp","dist-tags":{"latest":"0.11.0"},"versions":{"0.1.0":{"name":"@axonity-ai/mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.1.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"axonity-mcp":"dist/index.js"},"dist":{"shasum":"11f0f886c48667c0b6928e8359e0f2a6d0f877fd","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.1.0.tgz","fileCount":30,"integrity":"sha512-BSjNEJlvojfcH1T/6mfkkRZo46M3rzdPPfq85Xx8z4nmDu2DEVJZf7AzHKAEjHlPIzMiGKI8wAjRZ6lGj7LLQA==","signatures":[{"sig":"MEQCIGG1Nn3CRD61xN7j7NHAUPXPRRL4MQ9JYNIHKUA9LeszAiBr9UHWU+ouy21CUy5LoreUAUf+I6cZ7B2nJaZUmDwyGQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52779},"type":"module","engines":{"node":">=20"},"gitHead":"7739dd86190b3bb24e8916f67b72ca880c705e9b","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1784458178479_0.2760842119639788","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@axonity-ai/mcp","version":"0.2.2","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.2.2","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"axonity-mcp":"dist/index.js"},"dist":{"shasum":"9bb63466be7ee1bfa842be26f1e8ef5d7e6d71d7","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.2.2.tgz","fileCount":45,"integrity":"sha512-zhvTdEMvA0YGC4UMn9Ki+xeIkof0CNBNvzXub9UrDmBwgzjTE9CdOAIMtq+70Atx5GMwIhRD6lO8XHZghTvVvw==","signatures":[{"sig":"MEUCIQDvmEAyQKw/MoB+iQDshNc/XgOc0SaT1yr3zLrhWrZqOgIgLQ8UGuurlqwIvmCDKyCMqrJgrKUhGvnPnxBWd15FiLk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":171366},"type":"module","engines":{"node":">=20"},"gitHead":"8201a857d020c5136a3d6f6edbe95df6c68a7718","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.2_1784619897695_0.5555885943680166","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@axonity-ai/mcp","version":"0.3.2","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.3.2","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"axonity-mcp":"dist/index.js"},"dist":{"shasum":"c81bdb5df87551abdd824e5b420705af3f6f6fb7","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.3.2.tgz","fileCount":51,"integrity":"sha512-DhRrwF0ODXYfche/WFdlqx6zOgPSWmpCHifpjqTAhHnoehDSp1mn/OIcI2g1JMHvK3BYKEzpjz47hbiYaR4nZw==","signatures":[{"sig":"MEQCIBNDZa6EgM3qKjO/BOd+shDffrQwxrpulDcIlk5tR67yAiBYbCr4WrLGGHLXnnrveFkPPvuzlmqN8niVB5iO5xEH/Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":221550},"type":"module","engines":{"node":">=20"},"gitHead":"e8205af21c039b5a85dd09ee68b94abf2616a0a4","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.2_1785133723487_0.9647389846382499","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@axonity-ai/mcp","version":"0.3.3","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.3.3","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"527fcf135695488b30087ed5c29257cadb10f551","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.3.3.tgz","fileCount":51,"integrity":"sha512-6KQgRxZl8BdDuCTWtCkh7IMopVT11deYfZ4B4DnoFGrCJhIVxEcWdt1+ymP+P/sSmDsGyJUp+hUAym6yfxzmJw==","signatures":[{"sig":"MEUCIQCQOmfEdb8daW1kEnxnSj3uAwA4OMrY0v2wFJUrVTJYpwIgMQs3QeZ49WLtGZTVo42+gsCD7HyNdIppbpBaxwy3jsk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":222748},"type":"module","engines":{"node":">=20"},"gitHead":"78838cfd74e81e1caf043bcb67d7bd6dc2085b48","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.3_1785144025310_0.759631687986547","host":"s3://npm-registry-packages-npm-production"}},"0.3.4":{"name":"@axonity-ai/mcp","version":"0.3.4","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.3.4","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"a6b3c9f049e7b78a4d5ecdf123bd1d7336cc16d6","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.3.4.tgz","fileCount":51,"integrity":"sha512-n+VfqKDOQ3lUfEjHH8rNSDPWQJR4sWovVauqcsOSWFhk8o0HwKky/7AA8Lh2eDmucfkq33v60SuFvC9sfnIl6A==","signatures":[{"sig":"MEUCIQD4TATqTKTD5WSUABGxcg5RsWBsYR+2n+xWGHqDkArwQAIgb7+EvMuneNUrV0Mxu2x0lAzs/cGZbRHf43yslIaByAE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":241578},"type":"module","engines":{"node":">=20"},"gitHead":"075f18ca3ed244c6e1cc2d0b07e5fb6a11d175c9","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.4_1785311258911_0.640488729420098","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@axonity-ai/mcp","version":"0.4.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.4.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"4e7f068c7d09edb377684ec5ef2734717b093ef4","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.4.0.tgz","fileCount":51,"integrity":"sha512-jprI13p7yDM4tHePWdwvhAYqW5FVXF6f9uWWxodSTB408txcuzlsSTgTl6SsXEOlQPsPb62kP7b/EBURaepASg==","signatures":[{"sig":"MEYCIQD7qDDlv5lqas3qySRlXr2OsB+mnIChZEB5fSZxl63+cwIhAOm5McXUljTVL+LF6dXO5JDt5tAC+QXoD95DdYYiXXuV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":256221},"type":"module","engines":{"node":">=20"},"gitHead":"222749344e6d98e9b5b52538569b3f21176a3171","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.4.0_1785330263681_0.437628912336528","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@axonity-ai/mcp","version":"0.5.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.5.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"b05270a9eddd30f058b306251a5241de676da064","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.5.0.tgz","fileCount":51,"integrity":"sha512-2j4l2TbqNoGuQeI9lbmybXXuXa+yafcBQOZQlZFDZ4rXgPxFDIufu7i7Q+zFDk7oCXummiRCRwIgcLiwTC4Jtg==","signatures":[{"sig":"MEUCIQCURrCm5+YsFYJRwWcRFLTkH6luEIVqKqYCPVMUlF8xpQIgRL8CwdkU3NrBro4cw21+yPfGB8ZN1dpEpztHSEL+wDs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":263755},"type":"module","engines":{"node":">=20"},"gitHead":"b517fdbeaac3dd3377a6bfb0e253a0849f7e23b5","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.5.0_1785924082287_0.8173522838141167","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@axonity-ai/mcp","version":"0.6.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.6.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"a92095e8a05e13598b392fce7c71df89472b9a87","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.6.0.tgz","fileCount":51,"integrity":"sha512-vxxd8+mrjiMMSFrvHgExY5AVL7Nfu3DHrmhSb6MPsm6k2v+j3UfSmrwF5p8N45rjnHtUaW4Z94Mk7BP1f/dgAg==","signatures":[{"sig":"MEUCIQCymxJ3fJLXVxGGlaSCU4qkVZeJabnKQoQf/Jn1qBF9ZwIgBjVoJkfpV3VD4MpISSahbMo6luzE32hVnyu5d06FrEs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":268344},"type":"module","engines":{"node":">=20"},"gitHead":"414c3558fe0186cc4647c6173d01a9ae7b824b21","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.6.0_1786033076153_0.6555244801433067","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@axonity-ai/mcp","version":"0.7.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.7.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"f4924e594aa0b83392c51d13597294e935ebfbe1","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.7.0.tgz","fileCount":66,"integrity":"sha512-atauHF0UyLc9Cfg+fpzlPnlaJmfCD0h9XaRx2WgS8mt58vEOKX5fTquZTL7PwsY+/EL4OdhzzSxuRb4JcsULSg==","signatures":[{"sig":"MEUCIQDBbUBUVxGz3Z9+REt+8nqKLKx5HqFE7RZNJ77S+ocYZgIgMVnMHMWucfRSzXpvvP/7/KD9J990WEISmBt20LsoSQQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":407855},"type":"module","engines":{"node":">=20"},"gitHead":"7d0e135e6c6e1581d51a3eab6c1c181858992dc6","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","check:contract":"node scripts/check-contract-drift.mjs --flow \"${AXONITY_FLOW_PATH:-../axonity-flow}\"","prepublishOnly":"npm run build","generate:filters":"node scripts/generate-list-filters.mjs"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.7.0_1787400398852_0.7020787067284173","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@axonity-ai/mcp","version":"0.8.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.8.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"c3fbc6ccfb6b76eae91f8e42ef2272fd54593839","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.8.0.tgz","fileCount":72,"integrity":"sha512-2uSet6f1cywrFclEmqjwGGVANFQZ5OIz0Br0xkINUfrmYCQ9bOVywqFGMFPLIIp+VHeZODk9x/esyWYhdoiqOg==","signatures":[{"sig":"MEUCIDqK+4J3+WhOUnIkZqS8/BtNOqEeJs5WLX0fquPWWVMPAiEAocyR0stTvJS2vy2fL8S0T/3JdnbOmsWh+QnjtCBcnY0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":485790},"type":"module","engines":{"node":">=20"},"gitHead":"e34849cf06304b83217747680b9eb81bbc6ed0d9","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","check:contract":"node scripts/check-contract-drift.mjs --flow \"${AXONITY_FLOW_PATH:-../axonity-flow}\"","prepublishOnly":"npm run build","generate:filters":"node scripts/generate-list-filters.mjs"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.8.0_1787475630438_0.8964783107446213","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@axonity-ai/mcp","version":"0.9.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.9.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"edc10aabd3ee15a2dfa6b96609e38f8386a17d88","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.9.0.tgz","fileCount":75,"integrity":"sha512-OcvHGBZVF0FZlPOGr+wozul7lVXcbGsmtvc6kDMzQKfCo35Yvv55GeUFAg8wkDrz6q7NZY+h6K1MgdzlYMcoYA==","signatures":[{"sig":"MEQCIHGBM3gi9oQ5k5Y1h2zp2u4eCJYyerxwOd3s4MZpyGKCAiBOZWNR5URCjF88GQc7BiqBAgdHmmD9SGXdwktpvzMYjQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":520603},"type":"module","engines":{"node":">=20"},"gitHead":"11d2186d2d806770cb8fd21f19b2db5aeaf307f8","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","check:contract":"node scripts/check-contract-drift.mjs --flow \"${AXONITY_FLOW_PATH:-../axonity-flow}\"","prepublishOnly":"npm run build","generate:filters":"node scripts/generate-list-filters.mjs"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.9.0_1788416093053_0.11876043673819359","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@axonity-ai/mcp","version":"0.10.0","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"license":"MIT","_id":"@axonity-ai/mcp@0.10.0","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"dist":{"shasum":"4858c183c0443acaad2fc44a54a48d88f73eb833","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.10.0.tgz","fileCount":75,"integrity":"sha512-/Ntk2VPN662WL5K2rpgFSTvH8ituoy1mjwKuJ9Ia+3flfyN6Esz2egQSg/dxVjru86XnjJzF+R6efC0sDbuDHg==","signatures":[{"sig":"MEUCIGFlI8nbJo36wK+70rcmz9ap1zAQzDtcPTtPMHbsHsZoAiEAmmJwTFhHbRkpVn4Fp3pg0msZyZHQNn1A12SS93y+NZ8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIE+smbjPF2hUBOi6hupdVcdAoVNIKB0FPlhoXrnlg7W9AiEA06+OZkPn30RtMJ+ny+iTTRiR8tVWOv/1c73zSomdIaY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":531493},"type":"module","engines":{"node":">=20"},"gitHead":"9ac0e90792579995a15c79ed1bf3405da63e215f","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","release:major":"bash scripts/release.sh major","release:minor":"bash scripts/release.sh minor","release:patch":"bash scripts/release.sh patch","check:contract":"node scripts/check-contract-drift.mjs --flow \"${AXONITY_FLOW_PATH:-../axonity-flow}\"","prepublishOnly":"npm run build","generate:filters":"node scripts/generate-list-filters.mjs"},"_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.10.0_1788684679681_0.2996428809293763","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"_id":"@axonity-ai/mcp@0.11.0","bin":{"mcp":"dist/index.js","axonity-mcp":"dist/index.js"},"bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"dist":{"shasum":"c0b5dcfc0f3be2041459c6276bc9ca9550b3252d","tarball":"https://registry.npmjs.org/@axonity-ai/mcp/-/mcp-0.11.0.tgz","fileCount":78,"integrity":"sha512-V360L383fWsTgDQFQFHKKn/PRBF+wehrCnAQ5Z3tM8+VGXa5hZ+vb3ptap3BMOuPSee/npUhuzs33oHrDvf9Rg==","signatures":[{"sig":"MEQCIHrvfV4jY2kH0Jn0HfVDA3KxfBHPpSs7+QaYKbXKL7xAAiBCshvjr7ItD3cW5lfprmzfsP7icnW7cIlKZajejQwXdw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCWfyW3h6Gd9jIvlRouJavCEJo+jRXvJpPWkpiRpXfeqgIgaXnAneXg9oh2BkUNAjluZQmKsixEXQKJOzx+HHzJaPs="}],"unpackedSize":556308},"name":"@axonity-ai/mcp","type":"module","engines":{"node":">=20"},"gitHead":"1c291a730c51a7cc4f8cbebed697aad540ab65f4","license":"MIT","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","release:major":"bash scripts/release.sh major","release:minor":"bash scripts/release.sh minor","release:patch":"bash scripts/release.sh patch","check:contract":"node scripts/check-contract-drift.mjs --flow \"${AXONITY_FLOW_PATH:-../axonity-flow}\"","prepublishOnly":"npm run build","generate:filters":"node scripts/generate-list-filters.mjs"},"version":"0.11.0","_npmUser":{"name":"jonathanderamaix","email":"jonathan@axonity.ai"},"homepage":"https://github.com/AxonityAI/axonity-mcp#readme","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"_npmVersion":"10.9.8","description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","directories":{},"maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.8","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.16.0","vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.11.0_1788982523872_0.4421347142243073"}}},"time":{"created":"2026-07-19T10:49:38.357Z","modified":"2026-09-09T19:35:24.156Z","0.1.0":"2026-07-19T10:49:38.631Z","0.2.2":"2026-07-21T07:44:57.834Z","0.3.2":"2026-07-27T06:28:43.620Z","0.3.3":"2026-07-27T09:20:25.461Z","0.3.4":"2026-07-29T07:47:39.103Z","0.4.0":"2026-07-29T13:04:23.849Z","0.5.0":"2026-08-05T10:01:22.427Z","0.6.0":"2026-08-06T16:17:56.316Z","0.7.0":"2026-08-22T12:06:38.999Z","0.8.0":"2026-08-23T09:00:30.566Z","0.9.0":"2026-09-03T06:14:53.284Z","0.10.0":"2026-09-06T08:51:19.764Z","0.11.0":"2026-09-09T19:35:23.974Z"},"bugs":{"url":"https://github.com/AxonityAI/axonity-mcp/issues"},"license":"MIT","homepage":"https://github.com/AxonityAI/axonity-mcp#readme","keywords":["mcp","model-context-protocol","axonity","claude","agent"],"repository":{"url":"git+https://github.com/AxonityAI/axonity-mcp.git","type":"git"},"description":"Model Context Protocol server for Axonity Flow — lets an external agent (e.g. Claude Code) read, draft, and update workflows, agents and tools in an Axonity tenant.","maintainers":[{"name":"jonathanderamaix","email":"jonathan@axonity.ai"}],"readme":"# @axonity-ai/mcp — Axonity Flow MCP connector\n\nA local [Model Context Protocol](https://modelcontextprotocol.io) server that lets\nan external agent (e.g. **Claude Code** on your laptop) read, draft, update, and\nrecoverably delete **workflows, agents, tools, skills, policies, reference docs,\npersonas, output schemas, prompt snippets and flows** in your Axonity tenant —\nthe same verbs the internal Builder team has, minus direct publish.\n\nIt runs on your machine and talks to Axonity **only over the public REST API**,\nauthenticated with a per-tenant **service token**. The backend re-enforces\ntenant + scope on every call, so the connector is not a trust boundary.\n\n## Setup\n\n1. **Mint a service token** in Axonity → **Settings → API tokens**. Copy it once\n   (it starts with `axs_`); you won't see it again. Use a **read-only** token if\n   you only want the agent to read — it is genuinely enforced, any write from it\n   is refused with a 403. Every token expires (you choose 7, 15, 30, 60 or 90\n   days at mint time; there is no \"never\"), and there is no way for the agent to\n   check remaining lifetime in advance — an expired token fails exactly like a\n   revoked one, so mint a fresh one when that happens.\n2. **Add the connector to Claude Code:**\n\n   ```bash\n   claude mcp add axonity \\\n     --env AXONITY_TOKEN=axs_your_token_here \\\n     --env AXONITY_API_URL=https://app.axonity.ai \\\n     -- npx -y @axonity-ai/mcp\n   ```\n\n   `AXONITY_API_URL` is optional (defaults to the Axonity SaaS URL); set it if you\n   self-host.\n\n   Do **not** pass extra CLI arguments to `axonity-mcp`; startup only reads\n   environment variables. If arguments are supplied, the process exits with a\n   clear usage-style error.\n\n3. Ask Claude Code things like *\"list my Axonity workflows\"*, *\"create a workflow\n   called Onboarding\"*, or *\"add a step to workflow X\"*.\n\n## Tools\n\n345 tools total. `axonity_conventions` (read this first) covers the authoring\nrules — drafts vs live, optimistic locking, per-entity fields, delete/restore,\nand how to tell a retryable error from one that will never succeed.\n\nWhat the connector does **not** state is as deliberate as what it does: the\nmutation commands, the step types, the trigger types, the schedule-rule shapes\nand the three value vocabularies are all read live from\n`get_workflow_authoring_spec`, because every one of those lists drifted while it\nwas kept here. A conformance test asserts their absence.\n\n### The generic entity family\n\nEleven entities — **workflow, agent, tool, skill, policy, reference_doc,\npersona, output_schema, prompt_snippet, flow, data_table** — share one shape,\nthough not every entity gets every verb (see the per-entity notes below for the\nexceptions):\n\n| Tool (per `<entity>`) | What it does |\n|------|--------------|\n| `list_<plural>` | List the tenant's entities. |\n| `read_<entity>` | Read one by id (incl. its version — read before you update). |\n| `create_<entity>` | Create a new **draft**. |\n| `update_<entity>` | Update a draft (`expectedVersion` in the body; 409 on a stale write). |\n| `delete_<entity>` | Soft-delete. **Recoverable** — see `restore_<entity>`. |\n| `restore_<entity>` | Undo a delete. No version check. |\n| `list_deleted_<plural>` | Restore candidates. |\n| `discard_<entity>_draft` | Reset the draft to the last published state. |\n| `request_publish_<entity>` | Ask for a draft to be published — creates a pending approval; never publishes. |\n\nExceptions: `persona` has no `create_persona` (create only via\n`create_agent_persona`). And `list_data_tables` answers **one page**, not the\nwhole library — see Tables below.\n\nSome list routes narrow in the query, which is where narrowing belongs — the\nbackend applies it before the rows come back:\n`list_workflows({ stageId?, capabilityId? })`,\n`list_agents({ includeSystem? })`,\n`list_policies({ scope?, ownerId? })`,\n`list_reference_docs({ scope?, ownerId? })`,\n`list_prompt_snippets({ deleted? })`,\n`list_data_tables({ name?, status?, isDynamic? })`.\n\nThat table is **generated** from the pinned schema's own query parameters\n(`npm run generate:filters` → `src/generated/listFilters.ts`), not hand-listed.\nA filter the backend adds is exposed as soon as the snapshot is refreshed, and\na test fails if the two have parted. The argument names are camelCase; the wire\nkeeps whatever spelling each route declares, which is not consistent between\nthem and is not something a caller should have to know.\n\nPlus:\n- `get_workflow_authoring_spec` — everything **this deploy** can be built from,\n  read live from the server (`GET /workflows/operations`): the mutation\n  `operations`, the `triggerTypes`, the `stepTypes` (including the ones you may\n  not author, each with the reason and what to write instead), the\n  `scheduleRuleKinds` (each with an example the backend round-trips through its\n  own parser as it serves it), and **three vocabularies for a value's type that\n  are not interchangeable** — `parameterTypes` (a trigger parameter's or\n  workflow constant's `type`), `outputKinds` (a step output's or input's\n  `kind` — narrower, *different key*) and `schemaFieldKinds` (inside a field's\n  `schema`, which wins where present). Getting that last group wrong is silent:\n  a `kind` written on a trigger parameter is not a 422, it is a key nothing\n  reads, so the value falls back to text. Every list is generated from the\n  registry that *enforces* it, so the connector states none of them and a new\n  value is discoverable without a release here. `operations` is an index by\n  default; pass `types` for a command's live payload schema. `rulesVersion` is\n  a content hash over all seven — same hash, nothing to re-fetch.\n- `apply_workflow_mutations` for structural workflow edits (add steps, connect\n  edges) via mutation commands, sequenced and version-threaded for you.\n- `replace_workflow_document` for one-shot full-document replacement in a single\n  atomic PUT.\n- `read_workflow_trigger_parameters` — how to start the workflow:\n  `{ triggers, constants }`, every start with its own parameters and a `pinned`\n  flag marking the values the author owns.\n- `bulk_delete_workflows` — soft-delete several at once (each with its own\n  `expectedVersion`).\n\n### Version history, rollback, and version-level delete\n\nFor the eleven versioned entities (including `flow` and `data_table`):\n\n| Tool | What it does |\n|------|--------------|\n| `list_<entity>_versions` | List version history (checkpoints + named majors). |\n| `read_<entity>_version` | Read one, by **integer checkpoint number**. |\n| `restore_<entity>_version` | Roll the draft back to an old version (`expectedVersion` in body). |\n| `delete_<entity>_version` | Remove one history entry. Draft and published version are protected. |\n| `list_deleted_<entity>_versions` | Restore candidates for the row above. |\n| `restore_deleted_<entity>_version` | Undo the delete above. No version check. |\n| `read_<entity>_published` | The live snapshot, as opposed to the draft. |\n| `create_<entity>_major_version` | Cut a new **named** major version — \"Save As\" on the current draft. |\n| `ensure_<entity>_major_version` | Make sure a working draft major version exists. Idempotent. |\n| `name_<entity>_major_version` | Rename an existing major version (label a release). |\n\n`{version}` (an int) and `{versionId}` (a UUID) are two different identifiers\nacross these routes — the tool parameter names say which.\n\n### Also\n\n- **Personas**: `read_agent_persona`, `create_agent_persona` — agent-scoped,\n  since a persona can only be created through its agent. Everything else about\n  a persona (list, read, update, delete/restore, versions) is the generic\n  entity family above.\n- **Connectors** (a tool of type `connector`): `create_connector`,\n  `update_connector` — `authConfig` must be placeholders only; a human fills real\n  secrets in Axonity. (`create_tool`/`update_tool` carry the same guard, so a\n  connector authored either way is covered.)\n- **Toolboxes** (the group a tool is filed under): `list_toolboxes`,\n  `create_toolbox`, `update_toolbox`, `delete_toolbox`, `set_toolbox_tools`,\n  `assign_tool_toolbox`, `set_toolbox_auth`, `list_toolbox_dependent_tools`.\n  Read `list_toolboxes` before `create_tool` and pass `toolboxId` — a tool made\n  without one is ungrouped. Three things worth knowing before you write:\n  `set_toolbox_tools` **declares** the membership (anything you leave out is\n  evicted — `assign_tool_toolbox` moves a single tool and takes `null` to\n  ungroup); a box never changes what an agent may *call*, only how a tool is\n  *advertised* (agents link to individual tools, never to a box); and deleting a\n  box leaves its tools alive, ungrouped. `set_toolbox_auth` sets the credential a\n  box's tools share and carries the same placeholder guard as a connector.\n- **Attach / detach memory**: `attach_skill_to_agent`,\n  `attach_skill_to_workflow`, `attach_policy_to_agent`,\n  `attach_reference_to_agent`, `attach_reference_to_workflow`, and a\n  `detach_*_from_*` for each. Detaching removes the link only — the skill or\n  policy itself is untouched. Read the links back with `list_agent_skills`,\n  `list_agent_policies`, `list_agent_reference_docs`, `list_workflow_skills`\n  and `list_workflow_reference_docs`. The three agent read-backs take an\n  optional `workflowId` for the **composed runtime view** — what the agent's\n  prompt actually assembles inside that workflow, with a `linkSource` per row\n  saying why each item is there.\n- **What uses this?**: `list_workflows_using({ entityKind, entityId })` names\n  the workflows that reference a tool, agent, flow, output schema or workflow,\n  **and the steps they reference it in**, with `draft`/`published` per hit.\n  `list_dependent_agents({ entityKind, entityId })` is the same question for a\n  skill, policy or reference doc. Ask before editing anything shared — the\n  alternative is validating every workflow in the tenant.\n- **Prompt elements (placement)**: a `prompt_snippet` is a library item; it only\n  takes effect once placed into a flow step's prompt stack.\n  `read_workflow_prompt_stacks` / `read_flow_prompt_stacks` resolve a\n  workflow/flow to its steps and each step's `system`/`user` stacks (this is how\n  you find the `flowStepId`s). Then `attach_prompt_snippet_to_flow_step`\n  (`target` = `system`|`user`, with an order), `update_flow_step_prompt`,\n  `reorder_flow_step_prompts`, `detach_prompt_snippet_from_flow_step`, and\n  `list_flow_step_prompts` / `list_wildcard_prompts`.\n- **Company** (the tenant's single company document — a singleton, no id):\n  `read_company`, `update_company` (whole-document save with `expectedVersion`),\n  `list_company_versions`, `read_company_version`, `restore_company_version`,\n  `name_company_major_version`, `create_company_major_version`,\n  `ensure_company_major_version`, `read_company_published`,\n  `apply_company_mutation` (one validated, version-safe command — preferred\n  over the whole-document `update_company`, the same way\n  `apply_workflow_mutations` is preferred for a workflow), and\n  `request_publish_company` (takes no id — the\n  server resolves your tenant's one company; direct company publish is closed to\n  service tokens).\n- **Subworkflows**: `list_callable_workflows` — which workflows a `subprocess`\n  step may call, each with its `parameters` and `outcomes`, and a\n  `blockedReason` for the ones that cannot (never published, or no\n  `subprocess-invocation` trigger). Authoring both halves is ordinary\n  `apply_workflow_mutations` work — a callable workflow's signature goes into\n  the `add_trigger` call itself. `validate_workflow` **does** check a subprocess\n  target now (missing, self-call, deleted, unpublished, not callable), but\n  `list_callable_workflows` is still what you run first: it is how you pick a\n  target and read the interface you are binding to.\n- **The deploy, the tenant and its queues** (read-only): `read_deploy_contract`\n  (what this backend actually mounts — read it when a call fails in a way that\n  smells like a version mismatch), `list_users` (where an `ownerId` comes from),\n  `list_audit_events` (pass `actorKind: \"service_token\"` to read back what\n  external agents — including you — changed), `read_queue_overview`,\n  `list_in_flight_runs`, `read_task_queue_summary`, `list_task_queue`,\n  `read_task_queue_item`, `export_task_queue`, plus `read_model_tier_map` (what\n  `capabilityTier` resolves to), `read_concurrency_status`,\n  `read_concurrent_run_cap` and `read_for_each_rate`. Together these answer *why\n  is my run not moving* without asking a human to look at a screen. Every write\n  in these families — purging or replaying queue work, changing a cap or the\n  tier map, importing a tenant bundle, reading someone's notifications — is\n  deliberately absent and recorded in `test/denyList.ts`, the list\n  `test/exclusions.test.ts` enforces.\n- **Secrets** (read-only): `list_secrets`, `read_secret` — the catalogue a\n  connector's `authConfig.secretId` points at. Values are never returned by any\n  Axonity route; `valueKeys` says which keys a human has filled in, so you can\n  tell an unfinished secret from a finished one before wiring to it. Creating or\n  changing a secret is a human act in Axonity (#39).\n- **Catalog & cloning**: `list_system_tools` (read-only catalog — enabling one\n  for an agent is `update_agent` with the id added to `systemToolIds`),\n  `clone_flow`, `clone_prompt_snippet`, `list_tool_packages` (the import\n  allowlist `validate_tool_code` judges against), `list_templates` /\n  `read_template`.\n- **Tables** (`data_table`): the tenant's own reference data — a table an\n  author designs and maintains, and agents and decisions read. The whole\n  lifecycle is the generic family above; three things are not, and each is a\n  way to be quietly wrong:\n  - `list_data_tables` is **paged** (20 by default, 200 max), alone among the\n    library lists, because a tenant's reference data has no ceiling. Page one\n    is not the library — follow `nextCursor` while `hasMore`, or narrow with\n    `name`, which is exact and unique per workspace.\n  - **`rows` and `columns` are whole-collection fields.** Sending `rows`\n    through `update_data_table` replaces the table's content; one row there\n    deletes every other. `add_data_table_row`, `update_data_table_row` and\n    `delete_data_table_row` address a single row by a `matchColumn` /\n    `matchValue` pair and cannot touch the rest.\n  - **A table's derived tools follow its published version.** A published table\n    mints its own CRUD tools, so granting an agent access to one is ordinary\n    tool granting. `list_data_table_tools` reports `offered` (what the draft\n    would yield), `toolId` (whether a row exists) and `isLive` (whether a run\n    can reach it) separately — an author who ticked \"may add rows\" and has not\n    published has granted nothing yet.\n- `list_deleted_prompt_snippets` calls `/api/v1/prompt-snippets/deleted`; the\n  backend returns it as `{ items: [... ] }`, and the tool forwards that response\n  unchanged.\n\n### Validate and run before you publish\n\n| Tool | What it does |\n|------|--------------|\n| `validate_workflow` | Structural + schema check of a workflow document. Stateless and read-only-token safe; does not verify referenced agents/tools exist. |\n| `analyze_workflow_reachable_outputs` | What a given step can read from upstream — bind inputs to real fields instead of guessing. Stateless and read-only-token safe. |\n| `validate_tool_code` | Syntax and banned-pattern check for Python tool code. Stateless and read-only-token safe. |\n| `format_tool_code` | Format tool code with Black. Stateless and read-only-token safe. |\n| `execute_tool` | Actually RUN tool code (not just validate it) and see the real output. |\n| `execute_stored_connector` | Test-run an already-saved connector. The backend decrypts its real secret server-side — the agent supplies only input parameters and never sees the secret. |\n\n### Triggers — what makes a workflow run\n\n`list_/create_/delete_` for **webhook triggers** (plus\n`rotate_webhook_trigger`), **cron schedules**, and **conditional triggers**\n(plus `update_conditional_trigger`). Trigger deletes are **hard** deletes with\nno restore, and a webhook token is shown **once** at create or rotate.\n\n**A schedule is a claim you can now check.** `run_cron_schedule_now` fires one\nimmediately *without* moving `nextFireAt` — testing a schedule must not consume\nthe run it was going to make. Before it existed, \"every weekday at 07:00\" could\nonly be tested by coming back tomorrow, and what is usually wrong is not the\ntiming but whether it starts anything at all.\n\n**To pause a schedule, disarm it** — `set_cron_schedule_enabled`, not\n`delete_cron_schedule`. Deleting throws away the rules the author wrote and\nmakes \"stop this for a week\" indistinguishable from \"we do not do this any\nmore\". `list_all_cron_schedules` answers *what runs tonight?* across the tenant;\n`reconcile_cron_schedules` answers *is that actually what runs?* — it reports\nrather than tidying silently, and never arms something someone switched off.\n\n`create_cron_schedule` takes either `cronExpr` or the richer `rules`, and the\ntrigger must exist in the **published** document. Rule shapes come from\n`get_workflow_authoring_spec` → `scheduleRuleKinds`; this connector names none\nof its own.\n\n**A conditional trigger without a check starts the workflow every beat.** It\nwakes on its interval and, with nothing set, runs whether or not there was\nanything to do — a mailbox on fifteen minutes makes ninety-six empty runs a\nday. `checkKind` decides instead, and it is a gate ahead of the run being\ncreated: `\"automatic\"` is one tool call plus one rule on its answer, no model.\nIts `checkConfig` is `{ toolId, inputs?, rule: { field, op, value } }`, where\n`field` names a key of the *tool's* answer. `\"agent\"` is reserved for a model\njudging the condition and is refused today.\n\nSet it on `create_conditional_trigger` or on an existing trigger with\n`update_conditional_trigger` — everything authored before checks existed has\nnone, which `list_conditional_triggers` shows as `checkKind: null`. **To take a\ncheck off, send `checkKind: \"\"`**: the empty string clears the kind and its\nconfig together, where omitting the field leaves it standing. The connector\ndoes not judge a check — the backend validates it with the same function the\ndispatcher runs when the trigger fires, so a setting that saves is one that\nruns, and a bad one comes back as a refusal naming what to fix.\n\n### Runs — evaluating what you built\n\n`start_workflow_run` (test a workflow you built — it runs the **published**\nworkflow and really executes), `cancel_run`, `delete_run`, `list_runs`,\n`list_workflow_runs`, `read_run`, `read_run_trace`, `read_run_cost`,\n`read_runs_summary`, `archive_run` / `unarchive_run`, `bulk_archive_runs` /\n`bulk_delete_runs`. There is no findings endpoint — evaluation means reading a\nrun's validator verdicts and its trace.\n\n**Which start, and what it wants.** `read_workflow_trigger_parameters` answers\n`{ triggers, constants }` — every way the workflow can be started, each with its\nown parameters. Pass the one you mean to `start_workflow_run` as `triggerId`;\nomitting it fires the first, which on a workflow with a button *and* a schedule\nis an arbitrary choice. A parameter marked `pinned` is one the **author** owns:\nit is overwritten on every run, so a caller must not send it.\n\n**`read_run` omits the workflow snapshot by default.** It is immutable, it is\nnever the answer to a question about the run, and it measured 81% of one real\nresponse — an oversized response turns a call that succeeded into an error.\nPass `includeSnapshot: true` when you actually want to see what executed.\n\n**Start from the outline.** `read_run_outline` is the run's table of contents —\nthe run, its steps, and the items a fan-out handed out, flat with parent\npointers. It carries no bodies, so its size follows the run's *shape* rather\nthan its content: a launch over four thousand items costs about what one over\nfour costs. `itemCap` bounds the items listed per fan-out step and the remainder\nis counted in `counts.truncated`, never dropped silently —\n`read_run_outline_items` carries on from where the outline stopped, one step at\na time, walked by `offset` (safe here: a fan-out's items are fixed once handed\nout, so the ordering cannot shift under you). Then open only what\nyou want: `read_run_value` for one large step value (by the digest in\n`stepStates`) and `read_run_invocation_messages` for one agent's transcript (by\nthe id in `agentInvocations`). Reading a whole run to find one message is the\nhabit these replace.\n\n**A run can park rather than finish.** `read_run_waiting_on` says what it is\nwaiting for; `answer_run_question` answers an `ask_user` step and\n`send_run_message` sends a turn to a conversation run. Both record the input as\na person's, so use them on runs you started. Deciding a **plan approval** and\nrestarting a stuck run are deliberately absent — the first is the human review\nthe step exists to get, the second is `require_admin` and a service token is\nalways `role=\"member\"`. Both are recorded in `test/denyList.ts`, together\nwith stopping runs in bulk (admin), the tenant's storage footprint (admin), an\ninbound channel reply (authenticated by the email/WhatsApp adapter, not by a\nservice token) and the retired `workflow-memory` placeholder.\n\n**`list_todo_steps`** is the same question across the whole tenant: every step\nwaiting on a human, in any run. It is paged over the waiting **runs**, so\n`items` can be longer than `pageSize` — one run may park several steps. Follow\n`nextCursor` to the end before concluding anything about how much is waiting.\n\n**What an agent wrote to itself.** `list_run_session_memory` lists the files an\nagent left during a run (metadata only, up to 200 per run) and\n`read_run_session_memory_file` opens one. When the trace shows a decision but\nnot what it was reading, the reason is usually here. Workflow-bound reference\nmaterial is not — that lives in `reference_docs`.\n\n**Inside a launch**: `read_run_items_summary` is the roll-up (\"4,415 processed ·\n12 failed\"), `list_run_items({ outcome })` the paged rows — filter in the query,\nbecause the failures are scattered and sifting page one finds none of them.\n`list_run_tasks` and `read_run_for_each_progress` cover the children a run set\nin motion.\n\n`list_workflow_runs({ workflowId, status?, archivedOnly?, limit?, cursor? })` returns one\n**page** — `{ items, nextCursor, pageSize, hasMore }`, 20 by default and 200 at\nmost — so follow `nextCursor` while `hasMore` is true rather than treating the\nfirst page as the answer. It also lists **launches**, not runs: the per-item runs\na FOR EACH creates stay inside their launch, so a launch over 4,415 people is one\nentry carrying `forEachProgress`. `list_runs` is the tenant-wide list and is now\npaged the same way — `{ items, nextCursor, pageSize, hasMore }`, walked with\n`cursor`. It stopped answering with a bare array when the backend converted the\nroute; the `offset` it used to take is no longer read.\n\n### Approvals\n\n`list_publish_approvals({ status?, limit?, offset? })` and\n`get_publish_approval({ approvalId })` — how you find out whether a\n`request_publish_*` was approved or rejected. Approving and rejecting are\nhuman-only actions in Axonity.\n\n`request_publish_release({ workflowId, changeSummary? })` proposes a **release**:\na workflow *and everything its run needs* — the agents it runs, their tools and\npersonas, the flows it pins, the memory scoped to those agents — as ONE approval.\nPrefer it over a request per entity. Taking a tenant live entity-by-entity means\na hundred-odd approvals, none of which means anything on its own, and a human\nasked that many times is not reviewing. `list_publish_releases` and\n`get_publish_release` read one back — the release's members, and its readiness\nrecomputed as of now.\n\nUnlike `request_publish_bulk`, a release is **all-or-nothing and in dependency\norder**: approving it publishes every member or none, so a workflow can never go\nlive calling a tool that did not. The response carries the bundle's verdict —\n`ready`, `changedCount` of `totalCount` (unchanged members are already live and\nride along), `members` with why each is there, and `blockers` that name the\nmember in the way. Requesting is ours; deciding stays human, like everywhere\nelse here.\n\n## What this is for — and what it is not\n\n**Authoring.** An agent composing an entity from intent: drafting a workflow,\nwriting a tool, wiring memory onto an agent, and checking its own work. That is\nwhat these tools are built for.\n\n**Not bulk migration.** Do not use the connector to move many entities verbatim\nfrom one place to another. Axonity's config export/import moves bytes with no\nmodel in the path and fails closed on secrets; content routed through an agent\ncan be subtly altered in transit, which is precisely the risk a fidelity\nmigration cannot take.\n\n## Guardrails\n\nThese are enforced by the backend, not merely by convention:\n\n- **The connector never publishes.** `request_publish_*` creates a **pending\n  approval**; a human approves it in Axonity, and only then does the draft go\n  live. A direct publish from a service token is refused with a 403, so there is\n  no tool for it and no way around it.\n- **A read-only token is genuinely read-only for mutations.** Any write from a token\n  without the `write` scope is refused with a 403.\n- **The four stateless analysis tools are the exception:** `validate_workflow`,\n  `analyze_workflow_reachable_outputs`, `validate_tool_code`, and `format_tool_code`\n  can be called by read-only and write tokens because they never mutate state.\n- **The token is tenant-bound.** An agent cannot reach another tenant.\n- **Secrets never pass through the agent.** A connector's `authConfig` accepts\n  placeholders only; a write carrying something that looks like a real\n  credential is rejected before it leaves the connector. Tenant secrets\n  (`/api/v1/secrets`) are **readable and unwritable**: `list_secrets` /\n  `read_secret` give the catalogue and `valueKeys` (which keys are filled, never\n  their values) so an agent can point `authConfig.secretId` at the right entry,\n  and no tool can create, change or delete one — the backend refuses a service\n  token there too. A secret's `metadata` is stored unencrypted and readable\n  tenant-wide (axonity-flow#908), so credential-shaped entries in it are\n  withheld on read and listed under `metadataRedacted`.\n- **Errors carry a machine-readable `code`, not just prose.** A 409 can mean a\n  stale write (retry) or a live reference conflict (don't — see\n  `axonity_conventions`); the connector tells them apart by `code`, never by\n  matching the message text.\n- **No tool crosses the authority boundary.** A test drives the whole registered\n  surface and fails the build if any tool targets a publish / approve /\n  secret-write / service-token / deploy route (`test/denyList.ts`). The\n  rules are method-aware: `GET /api/v1/secrets` is allowed, every write verb on\n  it is not.\n- **Guidance can't silently drift from the backend.** The field/enum facts the\n  connector states are pinned to a vendored snapshot of the backend OpenAPI\n  schema; `test/conformance.test.ts` fails if a route or documented enum\n  diverges (see `test/fixtures/README.md`).\n- **Every backend route is decided, and the build says so.**\n  `test/completeness.test.ts` partitions all 444 operations in the pinned\n  snapshot into *covered by a tool* or *excluded by a rule that carries a\n  written reason*, and fails on anything in neither. A route nobody has decided\n  about is indistinguishable from one somebody is still working on, which is\n  what made \"is this connector finished?\" a question you could only answer with\n  an audit. It is now a build status: a new backend route arrives as a red build\n  asking **cover it, or exclude it with a reason?**\n\n**One known exception, not enforced:** a framework-provided `flow` is meant to\nbe read-only to a tenant, but the backend does not actually block\n`update_flow`/`delete_flow` against one. Prefer `clone_flow` over editing a\nframework flow in place.\n\n## Development\n\n```bash\nnpm install\nnpm run typecheck\nnpm test\nnpm run build   # emits dist/\n```\n\n## Releasing\n\n**One command.**\n\n```bash\nnpm run release:minor     # or release:patch / release:major\n```\n\nThat is the whole procedure. It refuses to start unless you are on `main` with\nnothing uncommitted, resets `main` to exactly what is on GitHub, then installs,\ntests and builds *before* touching the version — so anything that can fail,\nfails while there is still nothing to undo. Only then does it bump, push, tag,\npublish, and read the version back from npm to confirm it landed.\n\nYou need to be logged in first, once per machine. Run it in a real terminal:\n`npm login` prints a URL and waits for the browser, so an editor's two-minute\ncommand timeout will kill it mid-flow.\n\n```bash\nnpm login\nnpm whoami                # confirm the account\n```\n\n**Why a script and not a list of steps.** The list used to live here, and the\nORDER was load-bearing: sync first, or the version bump lands on a stale\ncheckout. That went wrong twice in one week, identically both times — the bump\nwas made on a tree missing the last merge, the branch push was refused, and the\ntag went up anyway. Recovering meant deleting a published tag and hard-resetting,\nwhich is not something a release should ever require. The script pushes the\nbranch *before* the tag for the same reason: a refused push then leaves nothing\nbehind.\n\n**Check the contract before a release that matters.** Shipping with a stale\nsnapshot is how the connector fell nine operations behind the backend without\nany test noticing:\n\n```bash\nnpm run check:contract          # expects ../axonity-flow; override with AXONITY_FLOW_PATH\n```\n\nIt dumps the schema from a local `axonity-flow` checkout and diffs it against\n`test/fixtures/openapi.snapshot.json`, naming every operation that moved. It\nruns here rather than in CI because the publish runs here — a gate in CI cannot\nstop a local `npm publish`.\n\nAfter releasing, optionally cut a GitHub release for the tag. That triggers\n`Verify release`, which rebuilds and packs the tagged commit without publishing\n— it catches a tag cut from a state CI cannot install.\n\nKeep npm 11 locally: Node 20 bundles npm 10, whose resolver writes an\nincompatible lockfile tree. CI pins npm 11 for the same reason.\n\n## Staying level with the backend\n\nThe snapshot every drift guard reads is only as fresh as the last time someone\nregenerated it — and once it wasn't: it sat nine operations behind the backend\nwhile the whole suite stayed green, because a snapshot that has not seen a route\ncannot report it missing.\n\n**Before a release, check it** (see §Releasing): `npm run check:contract` dumps\nthe schema from a local `axonity-flow` checkout and names every operation that\nmoved. It compares the contract surface — query parameters, request body,\nresponse shape — and not descriptions, so backend docstring churn does not cry\nwolf. This is the gate that counts, because the publish runs here too.\n\n**At startup, the connector asks the deploy what it mounts.** It calls\n`GET /api/v1/contract` once before accepting its first tool call and, if this\nbackend lacks a route this build needs, says which on stderr — instead of\nfailing on the twentieth call, mid-task. It is a diagnostic and never a\ndependency: a backend too old to serve `/contract`, an unreachable one, or a\nslow one all degrade to the previous behaviour and the connector starts\nnormally. The result is cached on the `contractHash` the route returns, so an\nunchanged deploy costs one request.\n\n**Not here: a scheduled job.** Watching for drift on a timer belongs in\n`axonity-flow`, not in this repository. The schema lives there, its CI already\nhas the backend's dependencies installed, and it can read this repository's\npinned snapshot over plain HTTPS because this repository is public — where the\nreverse needs a credential for a private repo, with an approval policy and an\nexpiry behind it. Tracked in axonity-mcp#48.\n","readmeFilename":"README.md"}