Tools
Inspect callable operations exposed by MCP servers.
A tool is one callable operation on an MCP server: a name, an input and output JSON Schema, and a side_effect_type of read, write, delete, or admin. Discovery sets that side-effect type automatically by scanning the tool's name and description for keywords — "delete", "remove", "drop" mark it delete; "create", "write", "update", "push", "merge", and similar mark it write; everything else defaults to read. It is a heuristic, not a static analysis of what the tool's code actually does, so it can be wrong for a tool whose name doesn't match its behavior — the catalog lets an operator see and correct it.
Every tool belongs to exactly one MCP server (mcp_server_id) and that ownership is what the catalog's server filter and per-server grouping are built on. A tool optionally carries a target_extractor — a small JSON spec, authored from the tool's detail card, that tells the gateway how to derive a resource URI from the tool's invocation arguments at call time. One mode reads a URI template populated from named arguments ({owner}/{repo} from an owner/repo pair); the other parses table names out of a SQL string argument. Without an extractor, a call is only governed at the tool level; with one, the gateway can also evaluate resource- and column-level policy against whatever the extractor resolves. The tool detail card includes a test runner that lets an operator try an extractor against sample arguments before saving it.
Risk tags and compliance tags are free-form labels attached to a tool at creation or discovery time and are what the catalog's search and filtering keys off alongside side-effect type. Policy coverage on a tool's card is not a catalog fact stored on the row — it's computed by looking up which published policies are attached to that specific tool ID, and whether any of them carry a deny effect.
A tool's lifecycle_state (draft, active, deprecated, archived) and version_hash track its evolution independent of governance state — a tool can be actively enforced against while still in draft, and a deprecated tool keeps whatever policies were bound to it until someone removes them.
Reference
Features
- description
- Every tool discovered from or registered on a connected MCP server, filterable by owning server, side-effect type, and whether it currently has a policy attached.
- description
- The tool's input and output JSON Schema as reported by the server, plus its optional target_extractor spec for deriving a resource URI from invocation arguments — editable and test-runnable from the tool detail card.
- description
- The read, write, delete, or admin side-effect type discovery inferred from the tool's name and description by keyword match, correctable by an operator when the inference is wrong.
- description
- Risk and compliance tags attached to a tool, used for search and filtering alongside its side-effect type.
- description
- The single MCP server that exposes this tool. Every tool belongs to exactly one server, and the catalog's server filter and grouping are built on that link.
- description
- Whether any published policy is attached to this specific tool, and whether one of them denies — computed by looking up policy bindings against the tool's ID, not stored on the tool row.
- description
- How the tool has actually been invoked, surfaced from recorded invocation and enforcement-decision history rather than from the tool's static definition.

Docs