Skip to content
979 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9721use crate::about::AboutOp;
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R222use crate::artifacts::ArtifactsOp;
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9723use crate::deployments::DeploymentsOp;
Packages: roles, Manage Actions access, source-label linking, soft delete and restore, package API24use crate::packages::PackagesOp;
Merge branch 'worktree-agent-a3abfcce648e87dca'25use crate::protection::ProtectionOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step26use crate::operations::Op;
Merge checks: statuses and check runs on every commit27use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge28use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar29use crate::security::SecurityOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step30
31pub struct Action {
32 pub name: &'static str,
33 pub op: Op,
34 /// One line, for the `action` field's description.
35 pub summary: &'static str,
36}
37
38pub struct Tool {
39 pub name: &'static str,
40 pub title: &'static str,
41 /// What it is for, in a sentence or two.
42 pub description: &'static str,
43 pub actions: &'static [Action],
44 /// The action a call without one runs.
45 pub default_action: Option<&'static str>,
46}
47
48const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
49 Action { name, op, summary }
50}
51
52pub const TOOLS: &[Tool] = &[
53 Tool {
54 name: "search",
55 title: "Search",
56 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
57 default_action: Some("code"),
58 actions: &[
59 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
60 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
61 a("entity", Op::GetEntity, "One catalog entry and its relations"),
62 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
63 ],
64 },
65 Tool {
66 name: "repository",
67 title: "Repositories",
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9768 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, see and dismiss their security alerts (secrets and vulnerable dependencies), read what their default branch says (languages, contributors, license), star them, and publish releases. Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step69 default_action: None,
70 actions: &[
71 a("list", Op::ListRepos, "Repositories you can see"),
72 a("get", Op::GetRepo, "One repository"),
73 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
74 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge75 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
76 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
77 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
78 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
79 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
80 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
81 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
82 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
83 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
84 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar85 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
86 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
87 a("create_label", Op::CreateLabel, "Create a label"),
88 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
89 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
90 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
91 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
92 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
93 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
94 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
95 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step96 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9797 a("languages", Op::About(AboutOp::GetLanguages), "Its languages by bytes, with colors and percentages"),
98 a("contributors", Op::About(AboutOp::ListContributors), "Who made it: commits per person, agent and author, by week"),
99 a("license", Op::About(AboutOp::GetLicense), "The license its LICENSE file holds"),
100 a("stargazers", Op::About(AboutOp::ListStargazers), "Who starred it"),
101 a("starred", Op::About(AboutOp::CheckStarred), "Whether you starred it, and how many have"),
102 a("star", Op::About(AboutOp::Star), "Star it"),
103 a("unstar", Op::About(AboutOp::Unstar), "Take your star back"),
104 a("list_starred", Op::About(AboutOp::ListStarred), "Repositories you starred"),
105 a("list_releases", Op::About(AboutOp::ListReleases), "Releases, newest first"),
106 a("latest_release", Op::About(AboutOp::GetLatestRelease), "The latest release"),
107 a("get_release", Op::About(AboutOp::GetRelease), "One release by id"),
108 a("get_release_by_tag", Op::About(AboutOp::GetReleaseByTag), "The release of a tag"),
109 a("create_release", Op::About(AboutOp::CreateRelease), "Publish a release of a tag, making the tag if needed"),
110 a("update_release", Op::About(AboutOp::UpdateRelease), "Change a release's title, notes, draft or prerelease"),
111 a("delete_release", Op::About(AboutOp::DeleteRelease), "Delete a release; its tag stays"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step112 a("rename_branch", Op::RenameBranch, "Rename a branch"),
113 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
114 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
115 a("archive", Op::ArchiveRepo, "Make it read-only"),
116 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
117 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
118 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
119 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
120 a("restore", Op::RestoreRepo, "Restore a deleted one"),
121 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily122 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
123 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
124 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step125 ],
126 },
127 Tool {
128 name: "issue",
129 title: "Issues",
130 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
131 default_action: None,
132 actions: &[
133 a("list", Op::ListIssues, "Issues on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents134 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step135 a("create", Op::CreateIssue, "Open an issue"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar136 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
137 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
138 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
139 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
140 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step141 a("close", Op::CloseIssue, "Close it without a pull request"),
142 a("reopen", Op::ReopenIssue, "Reopen it"),
143 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
144 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
145 ],
146 },
147 Tool {
148 name: "pull_request",
149 title: "Pull requests",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar150 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step151 default_action: None,
152 actions: &[
153 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents154 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step155 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
156 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar157 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step158 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
159 a("read_session", Op::ReadSession, "Its recorded session"),
160 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar161 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
162 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step163 a("review", Op::ReviewPullRequest, "Approve or request changes"),
164 a("close", Op::ClosePullRequest, "Close without merging"),
165 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
166 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
167 ],
168 },
169 Tool {
170 name: "agent",
171 title: "g1t agents",
172 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
173 default_action: None,
174 actions: &[
175 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
176 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
177 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
178 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
179 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
180 ],
181 },
182 Tool {
183 name: "plan",
184 title: "Plans",
Fast pages, required checks on the branch, self-hosted runners, honest incidents185 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step186 default_action: None,
187 actions: &[
188 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
189 a("get", Op::GetPlan, "A plan and the issues it proposes"),
190 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
191 ],
192 },
193 Tool {
194 name: "memory",
195 title: "Memory",
196 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
197 default_action: None,
198 actions: &[
199 a("recall", Op::Recall, "Search memory, or list it all"),
200 a("remember", Op::Remember, "Save one fact"),
201 ],
202 },
203 Tool {
204 name: "workflow",
205 title: "Workflows",
Merge branch 'worktree-agent-a3abfcce648e87dca'206 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Runs' artifacts: listing, a download link, deleting, and how long they are kept. Deployments wherever they run (reported from any CI, made by jobs with an `environment:`, or built on g1t.page), their statuses and environments, and reporting your own; environments' protection rules, approving or rejecting the jobs they hold, approving a pull request's run from outside, the token's default permissions and repository dispatch. Checks on commits: statuses, check runs (a g1t Actions job is one) and check suites, to read where a commit stands or report on it from CI or an integration. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step207 default_action: None,
208 actions: &[
209 a("list", Op::ListWorkflows, "Workflows on the default branch"),
210 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
211 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
212 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
213 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
214 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
215 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
216 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2217 a("list_artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), "A repository's artifacts, newest first; or a run's with run_artifacts"),
218 a("run_artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), "One run's artifacts"),
219 a("get_artifact", Op::Artifacts(ArtifactsOp::GetArtifact), "One artifact: size, digest, expiry, run"),
220 a("download_artifact", Op::Artifacts(ArtifactsOp::DownloadArtifact), "A 10-minute link to an artifact's zip"),
221 a("delete_artifact", Op::Artifacts(ArtifactsOp::DeleteArtifact), "Delete an artifact before it expires"),
222 a("artifact_retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), "Days the repository keeps artifacts"),
223 a("set_artifact_retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), "Change the days the repository keeps artifacts"),
Merge checks: statuses and check runs on every commit224 a("combined_status", Op::Checks(ChecksOp::GetCombinedStatus), "A commit's statuses and the state they add up to"),
225 a("list_statuses", Op::Checks(ChecksOp::ListCommitStatuses), "A commit's statuses, newest first"),
226 a("set_status", Op::Checks(ChecksOp::CreateCommitStatus), "Set a status on a commit"),
227 a("list_check_runs", Op::Checks(ChecksOp::ListCheckRunsForRef), "A commit's check runs, g1t Actions jobs included"),
228 a("get_check_run", Op::Checks(ChecksOp::GetCheckRun), "One check run with its report"),
229 a("check_run_annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), "What a check run says about lines of files"),
230 a("create_check_run", Op::Checks(ChecksOp::CreateCheckRun), "Report a check run on a commit"),
231 a("update_check_run", Op::Checks(ChecksOp::UpdateCheckRun), "Move a check run on, complete it, add annotations"),
232 a("rerequest_check_run", Op::Checks(ChecksOp::RerequestCheckRun), "Ask for a check run to run again"),
233 a("list_check_suites", Op::Checks(ChecksOp::ListCheckSuitesForRef), "A commit's check suites, one per reporter or workflow run"),
234 a("get_check_suite", Op::Checks(ChecksOp::GetCheckSuite), "One check suite"),
235 a("rerequest_check_suite", Op::Checks(ChecksOp::RerequestCheckSuite), "Ask for a check suite to run again"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97236 a("list_deployments", Op::Deployments(DeploymentsOp::ListDeployments), "Deployments wherever they run, newest first, filtered"),
237 a("get_deployment", Op::Deployments(DeploymentsOp::GetDeployment), "One deployment with every status it has had"),
238 a("create_deployment", Op::Deployments(DeploymentsOp::CreateDeployment), "Report a deployment of a ref to an environment"),
239 a("deployment_statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), "A deployment's statuses, newest first"),
240 a("create_deployment_status", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), "Report where a deployment is: in_progress, success, failure"),
241 a("list_environments", Op::Deployments(DeploymentsOp::ListEnvironments), "Environments with their current and latest deployments"),
Merge branch 'worktree-agent-a3abfcce648e87dca'242 a("get_environment", Op::Deployments(DeploymentsOp::GetEnvironment), "One environment by name, with its protection rules"),
243 a("update_environment", Op::Protection(ProtectionOp::UpdateEnvironment), "Set an environment's reviewers, wait timer and branches"),
244 a("delete_environment", Op::Protection(ProtectionOp::DeleteEnvironment), "Remove an environment's protection rules"),
245 a("pending_deployments", Op::Protection(ProtectionOp::GetPendingDeployments), "The environments holding a run's jobs"),
246 a("review_deployments", Op::Protection(ProtectionOp::ReviewPendingDeployments), "Approve or reject a run's jobs for its environments"),
247 a("approve_run", Op::Protection(ProtectionOp::ApproveWorkflowRun), "Let a run of a pull request from outside start"),
248 a("get_permissions", Op::Protection(ProtectionOp::GetWorkflowPermissions), "What a job's token gets without `permissions:`"),
249 a("set_permissions", Op::Protection(ProtectionOp::SetWorkflowPermissions), "Set it: read or write"),
250 a("get_approval_policy", Op::Protection(ProtectionOp::GetForkPrApproval), "Which pull requests' runs wait for approval"),
251 a("set_approval_policy", Op::Protection(ProtectionOp::SetForkPrApproval), "Set which pull requests' runs wait for approval"),
252 a("repository_dispatch", Op::Protection(ProtectionOp::CreateRepositoryDispatch), "Start repository_dispatch workflows with an event"),
253 a("get_workspace_permissions", Op::Protection(ProtectionOp::GetWorkspaceWorkflowPermissions), "A workspace's default and maximum token permissions"),
254 a("set_workspace_permissions", Op::Protection(ProtectionOp::SetWorkspaceWorkflowPermissions), "Set them, and whether jobs may open pull requests"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents255 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
256 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
257 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
258 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
259 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
260 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
261 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
262 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
263 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step264 ],
265 },
266 Tool {
Packages: roles, Manage Actions access, source-label linking, soft delete and restore, package API267 name: "package",
268 title: "Packages",
269 description: "A workspace's packages in every registry (container images, npm, Cargo, Maven, NuGet, RubyGems, Composer): their versions and downloads, deleting and restoring them within 30 days, their visibility and repository, who has a role on them, and which repositories' workflows may use them (Manage Actions access). Name one by workspace, package_type and package_name.",
270 default_action: None,
271 actions: &[
272 a("list", Op::Packages(PackagesOp::ListPackages), "A workspace's packages; state deleted for restorable ones"),
273 a("get", Op::Packages(PackagesOp::GetPackage), "One package: address, visibility, repository, downloads"),
274 a("versions", Op::Packages(PackagesOp::ListVersions), "Its versions with tags and downloads; state deleted too"),
275 a("get_version", Op::Packages(PackagesOp::GetVersion), "One version by id, version, digest or tag"),
276 a("update", Op::Packages(PackagesOp::UpdatePackage), "Set visibility, or inherit_access for a linked one"),
277 a("link", Op::Packages(PackagesOp::LinkPackage), "Link it to a repository of its workspace"),
278 a("unlink", Op::Packages(PackagesOp::UnlinkPackage), "Unlink it: the workspace's, private"),
279 a("access", Op::Packages(PackagesOp::ListAccess), "People and teams with a role on it"),
280 a("set_access", Op::Packages(PackagesOp::SetAccess), "Give a person or team read, write or admin"),
281 a("remove_access", Op::Packages(PackagesOp::RemoveAccess), "Take a person's or team's role away"),
282 a("actions_access", Op::Packages(PackagesOp::ListActionsAccess), "Repositories whose workflows may use it"),
283 a("set_actions_access", Op::Packages(PackagesOp::SetActionsAccess), "Let a repository's workflows read or write it"),
284 a("remove_actions_access", Op::Packages(PackagesOp::RemoveActionsAccess), "Stop a repository's workflows using it"),
285 a("delete", Op::Packages(PackagesOp::DeletePackage), "Delete it; restorable for 30 days"),
286 a("restore", Op::Packages(PackagesOp::RestorePackage), "Restore a deleted package"),
287 a("delete_version", Op::Packages(PackagesOp::DeleteVersion), "Delete a version; restorable for 30 days"),
288 a("restore_version", Op::Packages(PackagesOp::RestoreVersion), "Restore a deleted version"),
289 ],
290 },
291 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step292 name: "secret",
293 title: "Secrets and variables",
294 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
295 default_action: None,
296 actions: &[
297 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
298 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
299 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
300 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
301 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
302 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
303 ],
304 },
305 Tool {
306 name: "webhook",
307 title: "Webhooks",
308 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
309 default_action: None,
310 actions: &[
311 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
312 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
313 a("update", Op::UpdateWebhook, "Change address, events or active"),
314 a("delete", Op::DeleteWebhook, "Remove one"),
315 a("ping", Op::PingWebhook, "Send a ping"),
316 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
317 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
318 ],
319 },
320 Tool {
321 name: "access",
322 title: "Who has access",
323 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
324 default_action: None,
325 actions: &[
326 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
327 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
328 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
329 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
330 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
331 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
332 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
333 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
334 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
335 ],
336 },
337 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar338 name: "team",
339 title: "Teams",
340 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
341 default_action: None,
342 actions: &[
343 a("list", Op::ListTeams, "A workspace's teams you can see"),
344 a("get", Op::GetTeam, "One team"),
345 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
346 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
347 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
348 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
349 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
350 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
351 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
352 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
353 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
354 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
355 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
356 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
357 ],
358 },
359 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step360 name: "workspace",
361 title: "Workspaces",
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97362 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step363 default_action: None,
364 actions: &[
Merge branch 'worktree-agent-ad7c6d88d93adc817'365 a("get", Op::GetWorkspace, "A workspace's details and settings"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step366 a("create", Op::CreateWorkspace, "Create a workspace"),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member367 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
Merge branch 'worktree-agent-ad7c6d88d93adc817'368 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step369 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
370 a("invite_member", Op::InviteMember, "Invite an email address"),
371 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
372 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
373 a("connect_integration", Op::ConnectIntegration, "Connect one"),
AI Gateway: OpenAI's format, open models, and your own providers374 a("update_integration", Op::UpdateIntegration, "Change one: rotate its key, choose its AI Gateway models"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step375 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
376 a("test_integration", Op::TestIntegration, "Check its credentials"),
377 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
378 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97379 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
380 a("get_project", Op::GetProject, "One project"),
381 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
API: pinned projects over REST and MCP382 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
383 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
384 a("unpin_project", Op::UnpinProject, "Unpin a project"),
385 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge386 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
387 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
388 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
389 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
390 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
391 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step392 ],
393 },
394 Tool {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit395 name: "billing",
396 title: "Billing",
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens397 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit398 default_action: Some("usage"),
399 actions: &[
400 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
401 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
402 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
403 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
404 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
405 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
406 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens407 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit408 ],
409 },
410 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar411 name: "security",
412 title: "Security",
413 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
414 default_action: Some("secret_alerts"),
415 actions: &[
416 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
417 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
418 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
419 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
420 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
421 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
422 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
423 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
424 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
425 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
426 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
427 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
428 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
429 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
430 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
431 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
432 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
433 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
434 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
435 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
436 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
437 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
438 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
439 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
440 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
441 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
442 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
443 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
444 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
445 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
446 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
447 ],
448 },
449 Tool {
API: notifications over REST and MCP, with notifications scopes450 name: "notifications",
451 title: "Notifications",
452 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
453 default_action: Some("list"),
454 actions: &[
455 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
456 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
457 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
458 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
459 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
460 a("save", Op::SaveThread, "Save a thread, or unsave it"),
461 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
462 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
463 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
464 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
465 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
466 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
467 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
468 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
469 ],
470 },
471 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step472 name: "account",
473 title: "Your account",
474 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
475 default_action: Some("whoami"),
476 actions: &[
477 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
478 a("list_emails", Op::ListEmails, "Your addresses"),
479 a("add_email", Op::AddEmail, "Add an address"),
480 a("remove_email", Op::RemoveEmail, "Remove an address"),
481 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
482 a("list_invites", Op::ListInvites, "Your invites to g1t"),
483 a("create_invite", Op::CreateInvite, "Make an invite"),
484 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
485 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
486 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
487 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
488 ],
489 },
490];
491
492/// Operations that cannot be undone, or reach beyond g1t's own records:
493/// clients ask before running a tool that has any of them.
494fn destructive(op: Op) -> bool {
495 matches!(
496 op,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar497 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge498 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar499 | Op::DeleteWorkspace
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily500 | Op::UpdateWorkspace
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step501 | Op::DeleteRepo
502 | Op::PurgeRepo
503 | Op::TransferRepo
504 | Op::SetRepoVisibility
505 | Op::RemoveEmail
506 | Op::RemoveCollaborator
507 | Op::DisconnectIntegration
AI Gateway: OpenAI's format, open models, and your own providers508 | Op::UpdateIntegration
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step509 | Op::DeleteWebhook
510 | Op::DeleteActionsSecret
511 | Op::DeleteActionsVariable
512 | Op::SetActionsSecret
513 | Op::SetActionsVariable
514 | Op::SetModelRoutes
515 | Op::SetBasePermission
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar516 | Op::DeleteTeam
517 | Op::RemoveTeamRepo
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step518 | Op::MergePullRequest
Fast pages, required checks on the branch, self-hosted runners, honest incidents519 | Op::RemoveRunner
520 | Op::DeleteRunnerGroup
521 | Op::UpdateRunnerSettings
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step522 )
523}
524
525/// Whether an operation only reads.
526pub fn reads_only(op: Op) -> bool {
527 NO_SCOPE.contains(&op.name())
528 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
529}
530
531/// What decides which actions a caller sees.
532pub enum Gate<'a> {
533 /// No limit beyond the person's own role.
534 Everything,
535 /// A g1t agent's token: the operations its run lists.
536 Agent(&'a AgentScope),
537 /// An access token with scopes.
538 Token(&'a TokenAccess),
539}
540
541impl Gate<'_> {
542 pub fn allows(&self, op: Op) -> bool {
543 match self {
544 Gate::Everything => true,
545 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
546 Gate::Token(access) => {
547 if NO_SCOPE.contains(&op.name()) {
548 return true;
549 }
550 match scope_for(op.name()) {
551 Some(scope) => access.allows(scope),
552 None => access.scopes.is_none(),
553 }
554 }
555 }
556 }
557}
558
559impl Tool {
560 pub fn by_name(name: &str) -> Option<&'static Tool> {
561 TOOLS.iter().find(|tool| tool.name == name)
562 }
563
564 pub fn action(&self, name: &str) -> Option<&'static Action> {
565 // The tools are 'static; find through TOOLS to keep the lifetime.
566 TOOLS
567 .iter()
568 .find(|tool| tool.name == self.name)
569 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
570 }
571
572 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
573 TOOLS
574 .iter()
575 .find(|tool| tool.name == self.name)
576 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
577 .unwrap_or_default()
578 }
579
580 /// The flat input schema of the actions given.
581 pub fn input_schema(&self, actions: &[&Action]) -> Value {
582 let mut properties = Map::new();
583 let lines: Vec<String> = actions
584 .iter()
585 .map(|action| {
586 let required: Vec<String> = action.op.required();
587 if required.is_empty() {
588 format!("{}: {}.", action.name, action.summary)
589 } else {
590 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
591 }
592 })
593 .collect();
594 let mut action_schema = json!({
595 "type": "string",
596 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
597 "description": lines.join("\n"),
598 });
599 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
600 action_schema["default"] = json!(default);
601 }
602 properties.insert("action".to_owned(), action_schema);
603 for action in actions {
604 for (name, schema) in action.op.properties() {
605 merge_property(&mut properties, name, schema);
606 }
607 }
608 let mut required = vec![];
609 if self.default_action.is_none() {
610 required.push("action");
611 }
612 let mut schema = json!({ "type": "object", "properties": properties });
613 if !required.is_empty() {
614 schema["required"] = json!(required);
615 }
616 schema
617 }
618
619 /// The input schema keyed by action: one `oneOf` branch per action,
620 /// each with its own fields and the ones it needs.
621 pub fn discriminated(&self, actions: &[&Action]) -> Value {
622 let branches: Vec<Value> = actions
623 .iter()
624 .map(|action| {
625 let mut properties = Map::new();
626 properties.insert("action".to_owned(), json!({ "const": action.name }));
627 properties.extend(action.op.properties());
628 let mut required = vec![Value::String("action".to_owned())];
629 // The default action may leave `action` out.
630 if self.default_action == Some(action.name) {
631 required.clear();
632 }
633 required.extend(action.op.required().into_iter().map(Value::String));
634 json!({
635 "title": action.name,
636 "description": action.summary,
637 "type": "object",
638 "properties": properties,
639 "required": required,
640 })
641 })
642 .collect();
643 json!({ "type": "object", "oneOf": branches })
644 }
645
646 /// MCP's hints about the actions given: whether the tool only reads,
647 /// whether it can destroy something, and whether calling it twice is
648 /// the same as once.
649 pub fn annotations(&self, actions: &[&Action]) -> Value {
650 let read_only = actions.iter().all(|action| reads_only(action.op));
651 json!({
652 "title": self.title,
653 "readOnlyHint": read_only,
654 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
655 "idempotentHint": read_only,
656 "openWorldHint": false,
657 })
658 }
659
660 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
661 /// `None` when it may use none of its actions.
662 pub fn listed(&self, gate: &Gate) -> Option<Value> {
663 let actions = self.visible(gate);
664 if actions.is_empty() {
665 return None;
666 }
667 Some(json!({
668 "name": self.name,
669 "title": self.title,
670 "description": self.description,
671 "inputSchema": self.input_schema(&actions),
672 "annotations": self.annotations(&actions),
673 }))
674 }
675}
676
677/// Adds a property to a tool's flat schema. The first action to use a name
678/// describes it; a later one with other allowed values adds them.
679fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
680 match properties.get_mut(&name) {
681 None => {
682 properties.insert(name, schema);
683 }
684 Some(existing) => {
685 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
686 (existing.get("enum").cloned(), schema.get("enum"))
687 {
688 let mut merged = had;
689 for value in more {
690 if !merged.contains(value) {
691 merged.push(value.clone());
692 }
693 }
694 existing["enum"] = Value::Array(merged);
695 }
696 // Different kinds of value under one name: say less, accept both.
697 if existing.get("type") != schema.get("type")
698 && let Some(fields) = existing.as_object_mut()
699 {
700 fields.remove("type");
701 fields.remove("items");
702 }
703 }
704 }
705}
706
707/// What a call to a tool runs: the operation its action names, or why not.
708pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
709 let names = || {
710 tool.actions
711 .iter()
712 .map(|action| action.name)
713 .collect::<Vec<_>>()
714 .join(", ")
715 };
716 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
717 return Err(format!("Give an action: one of {}.", names()));
718 };
719 let Some(action) = tool.action(name) else {
720 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
721 };
722 let missing: Vec<String> = action
723 .op
724 .required()
725 .into_iter()
726 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
727 .collect();
728 if !missing.is_empty() {
729 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
730 }
731 Ok(action.op)
732}
733
734#[cfg(test)]
735mod tests {
736 use super::*;
737 use g1t_contracts::scopes::{Preset, Scope};
738
739 fn listed(gate: &Gate) -> Vec<Value> {
740 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
741 }
742
743 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
744 TokenAccess {
745 token_id: "tok_1".to_owned(),
746 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
747 legacy: false,
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens748 name: None,
Merge branch 'worktree-agent-a3abfcce648e87dca'749 ..TokenAccess::default()
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step750 }
751 }
752
753 #[test]
754 fn every_operation_is_exactly_one_action_of_one_tool() {
755 for op in Op::ALL {
756 let count = TOOLS
757 .iter()
758 .flat_map(|tool| tool.actions.iter())
759 .filter(|action| action.op == op)
760 .count();
761 assert_eq!(count, 1, "{} is {count} actions", op.name());
762 }
763 for tool in TOOLS {
764 let mut names = std::collections::HashSet::new();
765 for action in tool.actions {
766 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
767 }
768 if let Some(default) = tool.default_action {
769 assert!(tool.action(default).is_some(), "{}", tool.name);
770 }
771 }
Packages: roles, Manage Actions access, source-label linking, soft delete and restore, package API772 assert!(TOOLS.len() <= 18, "{} tools", TOOLS.len());
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step773 }
774
775 #[test]
776 fn every_operation_needs_exactly_one_scope_or_none() {
777 use g1t_contracts::scopes::OPERATIONS;
778 for op in Op::ALL {
779 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
780 let free = NO_SCOPE.contains(&op.name());
781 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
782 }
783 for (name, _) in OPERATIONS {
784 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
785 }
786 }
787
788 #[test]
789 fn each_tool_schema_is_valid_with_one_branch_per_action() {
790 for tool in TOOLS {
791 let actions: Vec<&Action> = tool.actions.iter().collect();
792 let flat = tool.input_schema(&actions);
793 assert_eq!(flat["type"], "object");
794 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
795 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
796 .as_array()
797 .unwrap()
798 .iter()
799 .map(|name| name.as_str().unwrap())
800 .collect();
801 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
802 for action in tool.actions {
803 for field in action.op.required() {
804 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
805 }
806 }
807 let keyed = tool.discriminated(&actions);
808 let branches = keyed["oneOf"].as_array().unwrap();
809 assert_eq!(branches.len(), tool.actions.len());
810 for (branch, action) in branches.iter().zip(tool.actions) {
811 assert_eq!(branch["properties"]["action"]["const"], action.name);
812 for field in branch["required"].as_array().unwrap() {
813 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
814 }
815 }
816 // A well-formed JSON Schema object throughout.
817 let text = serde_json::to_string(&flat).unwrap();
818 assert!(serde_json::from_str::<Value>(&text).is_ok());
819 }
820 }
821
822 #[test]
823 fn a_read_only_token_sees_read_actions_only() {
824 let access = token(Preset::ReadOnly.scopes());
825 let gate = Gate::Token(&access);
826 for tool in TOOLS {
827 for action in tool.visible(&gate) {
828 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
829 }
830 }
831 let tools = listed(&gate);
832 for tool in &tools {
833 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
834 assert_eq!(tool["annotations"]["destructiveHint"], false);
835 }
836 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar837 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step838 // Nothing of the agent tool is a read.
839 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
840 }
841
842 #[test]
843 fn a_narrow_token_sees_only_its_tools() {
844 let access = token(Some(vec![Scope::IssuesWrite]));
845 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar846 // Labels and milestones are the repository's, managed with issues:write.
847 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
API: notifications over REST and MCP, with notifications scopes848 // Notifications are a resource of their own: reading them lists
849 // only what reads.
850 let reader = token(Some(vec![Scope::NotificationsRead]));
851 let tools = listed(&Gate::Token(&reader));
852 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
853 assert_eq!(
854 notifications["inputSchema"]["properties"]["action"]["enum"],
855 json!(["list", "get", "subscription", "watching", "watched"])
856 );
857 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step858 let full = token(None);
859 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
860 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
861 }
862
863 #[test]
864 fn a_tool_that_can_destroy_says_so() {
865 let tools = listed(&Gate::Everything);
866 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
867 assert_eq!(repository["annotations"]["destructiveHint"], true);
868 assert_eq!(repository["annotations"]["readOnlyHint"], false);
869 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
870 assert_eq!(memory["annotations"]["destructiveHint"], false);
871 }
872
873 #[test]
874 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
875 let issue = Tool::by_name("issue").unwrap();
876 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
877 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
878 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
879 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
880 let search = Tool::by_name("search").unwrap();
881 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
882 let account = Tool::by_name("account").unwrap();
883 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
884 }
885
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar886 #[test]
887 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
888 let team = Tool::by_name("team").unwrap();
889 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
890 assert_eq!(
891 names,
892 [
893 "list",
894 "get",
895 "create",
896 "update",
897 "delete",
898 "list_members",
899 "set_member",
900 "remove_member",
901 "list_child_teams",
902 "list_repos",
903 "set_repo",
904 "remove_repo",
905 "set_review_assignment",
906 "list_user_teams",
907 ]
908 );
909 let reader = token(Some(vec![Scope::WorkspaceRead]));
910 let tools = listed(&Gate::Token(&reader));
911 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
912 assert_eq!(
913 listed_team["inputSchema"]["properties"]["action"]["enum"],
914 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
915 );
916 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
917 // A team's role on a repository is who has access.
918 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
919 let tools = listed(&Gate::Token(&admin));
920 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
921 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
922 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
923 let access = token(Some(vec![Scope::AccessAdmin]));
924 let tools = listed(&Gate::Token(&access));
925 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
926 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
927 // Both kinds of role a schema names are offered.
928 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
929 ["properties"]["role"]["enum"];
930 for role in ["member", "maintainer", "read", "admin"] {
931 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
932 }
933 assert_eq!(
934 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
935 Err("team.set_repo needs role.".to_owned())
936 );
937 }
938
939 #[test]
940 fn reviewers_and_code_owners_are_actions_of_their_tools() {
941 let pull = Tool::by_name("pull_request").unwrap();
942 assert_eq!(
943 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
944 Ok(Op::RequestReviewers)
945 );
946 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
947 let repository = Tool::by_name("repository").unwrap();
948 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
949 assert!(reads_only(Op::GetCodeownersErrors));
950 assert!(!reads_only(Op::RequestReviewers));
951 }
952
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step953 /// How much smaller `tools/list` is than one tool per operation. Run
954 /// with `--nocapture` to see the numbers.
955 #[test]
956 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
957 let before: Vec<Value> = Op::ALL
958 .into_iter()
959 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
960 .collect();
961 let after = listed(&Gate::Everything);
962 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
963 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
964 let agent = token(Preset::Agent.scopes());
965 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
966 let read = token(Preset::ReadOnly.scopes());
967 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
968 println!(
969 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
970 before.len(),
971 before_bytes / 4,
972 after.len(),
973 after_bytes / 4,
974 agent_bytes / 4,
975 read_bytes / 4,
976 );
977 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
978 }
979}

This file's history is long; its oldest lines are credited to the oldest commit read.