Skip to content
1,097 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9721use crate::about::AboutOp;
The artifacts service is services/artifacts, the Worker g1t-artifacts, bound as ARTIFACTS by the API, the site and the agents; its live rooms move to it with a Durable Object transfer from g1t-docs-service, and its database, bucket, indexes and queue keep their names. The git store's binding and settings are GITSTORE, its ops scripts gitstore-*, and workflow run artifacts keep their compatible API under run_artifacts modules. The deploy tool puts a Worker that has never deployed before the Workers in its stage that bind to it, and the deploy guide gives the cutover runbook.22use crate::run_artifacts::ArtifactsOp;
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca23use crate::deploy_keys::DeployKeysOp;
Merge branch 'mirroring' into artifacts-mode24use crate::mirrors::MirrorsOp;
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9725use crate::deployments::DeploymentsOp;
Merge packages: roles, Actions access, source label, soft delete, API26use crate::packages::PackagesOp;
Merge main into Artifacts Phase 227use crate::folios::FoliosOp;
Merge branch 'worktree-agent-a3abfcce648e87dca'28use crate::protection::ProtectionOp;
API and MCP for a workspace's personal access token rules, members' tokens and approvals29use crate::token_policy::TokenOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step30use crate::operations::Op;
Merge checks: statuses and check runs on every commit31use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge32use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar33use crate::security::SecurityOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step34
35pub struct Action {
36 pub name: &'static str,
37 pub op: Op,
38 /// One line, for the `action` field's description.
39 pub summary: &'static str,
40}
41
42pub struct Tool {
43 pub name: &'static str,
44 pub title: &'static str,
45 /// What it is for, in a sentence or two.
46 pub description: &'static str,
47 pub actions: &'static [Action],
48 /// The action a call without one runs.
49 pub default_action: Option<&'static str>,
50}
51
52const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
53 Action { name, op, summary }
54}
55
56pub const TOOLS: &[Tool] = &[
57 Tool {
58 name: "search",
59 title: "Search",
60 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
61 default_action: Some("code"),
62 actions: &[
63 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
64 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
65 a("entity", Op::GetEntity, "One catalog entry and its relations"),
66 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
67 ],
68 },
69 Tool {
70 name: "repository",
71 title: "Repositories",
Merge branch 'mirroring' into artifacts-mode72 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, see and dismiss their security alerts (secrets and vulnerable dependencies), read what their default branch says (languages, contributors, license), star them, publish releases, and look after their mirroring (take a mirror over, hand it back, or move it to g1t for good). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step73 default_action: None,
74 actions: &[
75 a("list", Op::ListRepos, "Repositories you can see"),
76 a("get", Op::GetRepo, "One repository"),
77 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
78 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge79 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
80 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
81 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
82 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
83 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
84 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
85 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
86 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
87 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
88 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar89 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
90 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
91 a("create_label", Op::CreateLabel, "Create a label"),
92 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
93 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
94 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
95 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
96 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
97 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
98 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
99 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step100 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97101 a("languages", Op::About(AboutOp::GetLanguages), "Its languages by bytes, with colors and percentages"),
102 a("contributors", Op::About(AboutOp::ListContributors), "Who made it: commits per person, agent and author, by week"),
103 a("license", Op::About(AboutOp::GetLicense), "The license its LICENSE file holds"),
104 a("stargazers", Op::About(AboutOp::ListStargazers), "Who starred it"),
105 a("starred", Op::About(AboutOp::CheckStarred), "Whether you starred it, and how many have"),
106 a("star", Op::About(AboutOp::Star), "Star it"),
107 a("unstar", Op::About(AboutOp::Unstar), "Take your star back"),
108 a("list_starred", Op::About(AboutOp::ListStarred), "Repositories you starred"),
109 a("list_releases", Op::About(AboutOp::ListReleases), "Releases, newest first"),
110 a("latest_release", Op::About(AboutOp::GetLatestRelease), "The latest release"),
111 a("get_release", Op::About(AboutOp::GetRelease), "One release by id"),
112 a("get_release_by_tag", Op::About(AboutOp::GetReleaseByTag), "The release of a tag"),
113 a("create_release", Op::About(AboutOp::CreateRelease), "Publish a release of a tag, making the tag if needed"),
114 a("update_release", Op::About(AboutOp::UpdateRelease), "Change a release's title, notes, draft or prerelease"),
115 a("delete_release", Op::About(AboutOp::DeleteRelease), "Delete a release; its tag stays"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step116 a("rename_branch", Op::RenameBranch, "Rename a branch"),
117 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
118 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
Merge branch 'mirroring' into artifacts-mode119 a("mirror", Op::Mirrors(MirrorsOp::GetMirror), "Its remotes: what it mirrors or is mirrored to"),
120 a("mirror_hand_back_plan", Op::Mirrors(MirrorsOp::GetHandBackPlan), "What handing a takeover back would do, ref by ref"),
121 a("mirror_take_over", Op::Mirrors(MirrorsOp::TakeOver), "Make g1t lead a mirror for now"),
122 a("mirror_ci", Op::Mirrors(MirrorsOp::SetCiFailover), "Run a mirror's workflows on g1t (on), or stop (off)"),
123 a("mirror_hand_back", Op::Mirrors(MirrorsOp::HandBack), "Send a takeover back, deciding diverged refs"),
124 a("mirror_move_to_g1t", Op::Mirrors(MirrorsOp::MoveToG1t), "Stop tracking the remote; g1t leads for good"),
125 a("mirror_sync", Op::Mirrors(MirrorsOp::SyncMirror), "Bring its remotes in step now"),
126 a("mirror_add_remote", Op::Mirrors(MirrorsOp::AddRemote), "Link another g1t or git host"),
127 a("mirror_update_remote", Op::Mirrors(MirrorsOp::UpdateRemote), "Change a remote's settings"),
128 a("mirror_remove_remote", Op::Mirrors(MirrorsOp::RemoveRemote), "Unlink a remote"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step129 a("archive", Op::ArchiveRepo, "Make it read-only"),
130 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
131 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
132 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
133 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
134 a("restore", Op::RestoreRepo, "Restore a deleted one"),
135 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily136 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
137 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
138 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step139 ],
140 },
141 Tool {
142 name: "issue",
143 title: "Issues",
144 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
145 default_action: None,
146 actions: &[
147 a("list", Op::ListIssues, "Issues on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents148 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step149 a("create", Op::CreateIssue, "Open an issue"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar150 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
151 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
152 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
153 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
154 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step155 a("close", Op::CloseIssue, "Close it without a pull request"),
156 a("reopen", Op::ReopenIssue, "Reopen it"),
157 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts158 a("edit_comment", Op::EditComment, "Change a comment's text: your own, or any with the Maintain role"),
159 a("delete_comment", Op::DeleteComment, "Delete a comment: your own, or any with the Maintain role"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step160 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
161 ],
162 },
163 Tool {
164 name: "pull_request",
165 title: "Pull requests",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar166 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step167 default_action: None,
168 actions: &[
169 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents170 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step171 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
172 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar173 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step174 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
175 a("read_session", Op::ReadSession, "Its recorded session"),
176 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts177 a("draft", Op::ConvertPullRequestToDraft, "Turn it back into a draft"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar178 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
179 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step180 a("review", Op::ReviewPullRequest, "Approve or request changes"),
181 a("close", Op::ClosePullRequest, "Close without merging"),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts182 a("reopen", Op::ReopenPullRequest, "Reopen a closed one"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step183 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
184 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
185 ],
186 },
187 Tool {
188 name: "agent",
189 title: "g1t agents",
190 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
191 default_action: None,
192 actions: &[
193 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
194 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
195 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
196 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
197 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
Every agent can have its own computer. A session that needs one wakes it: a home of its own on g1t cloud, one per agent and never shared, where it runs commands, reads and writes files and keeps what it made, with each session working in its own folder under a shared home; after ten idle minutes it sleeps, its home kept as a snapshot and restored when it wakes, and Reset wipes the home while memory and artifacts stay. Its shell and files are abilities with the usual choices, Alone, Alone when asked, Ask first or Never, offered only inside sessions and never to a chat reply; every command shows on the session with its output, and the agent's new Computer tab shows the state, the disk used of the five gigabytes included, the recent commands, and Wake, Put to sleep and Reset. Machine time counts only while it is awake, on the sandbox lines of the ledger that name the agent and who asked, held to the same spend caps as the session; the disk itself costs nothing in this version. The runner gained a long-lived supervisor that answers the computer's requests inside the container, and the runner service a computer per agent that keeps its snapshot in the agent homes bucket when one is attached, and says so when none is. The REST API and the agent tool can read a computer, wake it, put it to sleep and reset it. The agents, abilities, sessions, runners, billing and deploy guides say how it works and what an operator sets up; pinning a computer to your own runner, its browser and take-over come next.198 a("computer", Op::GetAgentComputer, "A workspace agent's own computer: state, disk, recent commands"),
199 a("wake_computer", Op::WakeAgentComputer, "Wake a workspace agent's computer (metered until it sleeps)"),
200 a("sleep_computer", Op::SleepAgentComputer, "Save its home and put it to sleep"),
201 a("reset_computer", Op::ResetAgentComputer, "Wipe its home; memory and artifacts are kept"),
202 a("computer_commands", Op::ListAgentComputerCommands, "The commands it ran most recently, with output"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step203 ],
204 },
205 Tool {
206 name: "plan",
207 title: "Plans",
Fast pages, required checks on the branch, self-hosted runners, honest incidents208 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step209 default_action: None,
210 actions: &[
211 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
212 a("get", Op::GetPlan, "A plan and the issues it proposes"),
213 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
214 ],
215 },
216 Tool {
217 name: "memory",
218 title: "Memory",
219 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
220 default_action: None,
221 actions: &[
222 a("recall", Op::Recall, "Search memory, or list it all"),
223 a("remember", Op::Remember, "Save one fact"),
224 ],
225 },
226 Tool {
227 name: "workflow",
228 title: "Workflows",
Merge branch 'worktree-agent-a3abfcce648e87dca'229 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Runs' artifacts: listing, a download link, deleting, and how long they are kept. Deployments wherever they run (reported from any CI, made by jobs with an `environment:`, or built on g1t.page), their statuses and environments, and reporting your own; environments' protection rules, approving or rejecting the jobs they hold, approving a pull request's run from outside, the token's default permissions and repository dispatch. Checks on commits: statuses, check runs (a g1t Actions job is one) and check suites, to read where a commit stands or report on it from CI or an integration. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step230 default_action: None,
231 actions: &[
232 a("list", Op::ListWorkflows, "Workflows on the default branch"),
233 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)234 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps; an earlier attempt with attempt"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step235 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
236 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)237 a("cancel", Op::CancelWorkflowRun, "Cancel a run, letting its jobs clean up; force stops them outright"),
238 a("rerun", Op::RerunWorkflowRun, "Run a finished run again: all, failed_only, or one job; debug for debug logging"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step239 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2240 a("list_artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), "A repository's artifacts, newest first; or a run's with run_artifacts"),
241 a("run_artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), "One run's artifacts"),
242 a("get_artifact", Op::Artifacts(ArtifactsOp::GetArtifact), "One artifact: size, digest, expiry, run"),
243 a("download_artifact", Op::Artifacts(ArtifactsOp::DownloadArtifact), "A 10-minute link to an artifact's zip"),
244 a("delete_artifact", Op::Artifacts(ArtifactsOp::DeleteArtifact), "Delete an artifact before it expires"),
245 a("artifact_retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), "Days the repository keeps artifacts"),
246 a("set_artifact_retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), "Change the days the repository keeps artifacts"),
Merge checks: statuses and check runs on every commit247 a("combined_status", Op::Checks(ChecksOp::GetCombinedStatus), "A commit's statuses and the state they add up to"),
248 a("list_statuses", Op::Checks(ChecksOp::ListCommitStatuses), "A commit's statuses, newest first"),
249 a("set_status", Op::Checks(ChecksOp::CreateCommitStatus), "Set a status on a commit"),
250 a("list_check_runs", Op::Checks(ChecksOp::ListCheckRunsForRef), "A commit's check runs, g1t Actions jobs included"),
251 a("get_check_run", Op::Checks(ChecksOp::GetCheckRun), "One check run with its report"),
252 a("check_run_annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), "What a check run says about lines of files"),
253 a("create_check_run", Op::Checks(ChecksOp::CreateCheckRun), "Report a check run on a commit"),
254 a("update_check_run", Op::Checks(ChecksOp::UpdateCheckRun), "Move a check run on, complete it, add annotations"),
255 a("rerequest_check_run", Op::Checks(ChecksOp::RerequestCheckRun), "Ask for a check run to run again"),
256 a("list_check_suites", Op::Checks(ChecksOp::ListCheckSuitesForRef), "A commit's check suites, one per reporter or workflow run"),
257 a("get_check_suite", Op::Checks(ChecksOp::GetCheckSuite), "One check suite"),
258 a("rerequest_check_suite", Op::Checks(ChecksOp::RerequestCheckSuite), "Ask for a check suite to run again"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97259 a("list_deployments", Op::Deployments(DeploymentsOp::ListDeployments), "Deployments wherever they run, newest first, filtered"),
260 a("get_deployment", Op::Deployments(DeploymentsOp::GetDeployment), "One deployment with every status it has had"),
261 a("create_deployment", Op::Deployments(DeploymentsOp::CreateDeployment), "Report a deployment of a ref to an environment"),
262 a("deployment_statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), "A deployment's statuses, newest first"),
263 a("create_deployment_status", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), "Report where a deployment is: in_progress, success, failure"),
264 a("list_environments", Op::Deployments(DeploymentsOp::ListEnvironments), "Environments with their current and latest deployments"),
Merge branch 'worktree-agent-a3abfcce648e87dca'265 a("get_environment", Op::Deployments(DeploymentsOp::GetEnvironment), "One environment by name, with its protection rules"),
266 a("update_environment", Op::Protection(ProtectionOp::UpdateEnvironment), "Set an environment's reviewers, wait timer and branches"),
267 a("delete_environment", Op::Protection(ProtectionOp::DeleteEnvironment), "Remove an environment's protection rules"),
268 a("pending_deployments", Op::Protection(ProtectionOp::GetPendingDeployments), "The environments holding a run's jobs"),
269 a("review_deployments", Op::Protection(ProtectionOp::ReviewPendingDeployments), "Approve or reject a run's jobs for its environments"),
270 a("approve_run", Op::Protection(ProtectionOp::ApproveWorkflowRun), "Let a run of a pull request from outside start"),
271 a("get_permissions", Op::Protection(ProtectionOp::GetWorkflowPermissions), "What a job's token gets without `permissions:`"),
272 a("set_permissions", Op::Protection(ProtectionOp::SetWorkflowPermissions), "Set it: read or write"),
273 a("get_approval_policy", Op::Protection(ProtectionOp::GetForkPrApproval), "Which pull requests' runs wait for approval"),
274 a("set_approval_policy", Op::Protection(ProtectionOp::SetForkPrApproval), "Set which pull requests' runs wait for approval"),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts275 a("get_access", Op::Protection(ProtectionOp::GetActionsAccess), "Which repositories may use this one's actions and workflows"),
276 a("set_access", Op::Protection(ProtectionOp::SetActionsAccess), "Let the workspace's private repositories use them, or not"),
Merge branch 'worktree-agent-a3abfcce648e87dca'277 a("repository_dispatch", Op::Protection(ProtectionOp::CreateRepositoryDispatch), "Start repository_dispatch workflows with an event"),
278 a("get_workspace_permissions", Op::Protection(ProtectionOp::GetWorkspaceWorkflowPermissions), "A workspace's default and maximum token permissions"),
279 a("set_workspace_permissions", Op::Protection(ProtectionOp::SetWorkspaceWorkflowPermissions), "Set them, and whether jobs may open pull requests"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents280 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
281 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
282 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
283 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
284 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
285 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
286 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
287 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
288 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step289 ],
290 },
291 Tool {
Merge packages: roles, Actions access, source label, soft delete, API292 name: "package",
293 title: "Packages",
294 description: "A workspace's packages in every registry (container images, npm, Cargo, Maven, NuGet, RubyGems, Composer): their versions and downloads, deleting and restoring them within 30 days, their visibility and repository, who has a role on them, and which repositories' workflows may use them (Manage Actions access). Name one by workspace, package_type and package_name.",
295 default_action: None,
296 actions: &[
297 a("list", Op::Packages(PackagesOp::ListPackages), "A workspace's packages; state deleted for restorable ones"),
298 a("get", Op::Packages(PackagesOp::GetPackage), "One package: address, visibility, repository, downloads"),
299 a("versions", Op::Packages(PackagesOp::ListVersions), "Its versions with tags and downloads; state deleted too"),
300 a("get_version", Op::Packages(PackagesOp::GetVersion), "One version by id, version, digest or tag"),
301 a("update", Op::Packages(PackagesOp::UpdatePackage), "Set visibility, or inherit_access for a linked one"),
302 a("link", Op::Packages(PackagesOp::LinkPackage), "Link it to a repository of its workspace"),
303 a("unlink", Op::Packages(PackagesOp::UnlinkPackage), "Unlink it: the workspace's, private"),
304 a("access", Op::Packages(PackagesOp::ListAccess), "People and teams with a role on it"),
305 a("set_access", Op::Packages(PackagesOp::SetAccess), "Give a person or team read, write or admin"),
306 a("remove_access", Op::Packages(PackagesOp::RemoveAccess), "Take a person's or team's role away"),
307 a("actions_access", Op::Packages(PackagesOp::ListActionsAccess), "Repositories whose workflows may use it"),
308 a("set_actions_access", Op::Packages(PackagesOp::SetActionsAccess), "Let a repository's workflows read or write it"),
309 a("remove_actions_access", Op::Packages(PackagesOp::RemoveActionsAccess), "Stop a repository's workflows using it"),
310 a("delete", Op::Packages(PackagesOp::DeletePackage), "Delete it; restorable for 30 days"),
311 a("restore", Op::Packages(PackagesOp::RestorePackage), "Restore a deleted package"),
312 a("delete_version", Op::Packages(PackagesOp::DeleteVersion), "Delete a version; restorable for 30 days"),
313 a("restore_version", Op::Packages(PackagesOp::RestoreVersion), "Restore a deleted version"),
314 ],
315 },
316 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step317 name: "secret",
318 title: "Secrets and variables",
319 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
320 default_action: None,
321 actions: &[
322 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
323 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
324 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
325 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
326 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
327 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
328 ],
329 },
330 Tool {
331 name: "webhook",
332 title: "Webhooks",
333 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
334 default_action: None,
335 actions: &[
336 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
337 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
338 a("update", Op::UpdateWebhook, "Change address, events or active"),
339 a("delete", Op::DeleteWebhook, "Remove one"),
340 a("ping", Op::PingWebhook, "Send a ping"),
341 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
342 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
343 ],
344 },
345 Tool {
346 name: "access",
347 title: "Who has access",
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca348 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, a workspace's base permission, and a repository's deploy keys.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step349 default_action: None,
350 actions: &[
351 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
352 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
353 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
354 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
355 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
356 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
357 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
358 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
359 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca360 a("list_deploy_keys", Op::DeployKeys(DeployKeysOp::ListDeployKeys), "SSH keys that reach this one repository"),
361 a("get_deploy_key", Op::DeployKeys(DeployKeysOp::GetDeployKey), "One deploy key, by id"),
362 a("add_deploy_key", Op::DeployKeys(DeployKeysOp::CreateDeployKey), "Add one; read-only unless read_only is false"),
363 a("remove_deploy_key", Op::DeployKeys(DeployKeysOp::DeleteDeployKey), "Delete one"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step364 ],
365 },
366 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar367 name: "team",
368 title: "Teams",
369 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
370 default_action: None,
371 actions: &[
372 a("list", Op::ListTeams, "A workspace's teams you can see"),
373 a("get", Op::GetTeam, "One team"),
374 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
375 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
376 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
377 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
378 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
379 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
380 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
381 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
382 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
383 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
384 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
385 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
386 ],
387 },
388 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step389 name: "workspace",
390 title: "Workspaces",
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97391 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step392 default_action: None,
393 actions: &[
Merge branch 'worktree-agent-ad7c6d88d93adc817'394 a("get", Op::GetWorkspace, "A workspace's details and settings"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step395 a("create", Op::CreateWorkspace, "Create a workspace"),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member396 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
Merge main (membership, two-factor, GitHub repo roles) into tokens397 a("update", Op::UpdateWorkspace, "Change its name, description, base permission, who may create teams, member privileges or the two-factor requirement"),
398 a("list_members", Op::ListMembers, "Its members, owners first, with their roles"),
399 a("update_member", Op::UpdateMember, "Make someone an owner or a member, billing manager or security manager"),
400 a("remove_member", Op::RemoveMember, "Remove someone from it"),
401 a("transfer_ownership", Op::TransferOwnership, "Hand it to another member: they become an owner, you a member"),
402 a("leave", Op::LeaveWorkspace, "Leave it yourself"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step403 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040)404 a("invite_member", Op::InviteMember, "Invite someone by username or email address"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step405 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
406 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
407 a("connect_integration", Op::ConnectIntegration, "Connect one"),
AI Gateway: OpenAI's format, open models, and your own providers408 a("update_integration", Op::UpdateIntegration, "Change one: rotate its key, choose its AI Gateway models"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step409 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
410 a("test_integration", Op::TestIntegration, "Check its credentials"),
411 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
412 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97413 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
414 a("get_project", Op::GetProject, "One project"),
415 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
API: pinned projects over REST and MCP416 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
417 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
418 a("unpin_project", Op::UnpinProject, "Unpin a project"),
419 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge420 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
421 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
422 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
423 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
424 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
425 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
API and MCP for a workspace's personal access token rules, members' tokens and approvals426 a("get_token_policy", Op::Tokens(TokenOp::GetTokenPolicy), "Its rules for personal access tokens"),
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers427 a("set_token_policy", Op::Tokens(TokenOp::SetTokenPolicy), "Change them: which tokens reach it, approval, lifetime"),
API and MCP for a workspace's personal access token rules, members' tokens and approvals428 a("list_member_tokens", Op::Tokens(TokenOp::ListMemberTokens), "Members' personal access tokens that reach it"),
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers429 a("list_token_requests", Op::Tokens(TokenOp::ListTokenRequests), "Tokens waiting for approval"),
API and MCP for a workspace's personal access token rules, members' tokens and approvals430 a("review_token_request", Op::Tokens(TokenOp::ReviewTokenRequest), "Approve or deny one"),
431 a("revoke_member_token", Op::Tokens(TokenOp::RevokeMemberToken), "Revoke a member's token in it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step432 ],
433 },
434 Tool {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit435 name: "billing",
436 title: "Billing",
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens437 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit438 default_action: Some("usage"),
439 actions: &[
440 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
441 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
442 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
443 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
444 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
445 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
446 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens447 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit448 ],
449 },
450 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar451 name: "security",
452 title: "Security",
453 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
454 default_action: Some("secret_alerts"),
455 actions: &[
456 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
457 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
458 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
459 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
460 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
461 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
462 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
463 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
464 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
465 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
466 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
467 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
468 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
469 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
470 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
471 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
472 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
473 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
474 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
475 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
476 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
477 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
478 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
479 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
480 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
481 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
482 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
483 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
484 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
485 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
486 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
487 ],
488 },
489 Tool {
API: notifications over REST and MCP, with notifications scopes490 name: "notifications",
491 title: "Notifications",
492 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
493 default_action: Some("list"),
494 actions: &[
495 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
496 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
497 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
498 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
499 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
500 a("save", Op::SaveThread, "Save a thread, or unsave it"),
501 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
502 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
503 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
504 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
505 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
506 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
507 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
508 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
509 ],
510 },
511 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step512 name: "account",
513 title: "Your account",
Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040)514 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to workspaces and repositories waiting for you.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step515 default_action: Some("whoami"),
516 actions: &[
517 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
518 a("list_emails", Op::ListEmails, "Your addresses"),
519 a("add_email", Op::AddEmail, "Add an address"),
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)520 a("confirm_email", Op::ConfirmEmail, "Confirm an address with the code from its email"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step521 a("remove_email", Op::RemoveEmail, "Remove an address"),
522 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
523 a("list_invites", Op::ListInvites, "Your invites to g1t"),
524 a("create_invite", Op::CreateInvite, "Make an invite"),
525 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040)526 a("list_workspace_invitations", Op::ListInvitations, "Invitations to workspaces for you"),
527 a("accept_workspace_invitation", Op::AcceptInvitation, "Accept one and join"),
528 a("decline_workspace_invitation", Op::DeclineInvitation, "Decline one"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step529 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
530 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
531 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
532 ],
533 },
Merge main into Artifacts Phase 2534 Tool {
535 name: "artifact",
536 title: "Artifacts",
537 description: "A workspace's docs, slides, designs and dashboards (Artifacts mode), as you can open them: list, search and read them (a doc's content is Markdown, with block ids to target), make them, edit them (a change with the edit role, a suggestion with comment), move, trash and restore them, their versions, and who can open them. Name one by its id (fol_…) or its address. Not the `workflow` tool's run artifacts. Slides, designs and dashboards answer that they are not here yet.",
538 default_action: None,
539 actions: &[
540 a("list", Op::Folios(FoliosOp::List), "Artifacts you can open; tab, kind, space, q; state trashed for the trash"),
541 a("search", Op::Folios(FoliosOp::Search), "Search them by words and meaning, with the passage that matched"),
542 a("get", Op::Folios(FoliosOp::Get), "One artifact: kind, title, space, owner, your role, who it is shared with"),
543 a("read", Op::Folios(FoliosOp::GetContent), "Its content: a doc's Markdown and block ids, and what you may do"),
544 a("versions", Op::Folios(FoliosOp::ListVersions), "Its saved versions, newest first"),
545 a("access", Op::Folios(FoliosOp::GetAccess), "Who can open it, and how"),
546 a("templates", Op::Folios(FoliosOp::ListTemplates), "Templates to start one from"),
547 a("spaces", Op::Folios(FoliosOp::ListSpaces), "The spaces in your sidebar"),
548 a("query_data", Op::Folios(FoliosOp::QueryDataset), "Run a dataset query as you, over what you can read"),
549 a("create", Op::Folios(FoliosOp::Create), "Make one: in a space, under a doc, or in your Private"),
550 a("update", Op::Folios(FoliosOp::Update), "Rename it, change its icon, or move it"),
551 a("edit", Op::Folios(FoliosOp::Edit), "Change its content: append, replace it all, a section or blocks"),
552 a("trash", Op::Folios(FoliosOp::Trash), "Move it to the trash; restorable for 30 days"),
553 a("restore", Op::Folios(FoliosOp::Restore), "Bring it back from the trash"),
554 a("restore_version", Op::Folios(FoliosOp::RestoreVersion), "Make an earlier version its content again"),
555 a("share", Op::Folios(FoliosOp::SetAccess), "Share it, change general access, or take access away"),
556 a("purge", Op::Folios(FoliosOp::Purge), "Delete one in the trash for good"),
557 ],
558 },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step559];
560
561/// Operations that cannot be undone, or reach beyond g1t's own records:
562/// clients ask before running a tool that has any of them.
563fn destructive(op: Op) -> bool {
564 matches!(
565 op,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar566 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge567 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar568 | Op::DeleteWorkspace
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily569 | Op::UpdateWorkspace
API and MCP for a workspace's personal access token rules, members' tokens and approvals570 | Op::Tokens(TokenOp::RevokeMemberToken | TokenOp::SetTokenPolicy)
Merge main (membership, two-factor, GitHub repo roles) into tokens571 | Op::RemoveMember
572 | Op::TransferOwnership
573 | Op::LeaveWorkspace
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step574 | Op::DeleteRepo
575 | Op::PurgeRepo
576 | Op::TransferRepo
577 | Op::SetRepoVisibility
578 | Op::RemoveEmail
579 | Op::RemoveCollaborator
580 | Op::DisconnectIntegration
AI Gateway: OpenAI's format, open models, and your own providers581 | Op::UpdateIntegration
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step582 | Op::DeleteWebhook
583 | Op::DeleteActionsSecret
584 | Op::DeleteActionsVariable
585 | Op::SetActionsSecret
586 | Op::SetActionsVariable
587 | Op::SetModelRoutes
588 | Op::SetBasePermission
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar589 | Op::DeleteTeam
590 | Op::RemoveTeamRepo
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step591 | Op::MergePullRequest
Fast pages, required checks on the branch, self-hosted runners, honest incidents592 | Op::RemoveRunner
593 | Op::DeleteRunnerGroup
594 | Op::UpdateRunnerSettings
Merge main into Artifacts Phase 2595 | Op::Folios(FoliosOp::SetAccess | FoliosOp::Purge)
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step596 )
597}
598
599/// Whether an operation only reads.
600pub fn reads_only(op: Op) -> bool {
601 NO_SCOPE.contains(&op.name())
602 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
603}
604
605/// What decides which actions a caller sees.
606pub enum Gate<'a> {
607 /// No limit beyond the person's own role.
608 Everything,
609 /// A g1t agent's token: the operations its run lists.
610 Agent(&'a AgentScope),
611 /// An access token with scopes.
612 Token(&'a TokenAccess),
613}
614
615impl Gate<'_> {
616 pub fn allows(&self, op: Op) -> bool {
617 match self {
618 Gate::Everything => true,
619 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
620 Gate::Token(access) => {
621 if NO_SCOPE.contains(&op.name()) {
622 return true;
623 }
624 match scope_for(op.name()) {
625 Some(scope) => access.allows(scope),
626 None => access.scopes.is_none(),
627 }
628 }
629 }
630 }
631}
632
633impl Tool {
634 pub fn by_name(name: &str) -> Option<&'static Tool> {
635 TOOLS.iter().find(|tool| tool.name == name)
636 }
637
638 pub fn action(&self, name: &str) -> Option<&'static Action> {
639 // The tools are 'static; find through TOOLS to keep the lifetime.
640 TOOLS
641 .iter()
642 .find(|tool| tool.name == self.name)
643 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
644 }
645
646 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
647 TOOLS
648 .iter()
649 .find(|tool| tool.name == self.name)
650 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
651 .unwrap_or_default()
652 }
653
654 /// The flat input schema of the actions given.
655 pub fn input_schema(&self, actions: &[&Action]) -> Value {
656 let mut properties = Map::new();
657 let lines: Vec<String> = actions
658 .iter()
659 .map(|action| {
660 let required: Vec<String> = action.op.required();
661 if required.is_empty() {
662 format!("{}: {}.", action.name, action.summary)
663 } else {
664 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
665 }
666 })
667 .collect();
668 let mut action_schema = json!({
669 "type": "string",
670 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
671 "description": lines.join("\n"),
672 });
673 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
674 action_schema["default"] = json!(default);
675 }
676 properties.insert("action".to_owned(), action_schema);
677 for action in actions {
678 for (name, schema) in action.op.properties() {
679 merge_property(&mut properties, name, schema);
680 }
681 }
682 let mut required = vec![];
683 if self.default_action.is_none() {
684 required.push("action");
685 }
686 let mut schema = json!({ "type": "object", "properties": properties });
687 if !required.is_empty() {
688 schema["required"] = json!(required);
689 }
690 schema
691 }
692
693 /// The input schema keyed by action: one `oneOf` branch per action,
694 /// each with its own fields and the ones it needs.
695 pub fn discriminated(&self, actions: &[&Action]) -> Value {
696 let branches: Vec<Value> = actions
697 .iter()
698 .map(|action| {
699 let mut properties = Map::new();
700 properties.insert("action".to_owned(), json!({ "const": action.name }));
701 properties.extend(action.op.properties());
702 let mut required = vec![Value::String("action".to_owned())];
703 // The default action may leave `action` out.
704 if self.default_action == Some(action.name) {
705 required.clear();
706 }
707 required.extend(action.op.required().into_iter().map(Value::String));
708 json!({
709 "title": action.name,
710 "description": action.summary,
711 "type": "object",
712 "properties": properties,
713 "required": required,
714 })
715 })
716 .collect();
717 json!({ "type": "object", "oneOf": branches })
718 }
719
720 /// MCP's hints about the actions given: whether the tool only reads,
721 /// whether it can destroy something, and whether calling it twice is
722 /// the same as once.
723 pub fn annotations(&self, actions: &[&Action]) -> Value {
724 let read_only = actions.iter().all(|action| reads_only(action.op));
725 json!({
726 "title": self.title,
727 "readOnlyHint": read_only,
728 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
729 "idempotentHint": read_only,
730 "openWorldHint": false,
731 })
732 }
733
734 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
735 /// `None` when it may use none of its actions.
736 pub fn listed(&self, gate: &Gate) -> Option<Value> {
737 let actions = self.visible(gate);
738 if actions.is_empty() {
739 return None;
740 }
741 Some(json!({
742 "name": self.name,
743 "title": self.title,
744 "description": self.description,
745 "inputSchema": self.input_schema(&actions),
746 "annotations": self.annotations(&actions),
747 }))
748 }
749}
750
751/// Adds a property to a tool's flat schema. The first action to use a name
752/// describes it; a later one with other allowed values adds them.
753fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
754 match properties.get_mut(&name) {
755 None => {
756 properties.insert(name, schema);
757 }
758 Some(existing) => {
759 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
760 (existing.get("enum").cloned(), schema.get("enum"))
761 {
762 let mut merged = had;
763 for value in more {
764 if !merged.contains(value) {
765 merged.push(value.clone());
766 }
767 }
768 existing["enum"] = Value::Array(merged);
769 }
770 // Different kinds of value under one name: say less, accept both.
771 if existing.get("type") != schema.get("type")
772 && let Some(fields) = existing.as_object_mut()
773 {
774 fields.remove("type");
775 fields.remove("items");
776 }
777 }
778 }
779}
780
781/// What a call to a tool runs: the operation its action names, or why not.
782pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
783 let names = || {
784 tool.actions
785 .iter()
786 .map(|action| action.name)
787 .collect::<Vec<_>>()
788 .join(", ")
789 };
790 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
791 return Err(format!("Give an action: one of {}.", names()));
792 };
793 let Some(action) = tool.action(name) else {
794 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
795 };
796 let missing: Vec<String> = action
797 .op
798 .required()
799 .into_iter()
800 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
801 .collect();
802 if !missing.is_empty() {
803 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
804 }
805 Ok(action.op)
806}
807
808#[cfg(test)]
809mod tests {
810 use super::*;
811 use g1t_contracts::scopes::{Preset, Scope};
812
813 fn listed(gate: &Gate) -> Vec<Value> {
814 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
815 }
816
817 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
818 TokenAccess {
819 token_id: "tok_1".to_owned(),
820 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
821 legacy: false,
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens822 name: None,
Merge branch 'worktree-agent-a3abfcce648e87dca'823 ..TokenAccess::default()
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step824 }
825 }
826
827 #[test]
828 fn every_operation_is_exactly_one_action_of_one_tool() {
829 for op in Op::ALL {
830 let count = TOOLS
831 .iter()
832 .flat_map(|tool| tool.actions.iter())
833 .filter(|action| action.op == op)
834 .count();
835 assert_eq!(count, 1, "{} is {count} actions", op.name());
836 }
837 for tool in TOOLS {
838 let mut names = std::collections::HashSet::new();
839 for action in tool.actions {
840 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
841 }
842 if let Some(default) = tool.default_action {
843 assert!(tool.action(default).is_some(), "{}", tool.name);
844 }
845 }
Merge main into Artifacts Phase 2846 assert!(TOOLS.len() <= 19, "{} tools", TOOLS.len());
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step847 }
848
849 #[test]
850 fn every_operation_needs_exactly_one_scope_or_none() {
851 use g1t_contracts::scopes::OPERATIONS;
852 for op in Op::ALL {
853 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
854 let free = NO_SCOPE.contains(&op.name());
855 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
856 }
857 for (name, _) in OPERATIONS {
858 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
859 }
860 }
861
862 #[test]
863 fn each_tool_schema_is_valid_with_one_branch_per_action() {
864 for tool in TOOLS {
865 let actions: Vec<&Action> = tool.actions.iter().collect();
866 let flat = tool.input_schema(&actions);
867 assert_eq!(flat["type"], "object");
868 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
869 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
870 .as_array()
871 .unwrap()
872 .iter()
873 .map(|name| name.as_str().unwrap())
874 .collect();
875 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
876 for action in tool.actions {
877 for field in action.op.required() {
878 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
879 }
880 }
881 let keyed = tool.discriminated(&actions);
882 let branches = keyed["oneOf"].as_array().unwrap();
883 assert_eq!(branches.len(), tool.actions.len());
884 for (branch, action) in branches.iter().zip(tool.actions) {
885 assert_eq!(branch["properties"]["action"]["const"], action.name);
886 for field in branch["required"].as_array().unwrap() {
887 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
888 }
889 }
890 // A well-formed JSON Schema object throughout.
891 let text = serde_json::to_string(&flat).unwrap();
892 assert!(serde_json::from_str::<Value>(&text).is_ok());
893 }
894 }
895
896 #[test]
897 fn a_read_only_token_sees_read_actions_only() {
898 let access = token(Preset::ReadOnly.scopes());
899 let gate = Gate::Token(&access);
900 for tool in TOOLS {
901 for action in tool.visible(&gate) {
902 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
903 }
904 }
905 let tools = listed(&gate);
906 for tool in &tools {
907 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
908 assert_eq!(tool["annotations"]["destructiveHint"], false);
909 }
910 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar911 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step912 // Nothing of the agent tool is a read.
913 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
914 }
915
916 #[test]
917 fn a_narrow_token_sees_only_its_tools() {
918 let access = token(Some(vec![Scope::IssuesWrite]));
919 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar920 // Labels and milestones are the repository's, managed with issues:write.
921 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
API: notifications over REST and MCP, with notifications scopes922 // Notifications are a resource of their own: reading them lists
923 // only what reads.
924 let reader = token(Some(vec![Scope::NotificationsRead]));
925 let tools = listed(&Gate::Token(&reader));
926 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
927 assert_eq!(
928 notifications["inputSchema"]["properties"]["action"]["enum"],
929 json!(["list", "get", "subscription", "watching", "watched"])
930 );
931 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step932 let full = token(None);
933 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
934 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
935 }
936
937 #[test]
938 fn a_tool_that_can_destroy_says_so() {
939 let tools = listed(&Gate::Everything);
940 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
941 assert_eq!(repository["annotations"]["destructiveHint"], true);
942 assert_eq!(repository["annotations"]["readOnlyHint"], false);
943 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
944 assert_eq!(memory["annotations"]["destructiveHint"], false);
945 }
946
947 #[test]
948 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
949 let issue = Tool::by_name("issue").unwrap();
950 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
951 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
952 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
953 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
954 let search = Tool::by_name("search").unwrap();
955 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
956 let account = Tool::by_name("account").unwrap();
957 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
958 }
959
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar960 #[test]
961 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
962 let team = Tool::by_name("team").unwrap();
963 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
964 assert_eq!(
965 names,
966 [
967 "list",
968 "get",
969 "create",
970 "update",
971 "delete",
972 "list_members",
973 "set_member",
974 "remove_member",
975 "list_child_teams",
976 "list_repos",
977 "set_repo",
978 "remove_repo",
979 "set_review_assignment",
980 "list_user_teams",
981 ]
982 );
983 let reader = token(Some(vec![Scope::WorkspaceRead]));
984 let tools = listed(&Gate::Token(&reader));
985 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
986 assert_eq!(
987 listed_team["inputSchema"]["properties"]["action"]["enum"],
988 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
989 );
990 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
991 // A team's role on a repository is who has access.
992 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
993 let tools = listed(&Gate::Token(&admin));
994 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
995 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
996 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
997 let access = token(Some(vec![Scope::AccessAdmin]));
998 let tools = listed(&Gate::Token(&access));
999 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
1000 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
1001 // Both kinds of role a schema names are offered.
1002 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
1003 ["properties"]["role"]["enum"];
1004 for role in ["member", "maintainer", "read", "admin"] {
1005 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
1006 }
1007 assert_eq!(
1008 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
1009 Err("team.set_repo needs role.".to_owned())
1010 );
1011 }
1012
1013 #[test]
1014 fn reviewers_and_code_owners_are_actions_of_their_tools() {
1015 let pull = Tool::by_name("pull_request").unwrap();
1016 assert_eq!(
1017 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
1018 Ok(Op::RequestReviewers)
1019 );
1020 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
1021 let repository = Tool::by_name("repository").unwrap();
1022 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
1023 assert!(reads_only(Op::GetCodeownersErrors));
1024 assert!(!reads_only(Op::RequestReviewers));
1025 }
1026
Merge main into Artifacts Phase 21027 /// The `artifact` tool offers each token only what its artifacts scope
1028 /// allows: reading, then changing, then sharing and deleting for good.
1029 /// Workflow runs' artifacts are the `workflow` tool's, under their own
1030 /// scope, and neither scope reaches the other's.
1031 #[test]
1032 fn the_artifact_tool_offers_what_the_artifacts_scope_allows() {
1033 let actions = |scopes: Vec<Scope>| -> Option<Value> {
1034 let access = token(Some(scopes));
1035 Tool::by_name("artifact").unwrap().listed(&Gate::Token(&access)).map(|tool| tool["inputSchema"]["properties"]["action"]["enum"].clone())
1036 };
1037 let reads = json!(["list", "search", "get", "read", "versions", "access", "templates", "spaces", "query_data"]);
1038 assert_eq!(actions(vec![Scope::ArtifactsRead]), Some(reads.clone()));
1039 let writes = actions(vec![Scope::ArtifactsWrite]).unwrap();
1040 for action in ["create", "update", "edit", "trash", "restore", "restore_version"] {
1041 assert!(writes.as_array().unwrap().contains(&json!(action)), "{action}");
1042 }
1043 assert!(!writes.as_array().unwrap().contains(&json!("share")) && !writes.as_array().unwrap().contains(&json!("purge")));
1044 let admin = actions(vec![Scope::ArtifactsAdmin]).unwrap();
1045 assert_eq!(admin.as_array().unwrap().len(), Tool::by_name("artifact").unwrap().actions.len());
1046 // Without an artifacts scope there is no artifact tool at all.
1047 assert_eq!(actions(vec![Scope::WorkflowsWrite, Scope::IssuesWrite]), None);
1048 // And an artifacts scope shows nothing of workflow runs' artifacts.
1049 let access = token(Some(vec![Scope::ArtifactsAdmin]));
1050 assert!(Tool::by_name("workflow").unwrap().listed(&Gate::Token(&access)).is_none());
1051 // The read-only and agent presets read artifacts and change none.
1052 for preset in [Preset::ReadOnly, Preset::Agent] {
1053 let access = token(preset.scopes());
1054 let tool = Tool::by_name("artifact").unwrap().listed(&Gate::Token(&access)).unwrap();
1055 assert_eq!(tool["inputSchema"]["properties"]["action"]["enum"], reads, "{}", preset.as_str());
1056 assert_eq!(tool["annotations"]["readOnlyHint"], true);
1057 }
1058 // Sharing and deleting for good can't be undone the same way.
1059 let tools = listed(&Gate::Everything);
1060 let artifact = tools.iter().find(|tool| tool["name"] == "artifact").unwrap();
1061 assert_eq!(artifact["annotations"]["destructiveHint"], true);
1062 assert!(artifact["description"].as_str().unwrap().contains("Not the `workflow` tool's run artifacts"));
1063 let tool = Tool::by_name("artifact").unwrap();
1064 assert_eq!(resolve(tool, &json!({ "action": "read", "workspace": "acme" })), Err("artifact.read needs artifact_id.".to_owned()));
1065 assert_eq!(
1066 resolve(tool, &json!({ "action": "edit", "workspace": "acme", "artifact_id": "fol_1", "markdown": "x" })),
1067 Ok(Op::Folios(FoliosOp::Edit))
1068 );
1069 }
1070
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1071 /// How much smaller `tools/list` is than one tool per operation. Run
1072 /// with `--nocapture` to see the numbers.
1073 #[test]
1074 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
1075 let before: Vec<Value> = Op::ALL
1076 .into_iter()
1077 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
1078 .collect();
1079 let after = listed(&Gate::Everything);
1080 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
1081 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
1082 let agent = token(Preset::Agent.scopes());
1083 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
1084 let read = token(Preset::ReadOnly.scopes());
1085 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
1086 println!(
1087 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
1088 before.len(),
1089 before_bytes / 4,
1090 after.len(),
1091 after_bytes / 4,
1092 agent_bytes / 4,
1093 read_bytes / 4,
1094 );
1095 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
1096 }
1097}

This file's history is long; its oldest lines are credited to the oldest commit read.