Docs

Tools

Inspect callable operations exposed by MCP servers.

A tool is one callable operation on an MCP server: a name, an input and output JSON Schema, and a side_effect_type of read, write, delete, or admin. Discovery sets that side-effect type automatically by scanning the tool's name and description for keywords — "delete", "remove", "drop" mark it delete; "create", "write", "update", "push", "merge", and similar mark it write; everything else defaults to read. It is a heuristic, not a static analysis of what the tool's code actually does, so it can be wrong for a tool whose name doesn't match its behavior — the catalog lets an operator see and correct it.

Every tool belongs to exactly one MCP server (mcp_server_id) and that ownership is what the catalog's server filter and per-server grouping are built on. A tool optionally carries a target_extractor — a small JSON spec, authored from the tool's detail card, that tells the gateway how to derive a resource URI from the tool's invocation arguments at call time. One mode reads a URI template populated from named arguments ({owner}/{repo} from an owner/repo pair); the other parses table names out of a SQL string argument. Without an extractor, a call is only governed at the tool level; with one, the gateway can also evaluate resource- and column-level policy against whatever the extractor resolves. The tool detail card includes a test runner that lets an operator try an extractor against sample arguments before saving it.

Risk tags and compliance tags are free-form labels attached to a tool at creation or discovery time and are what the catalog's search and filtering keys off alongside side-effect type. Policy coverage on a tool's card is not a catalog fact stored on the row — it's computed by looking up which published policies are attached to that specific tool ID, and whether any of them carry a deny effect.

A tool's lifecycle_state (draft, active, deprecated, archived) and version_hash track its evolution independent of governance state — a tool can be actively enforced against while still in draft, and a deprecated tool keeps whatever policies were bound to it until someone removes them.

Reference

Features

Tool inventory
description
Every tool discovered from or registered on a connected MCP server, filterable by owning server, side-effect type, and whether it currently has a policy attached.
Tool schemas
description
The tool's input and output JSON Schema as reported by the server, plus its optional target_extractor spec for deriving a resource URI from invocation arguments — editable and test-runnable from the tool detail card.
Read/write classification
description
The read, write, delete, or admin side-effect type discovery inferred from the tool's name and description by keyword match, correctable by an operator when the inference is wrong.
Sensitivity
description
Risk and compliance tags attached to a tool, used for search and filtering alongside its side-effect type.
Server ownership
description
The single MCP server that exposes this tool. Every tool belongs to exactly one server, and the catalog's server filter and grouping are built on that link.
Policy coverage
description
Whether any published policy is attached to this specific tool, and whether one of them denies — computed by looking up policy bindings against the tool's ID, not stored on the tool row.
Runtime usage
description
How the tool has actually been invoked, surfaced from recorded invocation and enforcement-decision history rather than from the tool's static definition.

Interfaces

data-plane serves /tools-catalog