# Serve MCP — full tool reference > Every MCP tool Serve MCP (servemcp.com) currently exposes, grouped by integration. Generated from the production database, filtered to integrations that are enabled and tools that are active. The short version of this document, covering the endpoint URL, authentication and pricing, is at https://servemcp.com/llms.txt — read that first. 1776 tools across 21 integrations: 1202 read-only, 574 write. Generated 2026-09-06. Each tool is listed with its exact MCP tool name and the flags a client sees: - `read-only` / `write` — whether calling it can change anything in the connected service. - `destructive` — deletes, revokes, blocks, or otherwise makes a change that is not trivially undone. Surfaced to clients as MCP's `destructiveHint`. - `off by default` — present on a new connection but switched off until a workspace member enables it. Every write tool is off by default; some read-only tools are too, to keep a newly connected workspace's tool list small enough for a client to choose from well. A tool being listed here does not mean it is callable on any given workspace. It must belong to a connected integration, be enabled on that connection, and the calling token's workspace role must permit it — READ members cannot invoke write tools. See https://servemcp.com/llms.txt for the full safety model. ## Cisco Meraki Read-only access to the full Cisco Meraki Dashboard API v1 GET surface. 494 tools: 494 read-only, 0 write. - `meraki_clip_device_camera` [read-only] — Generate a video clip of up to 5 minutes long. - `meraki_get_administered_identities_me` [read-only] — Returns the identity of the current user. - `meraki_get_administered_identities_me_api_keys` [read-only] — List the non-sensitive metadata associated with the API keys that belong to the user - `meraki_get_administered_licensing_subscription_entitlements` [read-only] — Retrieve the list of purchasable entitlements - `meraki_get_administered_licensing_subscription_subscriptions` [read-only] — List available subscriptions - `meraki_get_administered_licensing_subscription_subscriptions_compliance_statuses` [read-only] — Get compliance status for requested subscriptions - `meraki_get_device` [read-only] — Return a single device - `meraki_get_device_appliance_dhcp_subnets` [read-only] — Return the DHCP subnet information for an appliance - `meraki_get_device_appliance_performance` [read-only] — Return the performance score for a single MX. Only primary MX devices supported. If no data is available, a 204 error code is returned. - `meraki_get_device_appliance_prefixes_delegated` [read-only] — Return current delegated IPv6 prefixes on an appliance. - `meraki_get_device_appliance_prefixes_delegated_vlan_assignments` [read-only] — Return prefixes assigned to all IPv6 enabled VLANs on an appliance. - `meraki_get_device_appliance_radio_settings` [read-only] — Return the radio settings of an appliance - `meraki_get_device_appliance_uplinks_settings` [read-only] — Return the uplink settings for a secure router or security appliance - `meraki_get_device_camera_custom_analytics` [read-only] — Return custom analytics settings for a camera - `meraki_get_device_camera_quality_and_retention` [read-only] — Returns quality and retention settings for the given camera - `meraki_get_device_camera_sense` [read-only] — Returns sense settings for a given camera - `meraki_get_device_camera_sense_object_detection_models` [read-only] — Returns the MV Sense object detection model list for the given camera - `meraki_get_device_camera_video_link` [read-only] — Returns video link to the specified camera. If a timestamp is supplied, it links to that timestamp. - `meraki_get_device_camera_video_settings` [read-only] — Returns video settings for the given camera - `meraki_get_device_camera_wireless_profiles` [read-only] — Returns wireless profile assigned to the given camera - `meraki_get_device_cellular_gateway_lan` [read-only] — Show the LAN Settings of a MG - `meraki_get_device_cellular_gateway_port_forwarding_rules` [read-only] — Returns the port forwarding rules for a single MG. - `meraki_get_device_cellular_sims` [read-only] — Return the SIM and APN configurations for a cellular device. - `meraki_get_device_clients` [read-only] — List the clients of a device, up to a maximum of a month ago. The usage of each client is returned in kilobytes. If the device is a switch, the switchport is returned; otherwise the switchport field is null. - `meraki_get_device_live_tools_arp_table` [read-only] — Return an ARP table live tool job. - `meraki_get_device_live_tools_cable_test` [read-only] — Return a cable test live tool job. - `meraki_get_device_live_tools_leds_blink` [read-only] — Return a blink LEDs job - `meraki_get_device_live_tools_mac_table` [read-only] — Return a MAC table live tool job. - `meraki_get_device_live_tools_multicast_routing` [read-only] — Return a Multicast routing live tool job. - `meraki_get_device_live_tools_ping` [read-only] — Return a ping job. Latency unit in response is in milliseconds. Size is in bytes. - `meraki_get_device_live_tools_ping_device` [read-only] — Return a ping device job. Latency unit in response is in milliseconds. Size is in bytes. - `meraki_get_device_live_tools_ports_cycle` [read-only] — Return a cycle port live tool job. - `meraki_get_device_live_tools_throughput_test` [read-only] — Return a throughput test job - `meraki_get_device_live_tools_wake_on_lan` [read-only] — Return a Wake-on-LAN job - `meraki_get_device_lldp_cdp` [read-only] — List LLDP and CDP information for a device - `meraki_get_device_loss_and_latency_history` [read-only] — Get the uplink loss percentage and latency in milliseconds, and goodput in kilobits per second for MX, MG and Z devices. - `meraki_get_device_management_interface` [read-only] — Return the management interface settings for a device - `meraki_get_device_sensor_command` [read-only] — Returns information about the command's execution, including the status - `meraki_get_device_sensor_commands` [read-only] — Returns a historical log of all commands - `meraki_get_device_sensor_relationships` [read-only] — List the sensor roles for a given sensor or camera device. - `meraki_get_device_switch_port` [read-only] — Return a switch port - `meraki_get_device_switch_ports` [read-only] — List the switch ports for a switch - `meraki_get_device_switch_ports_statuses` [read-only] — Return the status for all the ports of a switch - `meraki_get_device_switch_ports_statuses_packets` [read-only] — Return the packet counters for all the ports of a switch - `meraki_get_device_switch_routing_interface` [read-only] — Return a layer 3 interface for a switch - `meraki_get_device_switch_routing_interface_dhcp` [read-only] — Return a layer 3 interface DHCP configuration for a switch - `meraki_get_device_switch_routing_interfaces` [read-only] — List layer 3 interfaces for a switch. Those for a stack may be found under switch stack routing. - `meraki_get_device_switch_routing_static_route` [read-only] — Return a layer 3 static route for a switch - `meraki_get_device_switch_routing_static_routes` [read-only] — List layer 3 static routes for a switch - `meraki_get_device_switch_warm_spare` [read-only] — Return warm spare configuration for a switch - `meraki_get_device_wireless_bluetooth_settings` [read-only] — Return the bluetooth settings for a wireless device - `meraki_get_device_wireless_connection_stats` [read-only] — Aggregated connectivity info for a given AP on this network - `meraki_get_device_wireless_electronic_shelf_label` [read-only] — Return the ESL settings of a device - `meraki_get_device_wireless_latency_stats` [read-only] — Aggregated latency info for a given AP on this network - `meraki_get_device_wireless_radio_settings` [read-only] — Return the manually configured radio settings overrides of a device, which take precedence over RF profiles. - `meraki_get_device_wireless_status` [read-only] — Return the SSID statuses of an access point - `meraki_get_device_wireless_zigbee_enrollment` [read-only] — Return an enrollment - `meraki_get_network` [read-only] — Return a network - `meraki_get_network_alerts_history` [read-only] — Return the alert history for this network - `meraki_get_network_alerts_settings` [read-only] — Return the alert configuration for this network - `meraki_get_network_appliance_client_security_events` [read-only] — List the security events for a client. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_appliance_connectivity_monitoring_destinations` [read-only] — Return the connectivity testing destinations for an MX network - `meraki_get_network_appliance_content_filtering` [read-only] — Return the content filtering settings for an MX network - `meraki_get_network_appliance_content_filtering_categories` [read-only] — List all available content filtering categories for an MX network - `meraki_get_network_appliance_firewall_cellular_firewall_rules` [read-only] — Return the cellular firewall rules for an MX network - `meraki_get_network_appliance_firewall_firewalled_service` [read-only] — Return the accessibility settings of the given service ('ICMP', 'web', or 'SNMP') - `meraki_get_network_appliance_firewall_firewalled_services` [read-only] — List the appliance services and their accessibility rules - `meraki_get_network_appliance_firewall_inbound_cellular_firewall_rules` [read-only] — Return the inbound cellular firewall rules for an MX network - `meraki_get_network_appliance_firewall_inbound_firewall_rules` [read-only] — Return the inbound firewall rules for an MX network - `meraki_get_network_appliance_firewall_l3_firewall_rules` [read-only] — Return the L3 firewall rules for an MX network - `meraki_get_network_appliance_firewall_l7_firewall_rules` [read-only] — List the MX L7 firewall rules for an MX network - `meraki_get_network_appliance_firewall_l7_firewall_rules_application_categories` [read-only] — Return the L7 firewall application categories and their associated applications for an MX network - `meraki_get_network_appliance_firewall_one_to_many_nat_rules` [read-only] — Return the 1:Many NAT mapping rules for an MX network - `meraki_get_network_appliance_firewall_one_to_one_nat_rules` [read-only] — Return the 1:1 NAT mapping rules for an MX network - `meraki_get_network_appliance_firewall_port_forwarding_rules` [read-only] — Return the port forwarding rules for an MX network - `meraki_get_network_appliance_firewall_settings` [read-only] — Return the firewall settings for this network - `meraki_get_network_appliance_port` [read-only] — Return per-port VLAN settings for a single secure router or security appliance port. - `meraki_get_network_appliance_ports` [read-only] — List per-port VLAN settings for all ports of a secure router or security appliance. - `meraki_get_network_appliance_prefixes_delegated_static` [read-only] — Return a static delegated prefix from a network - `meraki_get_network_appliance_prefixes_delegated_statics` [read-only] — List static delegated prefixes for a network - `meraki_get_network_appliance_rf_profile` [read-only] — Return a RF profile - `meraki_get_network_appliance_rf_profiles` [read-only] — List the RF profiles for this network - `meraki_get_network_appliance_security_events` [read-only] — List the security events for a network - `meraki_get_network_appliance_security_intrusion` [read-only] — Returns all supported intrusion settings for an MX network - `meraki_get_network_appliance_security_malware` [read-only] — Returns all supported malware settings for an MX network - `meraki_get_network_appliance_settings` [read-only] — Return the appliance settings for a network - `meraki_get_network_appliance_single_lan` [read-only] — Return single LAN configuration - `meraki_get_network_appliance_ssid` [read-only] — Return a single MX SSID - `meraki_get_network_appliance_ssids` [read-only] — List the MX SSIDs in a network - `meraki_get_network_appliance_static_route` [read-only] — Return a static route for an MX or teleworker network - `meraki_get_network_appliance_static_routes` [read-only] — List the static routes for an MX or teleworker network - `meraki_get_network_appliance_traffic_shaping` [read-only] — Display the traffic shaping settings for an MX network - `meraki_get_network_appliance_traffic_shaping_custom_performance_class` [read-only] — Return a custom performance class for an MX network - `meraki_get_network_appliance_traffic_shaping_custom_performance_classes` [read-only] — List all custom performance classes for an MX network - `meraki_get_network_appliance_traffic_shaping_rules` [read-only] — Display the traffic shaping settings rules for an MX network - `meraki_get_network_appliance_traffic_shaping_uplink_bandwidth` [read-only] — Returns the uplink bandwidth limits for your MX network. This may not reflect the affected device's hardware capabilities. For more information on your device's hardware capabilities, please consult our MX Family Datasheet - [https://meraki.cisco.com/product-collateral/mx-family-datasheet/?file] - `meraki_get_network_appliance_traffic_shaping_uplink_selection` [read-only] — Show uplink selection settings for an MX network - `meraki_get_network_appliance_uplinks_usage_history` [read-only] — Get the sent and received bytes for each uplink of a network. - `meraki_get_network_appliance_vlan` [read-only] — Return a VLAN - `meraki_get_network_appliance_vlans` [read-only] — List the VLANs for a Security Appliance network - `meraki_get_network_appliance_vlans_settings` [read-only] — Returns the enabled status of VLANs for the network - `meraki_get_network_appliance_vpn_bgp` [read-only] — Return a Hub BGP Configuration - `meraki_get_network_appliance_vpn_site_to_site_vpn` [read-only] — Return the site-to-site VPN settings of a network. Only valid for MX networks. - `meraki_get_network_appliance_warm_spare` [read-only] — Return MX warm spare settings - `meraki_get_network_bluetooth_client` [read-only] — Return a Bluetooth client. Bluetooth clients can be identified by their ID or their MAC. - `meraki_get_network_bluetooth_clients` [read-only] — List the Bluetooth clients seen by APs in this network - `meraki_get_network_camera_quality_retention_profile` [read-only] — Retrieve a single quality retention profile - `meraki_get_network_camera_quality_retention_profiles` [read-only] — List the quality retention profiles for this network - `meraki_get_network_camera_schedules` [read-only] — Returns a list of all camera recording schedules. - `meraki_get_network_camera_wireless_profile` [read-only] — Retrieve a single camera wireless profile. - `meraki_get_network_camera_wireless_profiles` [read-only] — List the camera wireless profiles for this network. - `meraki_get_network_cellular_gateway_connectivity_monitoring_destinations` [read-only] — Return the connectivity testing destinations for an MG network - `meraki_get_network_cellular_gateway_dhcp` [read-only] — List common DHCP settings of MGs - `meraki_get_network_cellular_gateway_subnet_pool` [read-only] — Return the subnet pool and mask configured for MGs in the network. - `meraki_get_network_cellular_gateway_uplink` [read-only] — Returns the uplink settings for your MG network. - `meraki_get_network_client` [read-only] — Return the client associated with the given identifier. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_client_policy` [read-only] — Return the policy assigned to a client on the network. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_clients` [read-only] — List the clients that have used this network in the timespan. The data is updated at most once every five minutes. - `meraki_get_network_clients_application_usage` [read-only] — Return the application usage data for clients. Usage data is in kilobytes. Clients can be identified by client keys or either the MACs or IPs depending on whether the network uses Track-by-IP. - `meraki_get_network_clients_bandwidth_usage_history` [read-only] — Returns a timeseries of total traffic consumption rates for all clients on a network within a given timespan, in megabits per second. - `meraki_get_network_clients_overview` [read-only] — Return overview statistics for network clients - `meraki_get_network_client_splash_authorization_status` [read-only] — Return the splash authorization for a client, for each SSID they've associated with through splash. Only enabled SSIDs with Click-through splash enabled will be included. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_clients_usage_histories` [read-only] — Return the usage histories for clients. Usage data is in kilobytes. Clients can be identified by client keys or either the MACs or IPs depending on whether the network uses Track-by-IP. - `meraki_get_network_client_traffic_history` [read-only] — Return the client's network traffic data over time. Usage data is in kilobytes. This endpoint requires detailed traffic analysis to be enabled on the Network-wide > General page. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_client_usage_history` [read-only] — Return the client's daily usage history. Usage data is in kilobytes. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. - `meraki_get_network_events` [read-only] — List the events for the network - `meraki_get_network_events_event_types` [read-only] — List the event type to human-readable description - `meraki_get_network_firmware_upgrades` [read-only] — Get firmware upgrade information for a network - `meraki_get_network_firmware_upgrades_staged_events` [read-only] — Get the Staged Upgrade Event from a network - `meraki_get_network_firmware_upgrades_staged_group` [read-only] — Get a Staged Upgrade Group from a network - `meraki_get_network_firmware_upgrades_staged_groups` [read-only] — List of Staged Upgrade Groups in a network - `meraki_get_network_firmware_upgrades_staged_stages` [read-only] — Order of Staged Upgrade Groups in a network - `meraki_get_network_floor_plan` [read-only] — Find a floor plan by ID - `meraki_get_network_floor_plans` [read-only] — List the floor plans that belong to your network - `meraki_get_network_group_policies` [read-only] — List the group policies in a network - `meraki_get_network_group_policy` [read-only] — Display a group policy - `meraki_get_network_insight_application_health_by_time` [read-only] — Get application health by time - `meraki_get_network_meraki_auth_user` [read-only] — Return the Meraki Auth splash guest, RADIUS, or client VPN user - `meraki_get_network_meraki_auth_users` [read-only] — List the authorized users configured under Meraki Authentication for a network (splash guest or RADIUS users for a wireless network, or client VPN users for a MX network) - `meraki_get_network_moves` [read-only] — Return a list of network move operations in the organization - `meraki_get_network_mqtt_broker` [read-only] — Return an MQTT broker - `meraki_get_network_mqtt_brokers` [read-only] — List the MQTT brokers for this network - `meraki_get_network_netflow` [read-only] — Return the NetFlow traffic reporting settings for a network - `meraki_get_network_network_health_channel_utilization` [read-only] — Get the channel utilization over each radio for all APs in a network. - `meraki_get_network_pii_pii_keys` [read-only] — List the keys required to access Personally Identifiable Information (PII) for a given identifier. Exactly one identifier will be accepted. If the organization contains org-wide Systems Manager users matching the key provided then there will be an entry with the key "0" containing the applicable keys. ## ALTERNATE PATH ``` /organizations/{organizationId}/pii/piiKeys ``` - `meraki_get_network_pii_request` [read-only] — Return a PII request ## ALTERNATE PATH ``` /organizations/{organizationId}/pii/requests/{requestId} ``` - `meraki_get_network_pii_requests` [read-only] — List the PII requests for this network or organization ## ALTERNATE PATH ``` /organizations/{organizationId}/pii/requests ``` - `meraki_get_network_pii_sm_devices_for_key` [read-only] — Given a piece of Personally Identifiable Information (PII), return the Systems Manager device ID(s) associated with that identifier. These device IDs can be used with the Systems Manager API endpoints to retrieve device details. Exactly one identifier will be accepted. ## ALTERNATE PATH ``` /organizations/{organizationId}/pii/smDevicesForKey ``` - `meraki_get_network_pii_sm_owners_for_key` [read-only] — Given a piece of Personally Identifiable Information (PII), return the Systems Manager owner ID(s) associated with that identifier. These owner IDs can be used with the Systems Manager API endpoints to retrieve owner details. Exactly one identifier will be accepted. ## ALTERNATE PATH ``` /organizations/{organizationId}/pii/smOwnersForKey ``` - `meraki_get_network_policies_by_client` [read-only] — Get policies for all clients with policies - `meraki_get_network_sensor_alerts_current_overview_by_metric` [read-only] — Return an overview of currently alerting sensors by metric - `meraki_get_network_sensor_alerts_overview_by_metric` [read-only] — Return an overview of alert occurrences over a timespan, by metric - `meraki_get_network_sensor_alerts_profile` [read-only] — Show details of a sensor alert profile for a network. - `meraki_get_network_sensor_alerts_profiles` [read-only] — Lists all sensor alert profiles for a network. - `meraki_get_network_sensor_mqtt_broker` [read-only] — Return the sensor settings of an MQTT broker. To get the broker itself, use /networks/{networkId}/mqttBrokers/{mqttBrokerId}. - `meraki_get_network_sensor_mqtt_brokers` [read-only] — List the sensor settings of all MQTT brokers for this network. To get the brokers themselves, use /networks/{networkId}/mqttBrokers. - `meraki_get_network_sensor_relationships` [read-only] — List the sensor roles for devices in a given network - `meraki_get_network_settings` [read-only] — Return the settings for a network - `meraki_get_network_sm_bypass_activation_lock_attempt` [read-only] — Bypass activation lock attempt status - `meraki_get_network_sm_device_cellular_usage_history` [read-only] — Return the client's daily cellular data usage history. Usage data is in kilobytes. - `meraki_get_network_sm_device_certs` [read-only] — List the certs on a device - `meraki_get_network_sm_device_connectivity` [read-only] — Returns historical connectivity data (whether a device is regularly checking in to Dashboard). - `meraki_get_network_sm_device_desktop_logs` [read-only] — Return historical records of various Systems Manager network connection details for desktop devices. - `meraki_get_network_sm_device_device_command_logs` [read-only] — Return historical records of commands sent to Systems Manager devices. Note that this will include the name of the Dashboard user who initiated the command if it was generated by a Dashboard admin rather than the automatic behavior of the system; you may wish to filter this out of any reports. - `meraki_get_network_sm_device_device_profiles` [read-only] — Get the installed profiles associated with a device - `meraki_get_network_sm_device_network_adapters` [read-only] — List the network adapters of a device - `meraki_get_network_sm_device_performance_history` [read-only] — Return historical records of various Systems Manager client metrics for desktop devices. - `meraki_get_network_sm_device_restrictions` [read-only] — List the restrictions on a device - `meraki_get_network_sm_devices` [read-only] — List the devices enrolled in an SM network with various specified fields and filters - `meraki_get_network_sm_device_security_centers` [read-only] — List the security centers on a device - `meraki_get_network_sm_device_softwares` [read-only] — Get a list of softwares associated with a device - `meraki_get_network_sm_device_wlan_lists` [read-only] — List the saved SSID names on a device - `meraki_get_network_sm_profiles` [read-only] — List all profiles in a network - `meraki_get_network_sm_target_group` [read-only] — Return a target group - `meraki_get_network_sm_target_groups` [read-only] — List the target groups in this network - `meraki_get_network_sm_trusted_access_configs` [read-only] — List Trusted Access Configs - `meraki_get_network_sm_user_access_devices` [read-only] — List User Access Devices and its Trusted Access Connections - `meraki_get_network_sm_user_device_profiles` [read-only] — Get the profiles associated with a user - `meraki_get_network_sm_users` [read-only] — List the owners in an SM network with various specified fields and filters - `meraki_get_network_sm_user_softwares` [read-only] — Get a list of softwares associated with a user - `meraki_get_network_snmp` [read-only] — Return the SNMP settings for a network - `meraki_get_network_splash_login_attempts` [read-only] — List the splash login attempts for a network - `meraki_get_network_switch_access_control_lists` [read-only] — Return the access control lists for a MS network - `meraki_get_network_switch_access_policies` [read-only] — List the access policies for a switch network. Only returns access policies with 'my RADIUS server' as authentication method - `meraki_get_network_switch_access_policy` [read-only] — Return a specific access policy for a switch network - `meraki_get_network_switch_alternate_management_interface` [read-only] — Return the switch alternate management interface for the network - `meraki_get_network_switch_dhcp_server_policy` [read-only] — Return the DHCP server settings. Blocked/allowed servers are only applied when default policy is allow/block, respectively - `meraki_get_network_switch_dhcp_server_policy_arp_inspection_trusted_servers` [read-only] — Return the list of servers trusted by Dynamic ARP Inspection on this network. These are also known as allow listed snoop entries - `meraki_get_network_switch_dhcp_server_policy_arp_inspection_warnings_by_device` [read-only] — Return the devices that have a Dynamic ARP Inspection warning and their warnings - `meraki_get_network_switch_dhcp_v4_servers_seen` [read-only] — Return the network's DHCPv4 servers seen within the selected timeframe (default 1 day) - `meraki_get_network_switch_dscp_to_cos_mappings` [read-only] — Return the DSCP to CoS mappings - `meraki_get_network_switch_link_aggregations` [read-only] — List link aggregation groups - `meraki_get_network_switch_mtu` [read-only] — Return the MTU configuration - `meraki_get_network_switch_port_schedules` [read-only] — List switch port schedules - `meraki_get_network_switch_qos_rule` [read-only] — Return a quality of service rule - `meraki_get_network_switch_qos_rules` [read-only] — List quality of service rules - `meraki_get_network_switch_qos_rules_order` [read-only] — Return the quality of service rule IDs by order in which they will be processed by the switch - `meraki_get_network_switch_routing_multicast` [read-only] — Return multicast settings for a network - `meraki_get_network_switch_routing_multicast_rendezvous_point` [read-only] — Return a multicast rendezvous point - `meraki_get_network_switch_routing_multicast_rendezvous_points` [read-only] — List multicast rendezvous points - `meraki_get_network_switch_routing_ospf` [read-only] — Return layer 3 OSPF routing configuration - `meraki_get_network_switch_settings` [read-only] — Returns the switch network settings - `meraki_get_network_switch_stack` [read-only] — Show a switch stack - `meraki_get_network_switch_stack_routing_interface` [read-only] — Return a layer 3 interface from a switch stack - `meraki_get_network_switch_stack_routing_interface_dhcp` [read-only] — Return a layer 3 interface DHCP configuration for a switch stack - `meraki_get_network_switch_stack_routing_interfaces` [read-only] — List layer 3 interfaces for a switch stack - `meraki_get_network_switch_stack_routing_static_route` [read-only] — Return a layer 3 static route for a switch stack - `meraki_get_network_switch_stack_routing_static_routes` [read-only] — List layer 3 static routes for a switch stack - `meraki_get_network_switch_stacks` [read-only] — List the switch stacks in a network - `meraki_get_network_switch_storm_control` [read-only] — Return the storm control configuration for a switch network - `meraki_get_network_switch_stp` [read-only] — Returns STP settings - `meraki_get_network_syslog_servers` [read-only] — List the syslog servers for a network - `meraki_get_network_topology_link_layer` [read-only] — List the LLDP and CDP information for all discovered devices and connections in a network. At least one MX or MS device must be in the network in order to build the topology. - `meraki_get_network_traffic` [read-only] — Return the traffic analysis data for this network. Traffic analysis with hostname visibility must be enabled on the network. - `meraki_get_network_traffic_analysis` [read-only] — Return the traffic analysis settings for a network - `meraki_get_network_traffic_shaping_application_categories` [read-only] — Returns the application categories for traffic shaping rules. Only applicable on networks with a security applicance. - `meraki_get_network_traffic_shaping_dscp_tagging_options` [read-only] — Returns the available DSCP tagging options for your traffic shaping rules. - `meraki_get_network_vlan_profile` [read-only] — Get an existing VLAN profile of a network - `meraki_get_network_vlan_profiles` [read-only] — List VLAN profiles for a network - `meraki_get_network_vlan_profiles_assignments_by_device` [read-only] — Get the assigned VLAN Profiles for devices in a network - `meraki_get_network_webhooks_http_server` [read-only] — Return an HTTP server for a network - `meraki_get_network_webhooks_http_servers` [read-only] — List the HTTP servers for a network - `meraki_get_network_webhooks_payload_template` [read-only] — Get the webhook payload template for a network - `meraki_get_network_webhooks_payload_templates` [read-only] — List the webhook payload templates for a network - `meraki_get_network_webhooks_webhook_test` [read-only] — Return the status of a webhook test for a network - `meraki_get_network_wireless_air_marshal` [read-only] — List Air Marshal scan results from a network - `meraki_get_network_wireless_alternate_management_interface` [read-only] — Return alternate management interface and devices with IP assigned - `meraki_get_network_wireless_billing` [read-only] — Return the billing settings of this network - `meraki_get_network_wireless_bluetooth_settings` [read-only] — Return the Bluetooth settings for a network. Bluetooth settings must be enabled on the network. - `meraki_get_network_wireless_channel_utilization_history` [read-only] — Return AP channel utilization over time for a device or network client - `meraki_get_network_wireless_client_connection_stats` [read-only] — Aggregated connectivity info for a given client on this network. Clients are identified by their MAC. - `meraki_get_network_wireless_client_connectivity_events` [read-only] — List the wireless connectivity events for a client within a network in the timespan. - `meraki_get_network_wireless_client_count_history` [read-only] — Return wireless client counts over time for a network, device, or network client - `meraki_get_network_wireless_client_latency_history` [read-only] — Return the latency history for a client. Clients can be identified by a client key or either the MAC or IP depending on whether the network uses Track-by-IP. The latency data is from a sample of 2% of packets and is grouped into 4 traffic categories: background, best effort, video, voice. Within these categories the sampled packet counters are bucketed by latency in milliseconds. - `meraki_get_network_wireless_client_latency_stats` [read-only] — Aggregated latency info for a given client on this network. Clients are identified by their MAC. - `meraki_get_network_wireless_clients_connection_stats` [read-only] — Aggregated connectivity info for this network, grouped by clients - `meraki_get_network_wireless_clients_latency_stats` [read-only] — Aggregated latency info for this network, grouped by clients - `meraki_get_network_wireless_connection_stats` [read-only] — Aggregated connectivity info for this network - `meraki_get_network_wireless_data_rate_history` [read-only] — Return PHY data rates over time for a network, device, or network client - `meraki_get_network_wireless_devices_connection_stats` [read-only] — Aggregated connectivity info for this network, grouped by node - `meraki_get_network_wireless_devices_latency_stats` [read-only] — Aggregated latency info for this network, grouped by node - `meraki_get_network_wireless_electronic_shelf_label` [read-only] — Return the ESL settings of a wireless network - `meraki_get_network_wireless_electronic_shelf_label_configured_devices` [read-only] — Get a list of all ESL eligible devices of a network - `meraki_get_network_wireless_ethernet_ports_profile` [read-only] — Show the AP port profile by ID for this network - `meraki_get_network_wireless_ethernet_ports_profiles` [read-only] — List the AP port profiles for this network - `meraki_get_network_wireless_failed_connections` [read-only] — List of all failed client connection events on this network in a given time range - `meraki_get_network_wireless_latency_history` [read-only] — Return average wireless latency over time for a network, device, or network client - `meraki_get_network_wireless_latency_stats` [read-only] — Aggregated latency info for this network - `meraki_get_network_wireless_mesh_statuses` [read-only] — List wireless mesh statuses for repeaters - `meraki_get_network_wireless_rf_profile` [read-only] — Return a RF profile - `meraki_get_network_wireless_rf_profiles` [read-only] — List RF profiles for this network - `meraki_get_network_wireless_settings` [read-only] — Return the wireless settings for a network - `meraki_get_network_wireless_signal_quality_history` [read-only] — Return signal quality (SNR/RSSI) over time for a device or network client - `meraki_get_network_wireless_ssid` [read-only] — Return a single MR SSID - `meraki_get_network_wireless_ssid_bonjour_forwarding` [read-only] — List the Bonjour forwarding setting and rules for the SSID - `meraki_get_network_wireless_ssid_device_type_group_policies` [read-only] — List the device type group policies for the SSID - `meraki_get_network_wireless_ssid_eap_override` [read-only] — Return the EAP overridden parameters for an SSID - `meraki_get_network_wireless_ssid_firewall_l3_firewall_rules` [read-only] — Return the L3 firewall rules for an SSID on an MR network - `meraki_get_network_wireless_ssid_firewall_l7_firewall_rules` [read-only] — Return the L7 firewall rules for an SSID on an MR network - `meraki_get_network_wireless_ssid_hotspot20` [read-only] — Return the Hotspot 2.0 settings for an SSID - `meraki_get_network_wireless_ssid_identity_psk` [read-only] — Return an Identity PSK - `meraki_get_network_wireless_ssid_identity_psks` [read-only] — List all Identity PSKs in a wireless network - `meraki_get_network_wireless_ssids` [read-only] — List the MR SSIDs in a network - `meraki_get_network_wireless_ssid_schedules` [read-only] — List the outage schedule for the SSID - `meraki_get_network_wireless_ssid_splash_settings` [read-only] — Display the splash page settings for the given SSID - `meraki_get_network_wireless_ssid_traffic_shaping_rules` [read-only] — Display the traffic shaping settings for a SSID on an MR network - `meraki_get_network_wireless_ssid_vpn` [read-only] — List the VPN settings for the SSID. - `meraki_get_network_wireless_usage_history` [read-only] — Return AP usage over time for a device or network client - `meraki_get_organization` [read-only] — Return an organization - `meraki_get_organization_action_batch` [read-only] — Return an action batch - `meraki_get_organization_action_batches` [read-only] — Return the list of action batches in the organization - `meraki_get_organization_adaptive_policy_acl` [read-only] — Returns the adaptive policy ACL information - `meraki_get_organization_adaptive_policy_acls` [read-only] — List adaptive policy ACLs in a organization - `meraki_get_organization_adaptive_policy_group` [read-only] — Returns an adaptive policy group - `meraki_get_organization_adaptive_policy_groups` [read-only] — List adaptive policy groups in a organization - `meraki_get_organization_adaptive_policy_overview` [read-only] — Returns adaptive policy aggregate statistics for an organization - `meraki_get_organization_adaptive_policy_policies` [read-only] — List adaptive policies in an organization - `meraki_get_organization_adaptive_policy_policy` [read-only] — Return an adaptive policy - `meraki_get_organization_adaptive_policy_settings` [read-only] — Returns global adaptive policy settings in an organization - `meraki_get_organization_admins` [read-only] — List the dashboard administrators in this organization - `meraki_get_organization_alerts_profiles` [read-only] — List all organization-wide alert configurations - `meraki_get_organization_api_requests` [read-only] — List the API requests made by an organization - `meraki_get_organization_api_requests_overview` [read-only] — Return an aggregated overview of API requests data - `meraki_get_organization_api_requests_overview_response_codes_by_interval` [read-only] — Tracks organizations' API requests by response code across a given time period - `meraki_get_organization_api_rest_provisioning_pipelines_jobs` [read-only] — List pipeline jobs, with optional status filtering - `meraki_get_organization_api_rest_provisioning_pipelines_jobs_overviews_by_pipeline` [read-only] — Retrieves pipeline overviews with aggregated job status counts - `meraki_get_organization_appliance_devices_redundancy_by_network` [read-only] — Return MX warm spare settings - `meraki_get_organization_appliance_dns_local_profiles` [read-only] — Fetch the local DNS profiles used in the organization - `meraki_get_organization_appliance_dns_local_profiles_assignments` [read-only] — Fetch the local DNS profile assignments in the organization - `meraki_get_organization_appliance_dns_local_records` [read-only] — Fetch the DNS records used in local DNS profiles - `meraki_get_organization_appliance_dns_split_profiles` [read-only] — Fetch the split DNS profiles used in the organization - `meraki_get_organization_appliance_dns_split_profiles_assignments` [read-only] — Fetch the split DNS profile assignments in the organization - `meraki_get_organization_appliance_firewall_multicast_forwarding_by_network` [read-only] — List Static Multicasting forwarding settings for MX networks - `meraki_get_organization_appliance_routing_vrfs_settings` [read-only] — Return the VRF setting for an organization. - `meraki_get_organization_appliance_security_events` [read-only] — List the security events for an organization - `meraki_get_organization_appliance_security_intrusion` [read-only] — Returns all supported intrusion settings for an organization - `meraki_get_organization_appliance_traffic_shaping_vpn_exclusions_by_network` [read-only] — Display VPN exclusion rules for MX networks. - `meraki_get_organization_appliance_uplinks_nat_by_network` [read-only] — Fetch uplink NAT settings of each network in the organization - `meraki_get_organization_appliance_uplinks_statuses_overview` [read-only] — Returns an overview of uplink statuses - `meraki_get_organization_appliance_uplink_statuses` [read-only] — List the uplink status of every Meraki MX and Z series appliances in the organization - `meraki_get_organization_appliance_uplinks_usage_by_network` [read-only] — Get the sent and received bytes for each uplink of all MX and Z networks within an organization. If more than one device was active during the specified timespan, then the sent and received bytes will be aggregated by interface. - `meraki_get_organization_appliance_vpn_site_to_site_ipsec_peers_slas` [read-only] — Get the list of available IPsec SLA policies for an organization - `meraki_get_organization_appliance_vpn_stats` [read-only] — Show VPN history stat for networks in an organization - `meraki_get_organization_appliance_vpn_statuses` [read-only] — Show VPN status for networks in an organization - `meraki_get_organization_appliance_vpn_third_party_vpnpeers` [read-only] — Return the third party VPN peers for an organization - `meraki_get_organization_appliance_vpn_vpn_firewall_rules` [read-only] — Return the firewall rules for an organization's site-to-site VPN - `meraki_get_organization_assurance_alert` [read-only] — Return a singular Health Alert by its id - `meraki_get_organization_assurance_alerts` [read-only] — Return all health alerts for an organization - `meraki_get_organization_assurance_alerts_overview` [read-only] — Return overview of active health alerts for an organization - `meraki_get_organization_assurance_alerts_overview_by_network` [read-only] — Return a Summary of Alerts grouped by network and severity - `meraki_get_organization_assurance_alerts_overview_by_type` [read-only] — Return a Summary of Alerts grouped by type and severity - `meraki_get_organization_assurance_alerts_overview_historical` [read-only] — Returns historical health alert overviews - `meraki_get_organization_assurance_alerts_taxonomy_categories` [read-only] — Return a list of Category Types - `meraki_get_organization_assurance_alerts_taxonomy_types` [read-only] — Return a list of alert types - `meraki_get_organization_branding_policies` [read-only] — List the branding policies of an organization - `meraki_get_organization_branding_policies_priorities` [read-only] — Return the branding policy IDs of an organization in priority order. IDs are ordered in ascending order of priority (IDs later in the array have higher priority). - `meraki_get_organization_branding_policy` [read-only] — Return a branding policy - `meraki_get_organization_camera_boundaries_areas_by_device` [read-only] — Returns all configured area boundaries of cameras - `meraki_get_organization_camera_boundaries_lines_by_device` [read-only] — Returns all configured crossingline boundaries of cameras - `meraki_get_organization_camera_custom_analytics_artifact` [read-only] — Get Custom Analytics Artifact - `meraki_get_organization_camera_custom_analytics_artifacts` [read-only] — List Custom Analytics Artifacts - `meraki_get_organization_camera_detections_history_by_boundary_by_interval` [read-only] — Returns analytics data for timespans - `meraki_get_organization_camera_onboarding_statuses` [read-only] — Fetch onboarding status of cameras - `meraki_get_organization_camera_permission` [read-only] — Retrieve a single permission scope - `meraki_get_organization_camera_permissions` [read-only] — List the permissions scopes for this organization - `meraki_get_organization_camera_role` [read-only] — Retrieve a single role. - `meraki_get_organization_camera_roles` [read-only] — List all the roles in this organization - `meraki_get_organization_campus_gateway_clusters` [read-only] — Get the details of campus gateway clusters - `meraki_get_organization_campus_gateway_devices_uplinks_local_overrides_by_device` [read-only] — Uplink overrides configured locally on Campus Gateway devices in an organization. - `meraki_get_organization_cellular_gateway_esims_inventory` [read-only] — The eSIM inventory of a given organization. - `meraki_get_organization_cellular_gateway_esims_service_providers` [read-only] — Service providers customers can add accounts for. - `meraki_get_organization_cellular_gateway_esims_service_providers_accounts` [read-only] — Inventory of service provider accounts tied to the organization. - `meraki_get_organization_cellular_gateway_esims_service_providers_accounts_communication_plans` [read-only] — The communication plans available for a given provider. - `meraki_get_organization_cellular_gateway_esims_service_providers_accounts_rate_plans` [read-only] — The rate plans available for a given provider. - `meraki_get_organization_cellular_gateway_uplink_statuses` [read-only] — List the uplink status of every Meraki MG cellular gateway in the organization - `meraki_get_organization_clients_bandwidth_usage_history` [read-only] — Return data usage (in megabits per second) over time for all clients in the given organization within a given time range. - `meraki_get_organization_clients_overview` [read-only] — Return summary information around client data usage (in kb) across the given organization. - `meraki_get_organization_clients_search` [read-only] — Return the client details in an organization - `meraki_get_organization_config_template` [read-only] — Return a single configuration template - `meraki_get_organization_config_templates` [read-only] — List the configuration templates for this organization - `meraki_get_organization_config_template_switch_profile_port` [read-only] — Return a switch template port - `meraki_get_organization_config_template_switch_profile_ports` [read-only] — Return all the ports of a switch template - `meraki_get_organization_config_template_switch_profiles` [read-only] — List the switch templates for your switch template configuration - `meraki_get_organization_configuration_changes` [read-only] — View the Change Log for your organization - `meraki_get_organization_devices` [read-only] — List the devices in an organization that have been assigned to a network. - `meraki_get_organization_devices_availabilities` [read-only] — List the availability information for devices in an organization. The data returned by this endpoint is updated every 5 minutes. - `meraki_get_organization_devices_availabilities_change_history` [read-only] — List the availability history information for devices in an organization. - `meraki_get_organization_devices_cellular_data_devices` [read-only] — List devices eligible for Cellular Data Management profile assignment in this organization. Returns paginated device assignment candidates with current profile, software version, modem, and SIM details. Supports filtering by device serials, profile IDs, device types, and supported SIM slots. - `meraki_get_organization_devices_cellular_data_profiles` [read-only] — List cellular data management profiles in this organization. Returns each configured cellular data management profile in this organization, including its rules and assigned-device summary counts. Supports filtering by `profileIds` and `serials` and uses cursor pagination. - `meraki_get_organization_devices_cellular_data_profiles_assignments` [read-only] — List Cellular Data Management Profile assignments in this organization. Returns paginated device-to-profile assignments and supports filtering by profile IDs and device serials. - `meraki_get_organization_devices_cellular_data_usage_by_device` [read-only] — List current cellular data usage for devices in this organization. Returns a paginated per-device view of current SIM usage in each device's current usage period (as set by the device's configuration). Supports filtering by device serials. - `meraki_get_organization_devices_cellular_data_usage_history_by_device_by_interval` [read-only] — List historical cellular data usage grouped by device and interval in this organization. Returns a paginated per-device time series with per-SIM totals and supports the standard t0, t1, timespan, and interval query parameters. - `meraki_get_organization_devices_cellular_geolocations` [read-only] — List the latest cellular geolocation telemetry for devices in an organization. Data is refreshed at most once every 90 minutes. - `meraki_get_organization_devices_cellular_uplinks_bands_by_device` [read-only] — List the latest cellular uplink signal information for devices in an organization. Data is refreshed at most once every 90 minutes. - `meraki_get_organization_devices_cellular_uplinks_towers_by_device` [read-only] — List the latest cellular tower information for devices in an organization. Data is refreshed at most once every 90 minutes. - `meraki_get_organization_devices_controller_migrations` [read-only] — Retrieve device migration statuses in an organization - `meraki_get_organization_devices_overview_by_model` [read-only] — Lists the count for each device model - `meraki_get_organization_devices_packet_capture_captures` [read-only] — List Packet Captures. The current license level allows storage of up to 10 capture files in the cloud. When this limit is reached and a new capture is taken, the oldest capture will be automatically deleted to ensure sufficient space. Additional storage for switches will be available with an advantage license at a future date. These future capabilities will be consistent with what is available today via advantage licensing for access points. - `meraki_get_organization_devices_packet_capture_schedules` [read-only] — List the Packet Capture Schedules - `meraki_get_organization_devices_power_modules_statuses_by_device` [read-only] — List the most recent status information for power modules in rackmount MX and MS devices that support them. The data returned by this endpoint is updated every 5 minutes. - `meraki_get_organization_devices_provisioning_statuses` [read-only] — List the provisioning statuses information for devices in an organization. - `meraki_get_organization_devices_statuses_overview` [read-only] — Return an overview of current device statuses - `meraki_get_organization_devices_system_memory_usage_history_by_interval` [read-only] — Return the memory utilization history in kB for devices in the organization. - `meraki_get_organization_devices_uplinks_addresses_by_device` [read-only] — List the current uplink addresses for devices in an organization. - `meraki_get_organization_devices_uplinks_loss_and_latency` [read-only] — Return the uplink loss and latency for every MX in the organization from at latest 2 minutes ago - `meraki_get_organization_early_access_features` [read-only] — List the available early access features for organization - `meraki_get_organization_early_access_features_opt_in` [read-only] — Show an early access feature opt-in for an organization - `meraki_get_organization_early_access_features_opt_ins` [read-only] — List the early access feature opt-ins for an organization - `meraki_get_organization_firmware_upgrades` [read-only] — Get firmware upgrade information for an organization - `meraki_get_organization_firmware_upgrades_by_device` [read-only] — Get firmware upgrade status for the filtered devices. This endpoint currently only supports Meraki switches and access points. - `meraki_get_organization_floor_plans_auto_locate_devices` [read-only] — List auto locate details for each device in your organization - `meraki_get_organization_floor_plans_auto_locate_statuses` [read-only] — List the status of auto locate for each floorplan in your organization - `meraki_get_organization_insight_applications` [read-only] — List all Insight tracked applications - `meraki_get_organization_insight_monitored_media_server` [read-only] — Return a monitored media server for this organization. Only valid for organizations with Meraki Insight. - `meraki_get_organization_insight_monitored_media_servers` [read-only] — List the monitored media servers for this organization. Only valid for organizations with Meraki Insight. - `meraki_get_organization_integrations_deployable` [read-only] — Provides a list of integrations that can be enabled for an Organization. - `meraki_get_organization_integrations_deployed` [read-only] — Provides a list of integrations enabled for an Organization. - `meraki_get_organization_integrations_xdr_networks` [read-only] — Returns the networks in the organization that have XDR enabled - `meraki_get_organization_inventory_device` [read-only] — Return a single device from the inventory of an organization - `meraki_get_organization_inventory_devices` [read-only] — Return the device inventory for an organization - `meraki_get_organization_inventory_devices_eox_overview` [read-only] — Fetch the EOX summary for an organization, including counts of devices that are end-of-sale, end-of-support, and end-of-support-soon. - `meraki_get_organization_inventory_devices_swaps_bulk` [read-only] — List of device swaps for a given request ID ({id}). - `meraki_get_organization_license` [read-only] — Display a license - `meraki_get_organization_licenses` [read-only] — List the licenses for an organization - `meraki_get_organization_licenses_overview` [read-only] — Return an overview of the license state for an organization - `meraki_get_organization_licensing_coterm_licenses` [read-only] — List the licenses in a coterm organization - `meraki_get_organization_login_security` [read-only] — Returns the login security settings for an organization. - `meraki_get_organization_networks` [read-only] — List the networks that the user has privileges on in an organization - `meraki_get_organization_openapi_spec` [read-only] — Return the OpenAPI Specification of the organization's API documentation in JSON - `meraki_get_organization_policies_assignments_by_client` [read-only] — Get policies for all clients with policies - `meraki_get_organization_policies_global_firewall_application_categories` [read-only] — List application categories with their associated applications - `meraki_get_organization_policies_global_firewall_rulesets` [read-only] — List Organization-Wide Policy Firewall Rulesets - `meraki_get_organization_policies_global_firewall_rulesets_rules` [read-only] — List Organization-Wide Policy Firewall Rules - `meraki_get_organization_policies_global_group_policies` [read-only] — List Organization-Wide Policies - `meraki_get_organization_policies_global_group_policies_adaptive_policy_groups_assignments` [read-only] — List adaptive policy group assignments - `meraki_get_organization_policies_global_group_policies_appliance_vlans_assignments` [read-only] — List appliance VLAN policy assignments - `meraki_get_organization_policies_global_group_policies_appliance_vlans_assignments_by_vlan` [read-only] — List policies by appliance VLANs - `meraki_get_organization_policies_global_group_policies_firewall_rulesets_assignments` [read-only] — List Organization-Wide Policy Ruleset Assignments - `meraki_get_organization_policy_object` [read-only] — Shows details of a Policy Object. - `meraki_get_organization_policy_objects` [read-only] — Lists Policy Objects belonging to the organization. - `meraki_get_organization_policy_objects_group` [read-only] — Shows details of a Policy Object Group. - `meraki_get_organization_policy_objects_groups` [read-only] — Lists Policy Object Groups belonging to the organization. - `meraki_get_organizations` [read-only] — List the organizations that the user has privileges on - `meraki_get_organization_saml` [read-only] — Returns the SAML SSO enabled settings for an organization. - `meraki_get_organization_saml_idp` [read-only] — Get a SAML IdP from your organization. - `meraki_get_organization_saml_idps` [read-only] — List the SAML IdPs in your organization. - `meraki_get_organization_saml_role` [read-only] — Return a SAML role - `meraki_get_organization_saml_roles` [read-only] — List the SAML roles for this organization - `meraki_get_organization_sase_connectors` [read-only] — List SSE Connectors for an organization - `meraki_get_organization_sase_integration` [read-only] — Get details of a Secure Access integration - `meraki_get_organization_sase_networks_eligible` [read-only] — List of MX networks or templates that can be enrolled into Secure Access - `meraki_get_organization_sase_regions` [read-only] — List regions - `meraki_get_organization_sase_sites` [read-only] — List of enrolled SASE sites in this organization - `meraki_get_organization_sase_sites_connectivity_history_by_site` [read-only] — Get the connectivity history of SASE sites in this organization - `meraki_get_organization_sase_sites_connectivity_overview` [read-only] — List high-level SASE site statuses (healthy, degraded, offline) - `meraki_get_organization_sensor_gateways_connections_latest` [read-only] — Returns latest sensor-gateway connectivity data. - `meraki_get_organization_sensor_readings_history` [read-only] — Return all reported readings from sensors in a given timespan, sorted by timestamp - `meraki_get_organization_sensor_readings_latest` [read-only] — Return the latest available reading for each metric from each sensor, sorted by sensor serial - `meraki_get_organization_sm_admins_role` [read-only] — Return a Limited Access Role - `meraki_get_organization_sm_admins_roles` [read-only] — List the Limited Access Roles for an organization - `meraki_get_organization_sm_apns_cert` [read-only] — Get the organization's APNS certificate - `meraki_get_organization_sm_sentry_policies_assignments_by_network` [read-only] — List the Sentry Policies for an organization ordered in ascending order of priority - `meraki_get_organization_sm_vpp_account` [read-only] — Get a hash containing the unparsed token of the VPP account with the given ID - `meraki_get_organization_sm_vpp_accounts` [read-only] — List the VPP accounts in the organization - `meraki_get_organization_snmp` [read-only] — Return the SNMP settings for an organization - `meraki_get_organization_spaces_integrate_status` [read-only] — Get the status of the Spaces integration in Meraki - `meraki_get_organization_splash_asset` [read-only] — Get a Splash Theme Asset - `meraki_get_organization_splash_themes` [read-only] — List Splash Themes - `meraki_get_organization_summary_switch_power_history` [read-only] — Returns the total PoE power draw for all switch ports in the organization over the requested timespan (by default the last 24 hours). The returned array is a newest-first list of intervals. The time between intervals depends on the requested timespan with 20 minute intervals used for timespans up to 1 day, 4 hour intervals used for timespans up to 2 weeks, and 1 day intervals for timespans larger than 2 weeks. - `meraki_get_organization_summary_top_appliances_by_utilization` [read-only] — Return the top 10 appliances sorted by utilization over given time range. - `meraki_get_organization_summary_top_applications_by_usage` [read-only] — Return the top applications sorted by data usage over given time range. Default unit is megabytes. - `meraki_get_organization_summary_top_applications_categories_by_usage` [read-only] — Return the top application categories sorted by data usage over given time range. Default unit is megabytes. - `meraki_get_organization_summary_top_clients_by_usage` [read-only] — Return metrics for organization's top 10 clients by data usage (in mb) over given time range. - `meraki_get_organization_summary_top_clients_manufacturers_by_usage` [read-only] — Return metrics for organization's top clients by data usage (in mb) over given time range, grouped by manufacturer. - `meraki_get_organization_summary_top_devices_by_usage` [read-only] — Return metrics for organization's top 10 devices sorted by data usage over given time range. Default unit is megabytes. - `meraki_get_organization_summary_top_devices_models_by_usage` [read-only] — Return metrics for organization's top 10 device models sorted by data usage over given time range. Default unit is megabytes. - `meraki_get_organization_summary_top_networks_by_status` [read-only] — List the client and status overview information for the networks in an organization. Usage is measured in kilobytes and from the last seven days. - `meraki_get_organization_summary_top_ssids_by_usage` [read-only] — Return metrics for organization's top 10 ssids by data usage over given time range. Default unit is megabytes. - `meraki_get_organization_summary_top_switches_by_energy_usage` [read-only] — Return metrics for organization's top 10 switches by energy usage over given time range. Default unit is joules. - `meraki_get_organization_switch_ports_by_switch` [read-only] — List the switchports in an organization by switch - `meraki_get_organization_switch_ports_clients_overview_by_device` [read-only] — List the number of clients for all switchports with at least one online client in an organization. - `meraki_get_organization_switch_ports_overview` [read-only] — Returns the counts of all active ports for the requested timespan, grouped by speed. An active port is a port that at any point during the timeframe is observed to be connected to a responsive device and isn't configured to be disabled. For a port that is observed at multiple speeds during the timeframe, it will be counted at the highest speed observed. The number of inactive ports, and the total number of ports are also provided. Only ports on switches online during the timeframe will be repres - `meraki_get_organization_switch_ports_statuses_by_switch` [read-only] — List the switchports in an organization - `meraki_get_organization_switch_ports_topology_discovery_by_device` [read-only] — List most recently seen LLDP/CDP discovery and topology information per switch port in an organization. - `meraki_get_organization_switch_ports_usage_history_by_device_by_interval` [read-only] — List the historical usage and traffic data of switchports in an organization. - `meraki_get_organization_uplinks_statuses` [read-only] — List the uplink status of every Meraki MX, MG and Z series devices in the organization - `meraki_get_organization_webhooks_alert_types` [read-only] — Return a list of alert types to be used with managing webhook alerts - `meraki_get_organization_webhooks_callbacks_status` [read-only] — Return the status of an API callback - `meraki_get_organization_webhooks_logs` [read-only] — Return the log of webhook POSTs sent - `meraki_get_organization_wireless_air_marshal_rules` [read-only] — Returns the current Air Marshal rules for this organization - `meraki_get_organization_wireless_air_marshal_settings_by_network` [read-only] — Returns the current Air Marshal settings for this network - `meraki_get_organization_wireless_clients_overview_by_device` [read-only] — List access point client count at the moment in an organization - `meraki_get_organization_wireless_controller_availabilities_change_history` [read-only] — List connectivity data of wireless LAN controllers in an organization. If it is HA setup, then only returns active WLC data start from switchover - `meraki_get_organization_wireless_controller_clients_overview_history_by_device_by_interval` [read-only] — List wireless client counts of wireless LAN controllers over time in an organization - `meraki_get_organization_wireless_controller_connections` [read-only] — List all access points associated with wireless LAN controllers in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l2_by_device` [read-only] — List wireless LAN controller layer 2 interfaces in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l2_statuses_change_history_by_device` [read-only] — List wireless LAN controller layer 2 interfaces history status in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l2_usage_history_by_interval` [read-only] — List wireless LAN controller layer 2 interfaces history usage in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l3_by_device` [read-only] — List wireless LAN controller layer 3 interfaces in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l3_statuses_change_history_by_device` [read-only] — List wireless LAN controller layer 3 interfaces history status in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_l3_usage_history_by_interval` [read-only] — List wireless LAN controller layer 3 interfaces history usage in an organization - `meraki_get_organization_wireless_controller_devices_interfaces_packets_overview_by_device` [read-only] — Retrieve the packet counters for the interfaces of a Wireless LAN controller - `meraki_get_organization_wireless_controller_devices_interfaces_usage_history_by_interval` [read-only] — Retrieve the traffic for the interfaces of a Wireless LAN controller - `meraki_get_organization_wireless_controller_devices_redundancy_failover_history` [read-only] — List the failover events of wireless LAN controllers in an organization - `meraki_get_organization_wireless_controller_devices_redundancy_statuses` [read-only] — List redundancy details of wireless LAN controllers in an organization. The failover count refers to the total failovers system happens from the moment of this device onboarding to Dashboard - `meraki_get_organization_wireless_controller_devices_system_utilization_history_by_interval` [read-only] — List cpu utilization data of wireless LAN controllers in an organization - `meraki_get_organization_wireless_controller_overview_by_device` [read-only] — List the overview information of wireless LAN controllers in an organization and it is updated every minute. - `meraki_get_organization_wireless_devices_channel_utilization_by_device` [read-only] — Get average channel utilization for all bands in a network, split by AP - `meraki_get_organization_wireless_devices_channel_utilization_by_network` [read-only] — Get average channel utilization across all bands for all networks in the organization - `meraki_get_organization_wireless_devices_channel_utilization_history_by_device_by_interval` [read-only] — Get a time-series of average channel utilization for all bands, segmented by device. - `meraki_get_organization_wireless_devices_channel_utilization_history_by_network_by_interval` [read-only] — Get a time-series of average channel utilization for all bands - `meraki_get_organization_wireless_devices_ethernet_statuses` [read-only] — List the most recent Ethernet link speed, duplex, aggregation and power mode and status information for wireless devices. - `meraki_get_organization_wireless_devices_packet_loss_by_client` [read-only] — Get average packet loss for the given timespan for all clients in the organization. - `meraki_get_organization_wireless_devices_packet_loss_by_device` [read-only] — Get average packet loss for the given timespan for all devices in the organization. Does not include device's own traffic. - `meraki_get_organization_wireless_devices_packet_loss_by_network` [read-only] — Get average packet loss for the given timespan for all networks in the organization. - `meraki_get_organization_wireless_devices_power_mode_history` [read-only] — Return a record of power mode changes for wireless devices in the organization. For each device, it provides a series of events with timestamps indicating when a power mode change occurred and the new mode. The events are ordered by timestamp. - `meraki_get_organization_wireless_devices_provisioning_deployments` [read-only] — List the zero touch deployments for wireless access points in an organization - `meraki_get_organization_wireless_devices_radsec_certificates_authorities` [read-only] — Query for details on the organization's RADSEC device Certificate Authority certificates (CAs). The primary CA signs all the certificates that devices present when establishing a secure connection to RADIUS servers via RADSEC protocol. This API returns an array of the status of all of the CAs as well as their contents, if they've been generated. An organization will have at most one CA unless the CA is being rotated. - `meraki_get_organization_wireless_devices_radsec_certificates_authorities_crls` [read-only] — Query for certificate revocation list (CRL) for the organization's RADSEC device Certificate Authorities (CAs). - `meraki_get_organization_wireless_devices_radsec_certificates_authorities_crls_deltas` [read-only] — Query for all delta certificate revocation list (CRL) for the organization's RADSEC device Certificate Authority (CA) with the given id. - `meraki_get_organization_wireless_devices_system_cpu_load_history` [read-only] — Return the CPU Load history for a list of wireless devices in the organization. - `meraki_get_organization_wireless_devices_wireless_controllers_by_device` [read-only] — List of Catalyst access points information - `meraki_get_organization_wireless_location_scanning_by_network` [read-only] — Return scanning API settings - `meraki_get_organization_wireless_location_scanning_receivers` [read-only] — Return scanning API receivers - `meraki_get_organization_wireless_mqtt_settings` [read-only] — Return MQTT Settings for networks - `meraki_get_organization_wireless_radio_rrm_by_network` [read-only] — List the AutoRF settings of an organization by network - `meraki_get_organization_wireless_rf_profiles_assignments_by_device` [read-only] — List the RF profiles of an organization by device - `meraki_get_organization_wireless_ssids_firewall_isolation_allowlist_entries` [read-only] — List the L2 isolation allow list MAC entry in an organization - `meraki_get_organization_wireless_ssids_open_roaming_by_network` [read-only] — Returns an array of objects, each containing SSID OpenRoaming configs for the corresponding network - `meraki_get_organization_wireless_ssids_statuses_by_device` [read-only] — List status information of all BSSIDs in your organization - `meraki_get_organization_wireless_zigbee_by_network` [read-only] — Return list of Zigbee configs - `meraki_get_organization_wireless_zigbee_devices` [read-only] — List the Zigbee wireless devices for an organization or the supplied network(s) - `meraki_get_organization_wireless_zigbee_disenrollment` [read-only] — Return a disenrollment - `meraki_get_organization_wireless_zigbee_door_locks` [read-only] — Return the list of door locks for a network ## DigitalOcean Droplets, VPCs/firewalls/load balancers/DNS, managed databases, and Kubernetes (DOKS). 339 tools: 152 read-only, 187 write. - `digitalocean_account_get_information` [read-only] — Retrieve account information for the current user. - `digitalocean_action_get` [read-only] — Get a specific action by ID. - `digitalocean_action_list` [read-only] — List actions with pagination. - `digitalocean_alert_policy_create` [write, off by default] — Create a new Alert Policy. - `digitalocean_alert_policy_delete` [write, off by default] — Delete an Alert Policy permanently. - `digitalocean_alert_policy_get` [read-only] — Get Alert Policy information by UUID. - `digitalocean_alert_policy_list` [read-only] — List all Alert Policies in your account with pagination. - `digitalocean_alert_policy_update` [write, off by default] — Update an Alert Policy. - `digitalocean_apps_create_app_from_spec` [write, off by default] — Creates an application from a given app spec. Within the app spec, a source has to be provided -- a Git repository, a Dockerfile, or a container image. - `digitalocean_apps_delete` [write, destructive, off by default] — Delete an existing app on DigitalOcean App Platform. This is a destructive operation and cannot be undone. - `digitalocean_apps_get_deployment_status` [read-only] — Retrieves the active deployment for an application on DigitalOcean App Platform. Useful for getting the current state of an app's latest deployment and its health status. - `digitalocean_apps_get_info` [read-only] — Get information about an application on DigitalOcean App Platform. - `digitalocean_apps_get_logs` [read-only] — Retrieves app logs for a specific app deployment and component on DigitalOcean App Platform. Returns both live and historic log URLs. - `digitalocean_apps_list` [read-only] — List all applications on DigitalOcean App Platform. Supports pagination -- use digitalocean_apps_get_info for full detail on a specific app. - `digitalocean_apps_update` [write, off by default] — Updates an existing application on DigitalOcean App Platform. Provide app_id and spec to deploy a new spec; omit spec to just trigger a fresh deployment (forced rebuild) of the app's current spec. - `digitalocean_balance_get` [read-only] — Get balance information for the user account. - `digitalocean_billing_history_list` [read-only] — List billing history with pagination. - `digitalocean_byoip_prefix_create` [write, off by default] — Create a new BYOIP prefix. - `digitalocean_byoip_prefix_delete` [write, destructive, off by default] — Delete a BYOIP prefix. This is irreversible. - `digitalocean_byoip_prefix_get` [read-only] — Get BYOIP prefix information by UUID. - `digitalocean_byoip_prefix_list` [read-only] — List BYOIP prefixes. - `digitalocean_byoip_prefix_resources_get` [read-only] — Get all resources for a BYOIP prefix. - `digitalocean_certificate_delete` [write, destructive, off by default] — Permanently delete a certificate. This cannot be undone and breaks TLS termination for anything still using it. - `digitalocean_certificate_get` [read-only] — Get certificate information by ID. - `digitalocean_certificate_list` [read-only] — List certificates with pagination. - `digitalocean_change_kernel_droplet` [write, off by default] — Change a droplet's kernel. - `digitalocean_custom_certificate_create` [write, off by default] — Upload a new custom TLS certificate from a private key, leaf certificate, and certificate chain. - `digitalocean_db_cluster_create` [write, off by default] — Create a new database cluster. - `digitalocean_db_cluster_create_topic` [write, off by default] — Create a topic for a Kafka cluster. - `digitalocean_db_cluster_create_user` [write, off by default] — Create a new database user for a cluster. - `digitalocean_db_cluster_delete` [write, destructive, off by default] — Delete a database cluster by its id. There is no way to recover a cluster once destroyed. - `digitalocean_db_cluster_delete_topic` [write, off by default] — Delete a Kafka topic by name. - `digitalocean_db_cluster_delete_user` [write, off by default] — Delete a database user from a cluster. - `digitalocean_db_cluster_get` [read-only] — Get a database cluster by its id. - `digitalocean_db_cluster_get_ca` [read-only] — Get the CA certificate for a cluster by its id. - `digitalocean_db_cluster_get_firewall_rules` [read-only] — Get firewall rules (inbound sources) for a database cluster. - `digitalocean_db_cluster_get_kafka_config` [read-only] — Get the Kafka broker config for a cluster. - `digitalocean_db_cluster_get_migration` [read-only] — Get the online migration status for a database cluster by its id. - `digitalocean_db_cluster_get_mongodb_config` [read-only] — Get the MongoDB config for a cluster by its id. - `digitalocean_db_cluster_get_mysql_config` [read-only] — Get the MySQL config for a cluster by its id. - `digitalocean_db_cluster_get_opensearch_config` [read-only] — Get the OpenSearch config for a cluster by its id. - `digitalocean_db_cluster_get_postgresql_config` [read-only] — Get the PostgreSQL config for a cluster by its id. - `digitalocean_db_cluster_get_redis_config` [read-only] — Get the Redis config for a cluster by its id. - `digitalocean_db_cluster_get_sql_mode` [read-only] — Get the SQL mode for a MySQL cluster by its id. - `digitalocean_db_cluster_get_topic` [read-only] — Get a Kafka topic by name. - `digitalocean_db_cluster_get_user` [read-only] — Get a database user by cluster id and user name. - `digitalocean_db_cluster_list` [read-only] — List all database clusters on this account. - `digitalocean_db_cluster_list_backups` [read-only] — List backups for a database cluster by its id. - `digitalocean_db_cluster_list_options` [read-only] — List available database options (engines, versions, sizes, regions, etc) for DigitalOcean managed databases. - `digitalocean_db_cluster_list_topics` [read-only] — List topics for a Kafka cluster by its id. - `digitalocean_db_cluster_list_users` [read-only] — List database users for a cluster. - `digitalocean_db_cluster_resize` [write, off by default] — Resize a database cluster by its id. At least one of size, num_nodes, or storage_size_mib must be provided. - `digitalocean_db_cluster_set_sql_mode` [write, off by default] — Set the SQL mode for a MySQL cluster by its id. Replaces the full set of modes. - `digitalocean_db_cluster_start_online_migration` [write, off by default] — Start an online migration for a database cluster by its id, streaming data in from an external source database. - `digitalocean_db_cluster_stop_online_migration` [write, off by default] — Stop an online migration for a database cluster by its id and migration_id. - `digitalocean_db_cluster_update_firewall_rules` [write, off by default] — Replace the firewall rules for a cluster with the given list. This is a full replace, not a merge. - `digitalocean_db_cluster_update_kafka_config` [write, off by default] — Update the Kafka broker config for a cluster. - `digitalocean_db_cluster_update_mongodb_config` [write, off by default] — Update the MongoDB config for a cluster by its id. - `digitalocean_db_cluster_update_mysql_config` [write, off by default] — Update the MySQL config for a cluster by its id. - `digitalocean_db_cluster_update_os_config` [write, off by default] — Update the OpenSearch config for a cluster by its id. - `digitalocean_db_cluster_update_psql_config` [write, off by default] — Update the PostgreSQL config for a cluster by its id. - `digitalocean_db_cluster_update_redis_config` [write, off by default] — Update the Redis config for a cluster by its id. - `digitalocean_db_cluster_update_topic` [write, off by default] — Update a Kafka topic's partition count, replication factor, or config. - `digitalocean_db_cluster_update_user` [write, off by default] — Update a database user's settings. - `digitalocean_db_cluster_upgrade_major_version` [write, destructive, off by default] — Upgrade the major version of a database cluster by its id. Requires the target version. This cannot be undone. - `digitalocean_dedicated_inference_create` [write, destructive, off by default] — Create a new Dedicated Inference instance. This provisions dedicated GPU capacity and incurs ongoing DigitalOcean spend for as long as it exists. Returns the instance and, if applicable, an initial auth token. - `digitalocean_dedicated_inference_delete` [write, destructive, off by default] — Delete a Dedicated Inference instance. This cannot be undone. - `digitalocean_dedicated_inference_get` [read-only] — Get details of a Dedicated Inference instance by ID. - `digitalocean_dedicated_inference_list` [read-only] — List Dedicated Inference instances with optional region/name filters and pagination. - `digitalocean_dedicated_inference_update` [write, off by default] — Update a Dedicated Inference instance. model_deployments must be provided and non-empty (DigitalOcean's own MCP server enforces this even though the underlying API schema allows omitting it). - `digitalocean_disable_backups_droplet` [write, off by default] — Disable backups on a droplet. - `digitalocean_disable_backups_droplets_tag` [write, off by default] — Disable backups on droplets by tag. - `digitalocean_docr_create` [write, off by default] — Create a new container registry. DigitalOcean accounts are limited to one registry. - `digitalocean_docr_delete` [write, destructive, off by default] — Delete a container registry. There is no way to recover it once deleted. - `digitalocean_docr_docker_credentials` [read-only] — Get Docker credentials for a container registry, as a Docker config.json payload. - `digitalocean_docr_garbage_collection_get` [read-only] — Get the active garbage collection for a container registry. - `digitalocean_docr_garbage_collection_list` [read-only] — List garbage collections for a container registry. - `digitalocean_docr_garbage_collection_start` [write, destructive, off by default] — Start a garbage collection for a container registry to free up storage. - `digitalocean_docr_garbage_collection_update` [write, off by default] — Update a garbage collection for a container registry, e.g. to cancel it. - `digitalocean_docr_get` [read-only] — Get a container registry by name. - `digitalocean_docr_list` [read-only] — List all container registries. - `digitalocean_docr_options` [read-only] — Get available container registry options, including subscription tiers and regions. - `digitalocean_docr_repository_list` [read-only] — List repositories in a container registry. - `digitalocean_docr_repository_manifest_delete` [write, destructive, off by default] — Delete a manifest from a repository in a container registry. - `digitalocean_docr_repository_manifest_list` [read-only] — List manifests for a repository in a container registry. - `digitalocean_docr_repository_tag_delete` [write, destructive, off by default] — Delete a tag from a repository in a container registry. - `digitalocean_docr_repository_tag_list` [read-only] — List tags for a repository in a container registry. - `digitalocean_docr_subscription_get` [read-only] — Get the current container registry subscription information. - `digitalocean_docr_subscription_update` [write, off by default] — Update the container registry subscription tier. - `digitalocean_docr_validate_name` [read-only] — Check if a container registry name is available. - `digitalocean_docs_find_for_service` [read-only] — Given a DigitalOcean service name (e.g. "droplets", "managed kubernetes", "app platform"), return a list of relevant documentation pages with titles and URLs. - `digitalocean_docs_get_page` [read-only] — Fetch the full markdown content of a specific DigitalOcean docs page. Returns clean markdown suitable for LLM consumption. - `digitalocean_docs_get_quickstart` [read-only] — Get the quickstart or getting-started guide for a DigitalOcean service. Returns the full content as clean markdown. - `digitalocean_docs_get_related` [read-only] — Extract and categorize all outbound documentation links from a specific docs page. Returns links grouped by type (how-to, reference, support, getting-started, concept, details). - `digitalocean_docs_search` [read-only] — Full-text search across DigitalOcean documentation. Returns ranked results with title, URL, and content snippet. - `digitalocean_docs_troubleshoot` [read-only] — Search for troubleshooting pages matching an error message or symptom. Returns the full content of the best matching support page, plus links to related pages. - `digitalocean_doks_create_cluster` [write, destructive, off by default] — Create a new DigitalOcean Kubernetes cluster with at least one node pool. This provisions real Droplets and incurs ongoing DigitalOcean spend for as long as the cluster exists. - `digitalocean_doks_create_nodepool` [write, off by default] — Create a new node pool in an existing DigitalOcean Kubernetes cluster. This provisions real Droplets. - `digitalocean_doks_delete_cluster` [write, destructive, off by default] — Permanently delete a DigitalOcean Kubernetes cluster and all its node pools. This cannot be undone. - `digitalocean_doks_delete_node` [write, destructive, off by default] — Delete a single node from a node pool in a DigitalOcean Kubernetes cluster. This cannot be undone -- the node pool will recreate a replacement node automatically unless the pool is already at its minimum size. - `digitalocean_doks_delete_nodepool` [write, destructive, off by default] — Permanently delete a node pool and all its nodes from a DigitalOcean Kubernetes cluster. This cannot be undone. - `digitalocean_doks_get_cluster` [read-only] — Get a DigitalOcean Kubernetes cluster's configuration and status. - `digitalocean_doks_get_cluster_upgrades` [read-only] — Get the Kubernetes versions a cluster is eligible to upgrade to. - `digitalocean_doks_get_credentials` [read-only] — Get short-lived Kubernetes API server credentials (server URL, certificate/token data) for a cluster. - `digitalocean_doks_get_kubeconfig` [read-only] — Get the kubeconfig YAML for a DigitalOcean Kubernetes cluster, for use with kubectl and other Kubernetes tooling. - `digitalocean_doks_get_nodepool` [read-only] — Get a single node pool in a DigitalOcean Kubernetes cluster. - `digitalocean_doks_list_clusters` [read-only] — List all DigitalOcean Kubernetes clusters on this account. - `digitalocean_doks_list_nodepools` [read-only] — List all node pools in a DigitalOcean Kubernetes cluster. - `digitalocean_doks_list_options` [read-only] — List available Kubernetes options: supported versions, regions, and node sizes for creating a cluster. - `digitalocean_doks_recycle_nodes` [write, off by default] — Recycle specific nodes in a node pool, replacing each with a new node. DigitalOcean's godo SDK marks the underlying RecycleNodePoolNodes call deprecated in favor of digitalocean_doks_delete_node with replace: true, but the endpoint remains live and is kept here for tool parity. - `digitalocean_doks_update_cluster` [write, off by default] — Update a DigitalOcean Kubernetes cluster's name, tags, maintenance policy, or upgrade settings. - `digitalocean_doks_update_nodepool` [write, off by default] — Update a node pool's size, tags, labels, taints, or autoscaling settings. - `digitalocean_doks_upgrade_cluster` [write, destructive, off by default] — Upgrade a DigitalOcean Kubernetes cluster to a new control-plane version. Check digitalocean_doks_get_cluster_upgrades first for valid target versions -- this can briefly disrupt the control plane. - `digitalocean_domain_create` [write, off by default] — Create a new domain. - `digitalocean_domain_delete` [write, destructive, off by default] — Permanently delete a domain and every DNS record under it. This cannot be undone. - `digitalocean_domain_get` [read-only] — Get domain information by name. - `digitalocean_domain_list` [read-only] — List domains with pagination. - `digitalocean_domain_record_create` [write, off by default] — Create a new domain record. - `digitalocean_domain_record_delete` [write, off by default] — Delete a domain record. - `digitalocean_domain_record_edit` [write, off by default] — Edit a domain record. - `digitalocean_domain_record_get` [read-only] — Get a domain record by domain name and record ID. - `digitalocean_domain_record_list` [read-only] — List domain records for a domain with pagination. - `digitalocean_droplet_action` [read-only] — Get a droplet action by droplet ID and action ID. - `digitalocean_droplet_backup_policy` [read-only] — Get a droplet's backup policy. - `digitalocean_droplet_create` [write, destructive, off by default] — Create a new droplet. Supports standard distribution images via image_id and 1-click marketplace app images via image_slug. Exactly one of image_id or image_slug must be provided. - `digitalocean_droplet_delete` [write, destructive, off by default] — Delete a droplet. - `digitalocean_droplet_enable_private_net` [write, destructive, off by default] — Enable private networking on a droplet. - `digitalocean_droplet_get` [read-only] — Get a droplet by its ID. - `digitalocean_droplet_kernels` [read-only] — Get available kernels for a droplet. - `digitalocean_droplet_list` [read-only] — List all droplets for the user. Supports pagination. - `digitalocean_enable_backups_droplet` [write, off by default] — Enable backups on a droplet. - `digitalocean_enable_backups_droplets_tag` [write, off by default] — Enable backups on droplets by tag. - `digitalocean_enable_ipv6_droplet` [write, off by default] — Enable IPv6 on a droplet. - `digitalocean_enable_ipv6_droplets_tag` [write, off by default] — Enable IPv6 on droplets by tag. - `digitalocean_enable_private_net_droplets_tag` [write, off by default] — Enable private networking on droplets by tag. - `digitalocean_firewall_add_droplets` [write, off by default] — Adds one or more droplets to a firewall. - `digitalocean_firewall_add_rules` [write, off by default] — Add one or more inbound and/or outbound rules to a firewall. - `digitalocean_firewall_add_tags` [write, off by default] — Adds one or more tags to a firewall. - `digitalocean_firewall_create` [write, off by default] — Create a new firewall with a single inbound and outbound rule, optionally applied to droplets and/or tags. - `digitalocean_firewall_delete` [write, destructive, off by default] — Permanently delete a firewall. This cannot be undone. - `digitalocean_firewall_get` [read-only] — Get firewall information by ID. - `digitalocean_firewall_list` [read-only] — List firewalls with pagination. - `digitalocean_firewall_remove_droplets` [write, off by default] — Removes one or more droplets from a firewall. - `digitalocean_firewall_remove_rules` [write, off by default] — Remove one or more inbound and/or outbound rules from a firewall. - `digitalocean_firewall_remove_tags` [write, off by default] — Removes one or more tags from a firewall. - `digitalocean_functions_create_access_key` [write, off by default] — Create an access key for a DigitalOcean Functions namespace. The secret appears ONLY in this response and cannot be retrieved later -- capture and store it immediately. Access keys grant programmatic data-plane access. - `digitalocean_functions_create_namespace` [write, off by default] — Create a new DigitalOcean Functions namespace. - `digitalocean_functions_create_or_update_action` [write, off by default] — Create or update an action in a DigitalOcean Functions namespace. If the action already exists it will be overwritten. - `digitalocean_functions_create_or_update_package` [write, off by default] — Create or update a package in a DigitalOcean Functions namespace. Packages are used to group related actions. - `digitalocean_functions_create_trigger` [write, off by default] — Create a scheduled trigger for a function in a DigitalOcean Functions namespace. Currently only SCHEDULED type triggers are supported. - `digitalocean_functions_delete_access_key` [write, off by default] — Delete an access key for a DigitalOcean Functions namespace. This is irreversible -- once deleted, the key's secret can never be used again. - `digitalocean_functions_delete_action` [write, destructive, off by default] — Delete an action from a DigitalOcean Functions namespace. - `digitalocean_functions_delete_namespace` [write, destructive, off by default] — Delete a DigitalOcean Functions namespace. This permanently removes the namespace and all its functions, packages, and triggers. - `digitalocean_functions_delete_package` [write, destructive, off by default] — Delete a package from a DigitalOcean Functions namespace. - `digitalocean_functions_delete_trigger` [write, off by default] — Delete a trigger from a DigitalOcean Functions namespace. - `digitalocean_functions_deployment_guide` [read-only] — Return the authoritative step-by-step guide for deploying a DigitalOcean function through this connector's tools. - `digitalocean_functions_get_action` [read-only] — Get detailed information about a specific action in a DigitalOcean Functions namespace, including its configuration and optionally its source code. - `digitalocean_functions_get_activation` [read-only] — Get the full activation record for a specific function invocation, including response, logs, timing, and status. - `digitalocean_functions_get_activation_logs` [read-only] — Get only the logs for a specific function activation. Useful for debugging function execution. - `digitalocean_functions_get_activation_result` [read-only] — Get only the result of a specific function activation. Returns the function's return value and status. - `digitalocean_functions_get_namespace` [read-only] — Get a DigitalOcean Functions namespace by ID. Returns full namespace details including api_host and key for data plane access. - `digitalocean_functions_get_package` [read-only] — Get detailed information about a specific package in a DigitalOcean Functions namespace, including its actions, parameters, and annotations. - `digitalocean_functions_get_trigger` [read-only] — Get a specific trigger in a DigitalOcean Functions namespace. - `digitalocean_functions_invoke_action` [write, off by default] — Invoke a function action in a DigitalOcean Functions namespace. By default this is a blocking invocation that waits for the result. - `digitalocean_functions_list_access_keys` [read-only] — List access keys for a DigitalOcean Functions namespace. Returns metadata only -- secret values are NOT returned and cannot be retrieved once a key has been created. - `digitalocean_functions_list_actions` [read-only] — List all actions in a DigitalOcean Functions namespace. Returns action metadata including name, namespace, version, and limits. - `digitalocean_functions_list_activations` [read-only] — List activations (invocation records) for a DigitalOcean Functions namespace. - `digitalocean_functions_list_namespaces` [read-only] — List all DigitalOcean Functions namespaces. Returns namespace metadata including api_host, region, label, and UUID. - `digitalocean_functions_list_packages` [read-only] — List all packages in a DigitalOcean Functions namespace. Packages group related actions together. - `digitalocean_functions_list_triggers` [read-only] — List all triggers for a DigitalOcean Functions namespace. - `digitalocean_functions_update_trigger` [write, off by default] — Update a trigger in a DigitalOcean Functions namespace. You can enable/disable the trigger or change the cron schedule. - `digitalocean_genai_batch_inference_cancel` [write, off by default] — Request cancellation of a batch inference job. The job may not be cancelled immediately -- poll with get to check status. - `digitalocean_genai_batch_inference_create` [write, off by default] — Create a new batch inference job. Requires a previously uploaded file (via genai_batch_inference_create_file + genai_batch_inference_upload_file). For the openai provider, endpoint is also required. - `digitalocean_genai_batch_inference_create_file` [write, off by default] — Create a presigned URL for uploading a batch inference JSONL input file. The file must have a .jsonl extension. Upload the file to the returned URL via HTTP PUT (genai_batch_inference_upload_file) before creating a batch job. - `digitalocean_genai_batch_inference_get` [read-only] — Get the current status and metadata of a batch inference job by its ID. - `digitalocean_genai_batch_inference_get_results` [read-only] — Get the results download URL for a completed batch inference job. Returns a presigned download URL and output file ID. Fails if the job has not completed. - `digitalocean_genai_batch_inference_list` [read-only] — List batch inference jobs with optional status filter and cursor-based pagination. Returns Relay-style edges with per-row cursors and page_info -- not the page/per_page pagination used elsewhere in this connector. - `digitalocean_genai_batch_inference_upload_file` [write, off by default] — Upload JSONL content to the presigned S3 URL returned by genai_batch_inference_create_file. The content should be newline-delimited JSON (one request per line). Must be called after create_file and before create. - `digitalocean_genai_create_evaluation_dataset` [write, off by default] — Create an agent-evaluation dataset by uploading CSV content (presign -> Spaces upload -> database record). The CSV must have a 'query' column whose cells hold JSON objects. Use the returned dataset_uuid with digitalocean_genai_create_evaluation_test_case. - `digitalocean_genai_create_evaluation_test_case` [write, off by default] — Create an evaluation test case that pairs a dataset with metrics for repeatable agent evaluation runs. - `digitalocean_genai_custom_models_delete` [write, destructive, off by default] — Delete a custom model by exact UUID or exact name. If name is given, it's resolved against the custom model list first -- an ambiguous or unmatched name fails without deleting anything. BUILD-TIME VERIFY: name resolution only scans the first page of results (per_page 200) rather than the full account roster DigitalOcean's own MCP server walks -- pass uuid directly for accounts with more custom models. - `digitalocean_genai_custom_models_get` [read-only] — Get the full catalog card for a custom model, including its status, architecture, source info, size, license, tags, active deployments, and cost estimate. - `digitalocean_genai_custom_models_import` [write, off by default] — Import a custom model from an external source (e.g. HuggingFace or a Spaces bucket). Starts an async import job. CONSENT REQUIRED on every call, including re-imports of the same model: present the import terms (storage cost, license, source) to the user and only pass accept_terms_and_conditions: true after they explicitly agree in this conversation. BUILD-TIME VERIFY: for source_type SOURCE_TYPE_HUGGINGFACE, DigitalOcean's own MCP server resolves an omitted commit_sha by calling out to the HuggingFace Hub API before import -- this connector does not replicate that lookup, so supply commit_sha explicitly for HuggingFace imports if the API requires it. - `digitalocean_genai_custom_models_list` [read-only] — List custom models -- one row per model, including failed imports (STATUS_FAILED). Optional status filter and pagination. For catalog + custom models together, use genai_models_unified_search. - `digitalocean_genai_custom_models_update_metadata` [write, off by default] — Update the metadata of an existing custom model. Editable fields include name, description, tags, input/output modalities, parameters, and license. At least one field must be provided. - `digitalocean_genai_get_evaluation_run` [read-only] — Get the status and results of an agent evaluation run. - `digitalocean_genai_inference_router_create` [write, off by default] — Create a GenAI model router. Requires a name and at least one fallback model; policies are optional. Each policy needs a task (task_slug or custom_task) and a selection_policy. - `digitalocean_genai_inference_router_delete` [write, destructive, off by default] — Delete a GenAI model router by UUID. - `digitalocean_genai_inference_router_get` [read-only] — Get a GenAI model router by UUID. - `digitalocean_genai_inference_router_list` [read-only] — List GenAI model routers with pagination. - `digitalocean_genai_inference_router_task_presets` [read-only] — List preset inference-router tasks (task_slug, name, models, etc.) from GET /v2/gen-ai/models/routers/tasks/presets. Use task_slug values when building policies for router create/update. - `digitalocean_genai_inference_router_update` [write, off by default] — Update a GenAI model router (PUT). At least one of name, description, policies (non-empty), or fallback_models must be supplied. - `digitalocean_genai_list_evaluation_metrics` [read-only] — List all available agent-evaluation metrics. - `digitalocean_genai_list_evaluation_test_cases` [read-only] — List evaluation test cases for a workspace. - `digitalocean_genai_model_eval_cancel_run` [write, off by default] — Cancel an in-progress model evaluation run by UUID. The run transitions to MODEL_EVALUATION_RUN_CANCELLING and then MODEL_EVALUATION_RUN_CANCELLED. Any partial results may be lost. - `digitalocean_genai_model_eval_create_custom_metric` [write, off by default] — Create a custom (LLM-as-judge) model evaluation metric. The judge model scores each response against scoring_prompt. The created metric appears in digitalocean_genai_model_eval_list_metrics (source EVALUATION_METRIC_SOURCE_CUSTOM) and its metric_uuid can be used in evaluation runs and presets. - `digitalocean_genai_model_eval_create_dataset` [write, off by default] — Upload and register a model evaluation dataset (presign -> Spaces upload -> database record). Accepts CSV content (with an 'input' column) or JSONL content (one JSON object per line with an 'input' field); a 'ground_truth' column/field is optional. Returns evaluation_dataset_uuid for use with digitalocean_genai_model_eval_create_run. - `digitalocean_genai_model_eval_create_run` [write, off by default] — Create a model evaluation run. Provide either eval_preset_uuid, or dataset_uuid + (judge_model_uuid or judge_model_name) + metric_uuids for inline configuration. candidate_model_name is always required. - `digitalocean_genai_model_eval_delete_custom_metric` [write, off by default] — Delete a custom model evaluation metric by UUID. Only custom metrics can be deleted; built-in catalog metrics cannot. After deletion the metric is no longer available for new evaluation runs; completed runs keep their results. - `digitalocean_genai_model_eval_delete_dataset` [write, off by default] — Delete an evaluation dataset by UUID. Works for both model and agent evaluation datasets. Permanent. - `digitalocean_genai_model_eval_delete_preset` [write, off by default] — Delete a saved model evaluation preset by UUID. Permanent; existing runs that referenced the preset are not affected. - `digitalocean_genai_model_eval_delete_run` [write, off by default] — Delete a model evaluation run by UUID. Permanent: the run record and its results cannot be recovered. - `digitalocean_genai_model_eval_get_preset` [read-only] — Get a single model evaluation preset by UUID. - `digitalocean_genai_model_eval_get_results_download_url` [read-only] — Get a presigned download URL for the full results of a model evaluation run. Short-lived (~15 min), points to a gzip-compressed JSON (.json.gz) file -- use it promptly. - `digitalocean_genai_model_eval_get_run` [read-only] — Get the status, details, and per-prompt results of a model evaluation run. - `digitalocean_genai_model_eval_list_datasets` [read-only] — List previously uploaded evaluation datasets so an existing dataset_uuid can be reused in digitalocean_genai_model_eval_create_run instead of uploading a new one. Defaults to model-evaluation datasets. - `digitalocean_genai_model_eval_list_metrics` [read-only] — List all available model evaluation metrics, including built-in catalog metrics and custom LLM-as-judge metrics. - `digitalocean_genai_model_eval_list_presets` [read-only] — List all model evaluation presets. Presets are reusable evaluation configurations containing a dataset, judge model, and metrics. - `digitalocean_genai_model_eval_list_runs` [read-only] — List model evaluation runs with optional filters. Each run includes its eval_run_uuid (use it with digitalocean_genai_model_eval_get_run / _cancel_run / _delete_run), name, status, and the candidate/judge model and dataset it used. - `digitalocean_genai_model_eval_run_workflow` [write, off by default] — Run a complete model evaluation workflow in one call: upload the dataset, create the evaluation run, and poll for a terminal result. Requires judge_model_uuid or judge_model_name (there is no preset shortcut here). - `digitalocean_genai_model_eval_update_custom_metric` [write, off by default] — Update an existing custom model evaluation metric. Only custom metrics can be updated; built-in catalog metrics cannot. - `digitalocean_genai_model_eval_update_run` [write, off by default] — Update a model evaluation run. Currently only the run name can be changed. - `digitalocean_genai_models_unified_search` [read-only] — PRIMARY tool for listing or searching models. Use when the user asks to list all models, show available models, or search by partial name. Returns both catalog and custom models. Empty query lists everything; partial query filters by case-insensitive substring match on model name. BUILD-TIME VERIFY: DigitalOcean's model catalog/custom-model list endpoints have no server-side search -- this fetches the first page of each (per_page 200) and filters client-side, matching godo's own SearchModels behavior but capped at 200 results per source. - `digitalocean_genai_run_evaluation_test_case` [write, off by default] — Run an evaluation test case against one or more agent deployments, producing one evaluation run per deployment. - `digitalocean_genai_run_evaluation_workflow` [write, off by default] — Run a complete agent evaluation workflow in one call: upload the dataset, find-or-create a test case in the workspace, run the evaluation against the given agent deployments, and poll for a terminal result. - `digitalocean_genai_update_evaluation_test_case` [write, off by default] — Update an evaluation test case's name, description, dataset, metrics, or star metric. - `digitalocean_get_invoice` [read-only] — Get the itemized line items for a specific invoice. - `digitalocean_image_action_convert` [write, off by default] — Convert an image (backup) to a snapshot. - `digitalocean_image_action_get` [read-only] — Retrieve the status of an image action. - `digitalocean_image_action_transfer` [write, off by default] — Transfer an image to another region. - `digitalocean_image_create` [write, off by default] — Create a custom image from a URL (e.g. QCOW2, ISO). - `digitalocean_image_delete` [write, destructive, off by default] — Delete an image or snapshot. - `digitalocean_image_get` [read-only] — Get a specific image by its numeric ID. - `digitalocean_image_list` [read-only] — List available images (snapshots, backups, distributions, applications). Supports pagination. - `digitalocean_image_update` [write, off by default] — Update an image's name. - `digitalocean_inference_model_catalog_get_card` [read-only] — Get the model metadata for a specific model UUID. - `digitalocean_inference_model_catalog_search` [read-only] — Search for models in the catalog using a search query. Returns a list of model UUIDs that match (case-insensitive substring match on name). An empty or missing search query returns all available models. - `digitalocean_invoice_list` [read-only] — List invoices with pagination. - `digitalocean_key_create` [write, off by default] — Create a new SSH key on the account. - `digitalocean_key_delete` [write, off by default] — Delete an SSH key from the account. - `digitalocean_key_get` [read-only] — Get a specific SSH key by ID. - `digitalocean_key_list` [read-only] — List SSH keys with pagination. - `digitalocean_lb_add_droplets` [write, off by default] — Add Droplets to a Load Balancer. - `digitalocean_lb_add_fwd_rules` [write, off by default] — Add Forwarding Rules to a Load Balancer. - `digitalocean_lb_create` [write, off by default] — Create a new Load Balancer. - `digitalocean_lb_delete` [write, destructive, off by default] — Delete a Load Balancer by ID. This is irreversible. - `digitalocean_lb_delete_cache` [write, off by default] — Delete the CDN cache of a global load balancer by ID. - `digitalocean_lb_get` [read-only] — Get a Load Balancer by ID. - `digitalocean_lb_list` [read-only] — List Load Balancers with pagination. - `digitalocean_lb_remove_droplets` [write, off by default] — Remove Droplets from a Load Balancer. - `digitalocean_lb_remove_fwd_rules` [write, off by default] — Remove Forwarding Rules from a Load Balancer. - `digitalocean_lb_update` [write, off by default] — Update a Load Balancer. - `digitalocean_lets_encrypt_certificate_create` [write, off by default] — Request a new DigitalOcean-managed Let's Encrypt certificate for one or more DNS names. - `digitalocean_marketplace_1_click_kubernetes_app_install` [write, off by default] — Install 1-click applications on a Kubernetes cluster. - `digitalocean_marketplace_1_click_list` [read-only] — List available 1-click applications from the DigitalOcean marketplace. - `digitalocean_nfs_attach` [write, off by default] — Attach a NFS file share to a VPC. - `digitalocean_nfs_detach` [write, off by default] — Detach a NFS file share from a VPC. - `digitalocean_nfs_file_share_create` [write, off by default] — Create a new NFS file share. - `digitalocean_nfs_file_share_delete` [write, destructive, off by default] — Delete a file share by ID. - `digitalocean_nfs_file_share_get` [read-only] — Get a file share by ID. - `digitalocean_nfs_file_share_list` [read-only] — List NFS file shares with optional region filter. Supports pagination. - `digitalocean_nfs_reassign` [write, off by default] — Reassign a NFS file share from one VPC to another. - `digitalocean_nfs_resize` [write, off by default] — Resize a NFS file share. - `digitalocean_nfs_snapshot` [write, off by default] — Create a snapshot of a NFS file share. - `digitalocean_nfs_snapshot_delete` [write, off by default] — Delete a NFS snapshot by ID. - `digitalocean_nfs_snapshot_get` [read-only] — Get a NFS snapshot by ID. - `digitalocean_nfs_snapshot_list` [read-only] — List all NFS snapshots. Supports pagination and filtering by region and share ID. - `digitalocean_nfs_switch_performance_tier` [write, off by default] — Switch the performance tier of a NFS file share. - `digitalocean_partner_attachment_create` [write, off by default] — Create a new partner attachment. - `digitalocean_partner_attachment_delete` [write, destructive, off by default] — Delete a partner attachment. This is irreversible. - `digitalocean_partner_attachment_get` [read-only] — Get partner attachment information by ID. - `digitalocean_partner_attachment_get_bgp_config` [read-only] — Get the BGP configuration of a partner attachment. - `digitalocean_partner_attachment_get_service_key` [read-only] — Get the service key of a partner attachment. - `digitalocean_partner_attachment_list` [read-only] — List partner attachments with pagination. - `digitalocean_partner_attachment_update` [write, off by default] — Update a partner attachment's name and/or the VPCs it's associated with. - `digitalocean_power_cycle_droplet` [write, off by default] — Power cycle a droplet. - `digitalocean_power_cycle_droplets_tag` [write, destructive, off by default] — Power cycle droplets by tag. - `digitalocean_power_off_droplet` [write, off by default] — Power off a droplet. - `digitalocean_power_off_droplets_tag` [write, destructive, off by default] — Power off droplets by tag. - `digitalocean_power_on_droplet` [write, off by default] — Power on a droplet. - `digitalocean_power_on_droplets_tag` [write, off by default] — Power on droplets by tag. - `digitalocean_reboot_droplet` [write, off by default] — Reboot a droplet. - `digitalocean_rebuild_droplet` [write, destructive, off by default] — Rebuild a droplet from an image. - `digitalocean_rebuild_droplet_by_slug` [write, destructive, off by default] — Rebuild a droplet using an image slug. - `digitalocean_region_list` [read-only] — List all available regions with features and droplet size availability. Supports pagination. - `digitalocean_rename_droplet` [write, off by default] — Rename a droplet. - `digitalocean_reserved_ip_assign` [write, off by default] — Assign a reserved IP to a droplet. - `digitalocean_reserved_ip_get` [read-only] — Get reserved IPv4 or IPv6 information by IP. - `digitalocean_reserved_ip_list` [read-only] — List reserved IPv4 or IPv6 addresses with pagination. - `digitalocean_reserved_ip_release` [write, destructive, off by default] — Release a reserved IPv4 or IPv6. This is irreversible -- the address returns to DigitalOcean's pool. - `digitalocean_reserved_ip_reserve` [write, off by default] — Reserve a new IPv4 or IPv6. - `digitalocean_reserved_ip_unassign` [write, off by default] — Unassign a reserved IP from a droplet. - `digitalocean_reset_droplet_password` [write, off by default] — Reset password for a droplet. - `digitalocean_resize_droplet` [write, off by default] — Resize a droplet. - `digitalocean_restore_droplet` [write, destructive, off by default] — Restore a droplet from a backup/snapshot. - `digitalocean_shutdown_droplet` [write, off by default] — Shutdown a droplet. - `digitalocean_shutdown_droplets_tag` [write, destructive, off by default] — Shutdown droplets by tag. - `digitalocean_size_list` [read-only] — List all available droplet sizes. Supports pagination. - `digitalocean_snapshot_droplet` [write, off by default] — Take a snapshot of a droplet. - `digitalocean_snapshot_droplets_tag` [write, off by default] — Take a snapshot of droplets by tag. - `digitalocean_spaces_cdn_create` [write, off by default] — Create a new CDN endpoint fronting a Space. - `digitalocean_spaces_cdn_delete` [write, destructive, off by default] — Delete a CDN endpoint. - `digitalocean_spaces_cdn_flush_cache` [write, off by default] — Flush the cache of a CDN endpoint. - `digitalocean_spaces_cdn_get` [read-only] — Get CDN endpoint information by ID. - `digitalocean_spaces_cdn_list` [read-only] — List CDN endpoints with pagination. - `digitalocean_spaces_key_create` [write, destructive, off by default] — Create a new Spaces key with full access. SECURITY WARNING: the returned secret key should never be committed to source control -- store it in environment variables or a secrets manager instead. - `digitalocean_spaces_key_delete` [write, off by default] — Delete a Spaces key. - `digitalocean_spaces_key_get` [read-only] — Get a specific Spaces key. - `digitalocean_spaces_key_list` [read-only] — List all Spaces keys. - `digitalocean_spaces_key_update` [write, off by default] — Update an existing Spaces key's name. - `digitalocean_uptimecheck_alert_create` [write, off by default] — Create a new UptimeCheck alert. - `digitalocean_uptimecheck_alert_delete` [write, off by default] — Delete an UptimeCheck alert. - `digitalocean_uptimecheck_alert_get` [read-only] — Get UptimeCheck Alert information by CheckID and AlertID. - `digitalocean_uptimecheck_alert_list` [read-only] — List UptimeCheck Alerts with pagination. - `digitalocean_uptimecheck_alert_update` [write, off by default] — Update an UptimeCheck alert. - `digitalocean_uptimecheck_create` [write, off by default] — Create a new UptimeCheck. - `digitalocean_uptimecheck_delete` [write, off by default] — Delete an UptimeCheck. - `digitalocean_uptimecheck_get` [read-only] — Get UptimeCheck information by ID. - `digitalocean_uptimecheck_get_state` [read-only] — Get UptimeCheck state/status information by ID. - `digitalocean_uptimecheck_list` [read-only] — List UptimeChecks with pagination. - `digitalocean_uptimecheck_update` [write, off by default] — Update an UptimeCheck. - `digitalocean_vector_db_create` [write, off by default] — Create a new managed Weaviate vector database cluster. Returns the cluster including its ID, status, and connection endpoints (endpoints.http, endpoints.grpc). - `digitalocean_vector_db_delete` [write, destructive, off by default] — Delete a vector database cluster by ID. This is irreversible. - `digitalocean_vector_db_get` [read-only] — Get a vector database cluster by ID. Returns the full cluster including status, config, and connection endpoints. - `digitalocean_vector_db_get_credentials` [read-only] — Get the admin credentials (user_id and api_token) for a vector database cluster. Use these together with the cluster's endpoints to connect a Weaviate client. - `digitalocean_vector_db_list` [read-only] — List vector database clusters. Supports pagination. Returns a summary of each cluster including its connection endpoints. - `digitalocean_vector_db_resize` [write, off by default] — Resize a vector database cluster to a new resource tier. - `digitalocean_volume_action_get` [read-only] — Get a volume action by ID. - `digitalocean_volume_action_list` [read-only] — List volume actions. - `digitalocean_volume_attach` [write, off by default] — Attach a volume to a droplet. - `digitalocean_volume_create` [write, off by default] — Create a new block storage volume. - `digitalocean_volume_delete` [write, destructive, off by default] — Delete a block storage volume by ID. - `digitalocean_volume_detach` [write, off by default] — Detach a volume from a droplet. - `digitalocean_volume_get` [read-only] — Get a block storage volume by ID. - `digitalocean_volume_list` [read-only] — List block storage volumes with optional name/region filters. Supports pagination. - `digitalocean_volume_resize` [write, off by default] — Resize a volume. - `digitalocean_volume_snapshot_create` [write, off by default] — Create a new snapshot from a volume. - `digitalocean_volume_snapshot_delete` [write, off by default] — Delete a snapshot by ID. - `digitalocean_volume_snapshot_get` [read-only] — Get a snapshot by ID. - `digitalocean_volume_snapshot_list` [read-only] — List snapshots for a volume. Supports pagination. - `digitalocean_vpc_create` [write, off by default] — Create a new VPC. - `digitalocean_vpc_delete` [write, destructive, off by default] — Permanently delete a VPC. Fails if it still has resources attached. This cannot be undone. - `digitalocean_vpc_get` [read-only] — Get VPC information by ID. - `digitalocean_vpc_list` [read-only] — List VPCs with pagination. - `digitalocean_vpc_list_members` [read-only] — List the resources (droplets, load balancers, etc.) that belong to a VPC. - `digitalocean_vpc_peering_create` [write, off by default] — Create a new VPC Peering connection between two VPCs. - `digitalocean_vpc_peering_delete` [write, destructive, off by default] — Permanently delete a VPC Peering connection. This cannot be undone. - `digitalocean_vpc_peering_get` [read-only] — Get VPC Peering information by ID. - `digitalocean_vpc_peering_list` [read-only] — List VPC Peering connections with pagination. ## Klaviyo Profiles, lists, campaigns, and flows for email/SMS marketing. 125 tools: 75 read-only, 50 write. - `klaviyo_add_profiles_to_list` [write, off by default] — Add a batch of profiles to a Klaviyo list by profile ID (max 1,000 per request). - `klaviyo_add_profile_to_list` [write, off by default] — Add one or more profiles to a Klaviyo list by profile ID. - `klaviyo_assign_template_to_campaign_message` [write, off by default] — Assign an existing email template to a campaign message. Use after creating both the template and the campaign. - `klaviyo_bulk_import_profiles` [write, off by default] — Create or update a batch of up to 10,000 profiles in a single job via Klaviyo's Bulk Profile Import API. - `klaviyo_bulk_suppress_profiles` [write, off by default] — Suppress email marketing for a batch of profiles by email address, or for all members of a list/segment. This is a bulk action affecting many profiles' deliverability and marketing status — requires confirm_suppress: true. - `klaviyo_bulk_unsuppress_profiles` [write, off by default] — Remove USER_SUPPRESSED suppressions for a batch of profiles by email address, or for all members of a list/segment (does not affect unsubscribes or INVALID_EMAIL/HARD_BOUNCE suppressions). This is a bulk action affecting many profiles' deliverability and marketing status — requires confirm_unsuppress: true. - `klaviyo_cancel_campaign_send` [write, off by default] — Cancel or revert the send of a currently sending or scheduled campaign. 'cancel' permanently cancels the campaign; 'revert' stops the send and returns the campaign to draft. - `klaviyo_clone_campaign` [write, off by default] — Create a copy of an existing Klaviyo campaign under a new name. - `klaviyo_clone_template` [write, off by default] — Create a copy of an existing Klaviyo template under a new name. - `klaviyo_create_campaign` [write, off by default] — Create a fully-populated email campaign in Klaviyo, including HTML content, audience, and optional scheduling. - `klaviyo_create_coupon` [write, off by default] — Create a coupon in Klaviyo, which coupon codes can then be generated under. - `klaviyo_create_coupon_codes` [write, off by default] — Bulk-generate unique coupon codes under an existing Klaviyo coupon. - `klaviyo_create_dnd_email_template` [write, off by default] — Create a new drag-and-drop (DND) email template from a structured definition of sections, rows, columns, and blocks, rather than raw HTML. - `klaviyo_create_event` [write, off by default] — Track a custom event for a profile in Klaviyo (e.g. Placed Order, Viewed Product). - `klaviyo_create_list` [write, off by default] — Create a new contact list in Klaviyo. - `klaviyo_create_or_update_profile` [write, off by default] — Create a new profile or update an existing one, matched by email/phone/external_id. Returns 201 if created, 200 if an existing profile was updated. Setting a field to null clears it; omitting a field leaves it unchanged. - `klaviyo_create_profile` [write, off by default] — Create a new customer profile in Klaviyo. - `klaviyo_create_segment` [write, off by default] — Create a dynamic segment in Klaviyo from a condition definition. - `klaviyo_create_tag` [write, off by default] — Create a new tag in Klaviyo for organizing campaigns, flows, lists, and segments. - `klaviyo_create_template` [write, off by default] — Create a reusable HTML email template in Klaviyo. - `klaviyo_create_template_preview_send_job` [write, off by default] — Send a test/preview email of a template to up to 5 recipient addresses, optionally rendered with merge-variable context. - `klaviyo_create_translation` [write, off by default] — BETA. Create a new translation collection linking a Klaviyo resource (campaign variation, flow message, template, or universal content block) to its localization settings for multi-language sends. Valid channel + resource combinations: email -> campaign-variation, flow-message, template, template-universal-content; sms -> campaign-variation, flow-message; mobile_push -> campaign-variation, flow-message; whatsapp -> template only. - `klaviyo_create_universal_content` [write, off by default] — Create a reusable universal content block in Klaviyo (button, drop_shadow, horizontal_rule, html, image, spacer, or text) that can be referenced across multiple email templates. - `klaviyo_delete_campaign` [write, off by default] — Delete a Klaviyo campaign. - `klaviyo_delete_list` [write, off by default] — Delete a Klaviyo list. - `klaviyo_delete_profile` [write, off by default] — Request deletion of a profile and its data (processed via Klaviyo's data privacy job queue). - `klaviyo_delete_segment` [write, off by default] — Delete a Klaviyo segment. - `klaviyo_delete_template` [write, off by default] — Delete a Klaviyo email template. - `klaviyo_delete_translation` [write, off by default] — BETA. Delete a translation collection by ID, removing all localization settings and translation values for the resource. - `klaviyo_delete_universal_content` [write, off by default] — Delete a Klaviyo universal content block. - `klaviyo_get_account` [read-only] — Get your Klaviyo account details and contact information. - `klaviyo_get_all_universal_content` [read-only] — List all universal content blocks in the Klaviyo account, optionally filtered by name, id, created/updated, or block type. - `klaviyo_get_bulk_create_catalog_items_job` [read-only] — Get the status of a Klaviyo bulk catalog item create job by job ID. - `klaviyo_get_bulk_create_catalog_items_jobs` [read-only] — List all Klaviyo bulk catalog item create jobs. - `klaviyo_get_bulk_create_variants_job` [read-only] — Get the status of a Klaviyo bulk catalog variant create job by job ID. - `klaviyo_get_bulk_create_variants_jobs` [read-only] — List all Klaviyo bulk catalog variant create jobs. - `klaviyo_get_bulk_delete_catalog_items_job` [read-only] — Get the status of a Klaviyo bulk catalog item delete job by job ID. - `klaviyo_get_bulk_delete_catalog_items_jobs` [read-only] — List all Klaviyo bulk catalog item delete jobs. - `klaviyo_get_bulk_delete_variants_job` [read-only] — Get the status of a Klaviyo bulk catalog variant delete job by job ID. - `klaviyo_get_bulk_delete_variants_jobs` [read-only] — List all Klaviyo bulk catalog variant delete jobs. - `klaviyo_get_bulk_import_profiles_job` [read-only] — Get the status of a bulk profile import job by ID. - `klaviyo_get_bulk_import_profiles_jobs` [read-only] — List all bulk profile import jobs, optionally filtered by status. - `klaviyo_get_bulk_suppress_profiles_job` [read-only] — Get the status of a bulk profile suppression job by ID. - `klaviyo_get_bulk_suppress_profiles_jobs` [read-only] — List all bulk profile suppression jobs, optionally filtered by status, list_id, or segment_id. - `klaviyo_get_bulk_unsuppress_profiles_job` [read-only] — Get the status of a bulk profile unsuppression job by ID. - `klaviyo_get_bulk_unsuppress_profiles_jobs` [read-only] — List all bulk profile unsuppression jobs, optionally filtered by status, list_id, or segment_id. - `klaviyo_get_bulk_update_catalog_items_job` [read-only] — Get the status of a Klaviyo bulk catalog item update job by job ID. - `klaviyo_get_bulk_update_catalog_items_jobs` [read-only] — List all Klaviyo bulk catalog item update jobs. - `klaviyo_get_bulk_update_variants_job` [read-only] — Get the status of a Klaviyo bulk catalog variant update job by job ID. - `klaviyo_get_bulk_update_variants_jobs` [read-only] — List all Klaviyo bulk catalog variant update jobs. - `klaviyo_get_campaign` [read-only] — Get details of a single Klaviyo campaign. - `klaviyo_get_campaign_message` [read-only] — Get the content/details of a single message within a Klaviyo campaign. - `klaviyo_get_campaign_recipient_estimation` [read-only] — Get the estimated recipient count for a Klaviyo campaign based on its current audience. - `klaviyo_get_campaign_recipient_estimation_job` [read-only] — Get the status of a campaign recipient estimation job triggered by refresh_campaign_recipient_estimation. - `klaviyo_get_campaign_report` [read-only] — Get campaign performance data (opens, clicks, conversions, deliveries, unsubscribes, etc.) matching what the Klaviyo UI shows, based on send date. Requires conversion_metric_id — use klaviyo_list_metrics to find the metric named 'Placed Order' as a sensible default if none is specified. - `klaviyo_get_campaign_send_job` [read-only] — Get the status of a campaign send job. - `klaviyo_get_catalog_categories` [read-only] — Get all catalog categories in a Klaviyo account. - `klaviyo_get_catalog_category` [read-only] — Get a specific Klaviyo catalog category by its compound ID. - `klaviyo_get_catalog_item` [read-only] — Get a specific Klaviyo catalog item (product) by its compound ID. - `klaviyo_get_catalog_items` [read-only] — Get all catalog items (products) in a Klaviyo account. - `klaviyo_get_catalog_variant` [read-only] — Get a specific Klaviyo catalog item variant by its compound ID. - `klaviyo_get_catalog_variants` [read-only] — Get all catalog item variants in a Klaviyo account. - `klaviyo_get_custom_metric` [read-only] — Get a single custom metric by ID, including its aggregation method and metric groups definition. - `klaviyo_get_custom_metrics` [read-only] — List all custom metrics (metrics with a custom aggregation definition) in the account. - `klaviyo_get_download_for_event_bulk_export_job` [read-only] — Get the download link(s) for a completed event bulk export job's gzipped CSV file. - `klaviyo_get_download_for_profile_bulk_export_job` [read-only] — Get the download link(s) for a completed profile bulk export job's gzipped CSV file. - `klaviyo_get_event` [read-only] — Get a single Klaviyo event by ID. - `klaviyo_get_event_bulk_export_job` [read-only] — Get the status and details of an event bulk export job. When complete, the response includes expiration and file size of the exported events file. - `klaviyo_get_events` [read-only] — List individual Klaviyo event records for a given filter (e.g. profile_id or metric_id). For aggregated metrics, prefer report/aggregate tools instead — this returns raw event rows. - `klaviyo_get_flow` [read-only] — Get a single Klaviyo flow's details and status. - `klaviyo_get_flow_action` [read-only] — Get details of a single action/step within a Klaviyo flow. - `klaviyo_get_flow_message` [read-only] — Get the content/details of a single message within a Klaviyo flow. - `klaviyo_get_flow_report` [read-only] — Get flow performance data (opens, clicks, conversions, deliveries, unsubscribes, etc.) matching what the Klaviyo UI shows, based on send date. Requires conversion_metric_id — use klaviyo_list_metrics to find the metric named 'Placed Order' as a sensible default if none is specified. - `klaviyo_get_flows_triggered_by_list` [read-only] — Get all Klaviyo flows that use the given list as their trigger. - `klaviyo_get_flows_triggered_by_metric` [read-only] — Get all Klaviyo flows that use the given metric as their trigger. - `klaviyo_get_flows_triggered_by_segment` [read-only] — Get all Klaviyo flows that use the given segment as their trigger. - `klaviyo_get_image` [read-only] — Get a single image from the Klaviyo image library by ID. - `klaviyo_get_list` [read-only] — Get a single Klaviyo list's details by ID. - `klaviyo_get_mapped_metric` [read-only] — Get the account-specific metric (or custom metric) that Klaviyo has mapped to a standard conceptual metric like 'revenue' or 'started_checkout'. - `klaviyo_get_mapped_metrics` [read-only] — List all mapped metrics in the account — the standard conceptual metrics (revenue, started_checkout, viewed_product, etc.) and which account-specific metric or custom metric each is mapped to. - `klaviyo_get_metric` [read-only] — Get a single metric by ID. - `klaviyo_get_metric_property` [read-only] — Get a single metric property by ID — a property key observed on events for a metric, with its inferred type and label. - `klaviyo_get_profile` [read-only] — Get details for a specific Klaviyo profile by ID. - `klaviyo_get_profile_bulk_export_job` [read-only] — Get the status and details of a profile bulk export job. When complete, the response includes expiration and file size of the exported profiles file. - `klaviyo_get_segment` [read-only] — Get a single Klaviyo segment's details and definition. - `klaviyo_get_tag` [read-only] — Get a single Klaviyo tag by ID. - `klaviyo_get_tag_group` [read-only] — Get a single Klaviyo tag group by ID. - `klaviyo_get_tag_groups` [read-only] — List all tag groups in the Klaviyo account. Tag groups organize tags into categories; every account has one default tag group. - `klaviyo_get_template` [read-only] — Get a single Klaviyo email template's details and HTML content. - `klaviyo_get_translation` [read-only] — BETA. Get a translation collection by ID, returning its localization settings (source/target locales, channel, fallback). Pass include_values to also get the source text and per-locale translations for each translatable field. - `klaviyo_get_translations` [read-only] — BETA. List all translation collections in the account. Each translation links a Klaviyo resource (campaign variation, flow message, template, or universal content block) to its localization settings. Supports filtering on channel, resource_type, and related_resource_id. - `klaviyo_get_universal_content` [read-only] — Get a single Klaviyo universal content block by ID. - `klaviyo_list_campaigns` [read-only] — List email campaigns in your Klaviyo account. - `klaviyo_list_email_templates` [read-only] — List email templates in the account with optional filtering and sorting. - `klaviyo_list_flows` [read-only] — List all automation flows in your Klaviyo account. - `klaviyo_list_images` [read-only] — List images in the Klaviyo account's image library. - `klaviyo_list_lists` [read-only] — List all contact lists in your Klaviyo account. - `klaviyo_list_metrics` [read-only] — List all metrics (event types) tracked in your Klaviyo account. - `klaviyo_list_profiles` [read-only] — List customer profiles in Klaviyo with optional filtering. - `klaviyo_list_segments` [read-only] — List all segments in your Klaviyo account. - `klaviyo_list_tags` [read-only] — List all tags in the Klaviyo account. - `klaviyo_merge_profiles` [write, off by default] — Merge a duplicate profile into a primary profile, combining their history. - `klaviyo_query_metric_aggregates` [read-only] — Aggregate raw event data for a metric, optionally grouped by dimensions (e.g. $message, $flow, $campaign_channel) and broken into hour/day/week/month intervals. IMPORTANT: aggregates by EVENT time (when the event fired), not send time — for campaign/flow performance matching the Klaviyo UI, use klaviyo_get_campaign_report or klaviyo_get_flow_report instead. Use this only for time-series/dimension breakdowns those two don't support. - `klaviyo_query_segment_series` [read-only] — Get segment membership statistics (members_added, members_removed, net_members_changed, total_members) as a time series broken into hourly/daily/weekly/monthly intervals. Data unavailable before June 1 2023; max timeframe span 1 year. - `klaviyo_query_segment_values` [read-only] — Get aggregate segment membership statistics (members_added, members_removed, net_members_changed, total_members) as totals across a timeframe, not broken into a time series. Data unavailable before June 1 2023; max timeframe span 1 year. - `klaviyo_refresh_campaign_recipient_estimation` [write, off by default] — Trigger an async job to recompute the estimated recipient count for a campaign. Poll with get_campaign_recipient_estimation_job, then read the result with get_campaign_recipient_estimation. - `klaviyo_remove_profiles_from_list` [write, off by default] — Remove one or more profiles from a Klaviyo list by profile ID (max 1,000 per request). Does not change subscription/consent status. - `klaviyo_render_template` [read-only] — Render a Klaviyo template with sample data to preview the final HTML/text output. - `klaviyo_send_campaign` [write, off by default] — Trigger an immediate send of a Klaviyo campaign. - `klaviyo_subscribe_profile` [write, off by default] — Opt a profile in to email or SMS marketing consent for a specific list. - `klaviyo_tag_resource` [write, off by default] — Apply an existing tag to a campaign, flow, list, or segment. - `klaviyo_unsubscribe_profile` [write, off by default] — Opt a profile out of email or SMS marketing consent for a specific list. - `klaviyo_update_campaign` [write, off by default] — Update a Klaviyo campaign's name, audience, or schedule. - `klaviyo_update_campaign_message` [write, off by default] — Update the content of an email campaign message (subject, preview text, from address, reply-to, cc/bcc, label). - `klaviyo_update_dnd_email_template` [write, off by default] — Update an existing drag-and-drop (DND) email template's name, text, or structured definition. The definition fully replaces the existing one — partial section/block updates are not supported. - `klaviyo_update_flow_status` [write, off by default] — Activate, pause (manual), or set a Klaviyo flow to draft. Cannot create or edit flow logic — Klaviyo's API doesn't support authoring flows. - `klaviyo_update_image` [write, off by default] — Rename an image in the Klaviyo library or hide/unhide it from the asset library. - `klaviyo_update_image_for_campaign_message` [write, off by default] — Set or swap the image used inside a specific Klaviyo campaign message. Provide the ID of an existing image, e.g. one uploaded with klaviyo_upload_image_from_url. - `klaviyo_update_list` [write, off by default] — Update a Klaviyo list's name or opt-in process. - `klaviyo_update_profile` [write, off by default] — Update an existing Klaviyo profile's attributes or custom properties. - `klaviyo_update_segment` [write, off by default] — Update a Klaviyo segment's name or condition definition. - `klaviyo_update_template` [write, off by default] — Update an existing Klaviyo email template's name or HTML content. - `klaviyo_update_translation` [write, off by default] — BETA. Update a translation's settings and/or import translation values. All attributes are optional; only provided fields are updated. To import values, first call klaviyo_get_translation with include_values, then provide the values array with updated translations (each value has a composite id like 'scheduled_message::abc::subject' and a translations map of locale codes to translated text). - `klaviyo_update_universal_content` [write, off by default] — Update a Klaviyo universal content block's name or definition. The definition can only be updated for button, drop_shadow, horizontal_rule, html, image, spacer, and text block types. - `klaviyo_upload_image_from_url` [write, off by default] — Import an image into Klaviyo's image library from a public URL, for use in campaigns/templates. ## GitHub Repositories, issues, pull requests, Actions, code/secret/dependency security alerts, Discussions, Projects, gists, notifications, and more. 124 tools: 63 read-only, 61 write. - `github_actions_get` [read-only] — Get details about specific GitHub Actions resources -- individual workflows, workflow runs, jobs, and artifacts by their unique IDs. Select the resource with 'method'. - `github_actions_list` [read-only] — List GitHub Actions resources -- workflows in a repository, or workflow runs/jobs/artifacts for a specific workflow or run. Select the resource with 'method'. - `github_actions_run_trigger` [write, off by default] — Trigger GitHub Actions workflow operations, including running, re-running, cancelling workflow runs, and deleting workflow run logs. - `github_add_comment_to_pending_review` [write, off by default] — Add a review comment to the requester's latest pending pull request review. A pending review must already exist. - `github_add_issue_comment` [write, off by default] — Add a comment and/or reaction to a specific issue or issue comment in a GitHub repository. Also works for pull requests (pass the PR number as issue_number). - `github_add_issue_comment_reaction` [write, off by default] — Add a reaction to an issue or pull request comment. - `github_add_issue_reaction` [write, off by default] — Add a reaction to an issue or pull request. - `github_add_pull_request_review_comment` [write, off by default] — Add a review comment to the current user's pending pull request review. A pending review must already exist. - `github_add_pull_request_review_comment_reaction` [write, off by default] — Add a reaction to a pull request review comment. - `github_add_reply_to_pull_request_comment` [write, off by default] — Add a reply and/or reaction to an existing pull request comment. Can create a reply comment, add an emoji reaction, or both. At least one of body or reaction is required. - `github_add_sub_issue` [write, off by default] — Add a sub-issue to a parent issue. - `github_assign_copilot_to_issue` [write, off by default] — Assign Copilot to a specific issue in a GitHub repository. Outcome: a Pull Request created with source code changes to resolve the issue. - `github_assign_copilot_to_issue_with_intent` [write, off by default] — Assign Copilot to a specific issue, with intent metadata (rationale, confidence, is_suggestion) attached. Prefer this over assign_copilot_to_issue when available. - `github_create_branch` [write, off by default] — Create a new branch in a GitHub repository. - `github_create_gist` [write, off by default] — Create a new gist. - `github_create_issue` [write, off by default] — Create a new issue in a GitHub repository with a title and optional body. - `github_create_or_update_file` [write, off by default] — Create or update a single file in a GitHub repository. If updating, provide the SHA of the file being updated (get it from get_file_contents). - `github_create_pull_request` [write, off by default] — Create a new pull request in a GitHub repository. - `github_create_pull_request_review` [write, off by default] — Create a review on a pull request. If event is provided, the review is submitted immediately; otherwise a pending review is created. - `github_create_repository` [write, off by default] — Create a new GitHub repository in your account or a specified organization. - `github_create_repository_ruleset` [write, off by default] — Create a new ruleset at the repository, organization, or enterprise level. - `github_custom_properties_read` [read-only] — Read custom properties at the repository, organization, or enterprise level. At the repository level this returns the property values assigned to a repository; at the organization and enterprise levels it returns the property definitions (schema). - `github_custom_properties_write` [write, off by default] — Create or update custom properties at the repository, organization, or enterprise level. At the repository level this sets property values (the properties must already be defined for the organization). Organization and enterprise definition writes preserve omitted writable fields by reading current definitions immediately before updating; concurrent definition updates remain last-write-wins. - `github_delete_file` [write, destructive, off by default] — Delete a file from a GitHub repository. IRREVERSIBLE -- requires explicit confirmation. - `github_delete_pending_pull_request_review` [write, off by default] — Delete a pending pull request review. - `github_delete_repository` [write, destructive, off by default] — Delete a GitHub repository. IRREVERSIBLE -- requires explicit confirmation of the exact owner/repository name before executing. - `github_discussion_comment_write` [write, off by default] — Write operations for discussion comments: add a top-level comment, reply, update, delete, or mark/unmark as the answer -- selected via a method parameter. - `github_dismiss_notification` [write, off by default] — Dismiss a notification by marking it as read or done. - `github_find_duplicate` [read-only] — Find likely duplicate issues for an existing issue in a GitHub repository. Read-only: returns ranked candidate issues with a similarity score and confidence, does not close/link/modify anything. - `github_fork_repository` [write, off by default] — Fork a GitHub repository to your account or a specified organization. - `github_get_code_quality_finding` [read-only] — Get details of a specific code quality finding in a GitHub repository. - `github_get_code_scanning_alert` [read-only] — Get details of a specific code scanning alert in a GitHub repository. - `github_get_commit` [read-only] — Get details for a commit from a GitHub repository. - `github_get_dependabot_alert` [read-only] — Get details of a specific dependabot alert in a GitHub repository. - `github_get_discussion` [read-only] — Get a specific discussion by ID. - `github_get_discussion_comments` [read-only] — Get comments from a discussion. - `github_get_file_blame` [read-only] — Get git blame information for a file, showing the commit that last modified each line. Uses GitHub's GraphQL API since blame has no REST equivalent. Optionally restrict to a line window with start_line/end_line. - `github_get_file_contents` [read-only] — Get the contents of a file or directory from a GitHub repository. Returns GitHub's native Contents API shape -- file content comes back base64-encoded, directories come back as an array of entries. - `github_get_gist` [read-only] — Get gist content of a particular gist, by gist ID. - `github_get_global_security_advisory` [read-only] — Get a global security advisory. - `github_get_issue` [read-only] — Get details of a specific GitHub issue. - `github_get_job_logs` [read-only] — Get logs for GitHub Actions workflow jobs -- a specific job (job_id) or all failed jobs in a run (run_id with failed_only=true). - `github_get_label` [read-only] — Get a specific label from a repository. - `github_get_latest_release` [read-only] — Get the latest release in a GitHub repository. - `github_get_me` [read-only] — Get details of the authenticated GitHub user. Use this when a request is about the user's own profile, or when information is missing to build other tool calls. - `github_get_notification_details` [read-only] — Get detailed information for a specific GitHub notification. - `github_get_pull_request` [read-only] — Get details of a specific GitHub pull request. - `github_get_release_by_tag` [read-only] — Get a specific release by its tag name in a GitHub repository. - `github_get_repository_tree` [read-only] — Get the tree structure (files and directories) of a GitHub repository at a specific ref or SHA. - `github_get_secret_scanning_alert` [read-only] — Get details of a specific secret scanning alert in a GitHub repository. - `github_get_tag` [read-only] — Get details about a specific git tag in a GitHub repository. - `github_get_team_members` [read-only] — Get member usernames of a specific team in an organization. Limited to organizations accessible with current credentials. - `github_get_teams` [read-only] — Get details of the teams the current user is a member of. Limited to organizations accessible with current credentials. - `github_issue_dependency_read` [read-only] — Read an issue's dependency relationships: the issues that block it (blocked_by) or the issues it blocks (blocking). - `github_issue_dependency_write` [write, off by default] — Add or remove an issue dependency relationship. Use type 'blocked_by' or 'blocking'. - `github_issue_read` [read-only] — Get information about a specific issue in a GitHub repository. - `github_issue_write` [write, off by default] — Create a new or update an existing issue in a GitHub repository. - `github_label_write` [write, off by default] — Perform write operations on repository labels (create/update/delete a label). To set labels on an issue, use issue_write instead. - `github_list_branches` [read-only] — List branches in a GitHub repository. - `github_list_code_scanning_alerts` [read-only] — List code scanning alerts in a GitHub repository. - `github_list_commits` [read-only] — Get list of commits of a branch in a GitHub repository. - `github_list_dependabot_alerts` [read-only] — List dependabot alerts in a GitHub repository. - `github_list_discussion_categories` [read-only] — List discussion categories with their id and name, for a repository or organization. - `github_list_discussions` [read-only] — List discussions for a repository or organization. - `github_list_gists` [read-only] — List gists for a user (defaults to the authenticated user). - `github_list_global_security_advisories` [read-only] — List global security advisories from GitHub. - `github_list_issue_fields` [read-only] — List issue fields for a repository or organization -- field definitions including name, type, and valid options for single_select fields. When repo is omitted, returns org-level fields directly. - `github_list_issues` [read-only] — List issues in a GitHub repository. For pagination, use the 'endCursor' from the previous response's 'pageInfo' in the 'after' parameter. - `github_list_issue_types` [read-only] — List supported issue types for a repository or its owner organization. When repo is omitted, returns org-level issue types directly. - `github_list_label` [read-only] — List labels from a repository, ordered by issue count (descending) so the most-used labels are returned first. - `github_list_notifications` [read-only] — List GitHub notifications for the authenticated user -- unread, mentions, review requests, assignments, and updates on issues/PRs. - `github_list_org_repository_security_advisories` [read-only] — List repository security advisories for a GitHub organization. - `github_list_pull_requests` [read-only] — List pull requests in a GitHub repository. If the caller wants to filter by author, use search_pull_requests instead. - `github_list_releases` [read-only] — List releases in a GitHub repository. - `github_list_repositories` [read-only] — List repositories for the authenticated user or organization. - `github_list_repository_collaborators` [read-only] — List collaborators of a GitHub repository. - `github_list_repository_security_advisories` [read-only] — List repository security advisories for a GitHub repository. - `github_list_secret_scanning_alerts` [read-only] — List secret scanning alerts in a GitHub repository. - `github_list_starred_repositories` [read-only] — List starred repositories for the authenticated user, or for a given username. - `github_list_tags` [read-only] — List git tags in a GitHub repository. - `github_manage_notification_subscription` [write, off by default] — Manage a notification subscription: ignore, watch, or delete a notification thread subscription. - `github_manage_repository_notification_subscription` [write, off by default] — Manage a repository notification subscription: ignore, watch, or delete notifications for a given repository. - `github_mark_all_notifications_read` [write, off by default] — Mark all notifications as read. - `github_merge_pull_request` [write, off by default] — Merge a pull request in a GitHub repository. - `github_projects_get` [read-only] — Get details about specific GitHub Projects v2 resources -- individual projects, project fields, project items, and project views by their unique IDs, selected via a method parameter. - `github_projects_list` [read-only] — List GitHub Projects v2 resources -- projects for a user/organization, or fields/items/views/status updates for a specific project, selected via a method parameter. - `github_projects_write` [write, off by default] — Create and manage GitHub Projects v2: create projects, add/update/delete items, bulk-update many items at once, manage views, create status updates, add iteration fields -- selected via a method parameter. - `github_pull_request_read` [read-only] — Get information on a specific pull request. method selects what to retrieve: get (details), get_diff (raw diff), get_status (combined commit status of the head commit), get_files (changed files), get_commits (commits on the PR), get_review_comments (review threads, cursor-paginated via after), get_reviews (submitted/pending reviews), get_comments (issue-style PR comments), get_check_runs (CI check runs for the head commit). - `github_pull_request_review_write` [write, off by default] — Create and/or submit/delete a review of a pull request. method selects the operation: create (start a pending review, or submit immediately if event is given), submit_pending (submit the caller's existing pending review), delete_pending (delete the caller's existing pending review), resolve_thread/unresolve_thread (operate on a review thread by thread_id; owner/repo/pull_number are ignored for these two methods but still required by the schema). - `github_push_files` [write, off by default] — Push multiple files to a GitHub repository in a single commit. The target branch must already exist -- create it first with create_branch if needed. - `github_remove_sub_issue` [write, off by default] — Remove a sub-issue from a parent issue. - `github_repository_ruleset_read` [read-only] — Read rulesets at the repository, organization, or enterprise level, and rule suites (rule evaluation results) at the repository or organization level. Select the level with 'level' and the operation with 'method'. - `github_reprioritize_sub_issue` [write, off by default] — Reprioritize (reorder) a sub-issue relative to other sub-issues. - `github_request_copilot_review` [write, off by default] — Request a GitHub Copilot code review for a pull request. - `github_request_pull_request_reviewers` [write, off by default] — Request reviewers for a pull request. - `github_resolve_review_thread` [write, off by default] — Resolve a review thread on a pull request. Resolving an already-resolved thread is a no-op. - `github_search_code` [read-only] — Fast and precise code search across ALL GitHub repositories using GitHub's native search engine. - `github_search_commits` [read-only] — Search for commits across GitHub repositories using GitHub's commit search syntax. Searches the default branch only. Scope with repo:owner/repo, org:, or user: -- unscoped queries match across all of GitHub. - `github_search_issues` [read-only] — Search issues using GitHub issues search syntax, scoped to is:issue. - `github_search_orgs` [read-only] — Find GitHub organizations by name, location, or other organization metadata. - `github_search_pull_requests` [read-only] — Search for pull requests in GitHub repositories, using GitHub issue search syntax already scoped to is:pr. - `github_search_repositories` [read-only] — Find GitHub repositories by name, description, readme, topics, or other metadata. - `github_search_users` [read-only] — Find GitHub users by username, real name, or other profile information. - `github_set_issue_fields` [write, off by default] — Set issue field values for an issue. Fields are organization-level custom fields. - `github_star_repository` [write, off by default] — Star a GitHub repository. - `github_sub_issue_write` [write, off by default] — Add a sub-issue to a parent issue in a GitHub repository. - `github_submit_pending_pull_request_review` [write, off by default] — Submit a pending pull request review. Requires a pending review already exist for the caller on this pull request. - `github_ui_get` [read-only] — Fetch reference data for common issue/PR fields: labels, assignees, milestones, issue types, branches, issue fields, reviewers. Useful for discovering valid values before creating/updating an issue or PR. - `github_unresolve_review_thread` [write, off by default] — Unresolve a previously resolved review thread. Unresolving an already-unresolved thread is a no-op. - `github_unstar_repository` [write, off by default] — Unstar a GitHub repository. - `github_update_gist` [write, off by default] — Update an existing gist. - `github_update_issue_assignees` [write, off by default] — Update (replace) the assignees of an existing issue. - `github_update_issue_body` [write, off by default] — Update the body content of an existing issue. - `github_update_issue_labels` [write, off by default] — Update (replace) the labels of an existing issue. - `github_update_issue_milestone` [write, off by default] — Update the milestone of an existing issue. - `github_update_issue_state` [write, off by default] — Update the state of an existing issue (open or closed), with an optional state reason. - `github_update_issue_title` [write, off by default] — Update the title of an existing issue. - `github_update_issue_type` [write, off by default] — Set or remove the type of an existing issue. Pass null/omit to remove the current type. - `github_update_pull_request` [write, off by default] — Update an existing pull request in a GitHub repository. Provide at least one of title/body/state/draft/base/maintainer_can_modify/reviewers. - `github_update_pull_request_body` [write, off by default] — Update the body description of an existing pull request. - `github_update_pull_request_branch` [write, off by default] — Update the branch of a pull request with the latest changes from the base branch. - `github_update_pull_request_draft_state` [write, off by default] — Mark a pull request as draft or ready for review. - `github_update_pull_request_state` [write, off by default] — Update the state of an existing pull request (open or closed). - `github_update_pull_request_title` [write, off by default] — Update the title of an existing pull request. ## WordPress Diagnose and maintain a WordPress site over SSH, WP-CLI, and the WordPress and WooCommerce REST APIs. One connection manages one site. 109 tools: 80 read-only, 29 write. - `cpanel_provision_readonly_db_user` [write, destructive, off by default] — Creates a MySQL user through cPanel with SELECT and nothing else, granted on one database, and stores its credentials encrypted for the database tools to use. Run this once per site to enable the wordpress_db_* query tools. The point is that the resulting credential physically CANNOT write, and specifically has no FILE privilege — so `SELECT ... INTO OUTFILE` (which writes a webshell) and `LOAD_FILE()` (which reads arbitrary server files) are impossible rather than filtered. That is a guarantee from MySQL rather than from our own parsing, which is why database access waited for this. Modifies the hosting account by creating a database user. - `elementor_css_regenerate` [write, off by default] — Clears and regenerates Elementor's compiled per-page CSS. Low risk — the CSS is derived and rebuilds on the next page load — but on a busy site it causes a brief load spike while it does. The usual fix for 'I changed something in Elementor and the site still shows the old styling'. Modifies live site state. - `elementor_pages` [read-only] — Lists the posts and pages actually built with Elementor, found by their _elementor_edit_mode meta rather than by guessing from content. Important because a site can mix Elementor pages with ordinary ones, and editing an Elementor page through the normal content tools changes nothing a visitor sees. Read-only. - `elementor_page_structure` [read-only] — Returns the element tree of one Elementor page: every section, column and widget with its element id, widget type and a short text preview. The element ids are what elementor_text_replace targets. Structure only — it does not return full settings, which are large and mostly styling. Read-only. - `elementor_status` [read-only] — Reports whether Elementor is active, its version, and whether Elementor Pro is present. Call this before any other elementor_ tool. Read-only. - `elementor_text_replace` [write, destructive, off by default] — Replaces text in one Elementor widget setting, identified by post id, element id and setting key. Parses the document, changes that one setting, and writes the whole document back — it never does text substitution across the raw JSON, because a blind replace can match inside a CSS class or URL and corrupt the document, which renders as a blank page with no error. Takes a checkpoint of the whole document first and regenerates Elementor's CSS afterwards. Modifies the live site. - `elementor_text_replace_preview` [read-only] — Shows exactly what one Elementor text change would do — the current value, the proposed value, and how many occurrences match — without changing anything. Call this before elementor_text_replace so the change can be described before it is made. Read-only. - `elementor_text_search` [read-only] — Searches the visible text of Elementor pages for a phrase and returns every match with its post id, element id and setting key — exactly what elementor_text_replace needs. This is how you find a typo that ordinary post search cannot see, because Elementor text is not in post_content. Read-only. - `elementor_widget_get` [read-only] — Returns one widget's full settings by element id, including the raw text values with their HTML intact. Read this before replacing text, because the stored value usually contains markup that must be preserved. Read-only. - `hosting_disk_usage` [read-only] — Free and used disk space on the filesystem holding the site, plus the size of the site root and of wp-content's largest subdirectories. A nearly-full disk causes failed uploads, failed updates and database write errors, and is worth ruling out early on any 'suddenly broken' report. Read-only. - `hosting_environment_info` [read-only] — Server-level facts for one site: PHP version and the limits that matter (memory_limit, max_execution_time, upload_max_filesize, post_max_size), loaded PHP extensions, OPcache status, the operating system, and the web server. Read-only. This is server configuration, distinct from wordpress_get_site_info which reports WordPress itself. - `hosting_file_delete` [write, destructive, off by default] — Deletes one file under wp-content/, after copying it to a checkpoint so it can be restored. DESTRUCTIVE. Refuses directories — removing a directory tree is not something this offers, because the blast radius of a wrong path is unbounded. Modifies the live site. - `hosting_file_metadata` [read-only] — Size, permissions, owner and modification time for one file or directory inside the site root, without reading its contents. Useful for checking whether a file changed recently, or why it is not writable. Read-only. - `hosting_file_patch` [write, destructive, off by default] — Replaces one exact occurrence of a string in a file, leaving the rest untouched. Safer than hosting_file_write for a targeted change — fixing a typo, changing a constant — because it cannot accidentally discard the rest of the file. Fails if the search string is absent or appears more than once, so the change is unambiguous. Takes a checkpoint first. Modifies the live site. - `hosting_file_permissions_get` [read-only] — Reads the octal mode, owner and group of a file or directory, and says whether the SSH user can write to it. The usual answer to 'the update failed' and 'the media upload failed' is here. Read-only. - `hosting_file_permissions_set` [write, destructive, off by default] — Sets the octal mode of one file or directory under wp-content/. Restricted to a safe set of modes: 644 and 664 for files, 755 and 775 for directories. World-writable modes such as 777 are refused outright — they are a common bad fix for an upload problem and they let any other account on a shared host modify the site. Modifies the live site. - `hosting_file_write` [write, destructive, off by default] — Writes content to a file under wp-content/, replacing it entirely, after taking a checkpoint of the current version. Creates the file if it does not exist. DESTRUCTIVE: this replaces the whole file, not part of it — use hosting_file_patch to change one section. Writing to a PHP file that WordPress loads can take the site down immediately; the tool verifies WordPress still bootstraps afterwards and reports if it does not. - `hosting_file_write_preview` [read-only] — Shows exactly what a write would change without changing anything: whether the file exists, its current size and a diff-style summary of the replacement. Call this before hosting_file_write when the content is generated or the file is important, so the change can be described before it is made. Read-only. - `hosting_list_directory` [read-only] — Lists the contents of one directory inside the site root, with sizes, permissions and modification times. Paths are relative to the WordPress root and confined to it -- traversal outside, and credential files such as wp-config.php, are refused. Read-only. - `hosting_list_logs` [read-only] — Finds the log files ServeMCP can read for this site -- the WordPress debug log, PHP error logs, and common host log locations -- with their sizes and last-modified times. Call this before hosting_read_log to find out what exists. Read-only. - `hosting_read_file` [read-only, off by default] — Reads a text file inside the site root. Output is capped and secret-looking content is redacted before it leaves the server. wp-config.php is always refused, read included -- it holds the database password and every authentication salt; the safe constants from it are available through wordpress_get_site_info instead. OFF BY DEFAULT: reading arbitrary site files is a meaningful disclosure and should be enabled deliberately. Read-only. - `hosting_read_log` [read-only, off by default] — Reads the last N lines of a log file found by hosting_list_logs, newest last, with secrets redacted. Optionally filters to lines matching a term, which is the fast path to 'show me the fatal errors'. Logs frequently contain database credentials and customer personal data in stack traces, so this is OFF BY DEFAULT and its output is redacted. Read-only. - `hosting_recently_modified_files` [read-only] — Lists files under wp-content modified within the last N hours, newest first. This is one of the highest-value diagnostics available: when a site breaks without explanation, the files that changed just before it are usually the cause, and unexpected recently-modified PHP files are also a primary compromise signal. Reports observed filesystem modification times, which is evidence of a change but not proof of who made it. Read-only. - `seo_indexing_issues` [read-only] — Scans published posts and pages for the settings that quietly keep them out of search results: per-post noindex, a missing or over-length meta description, a missing SEO title, and a canonical pointing elsewhere. Combines that with the site-wide robots.txt and 'discourage search engines' setting. Read-only. This reports what the site is telling search engines, not what search engines have actually done — ServeMCP cannot see Search Console. - `seo_metadata_get` [read-only] — Reads the SEO title, meta description, canonical URL, robots directives and focus keyword for one post or page, from whichever supported plugin is active. An empty title or description means the plugin is falling back to its template, not that the page has none. Read-only. - `seo_metadata_update` [write, destructive, off by default] — Sets the SEO title, meta description or canonical URL for one post, recording the previous values as a checkpoint. Modifies the live site — these appear in search results and in social previews, and search engines may take days to re-crawl. Setting a canonical to another URL tells search engines this page is a duplicate and should not rank, so it is refused unless the URL is on the same site. - `seo_robots_get` [read-only] — Fetches the site's robots.txt and highlights rules that block crawling. A stray 'Disallow: /' — which WordPress serves automatically whenever the 'Discourage search engines' setting is on — removes the entire site from search results, and is one of the most common and least visible SEO faults. Read-only. - `seo_sitemap_status` [read-only] — Fetches the site's XML sitemap index and reports whether it responds, how many sub-sitemaps it lists, and its content type. Checks the active plugin's sitemap path and the WordPress core path. A sitemap returning 404 or HTML is a common and quiet cause of pages not being indexed. Read-only. - `seo_status` [read-only] — Reports which SEO plugin is active, its version, and whether ServeMCP can read and write its fields. Yoast SEO and Rank Math are supported; All in One SEO is detected but not supported, because since v4 it stores per-post data in its own database table rather than in post meta. Call this before any other seo_ tool. Read-only. - `woocommerce_action_scheduler_failed` [read-only] — Lists WooCommerce background actions that failed, with their hook, group and scheduled time. Each row is work the store intended to do and did not — a renewal not charged, an email not sent, a webhook not delivered. Read-only. - `woocommerce_action_scheduler_run` [write, destructive, off by default] — Runs WooCommerce's due background actions now, which is the documented way to drain a stuck queue. Modifies the live store, and the side effects are whatever the queued work does — sending customer emails, charging subscription renewals, delivering webhooks, adjusting stock. Draining a large backlog can therefore send a burst of real customer emails. Bounded by a batch limit and a hard timeout; run it repeatedly rather than raising the batch. - `woocommerce_action_scheduler_status` [read-only] — Counts WooCommerce background actions by status and reports how far behind the queue is. Action Scheduler runs the work WooCommerce defers — emails, subscription renewals, stock sync, webhook delivery, analytics — so a backed-up or failing queue is the usual explanation for 'orders are stuck', 'emails stopped', or 'inventory is not syncing' when nothing else looks wrong. Read-only. - `woocommerce_checkout_diagnostics` [read-only] — Checks the things that stop customers completing checkout: enabled payment gateways, shipping zones with no method, HTTPS and outbound-request health from WooCommerce's own system status, recent failed orders, and whether the cart and checkout pages resolve. Read-only, safe on a live store. Use when checkout is reported broken but no single order explains it. - `woocommerce_coupon_create` [write, destructive, off by default] — Creates a discount coupon. Modifies the live store: the code is usable by customers as soon as it exists, so a mistyped amount or a missing expiry is immediately spendable. Prefer setting an expiry and a usage limit. - `woocommerce_coupons_list` [read-only] — Lists discount coupons with their code, type, amount, usage counts and limits, and expiry. Read-only. - `woocommerce_customer_get` [read-only, off by default] — Full detail for one customer including billing and shipping addresses and order history totals. Returns personal data; off by default. Read-only. - `woocommerce_customers_list` [read-only, off by default] — Lists store customers with email, name, order count and spend. Returns personal data, so this is off by default and must be enabled deliberately. Read-only. - `woocommerce_inventory_diagnostics` [read-only] — Investigates why a SKU's stock is not what someone expects: resolves the SKU to its product and variations, reports which record actually holds the stock, checks whether stock management is enabled at all, and surfaces the background-queue and log evidence that explains a sync that is not running. Built for 'inventory is not updating'. Read-only. - `woocommerce_inventory_get` [read-only] — Resolves a SKU to its product or variation and reports the authoritative stock state: managed or not, quantity, status, backorder policy, and which record actually holds the stock. Built for 'why does the site say out of stock' -- it checks the variation as well as the parent, which is where that question usually goes wrong. Read-only. - `woocommerce_inventory_update` [write, destructive, off by default] — Sets stock quantity or stock status for one product or variation, recording the previous values as a checkpoint first. Modifies the live store, and stock changes are immediately visible to customers. Targets a variation directly when variation_id is given -- setting stock on a variable parent has no effect on what the storefront shows. - `woocommerce_log_read` [read-only, off by default] — Reads the tail of one WooCommerce log file listed by woocommerce_logs_list, with secrets redacted and an optional filter. Gateway logs contain the request and response detail behind a declined or errored payment. OFF BY DEFAULT: these logs routinely contain customer names, addresses and partial payment details. Read-only. - `woocommerce_logs_list` [read-only] — Lists the log files WooCommerce and its extensions have written, newest first, with sizes and dates. Payment gateways write their request and failure detail here under their own source name, which is usually where a failed payment's real cause lives. Read-only. - `woocommerce_order_diagnostics` [read-only] — Gathers everything relevant to a single order in one call: the order itself, its notes (where gateways record decline reasons), any WooCommerce log lines mentioning it, recent PHP fatals, and the state of the background queue. Built for 'why did order 12345 fail'. Returns labelled evidence and draws no conclusion. Read-only. Contains customer personal data. - `woocommerce_order_get` [read-only] — Full detail for one order: line items, addresses, totals, taxes, shipping, payment metadata, refunds and the order's own notes. This is the starting point for any question about a specific order. Read-only. Contains customer personal data. - `woocommerce_orders_list` [read-only] — Lists orders with a compact projection: number, status, total, dates, payment method and customer. Filter by status, customer, date range or search. Filtering to status 'failed' is the fastest way to see whether checkout is broken and since when. Read-only. - `woocommerce_order_update` [write, destructive, off by default] — Changes an order's status, optionally adding a note. Records the previous status as a checkpoint. DESTRUCTIVE and consequential beyond the database: WooCommerce fires actions on status change, which commonly send customer emails, trigger fulfilment integrations, restock inventory (on cancelled/refunded) and issue payment captures. Marking an order 'completed' typically emails the customer. Modifies the live store. - `woocommerce_payment_gateways` [read-only] — Lists payment gateways with their enabled state, title and order. The first thing to check for 'customers cannot pay' — a gateway that is installed but disabled, or enabled but missing credentials, looks identical from the storefront. Gateway settings are returned with secret values redacted. Read-only. - `woocommerce_product_get` [read-only] — Full detail for one product, including descriptions, categories, images, attributes, dimensions and metadata. Use after woocommerce_products_list when the trimmed row is not enough. Read-only. - `woocommerce_products_list` [read-only] — Lists products with a compact projection: id, name, SKU, type, status, prices, and stock. Supports search, SKU lookup, status and stock filters, and pagination. Returns trimmed rows rather than full product objects, because a full Woo product is routinely 30-60KB and a page of them would exceed the result limit while adding nothing useful. Read-only. - `woocommerce_product_update` [write, destructive, off by default] — Updates fields on one product: name, status, prices, description, or SKU. Records the previous values as a checkpoint. Modifies the live store — price and status changes are immediately visible to customers. Does not touch stock; use woocommerce_inventory_update for that. - `woocommerce_shipping_zones` [read-only] — Lists shipping zones with their regions and the methods enabled in each. The usual explanation for 'no shipping options at checkout' is an address that matches no zone, or a zone with no enabled method. Read-only. - `woocommerce_system_status` [read-only] — WooCommerce's own system report: versions, database status, active plugins, theme, template overrides, and the environment checks Woo itself flags. Outdated template overrides after a Woo update are a frequent and hard-to-spot cause of broken cart and checkout pages, and this is where they surface. Read-only. - `woocommerce_variations_list` [read-only] — Lists the variations of a variable product, with their own SKUs, prices and stock. A variable product's own stock fields are usually empty -- the real inventory lives on its variations, which is the single most common source of confusion about Woo stock levels. Read-only. - `wordpress_activate_plugin` [write, off by default] — Activates one already-installed plugin. Records a state checkpoint first so the change can be reversed, and verifies WordPress still loads afterwards. Modifies the live site. Does NOT install anything -- the plugin must already be present; use wordpress_list_plugins to confirm. - `wordpress_categories_list` [read-only] — Lists post categories with their ids, slugs, post counts and parents. The ids are what wordpress_post_create and wordpress_post_update expect. Read-only. - `wordpress_checkpoint_create` [write, off by default] — Copies one plugin or theme directory to a checkpoint on the site's own server, so a change you are about to make by hand can be undone. The write tools create their own checkpoints automatically -- this is for changes made outside ServeMCP. Scoped to a single component and capped at 200MB; a whole site is far too large and needs a real backup. Checkpoints are operation rollback, not backups: they are stored on the site's own server, are scoped to a single component, and expire after 7 days. They do not survive server loss. Modifies the customer's server by writing files. - `wordpress_comment_moderate` [write, destructive, off by default] — Approves, holds, spams or trashes one comment. Marking as spam trains the site's spam filter, which is a side effect beyond this one comment. Modifies the live site — approving publishes the comment for all visitors immediately. - `wordpress_comments_list` [read-only, off by default] — Lists comments with their status, author and the post each belongs to. Filter to status='hold' to see the moderation queue. Returns commenter names and email addresses, so this is off by default. Read-only. - `wordpress_core_check_updates` [read-only] — Asks wordpress.org whether a newer WordPress core version is available for this site. Read-only: it reports what is available and changes nothing. ServeMCP does not perform core updates -- the only honest rollback for one is a full-site backup, which is not yet available. - `wordpress_core_verify_checksums` [read-only] — Compares every WordPress core file against the official wordpress.org manifest for the installed version and reports mismatches or unexpected files. The strongest single signal that core has been tampered with. Read-only, and slow on large installs. A clean result does not prove a site is uncompromised -- it only covers core files, not plugins, themes or uploads. - `wordpress_cron_due_events` [read-only] — Returns only the cron events that are due or overdue, with how far behind each is. A large or growing backlog here is one of the clearest signals behind 'the site is slow', 'emails stopped sending', or 'orders are stuck' -- WP-Cron only fires on page requests, so a low-traffic site silently stops processing. Read-only. - `wordpress_db_autoload_options` [read-only] — Lists the largest autoloaded options with their exact sizes and a running total. Autoloaded options are read from the database on EVERY request, so their combined weight is one of the few numbers that reliably correlates with a slow site — WordPress itself flags totals above 800KB. This gives the per-option breakdown that makes the total actionable, rather than just the number. Read-only. - `wordpress_db_health` [read-only] — Reports total database size and runs MySQL's own CHECK TABLE across the WordPress tables, reporting any that are not OK. Read-only. This uses WP-CLI's structured subcommands, not raw SQL -- ServeMCP does not expose arbitrary queries. - `wordpress_db_orphaned_metadata` [read-only] — Counts post, comment and term metadata rows whose parent no longer exists. These accumulate when plugins are removed or posts are hard-deleted, and on an old site they can be a large fraction of the database. Reports counts only and deletes nothing — cleaning them up is a write this integration does not offer, because a plugin can legitimately store metadata against ids it manages itself. Read-only. - `wordpress_db_query` [read-only, off by default] — Runs a SELECT, SHOW, DESCRIBE or EXPLAIN query against the site's WordPress database and returns the rows. Uses a MySQL user holding SELECT on one database and nothing else — with no FILE privilege, so INTO OUTFILE and LOAD_FILE are impossible at the server rather than filtered by us. Requires cpanel_provision_readonly_db_user to have been run once. Results are bounded and a LIMIT is applied automatically. Read-only, genuinely: the credential cannot write. - `wordpress_db_search` [read-only, off by default] — Searches post content, titles and option values for a string and reports where it appears, with counts per table. Built for questions ordinary WordPress search cannot answer: finding a hardcoded old domain, a stray tracking script, or which option holds a value. Uses the read-only credential and returns bounded results. Read-only. - `wordpress_db_table_report` [read-only] — Reports every table in the WordPress database with row counts, data and index sizes, engine and collation. More detail than wordpress_db_table_sizes: it separates index weight from data weight, which is what tells you whether a large table is large because of content or because of indexes. Read-only. - `wordpress_db_table_sizes` [read-only] — Lists WordPress database tables largest first, with row counts and sizes. The fastest way to find what is actually bloating a database -- usually wp_options, wp_postmeta, an Action Scheduler table, or a logging plugin's table. Read-only, via WP-CLI's structured output rather than SQL. - `wordpress_deactivate_plugin` [write, destructive, off by default] — Deactivates one plugin. Marked destructive because deactivating a security, caching or commerce plugin can take a site offline or expose it -- this is a consequential change even though it is easily reversed. Records a state checkpoint and verifies WordPress still loads. Modifies the live site. This is the standard first move when a plugin is suspected of causing a fatal error. - `wordpress_delete_expired_transients` [write, off by default] — Deletes transients whose expiry has already passed. Low risk: these are cache entries WordPress already considers invalid, and anything still needed is regenerated on demand. Modifies live site state. - `wordpress_diagnose_issue` [read-only] — Gathers a targeted evidence bundle for a reported symptom -- HTTP response and redirects, recent PHP fatals, files changed recently, plugin and update state, cron backlog, disk and database facts -- choosing which probes to run based on the symptom. Returns raw evidence with provenance for you to reason over; it deliberately does NOT decide the cause itself. Read-only and safe to run on a production site at any time. Use this rather than calling ten low-level tools by hand when someone reports something broken. - `wordpress_flush_cache` [write, off by default] — Flushes the WordPress object cache. Low risk and trivially reversible -- the cache simply repopulates -- but on a busy site it causes a brief load spike as caches rebuild. Has no effect on page caches served by a plugin or CDN. Modifies live site state. - `wordpress_get_checkpoint` [read-only] — Full detail for one checkpoint, including the manifest recording the state before the change -- previous plugin versions, the prior option value, or the files copied. Read this before restoring, and to recover a previous value you intend to set back by hand. Checkpoints are operation rollback, not backups: they are stored on the site's own server, are scoped to a single component, and expire after 7 days. They do not survive server loss. Read-only. - `wordpress_get_option` [read-only] — Reads one WordPress option by name. Values are returned both interpreted and raw where they differ, because many plugin options are PHP-serialized. Secret-looking values are redacted before they leave the server -- plugin option blobs routinely contain payment-gateway keys. Read-only. - `wordpress_get_plugin` [read-only] — Detail for one installed plugin: version, activation state, available update, author and description. Use after wordpress_list_plugins when you need more about a specific plugin. Read-only. - `wordpress_get_site_info` [read-only] — Core facts about one WordPress install: version, whether an update is available, multisite status, site and home URLs, environment type, debug configuration, and whether maintenance mode is on. This is the cheapest orientation call for a site you have not looked at yet. Read-only. - `wordpress_health_check` [read-only] — One comprehensive read-only health report for a site, gathered in a single SSH session: WordPress and PHP versions, update counts, plugin and theme state, cron backlog, database size and largest tables, disk space, recent PHP fatal errors, core checksum verification, and the site's HTTP response. Returns an overall status with severity-ranked findings and recommended next actions. Never changes anything. This is the right first call for 'check my site and tell me if anything is wrong'. Degrades gracefully: anything it could not determine is listed under `unavailable` with the reason, rather than being silently omitted. - `wordpress_http_check` [read-only] — Fetches a path on the site over HTTPS and reports the status code, the full redirect chain, response time, server and cache headers, and TLS certificate validity with days remaining. Also probes the WordPress REST API root. This is the outside-in view -- what a visitor actually gets -- and pairs with the server-side tools when a site is reported down, slow, or looping. Restricted to the site's own registered domain. Read-only. - `wordpress_list_checkpoints` [read-only] — Lists the rollback checkpoints ServeMCP holds for a site, newest first, with the tool that created each, what it covers, its size and expiry. Use this to find what can be undone. Checkpoints are operation rollback, not backups: they are stored on the site's own server, are scoped to a single component, and expire after 7 days. They do not survive server loss. Read-only. - `wordpress_list_cron_events` [read-only] — Lists scheduled WP-Cron events with their next-run times and recurrence. Read-only. - `wordpress_list_plugins` [read-only] — Lists every installed plugin with its activation state, installed version, whether an update is available and to which version, and auto-update setting. The first call for 'what is outdated', 'what is active', or 'is plugin X installed'. Read-only. - `wordpress_list_sites` [read-only] — Lists every WordPress site connected to this workspace, with the handle to pass as `site` to every other WordPress tool. Start here when you do not already know a site's handle. Read-only; touches no customer server. - `wordpress_list_themes` [read-only] — Lists installed themes with the active one marked, plus versions and available updates. Read-only. - `wordpress_list_users` [read-only, off by default] — Lists WordPress users with their roles and registration dates. Returns personal data (names, email addresses), so it is OFF BY DEFAULT and must be enabled per workspace. The security-relevant use is spotting administrator accounts nobody recognises. Read-only. - `wordpress_media_delete` [write, destructive, off by default] — Permanently deletes a media item and its generated thumbnail files. DESTRUCTIVE and not reversible: WordPress does not trash media, and any post still referencing the file will show a broken image. Check the attached_to_post field from wordpress_media_list first. Modifies the live site. - `wordpress_media_list` [read-only] — Lists media library items with type, MIME, file size and the post each is attached to. Useful for finding what is consuming uploads space and for locating an image by name. Read-only. - `wordpress_page_get` [read-only] — Full detail for one page including its raw editable content, parent, menu order and page template. Read the raw content before editing — the rendered version has blocks and shortcodes already expanded and cannot be written back. Read-only. - `wordpress_pages_list` [read-only] — Lists pages newest-modified first, including drafts. Pages are the site's structural content — home, contact, policies — so this is usually where 'fix the typo on the homepage' starts. Read-only. - `wordpress_page_update` [write, destructive, off by default] — Updates a page's title, content or status, recording the previous values as a checkpoint. Modifies the live site — an edit to a published page is visible to visitors immediately. Pages built with a page builder (Elementor, Divi, Beaver) store their layout separately, and editing content here can be ignored or can break the layout; check wordpress_site_capabilities for an active builder before editing. - `wordpress_performance_check` [read-only] — Measures the outside and inspects the inside of a site in one pass: homepage timing and TTFB, redirect count, cache and CDN headers, PHP version and memory limit, OPcache, object-cache backend, autoloaded option weight, database and largest-table sizes, cron backlog, plugin count, and expired transients. Returns measured facts with the thresholds that make them meaningful. Read-only. IMPORTANT: ServeMCP has no profiler inside PHP, so it cannot say which plugin is slow — it reports evidence and leaves the correlation to you. - `wordpress_plugin_verify_checksums` [read-only] — Compares a plugin's files against the wordpress.org manifest for its installed version and reports modified or unexpected files. Useful when a plugin is suspected of being tampered with, or after an unexplained behaviour change. Only works for plugins distributed through wordpress.org -- premium and custom plugins have no published checksums and will report as unverifiable rather than as clean. Read-only. - `wordpress_post_create` [write, off by default] — Creates a post. Defaults to draft status deliberately — a tool that publishes by default turns a small mistake into something customers see. Pass status='publish' explicitly to publish. Modifies the live site. - `wordpress_post_delete` [write, destructive, off by default] — Moves a post to trash, or permanently deletes it with force=true. Trashing is reversible from wp-admin; force=true is NOT — it bypasses the trash and no revision survives. DESTRUCTIVE. Modifies the live site. - `wordpress_post_get` [read-only] — Full detail for one post including its raw content, which is what you need before editing it — the rendered version has shortcodes and blocks already expanded and cannot be written back. Read-only. - `wordpress_posts_list` [read-only] — Lists posts newest-modified first, with title, slug, status, author and excerpt. Includes drafts and private posts, which is why it needs an application password rather than being readable anonymously. Read-only. - `wordpress_post_update` [write, destructive, off by default] — Updates a post's title, content, status or taxonomy, recording the previous values as a checkpoint first. Modifies the live site — editing a published post changes what visitors see immediately. WordPress also keeps its own revision, so an edit is recoverable from wp-admin even without the checkpoint. - `wordpress_recent_changes` [read-only] — Answers 'what changed recently?' by combining three separately-labelled sources: files modified on disk, plugin and theme versions WordPress records as recently updated, and changes ServeMCP itself made (from its own audit log and checkpoints). Each is reported with explicit provenance and they are NEVER merged, because 'this file changed' and 'we changed this' are different claims with different reliability. Read-only. The usual companion to a site that broke without an obvious cause. - `wordpress_restore_checkpoint` [write, destructive, off by default] — Restores a file checkpoint over its original location, replacing the current files. This is how you undo a plugin or theme update that broke a site. DESTRUCTIVE: it deletes what is there now and puts the checkpointed copy back, so any change made since the checkpoint is lost. Requires ADMIN. State-only checkpoints (plugin activation, option values) cannot be restored this way -- reverse those with the matching tool, using the previous value from wordpress_get_checkpoint. Checkpoints are operation rollback, not backups: they are stored on the site's own server, are scoped to a single component, and expire after 7 days. They do not survive server loss. - `wordpress_restore_file_checkpoint` [write, destructive, off by default] — Restores one file from a checkpoint taken by a write, patch or delete, putting the previous version back. If the checkpoint recorded that the file did not exist, this deletes it instead — which is the correct reversal of a create. Verifies WordPress still bootstraps afterwards. Requires ADMIN. DESTRUCTIVE: whatever is at that path now is replaced. - `wordpress_search_options` [read-only] — Lists option names matching a pattern, with their sizes and autoload flags -- without returning the values. Built for two questions: which plugin owns an option, and what is bloating the autoloaded option set (a classic cause of slow admin pages). Read-only. - `wordpress_security_scan` [read-only] — Runs practical security HEURISTICS: core checksum verification, PHP files in the uploads directory (which should never contain executable code), recently modified PHP files, administrator account count, whether WP_DEBUG or a public debug.log is exposing information, and file permissions on sensitive paths. Read-only and never deletes or quarantines anything. IMPORTANT: this is not malware detection and must not be described as such -- a clean result is weak evidence, and a finding is a prompt to investigate rather than proof of compromise. - `wordpress_set_option` [write, destructive, off by default] — Sets one WordPress option, recording the previous value as a checkpoint first. Modifies the live site. A protected set is always refused: siteurl and home (which take a site offline instantly), active_plugins, template and stylesheet (which bypass the activation tools and their checkpoints), and users_can_register with default_role (a privilege-escalation pair). Change those from wp-admin if you are certain. - `wordpress_settings_get` [read-only] — Reads the general site settings the REST API exposes: title, tagline, timezone, date and time formats, language, default category, and whether comments and registration are open. Read-only. - `wordpress_site_capabilities` [read-only] — Reports what ServeMCP can actually do on one site: SSH, WP-CLI and its version, PHP version, whether wp-content is writable, free disk, and whether WooCommerce is active. Call this first when a tool has failed with a capability error, or to decide between two approaches. Re-detects live over SSH when the cached answer is older than 24 hours. - `wordpress_tags_list` [read-only] — Lists post tags with their ids, slugs and post counts. The ids are what wordpress_post_create and wordpress_post_update expect. Read-only. - `wordpress_test_cron` [read-only] — Checks whether WP-Cron can actually run on this site by performing a spawn test, and reports whether DISABLE_WP_CRON is set. Use when scheduled work appears stuck. Read-only: it tests the mechanism without running any due jobs. - `wordpress_transient_stats` [read-only] — Counts transients and how many have expired but not been cleaned up. A large expired-transient population bloats wp_options and slows every page load that autoloads them. Read-only. - `wordpress_update_plugin` [write, destructive, off by default] — Updates one installed plugin to its latest version. Copies the plugin's directory to a checkpoint on the site's own server first, applies the update, then verifies WordPress still loads and no new fatal error appeared. With rollback_on_failure (the default) a failed verification restores the previous version automatically and reports what went wrong. Modifies the live site, one plugin per call. If this times out the update may have PARTIALLY applied -- re-read wordpress_list_plugins before retrying rather than calling again. - `wordpress_update_theme` [write, destructive, off by default] — Updates one installed theme to its latest version, taking a file checkpoint of the theme directory first and verifying WordPress still loads afterwards. Modifies the live site. Updating the ACTIVE theme is the higher-risk case, since a broken active theme takes the front end down immediately. ## Meta (Facebook & Instagram) Facebook Pages, Instagram, and ad campaign management. 92 tools: 54 read-only, 38 write. - `meta_ads_activate_entity` [write, destructive, off by default] — Start delivery on a paused campaign, ad set or ad. THIS BEGINS SPENDING REAL MONEY immediately. Reports the entity's current budget back so the amount at risk is visible before and after. - `meta_ads_boost_instagram_post` [write, off by default] — Turn an existing organic Instagram post into an ad creative, ready to run. This creates only the creative -- pass its id to meta_ads_create_ad_set and meta_ads_create_ad to actually start delivery, the same two-step flow every other ad creation path in this integration uses. Not every post can be boosted (copyrighted music and interactive filters are excluded); check with meta_ads_get_ad_preview first if unsure. - `meta_ads_connect_catalog_event_source` [write, off by default] — Connect a pixel, app or offline event set to a catalog, enabling dynamic ads to retarget people who interacted with its products. - `meta_ads_create_abtest` [write, off by default] — Create a split test comparing two or more campaigns, ad sets, or (for a creative test) ads. Traffic is divided between cells by treatmentPercentage, which must sum to 100 across all cells. - `meta_ads_create_ad` [write, off by default] — Create an ad by attaching a creative to an ad set. Always created PAUSED — the ad set and campaign must also be active before anything delivers. - `meta_ads_create_ad_set` [write, off by default] — Create an ad set under a campaign with targeting, budget, schedule and optimization goal. Always created PAUSED. For conversion optimization you must supply promotedObject naming the pixel and event. - `meta_ads_create_campaign` [write, off by default] — Create a Meta ad campaign. Always created PAUSED - use meta_ads_activate_entity to start spending. Supports objective, daily or lifetime budget, bid strategy, spend cap and special ad categories. - `meta_ads_create_catalog` [write, off by default] — Create a new, empty product catalog on a Business Portfolio. Use vertical 'commerce' for a standard e-commerce product catalog, or 'test_vertical' for a catalog meant purely for testing. - `meta_ads_create_catalog_feed` [write, off by default] — Register a recurring feed on a catalog: a URL Meta fetches on a schedule to keep the catalog's products in sync. - `meta_ads_create_catalog_feed_rule` [write, off by default] — Add a rule that transforms or maps an attribute during feed ingestion, e.g. set availability to 'out of stock' when inventory is 0. Applies to future imports, not products already loaded. - `meta_ads_create_catalog_feed_upload_session` [write, off by default] — Trigger an immediate, one-time import from a feed's URL, without waiting for its next scheduled run. Useful right after fixing a feed problem. - `meta_ads_create_catalog_product` [write, off by default] — Add a single product to a catalog. retailerId is your own SKU and must be unique within the catalog — re-using one updates that product instead of creating a duplicate. For bulk loading, use a product feed instead. - `meta_ads_create_catalog_product_set` [write, off by default] — Create a product set from a filter rule, e.g. {and:[{category:{i_contains:'shoes'}}]}. The set stays live — products entering or leaving the catalog that match the filter join or drop automatically. - `meta_ads_create_creative` [write, off by default] — Create an ad creative — either a link ad from an image plus copy, or a promotion of an existing Page or Instagram post. Returns a creative ID for meta_ads_create_ad. - `meta_ads_create_custom_audience` [write, off by default] — Create a custom audience. CUSTOM creates an empty customer list to populate with meta_ads_update_custom_audience_users. WEBSITE and ENGAGEMENT need a rule. LOOKALIKE needs an origin audience, country and ratio. - `meta_ads_create_lift_study` [write, off by default] — Create a conversion lift study: a holdout-based measurement of the real incremental conversions your ads cause, as opposed to conversions that would have happened anyway. - `meta_ads_delete_catalog_feed` [write, destructive, off by default] — Permanently delete a product feed and its schedule. Products already imported through it are not removed — only the recurring sync stops. - `meta_ads_delete_catalog_feed_rule` [write, destructive, off by default] — Permanently delete a feed transformation rule. Future imports stop applying it; products already transformed by it are not reverted. - `meta_ads_delete_catalog_product` [write, destructive, off by default] — Permanently remove a product from a catalog. Cannot be undone, and the product drops out of any product set or dynamic ad using it immediately. - `meta_ads_delete_catalog_product_set` [write, destructive, off by default] — Permanently delete a product set. Any ad set targeting it as a Dynamic Ads audience stops delivering. Products themselves are not affected. - `meta_ads_delete_custom_audience` [write, destructive, off by default] — Permanently delete a custom audience. This cannot be undone, and any ad set targeting it stops delivering to that audience. Refuses while ad sets still reference it unless force is set. - `meta_ads_disconnect_catalog_event_source` [write, destructive, off by default] — Remove a pixel, app or offline event set from a catalog. Dynamic ads retargeting driven by that source stops for this catalog. - `meta_ads_get_abtest` [read-only, off by default] — Details, status and results for an existing A/B (split) test — cells, allocation, and per-objective results once concluded. - `meta_ads_get_activity_logs` [read-only, off by default] — Activity log entries for an ad account -- who changed what, and when. Filter by date range or category (e.g. BUDGET, STATUS, TARGETING). - `meta_ads_get_ad_account_pages` [read-only, off by default] — List the Facebook Pages that have been used for ads on a specific ad account. - `meta_ads_get_ad_images` [read-only, off by default] — List images uploaded to an ad account, for use as ad creative. Filter by name or hash, or by minimum dimensions. - `meta_ads_get_ad_preview` [read-only, off by default] — Render a preview of an ad, an existing creative, or a not-yet-created creative spec, in a specific placement. Returns an iframe HTML snippet valid for 24 hours. Use this before creating a creative to see how it will actually look. - `meta_ads_get_ad_videos` [read-only, off by default] — List videos uploaded to an ad account, for use as ad creative. Filter by length or aspect ratio. - `meta_ads_get_catalog_data_sources` [read-only, off by default] — List the feeds and other data sources supplying product data to a catalog — where its inventory actually comes from. - `meta_ads_get_catalog_details` [read-only, off by default] — Configuration for one product catalog: vertical, product and feed counts, owning business, and default fallback image. - `meta_ads_get_catalog_diagnostics` [read-only] — Issues on a catalog that may block or degrade ad delivery — missing required fields, disapproved products, feed errors. - `meta_ads_get_catalog_dynamic_ads_health` [read-only, off by default] — Whether a catalog is healthy enough to serve Advantage+ catalog ads — Meta's Dynamic Ads checks, the same check type pixels use. - `meta_ads_get_catalog_event_sources` [read-only, off by default] — List the pixels, apps and offline event sets connected to a catalog for dynamic ads attribution — distinct from data sources, which supply the products rather than the conversion events. - `meta_ads_get_catalog_feed_details` [read-only, off by default] — Configuration for one product feed: source URL and schedule, file format, and when it last ran. - `meta_ads_get_catalog_feed_rules` [read-only, off by default] — List the transformation rules applied to a feed on ingestion — e.g. rewriting availability or excluding rows matching a condition. - `meta_ads_get_catalog_feeds` [read-only] — List the product feeds configured on a catalog. Meta's own tools require a feed ID directly; this is the tool that finds one. - `meta_ads_get_catalog_feed_upload_sessions` [read-only, off by default] — History of import runs for a feed — when each ran, and how many products it added, updated or removed. - `meta_ads_get_catalog_product_details` [read-only, off by default] — Full attributes for one product by its Meta product ID. - `meta_ads_get_catalog_product_set_details` [read-only, off by default] — The filter rule and product count for one product set. - `meta_ads_get_catalog_product_set_products` [read-only, off by default] — List the products currently matching a product set's filter. - `meta_ads_get_catalog_product_sets` [read-only] — List the product sets defined on a catalog — filtered subsets of its products, used to scope a dynamic ad to e.g. one category or everything on sale. - `meta_ads_get_catalogs` [read-only] — List the product catalogs a Business Portfolio owns or manages for a client, tagged OWNED or CLIENT — the agency case. A catalog holds the products behind dynamic and Advantage+ catalog ads. - `meta_ads_get_creative_ads` [read-only, off by default] — List the ads in an account that use a specific creative. Meta has no direct reverse-lookup edge for this, so it scans the account's ads and filters client-side -- on a very large account, ads outside the page window fetched may be missed; raise maxPages if the creative isn't found. - `meta_ads_get_creatives` [read-only] — List ad creatives in an account, to reuse an existing one rather than building another. - `meta_ads_get_custom_audience` [read-only, off by default] — Details for a single custom audience: size, status, subtype, and when it was created or last updated. - `meta_ads_get_custom_audience_adsets` [read-only] — List the ad sets currently targeting a custom audience. Check this before deleting or shrinking an audience — those ad sets stop delivering to it. - `meta_ads_get_custom_audiences` [read-only] — List custom audiences on an ad account with size, subtype and delivery status. Use to see which audiences exist before targeting them. - `meta_ads_get_custom_conversions` [read-only] — List the custom conversions defined on an ad account: the rule each one matches, the standard event category it reports as, its value, and which dataset feeds it. These are the conversion events available as ad set optimization goals. - `meta_ads_get_dataset_details` [read-only, off by default] — Full configuration for one dataset (pixel): automatic advanced matching and which fields it matches on, first-party cookie status, data use setting, owner, and when it last received an event. Set includeInstallCode to also return the pixel install snippet. - `meta_ads_get_dataset_event_rules` [read-only, off by default] — List the event rules on a dataset — the rules created by the Event Setup Tool that derive a standard event such as Purchase from a page URL or a click, plus any domain-control rules that drop events. Pass ruleId instead for one rule's full condition set. - `meta_ads_get_dataset_quality` [read-only] — Event Match Quality for a dataset: Meta's 0-10 composite score per event, the coverage of each identifier feeding it, and how much more conversion reporting each identifier could unlock. Adds Meta's own diagnostics, the browser/Conversions API split, events dropped for carrying unhashed PII, and time since last event. This is the tool for why conversions are under-reporting. - `meta_ads_get_datasets` [read-only] — List the datasets — what Events Manager calls pixels — on an ad account or a Business Portfolio. Supply businessId to see every dataset the portfolio owns or is shared, which is usually more than the ad account edge returns. Returns configuration and last-fired time, not the install snippet. - `meta_ads_get_dataset_stats` [read-only, off by default] — Event volume received by a dataset, in hourly buckets, broken down by a dimension. Use aggregation 'event' for the event mix, 'event_source' to split browser from Conversions API, 'match_keys' for which identifiers arrive, 'url' for the pages firing. Meta keeps only the last 28 days. - `meta_ads_get_entities` [read-only] — List campaigns, ad sets or ads in an ad account with their configuration - budgets, status, objective, targeting, optimization goal and schedule. Use meta_ads_insights for performance metrics. - `meta_ads_get_errors` [read-only, off by default] — Delivery-blocking errors and issues for a campaign, ad set, ad, or the whole ad account. Check this when something isn't spending or delivering as expected. - `meta_ads_get_ig_accounts` [read-only, off by default] — List the Instagram Business or Creator accounts linked to an ad account. - `meta_ads_get_lift_study` [read-only, off by default] — Details, status and results for an existing conversion lift study — cells, measurement objectives, and incrementality results once concluded. - `meta_ads_get_opportunity_score` [read-only, off by default] — The ad account's optimization score (0-100), with the specific recommendations behind it. Higher means campaigns, ad sets and ads are closer to Meta's own best-practice configuration. - `meta_ads_get_pages_for_business` [read-only, off by default] — List the Facebook Pages owned by a Business Portfolio. For pages shared with the business by another business or agency, use meta_discover_assets instead. - `meta_ads_get_product_catalog_membership` [read-only, off by default] — List the product sets a given product belongs to — check this before deleting or excluding a product to see what else references it. - `meta_ads_insights` [read-only] — Full Meta Ads performance reporting at account, campaign, ad set or ad level. Supports explicit date ranges or presets, any Meta metric, breakdowns (platform, placement, age, gender, country, device), conversion-action breakdowns, server-side filtering, sorting and time bucketing. Use this for any question about spend, ROAS, CPA, CTR, conversions or trends. - `meta_ads_list_experiments` [read-only] — List the A/B tests and conversion lift studies on a Business Portfolio or ad account, optionally filtered by type. - `meta_ads_search_catalog_products` [read-only] — List or search products in a catalog. Pass retailerId for a direct lookup, or filter for a structured query (e.g. {availability:{eq:'out of stock'}}). With neither, lists the first page. - `meta_ads_update_catalog` [write, off by default] — Rename a catalog or change its default/fallback image. Does not change vertical or business ownership — those are fixed at creation. - `meta_ads_update_catalog_feed` [write, off by default] — Rename a feed or change its fetch schedule. - `meta_ads_update_catalog_product` [write, off by default] — Update fields on an existing product. Only the fields supplied are changed — availability and price are the two updated most often, e.g. when stock or a sale ends. - `meta_ads_update_catalog_product_set` [write, off by default] — Rename a product set or change its filter rule. - `meta_ads_update_custom_audience` [write, off by default] — Rename an audience, change its description, or update its rule. Does not change membership. - `meta_ads_update_custom_audience_users` [write, destructive, off by default] — Add or remove people on a customer-list audience. Supply plain values — email, phone, name, city and so on — and they are normalised and SHA-256 hashed before leaving this server; Meta never receives, and this server never stores or logs, the raw values. Returns counts only. - `meta_ads_update_entity` [write, off by default] — Update fields on an existing campaign, ad set or ad - rename, change budget, adjust bid or pause it. Cannot activate a paused entity; use meta_ads_activate_entity for that. - `meta_ads_update_experiment` [write, destructive, off by default] — Rename an A/B test or lift study, extend or shorten its end time before it concludes, or cancel it early by setting endTime to now. start_time and cell allocations cannot change once a study has started — create a new study instead. - `meta_create_ad_set` [write, off by default] — Create an ad set. meta_ads_create_ad_set supports promoted objects, schedules and attribution, and enforces a spend ceiling. - `meta_create_campaign` [write, off by default] — Create a campaign, paused by default. meta_ads_create_campaign supports more fields and enforces a spend ceiling. - `meta_create_instagram_post` [write, off by default] — Publish an image or reel to the Instagram Business account linked to a Page. - `meta_create_post` [write, off by default] — Create a post on a Facebook Page, optionally with a link, image, or scheduled publish time. - `meta_delete_post` [write, destructive, off by default] — Permanently delete a post from a Facebook Page. This cannot be undone. - `meta_discover_assets` [read-only] — Discover every ad account, Page and Business Portfolio this connection can reach, across all businesses. Use this first to find the right account IDs — it sees accounts that List Ad Accounts cannot. - `meta_get_campaign_insights` [read-only] — Basic performance for a single campaign. meta_ads_insights is far more capable — explicit date ranges, any metric, breakdowns, filtering and sorting at any level. - `meta_get_instagram_insights` [read-only] — Impressions, reach and engagement for a single Instagram media item. - `meta_get_page_insights` [read-only] — Page-level metrics such as fans, impressions and engaged users. - `meta_get_post_insights` [read-only] — Impressions, engaged users, clicks and reactions for a single Page post. - `meta_hide_comment` [write, off by default] — Hide or unhide a comment. Reversible — pass hide: false to restore it. - `meta_list_ad_accounts` [read-only] — List ad accounts directly attached to the connected user. Does NOT include accounts held in a Business Portfolio — use meta_discover_assets for those. - `meta_list_business_ad_accounts` [read-only] — List ad accounts belonging to a Business Portfolio, separated into owned and client accounts. Use for agency-managed accounts. - `meta_list_businesses` [read-only] — List the Meta Business Portfolios the connected account can access. Ad accounts held in a business are not returned by List Ad Accounts. - `meta_list_campaigns` [read-only] — List campaigns in an ad account. meta_ads_get_entities is more capable and also covers ad sets and ads. - `meta_list_comments` [read-only] — List comments on a Facebook or Instagram post. - `meta_list_instagram_posts` [read-only] — List recent media on the Instagram Business account linked to a Page. - `meta_list_pages` [read-only] — List the Facebook Pages the connected account manages. - `meta_list_posts` [read-only] — List recent posts on a Facebook Page. - `meta_reply_to_comment` [write, off by default] — Post a public reply to a comment. The reply is visible to everyone who can see the thread. - `meta_update_campaign_status` [write, destructive, off by default] — Change a campaign's status. ACTIVE starts spending; DELETED cannot be undone. ## Microsoft Azure Core-infrastructure slice of Azure Resource Manager. 77 tools: 50 read-only, 27 write. - `azure_acr_registry_list` [read-only] — List Azure Container Registries in a resource group, or across the whole subscription if resourceGroupName is omitted. - `azure_acr_repository_list` [read-only] — List repositories (image names) stored in an Azure Container Registry. DATA-PLANE -- not functional yet; see this file's header comment for why. - `azure_aks_cluster_get` [read-only] — Get details of a single AKS managed cluster, including its Kubernetes version and network profile. - `azure_aks_cluster_list` [read-only] — List all AKS (Azure Kubernetes Service) managed clusters across the subscription. - `azure_aks_nodepool_list` [read-only] — List the node pools (system and user) configured on an AKS managed cluster. - `azure_appservice_database_add` [write, off by default] — Add a database connection string to a web app. Not destructive: this reads the existing connection strings first and adds the new one to them, rather than replacing the whole collection. - `azure_appservice_deployment_list` [read-only] — List deployment history for a web app -- status, timestamps, commit/author info where available. - `azure_appservice_diagnostic_list` [read-only] — List the diagnostic detectors available for a web app (e.g. 'high CPU', 'app crashes') -- use with azure_appservice_diagnostic_run to actually run one. - `azure_appservice_diagnostic_run` [read-only] — Run a specific diagnostic detector against a web app and return its analysis (e.g. root-causing high CPU or crashes over a time window). - `azure_appservice_webapp_change_state` [write, destructive, off by default] — Start, stop, or restart a web app. Stopping or restarting a running production app causes an outage for its users -- requires confirm: true. - `azure_appservice_webapp_get` [read-only] — Get a single App Service web app's details (state, host names, SKU, runtime). - `azure_appservice_webapp_list` [read-only] — List App Service web apps in a subscription, optionally scoped to one resource group. - `azure_appservice_webapp_settings_get` [read-only] — Get a web app's application settings (key-value pairs). SENSITIVE: these commonly include connection strings, API keys, and other secrets in plaintext -- treat the output as you would a Key Vault secret read. - `azure_appservice_webapp_settings_update` [write, destructive, off by default] — Replace a web app's application settings. DESTRUCTIVE: ARM's appsettings write is a full REPLACE of the entire settings collection, not a merge -- any existing key you don't include here is silently removed. Read the current settings with azure_appservice_webapp_settings_get first and include every key you want kept. - `azure_compute_disk_create` [write, destructive, off by default] — Create a managed disk (empty, or from a source). Provisions billable storage. - `azure_compute_disk_delete` [write, destructive, off by default] — Permanently delete a managed disk and all data on it. IRREVERSIBLE. - `azure_compute_disk_get` [read-only] — Get a single managed disk by name. - `azure_compute_disk_list` [read-only] — List managed disks in a subscription, optionally scoped to a resource group. - `azure_compute_disk_update` [write, destructive, off by default] — Resize or change the SKU of an existing managed disk. Can shrink availability of the disk mid-flight if attached to a running VM. - `azure_compute_vm_create` [write, destructive, off by default] — Create/deploy a new virtual machine with its OS disk. Provisions billable compute and storage. - `azure_compute_vm_delete` [write, destructive, off by default] — Permanently delete a virtual machine. Does NOT delete its disks or NICs by default -- those are separate resources. IRREVERSIBLE. - `azure_compute_vm_get` [read-only] — Get a single virtual machine by name, including its current provisioning state. - `azure_compute_vm_list` [read-only] — List virtual machines in a subscription, optionally scoped to a resource group. - `azure_compute_vm_power_state` [write, destructive, off by default] — Start, stop (power off but keep billing for allocated hardware), restart, or deallocate (stop AND release the underlying hardware, stopping compute billing) a virtual machine. Deallocating or stopping a running VM interrupts anything running on it. - `azure_compute_vmss_create` [write, destructive, off by default] — Create a VM Scale Set. Provisions billable compute across `instanceCount` instances. - `azure_compute_vmss_delete` [write, destructive, off by default] — Permanently delete a VM Scale Set AND ALL of its instances. IRREVERSIBLE. - `azure_compute_vmss_get` [read-only] — Get a single VM Scale Set by name, including its current instance count and provisioning state. - `azure_compute_vmss_list` [read-only] — List VM Scale Sets in a subscription, optionally scoped to a resource group. - `azure_compute_vmss_update` [write, destructive, off by default] — Reconfigure an existing VM Scale Set, e.g. change its instance count (scale out/in). - `azure_compute_vm_update` [write, destructive, off by default] — Reconfigure an existing virtual machine (e.g. resize it). Resizing can require the VM to be deallocated first depending on the target size. - `azure_cosmos_account_list` [read-only] — List Cosmos DB accounts in a resource group, or across the whole subscription if resourceGroupName is omitted. - `azure_cosmos_container_list` [read-only] — List the containers inside a SQL (Core) API Cosmos DB database. - `azure_cosmos_database_list` [read-only] — List the SQL (Core) API databases under a Cosmos DB account. Accounts using another API (MongoDB, Cassandra, Gremlin, Table) expose their databases/keyspaces/tables under different ARM sub-resource types not covered here. - `azure_cosmos_item_get` [read-only] — Get a single document by id and partition key from a Cosmos DB container. DATA-PLANE -- not functional yet; see this file's header comment for why. - `azure_cosmos_item_list_recent` [read-only] — List the most recently modified documents in a Cosmos DB container, ordered by the system _ts property. DATA-PLANE -- not functional yet; see this file's header comment for why. - `azure_cosmos_item_query` [read-only] — List items from a Cosmos DB container via a custom SQL (Core) API query. DATA-PLANE -- not functional yet; see this file's header comment for why. - `azure_cosmos_schema_infer` [read-only] — Infer an approximate schema (top-level field names and types) for a Cosmos DB container by sampling documents. DATA-PLANE -- not functional yet; see this file's header comment for why. - `azure_keyvault_certificate_create` [write, off by default] — Create/issue a new certificate (a new version, if the name already exists). This starts an async issuance operation against the vault's configured issuer (self-signed by default). Does not import existing PFX/PEM material -- that's azmcp's certificate_import, out of scope for this pass (see file header). DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_certificate_get` [read-only] — Get a certificate's public portion (cer/PEM) and metadata by name. Never returns the private key -- pair azure_keyvault_key_get / azure_keyvault_secret_get against the same name for exportable material where the vault's policy allows it. DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_certificate_list` [read-only] — List certificates in a vault by name and metadata (never returns private key material). DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_key_create` [write, off by default] — Create a new key (a new version, if the name already exists -- old versions remain readable, unlike a secret). DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_key_get` [read-only] — Get a key's public portion and metadata by name. Never returns private key material -- Key Vault keys are non-exportable by design. DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_key_list` [read-only] — List keys in a vault by name and metadata (never returns private key material). DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_secret_create` [write, destructive, off by default] — Create/set a secret's value. IMPORTANT: if a secret with this name already exists, this SILENTLY adds a new current version -- every future reader gets the new value with no separate warning. Marked destructive for that reason (see this file's header 'Secret-flag, not Destructive-flag' comment), even though nothing is deleted. DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_secret_get` [read-only] — Get a secret by name. SENSITIVE: the response includes the secret's live plaintext VALUE, not just metadata -- treat the output as confidential. DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_keyvault_secret_list` [read-only] — List secrets in a vault by name and metadata ONLY -- does not return secret values (Azure's list API never does; use azure_keyvault_secret_get per-name for a value). DATA-plane operation against {vaultName}.vault.azure.net -- see this file's header KNOWN GAP comment. - `azure_monitor_activity_log_list` [read-only] — List Azure Activity Log events (control-plane operations like create/update/delete) for a subscription, optionally scoped to one resource and a time window. - `azure_monitor_log_query` [read-only] — Run a KQL query against diagnostic/activity logs for ONE resource, scoped via the resource's Log Analytics workspace. Uses ARM's query proxy -- see file header for the data-plane-vs-management-plane gap this works around. - `azure_monitor_metric_definitions_list` [read-only] — List the metric names/units/supported aggregations available for a resource, so you know what to pass to azure_monitor_metrics_query. - `azure_monitor_metrics_batch_query` [read-only] — Query the same metric(s) across multiple resources at once. COMPATIBILITY SHIM: Azure's real Metrics Batch API is a data-plane-only regional endpoint (metrics.monitor.azure.com) this connector can't reach with its ARM-only token -- this fans out to one ARM metrics call per resourceId instead. Correct results, but N HTTP calls, not Azure's real single batch call. - `azure_monitor_metrics_query` [read-only] — Query one or more metric time series for a single resource over a time window (e.g. CPU percentage for a VM, request count for a web app). - `azure_monitor_table_list` [read-only] — List the tables available in a Log Analytics workspace. - `azure_monitor_table_type_list` [read-only] — List the distinct table types (e.g. Microsoft, CustomLog) present in a Log Analytics workspace. INFERRED: ARM has no dedicated 'table types' endpoint documented -- this calls the same Tables-List API as azure_monitor_table_list and summarizes the distinct properties.schema.tableType values found. BUILD-TIME VERIFY this matches Azure's real azmcp_monitor_table_type_list behavior before shipping. - `azure_monitor_workspace_list` [read-only] — List Log Analytics workspaces in a subscription, optionally scoped to one resource group. - `azure_monitor_workspace_log_query` [read-only] — Run a KQL query across an ENTIRE Log Analytics workspace -- not scoped to one resource. Results are capped at 2000 rows; add explicit filters/aggregation to your KQL rather than relying on the cap. Uses ARM's query proxy -- see file header for the known data-plane gap. - `azure_sql_database_create` [write, destructive, off by default] — Create a new database on an existing Azure SQL server. - `azure_sql_database_delete` [write, destructive, off by default] — Delete a single database from an Azure SQL server. Irreversible. - `azure_sql_database_get` [read-only] — Get details, including current SKU/tier, of a single database on an Azure SQL server. - `azure_sql_database_list` [read-only] — List all databases on an Azure SQL server. - `azure_sql_database_rename` [write, destructive, off by default] — Rename a database in place on the same server. - `azure_sql_database_update` [write, destructive, off by default] — Scale or reconfigure an existing database's performance SKU (e.g. change service tier or compute size). - `azure_sql_elastic_pool_list` [read-only] — List the elastic pools configured on an Azure SQL server. - `azure_sql_server_create` [write, destructive, off by default] — Create a new Azure SQL logical server with admin credentials. administratorLoginPassword is write-only -- Azure never echoes it back in responses, and this tool does not persist or log it beyond the request itself. - `azure_sql_server_delete` [write, destructive, off by default] — Delete an Azure SQL logical server and every database on it. Irreversible. - `azure_sql_server_entra_admin_list` [read-only] — List the Microsoft Entra ID (Azure AD) administrators configured on an Azure SQL server. - `azure_sql_server_firewall_rule_create` [write, destructive, off by default] — Create or overwrite a server-level firewall rule, opening an IP range to the server's public endpoint. Widening network access to a database server is a security-sensitive change. - `azure_sql_server_firewall_rule_delete` [write, destructive, off by default] — Delete a server-level firewall rule, revoking the IP range it granted access to. - `azure_sql_server_firewall_rule_list` [read-only] — List the server-level firewall rules on an Azure SQL server. - `azure_sql_server_get` [read-only] — Get details of a single Azure SQL logical server. - `azure_sql_server_list` [read-only] — List all Azure SQL logical servers in a resource group. - `azure_storage_account_create` [write, destructive, off by default] — Create a storage account. Provisions billable storage infrastructure. True ARM management-plane call. - `azure_storage_account_get` [read-only] — Get a single storage account by name. True ARM management-plane call. - `azure_storage_account_list` [read-only] — List storage accounts in a subscription, optionally scoped to a resource group. True ARM management-plane call. - `azure_storage_blob_list` [read-only] — List blobs in a container. DATA-plane operation against *.blob.core.windows.net -- see this file's header KNOWN GAP comment: requires a storage.azure.com token audience this connector does not yet request. - `azure_storage_blob_upload` [write, off by default] — Upload a small blob (base64-encoded content, capped at 5MB decoded) to a container, ONLY IF a blob of that name doesn't already exist. For anything larger or requiring streaming/chunked/multi-part upload, this control-plane REST tool is not sufficient -- use a real Data Plane SDK client instead. DATA-plane operation against *.blob.core.windows.net -- see this file's header KNOWN GAP comment: requires a storage.azure.com token audience this connector does not yet request. - `azure_storage_container_create` [write, destructive, off by default] — Create a blob container in a storage account. DATA-plane operation against *.blob.core.windows.net -- see this file's header KNOWN GAP comment: requires a storage.azure.com token audience this connector does not yet request. - `azure_storage_container_list` [read-only] — List blob containers in a storage account. DATA-plane operation against *.blob.core.windows.net -- see this file's header KNOWN GAP comment: requires a storage.azure.com token audience this connector does not yet request. ## Stripe Customers, payments, refunds, invoices, subscriptions, products/pricing, and disputes on a customer's own Stripe account. Customers supply their own restricted API key per connection, scoped to only the resources they want ServeMCP to touch. 73 tools: 44 read-only, 29 write. - `stripe_cancel_subscription` [write, destructive, off by default] — Cancel a subscription IMMEDIATELY. This is irreversible -- for a reversible, end-of-period cancellation, use stripe_update_subscription with cancel_at_period_end: true instead. confirm_subscription_id is a deliberate safety echo, must exactly match subscription_id. - `stripe_close_dispute` [write, destructive, off by default] — Accept a dispute, closing it. This PERMANENTLY FORFEITS the disputed amount -- confirm_amount is a deliberate safety echo, must exactly match the dispute's amount. - `stripe_create_checkout_session` [write, off by default] — Create a checkout session (a hosted payment page URL). Ungated -- no money moves until the end customer actually completes payment on Stripe's own page. - `stripe_create_coupon` [write, off by default] — Create a coupon -- either percent_off or amount_off (with currency), not both. - `stripe_create_credit_note` [write, destructive, off by default] — Issue a credit note against an invoice. When refund_amount is set, this triggers a REAL refund of the charge associated with the invoice -- confirm_amount is a deliberate safety echo, must exactly match refund_amount (or 0 if no refund is being issued, only a balance credit). - `stripe_create_customer` [write, off by default] — Create a new customer. - `stripe_create_invoice` [write, off by default] — Create a draft invoice for a customer. Does not charge anything until finalized. - `stripe_create_invoice_item` [write, off by default] — Add a line item to a customer's next invoice (or a specific draft invoice). - `stripe_create_payment_link` [write, off by default] — Create a shareable payment link. - `stripe_create_price` [write, off by default] — Create a price for a product. Prices are immutable once created -- to change an amount, create a new price and archive the old one (stripe_update_price cannot touch unit_amount). - `stripe_create_product` [write, off by default] — Create a product. - `stripe_create_promotion_code` [write, off by default] — Create a customer-facing promotion code tied to an existing coupon. - `stripe_create_refund` [write, destructive, off by default] — Refund a charge or payment intent, in full or in part. This moves real money back to the customer -- confirm_amount is a deliberate safety echo: Stripe amounts are in the currency's smallest unit (cents for USD), and this catches both a 100x unit error and refunding the wrong total. It must exactly match `amount` if provided, or the charge/payment intent's full remaining amount if `amount` is omitted. - `stripe_create_subscription` [write, off by default] — Create a new subscription for a customer. Consider calling stripe_preview_invoice first if proration matters. - `stripe_create_webhook_endpoint` [write, off by default] — Register a new webhook endpoint on the customer's account. The signing secret is returned once in the response and never stored by ServeMCP -- record it immediately, it cannot be retrieved again. - `stripe_delete_coupon` [write, destructive, off by default] — Permanently delete a coupon. Existing promotion codes/subscriptions using it are unaffected, but it can no longer be applied to new ones. - `stripe_finalize_invoice` [write, destructive, off by default] — Finalize a draft invoice -- locks its invoice number and, depending on the customer's payment settings, may immediately attempt to charge them. Not reversible. - `stripe_get_balance` [read-only] — Retrieve the current account balance (available and pending, per currency). - `stripe_get_balance_transaction` [read-only] — Retrieve a single balance transaction by ID. - `stripe_get_charge` [read-only] — Retrieve a single charge by ID. - `stripe_get_checkout_session` [read-only] — Retrieve a single checkout session by ID. - `stripe_get_checkout_session_line_items` [read-only] — Retrieve the line items for a checkout session. - `stripe_get_coupon` [read-only] — Retrieve a single coupon by ID. - `stripe_get_credit_note` [read-only] — Retrieve a single credit note by ID. - `stripe_get_customer` [read-only] — Retrieve a single customer by ID. - `stripe_get_dispute` [read-only] — Retrieve a single dispute by ID. - `stripe_get_invoice` [read-only] — Retrieve a single invoice by ID, including its line items. - `stripe_get_invoice_item` [read-only] — Retrieve a single invoice item by ID. - `stripe_get_payment_intent` [read-only] — Retrieve a single payment intent by ID. - `stripe_get_payment_link` [read-only] — Retrieve a single payment link by ID. - `stripe_get_payment_link_line_items` [read-only] — Retrieve the line items on a payment link. - `stripe_get_payment_method` [read-only] — Retrieve a single payment method by ID. - `stripe_get_payout` [read-only] — Retrieve a single payout by ID. - `stripe_get_price` [read-only] — Retrieve a single price by ID. - `stripe_get_product` [read-only] — Retrieve a single product by ID. - `stripe_get_promotion_code` [read-only] — Retrieve a single promotion code by ID. - `stripe_get_refund` [read-only] — Retrieve a single refund by ID. - `stripe_get_subscription` [read-only] — Retrieve a single subscription by ID. - `stripe_get_webhook_endpoint` [read-only] — Retrieve a single webhook endpoint by ID. - `stripe_list_balance_transactions` [read-only] — List balance transactions (charges, refunds, payouts, fees, etc.), optionally filtered by type. - `stripe_list_charges` [read-only] — List charges, optionally filtered by customer. - `stripe_list_checkout_sessions` [read-only] — List checkout sessions, optionally filtered by customer. - `stripe_list_coupons` [read-only] — List coupons. - `stripe_list_credit_notes` [read-only] — List credit notes, optionally filtered by customer or invoice. - `stripe_list_customers` [read-only] — List customers, optionally filtered by email. - `stripe_list_disputes` [read-only] — List disputes, optionally filtered by charge or payment intent. - `stripe_list_invoice_items` [read-only] — List invoice items, optionally filtered by customer or invoice. - `stripe_list_invoices` [read-only] — List invoices, optionally filtered by customer or subscription. - `stripe_list_payment_intents` [read-only] — List payment intents, optionally filtered by customer. - `stripe_list_payment_links` [read-only] — List payment links, optionally filtered by active state. - `stripe_list_payment_methods` [read-only] — List a customer's saved payment methods. - `stripe_list_payouts` [read-only] — List payouts. Read-only -- ServeMCP does not expose payout creation. - `stripe_list_prices` [read-only] — List prices, optionally filtered by product or active state. - `stripe_list_products` [read-only] — List products, optionally filtered by active state. - `stripe_list_promotion_codes` [read-only] — List promotion codes, optionally filtered by coupon or active state. - `stripe_list_refunds` [read-only] — List refunds, optionally filtered by charge. - `stripe_list_subscription_items` [read-only] — List the line items on a subscription. - `stripe_list_subscriptions` [read-only] — List subscriptions, optionally filtered by customer or status. - `stripe_list_subscription_schedules` [read-only] — List subscription schedules, optionally filtered by customer. - `stripe_list_webhook_endpoints` [read-only] — List the account's configured webhook endpoints. - `stripe_mark_invoice_uncollectible` [write, destructive, off by default] — Mark an invoice as uncollectible -- writes off the amount as bad debt. confirm_amount is a deliberate safety echo, must exactly match the invoice's amount_due. - `stripe_preview_invoice` [read-only] — Simulate what an invoice would look like WITHOUT creating anything -- Stripe's real dry-run primitive. Call this before stripe_create_subscription/stripe_update_subscription when proration is involved, to show the customer the actual dollar impact before committing. - `stripe_update_coupon` [write, off by default] — Update a coupon's name or metadata. Discount amount/percent/duration cannot be changed once created. - `stripe_update_customer` [write, off by default] — Update an existing customer's details. - `stripe_update_dispute_evidence` [write, off by default] — Submit or update evidence for a dispute. No direct money effect, but Stripe forecloses further submission once evidence is marked submitted -- treat as a one-shot action per dispute. - `stripe_update_invoice` [write, off by default] — Update a draft invoice's details. - `stripe_update_invoice_item` [write, off by default] — Update an invoice item that hasn't been invoiced yet. - `stripe_update_payment_link` [write, off by default] — Update a payment link's active state. There is no delete endpoint -- set active: false to deactivate. - `stripe_update_price` [write, off by default] — Update a price's active state, nickname, or metadata. The amount is immutable by Stripe's own design -- this cannot change unit_amount; use stripe_create_price for a new amount. - `stripe_update_product` [write, off by default] — Update a product's details. - `stripe_update_promotion_code` [write, off by default] — Update a promotion code -- the only way to deactivate one (there is no delete endpoint). Set active: false to deactivate. - `stripe_update_subscription` [write, off by default] — Update an existing subscription -- change items/quantity, or schedule a reversible cancellation via cancel_at_period_end (the subscription keeps running until the current period ends, and can be un-scheduled by calling this again with cancel_at_period_end: false). For an IMMEDIATE, irreversible cancellation use stripe_cancel_subscription instead. Consider stripe_preview_invoice first if items change. - `stripe_void_invoice` [write, destructive, off by default] — Void an invoice -- permanently cancels it. Only possible before it's paid. confirm_amount is a deliberate safety echo, must exactly match the invoice's total. ## Loops Full SaaS email-marketing/automation platform coverage. 65 tools: 29 read-only, 36 write. - `loops_add_workflow_branch` [write, off by default] — Add a sibling branch to a branch node (e.g. another variant to an ExperimentBranchNode, or another condition path to a BranchNode). - `loops_change_workflow_mailing_list` [write, off by default] — Change (or clear, with mailingListId: null) the mailing list a workflow sends to. If contacts are queued that the new list would exclude, Loops returns queuedContactsFound instead of applying the change -- retry with queuedContactPolicy: "discard" to proceed and discard them. - `loops_complete_upload` [write, off by default] — Finalize an upload after the file bytes have been PUT to the presigned URL from loops_create_upload. - `loops_create_audience_segment` [write, off by default] — Create a new audience segment from a filter definition. The exact filter schema is Loops-specific (contact property/event conditions) -- pass it through as-is from Loops' own segment-builder export or documentation. - `loops_create_campaign` [write, off by default] — Create a new campaign. Defaults to the team's default campaign group if campaignGroupId is omitted. Does not send it -- Loops has no API send trigger. - `loops_create_campaign_group` [write, off by default] — Create a new campaign group. - `loops_create_component` [write, off by default] — Create a new reusable email component from an LMX body. - `loops_create_contact` [write, off by default] — Create a new contact. - `loops_create_contact_property` [write, off by default] — Define a new custom contact property. Must exist before it can be set via loops_create_contact/loops_update_contact. - `loops_create_theme` [write, off by default] — Create a new email theme. - `loops_create_transactional_email` [write, off by default] — Create a new transactional email template. - `loops_create_transactional_group` [write, off by default] — Create a new transactional email group. - `loops_create_upload` [write, off by default] — Start an image upload. Returns an emailAssetId and a presigned URL -- PUT the raw file bytes to that URL yourself (matching contentType/contentLength), then call loops_complete_upload. - `loops_create_workflow` [write, off by default] — Create a new, empty marketing-automation workflow. - `loops_create_workflow_node` [write, off by default] — Insert a new node into a workflow's graph, either between two existing nodes, before one, or after one. To configure the node further after creation, use loops_update_workflow_node. - `loops_delete_contact` [write, destructive, off by default] — Permanently delete a contact. IRREVERSIBLE. - `loops_delete_workflow` [write, destructive, off by default] — Permanently delete a workflow and its entire node graph. IRREVERSIBLE. - `loops_delete_workflow_node` [write, destructive, off by default] — Delete a single workflow node. Its children are reconnected to its former parent. IRREVERSIBLE. - `loops_delete_workflow_node_recursively` [write, destructive, off by default] — Delete a workflow node AND every node beneath it in the graph. IRREVERSIBLE and affects more than a single-node delete -- use with care. - `loops_ensure_transactional_draft` [write, off by default] — Ensure a draft email message exists for a transactional email, creating one if needed, so it can be edited before publishing. - `loops_find_contact` [read-only] — Find a contact by email or userId. Provide at least one. - `loops_get_audience_segment` [read-only] — Get a single audience segment and its filter definition. - `loops_get_campaign` [read-only] — Get a single campaign. - `loops_get_campaign_group` [read-only] — Get a single campaign group. - `loops_get_component` [read-only] — Get a single reusable component's content. - `loops_get_contact_suppression` [read-only] — Check whether a contact is on the suppression list (e.g. from a bounce or spam complaint). - `loops_get_email_message` [read-only] — Get a single email message's content (subject, body, LMX). - `loops_get_email_message_guardian` [read-only] — Run Loops' "Guardian" quality/deliverability checks (broken links, spam-trigger phrases, missing unsubscribe, etc.) on an email message. - `loops_get_event_pattern` [read-only] — Get a single event pattern by ID. - `loops_get_event_pattern_by_name` [read-only] — Get a single event pattern by its event name. - `loops_get_theme` [read-only] — Get a single theme's styles. - `loops_get_transactional_email` [read-only] — Get a single transactional email template. - `loops_get_transactional_group` [read-only] — Get a single transactional email group. - `loops_get_workflow` [read-only] — Get a single workflow, including its current revision token (needed for any mutation) and node graph. - `loops_get_workflow_node` [read-only] — Get a single node in a workflow's automation graph. - `loops_list_audience_segments` [read-only] — List audience segments on this team. - `loops_list_campaign_groups` [read-only] — List campaign groups on this team. - `loops_list_campaigns` [read-only] — List campaigns on this team. - `loops_list_components` [read-only] — List reusable email components (content blocks) on this team. - `loops_list_contact_properties` [read-only] — List custom contact properties defined on this team. - `loops_list_dedicated_sending_ips` [read-only] — List this team's dedicated sending IP addresses. - `loops_list_event_patterns` [read-only] — List event patterns (distinct event names this team has sent, with usage metadata) recognized on this team. - `loops_list_mailing_lists` [read-only] — List every mailing list on this team. Not paginated -- Loops returns the full list in one call. - `loops_list_published_transactional_emails` [read-only] — List published transactional emails via Loops' legacy, unpaginated endpoint. Prefer loops_list_transactional_emails for new integrations -- kept for parity with an older API path Loops still publishes. - `loops_list_themes` [read-only] — List email themes on this team. - `loops_list_transactional_emails` [read-only] — List transactional email templates on this team. - `loops_list_transactional_groups` [read-only] — List transactional email groups on this team. - `loops_list_workflows` [read-only] — List marketing-automation workflows on this team. - `loops_preview_email_message` [write, off by default] — Send a preview/test send of an email message to check rendering. Sends a real email, but only a test preview, not to real recipients. - `loops_publish_transactional_email` [write, destructive, off by default] — Publish a transactional email's draft, making it the live version sent by loops_send_transactional_email. Cannot be undone. - `loops_remove_contact_suppression` [write, off by default] — Remove a contact from the suppression list so they can receive email again. Rate-quota-gated by Loops: a limited number of removals are allowed per rolling 30-day period -- the response includes the remaining quota. - `loops_reroute_workflow_node_connection` [write, off by default] — Reroute a node's single outgoing connection to point at a different target node. - `loops_send_event` [write, off by default] — Send a custom event for a contact. Events can trigger workflows. Provide email and/or userId to identify the contact. - `loops_send_transactional_email` [write, off by default] — Send a transactional email to a contact using a published transactional email template. - `loops_test_api_key` [read-only] — Check whether this connection's API key is valid, and which Loops team it's scoped to. - `loops_update_campaign` [write, off by default] — Update an existing campaign's targeting, group, or schedule. - `loops_update_campaign_group` [write, off by default] — Rename a campaign group. - `loops_update_component` [write, off by default] — Update a component's name or LMX content. - `loops_update_contact` [write, off by default] — Update an existing contact. Identify it with email and/or userId. - `loops_update_email_message` [write, off by default] — Update an email message's subject, body, or theme. - `loops_update_theme` [write, off by default] — Update a theme's name or styles. - `loops_update_transactional_email` [write, off by default] — Update a transactional email template's name or group. - `loops_update_transactional_group` [write, off by default] — Rename a transactional email group. - `loops_update_workflow_node` [write, off by default] — Update a workflow node's type-specific configuration (e.g. a SendEmailAction's email message, a TimerAction's delay, an AudienceFilter's conditions). - `loops_update_workflow_properties` [write, off by default] — Update a workflow's name and/or description. Provide at least one. ## WHM (WebHost Manager) Server-level hosting administration against cPanel's WHM API v1. 53 tools: 27 read-only, 26 write. - `whm_account_bandwidth` [read-only] — Return bandwidth usage for the cPanel accounts on the server for a given month. If this connection has an account allowlist, only allowed accounts are returned. - `whm_account_counts` [read-only] — Return a reseller's total accounts, suspended accounts, and account creation limit. Omit the user to report on the account the API token belongs to. - `whm_account_summary` [read-only] — Return the summary for one cPanel account: its owner, package, disk usage, primary domain, suspension state and contact email. Identify the account by username or by one of its domains. - `whm_activate_restore_queue` [write, destructive, off by default] — Start WHM's restoration queue, carrying out every restoration queued by whm_restore_account_backup. This is the call that actually overwrites live account data with backup contents, and it starts the ENTIRE queue -- including any restorations queued outside ServeMCP -- so read the queue in WHM before running it. Anything created since each backup was taken is lost. This cannot be limited to one account. - `whm_add_dns_zone` [write, off by default] — Create a new DNS zone for a domain, seeded from a WHM zone template (A records, MX, and PTR). This creates DNS only -- it does not create a cPanel account or a web vhost. - `whm_add_zone_record` [write, off by default] — Add a DNS record to an existing zone. Supply the payload fields matching the record type: address (A/AAAA), cname (CNAME), exchange and preference (MX), txtdata (TXT), priority/weight/port/target (SRV), or flag/tag/value (CAA). Adding a record renumbers the lines below it, so any line number read before this call is stale afterwards. - `whm_api_function_list` [read-only] — Return the alphabetical list of WHM API 1 functions available on this server. Useful for confirming what this cPanel version supports and what the token is privileged to call. This does NOT list installed applications or software packages. - `whm_autossl_check` [write, off by default] — Queue an AutoSSL run for one cPanel account, issuing or renewing certificates for its domains. This is a real request to a public certificate authority, not a dry run: it performs domain control validation and consumes issuance quota. Certificate authorities rate-limit per registered domain per week, so repeated calls against the same account can exhaust the quota and block legitimate renewals for days. Run it once and read the outcome with whm_autossl_get_user_status rather than polling by re-running it. - `whm_autossl_get_providers` [read-only] — List the AutoSSL certificate providers available on this server and which one is currently enabled. - `whm_autossl_get_user_status` [read-only] — Report the AutoSSL domain-control-validation problems for one cPanel account -- the domains AutoSSL could not secure and why. An empty result means AutoSSL found nothing wrong, which is the normal healthy state. - `whm_change_account_package` [write, off by default] — Move a cPanel account onto a different hosting package. The account's disk quota, bandwidth limit, domain limits and feature list are all re-applied from the new package, so moving to a smaller package can put an account immediately over quota. - `whm_change_account_password` [write, destructive, off by default] — Set a new password for a cPanel account. This immediately invalidates the password the account holder is currently using -- they are locked out of cPanel, FTP and webmail until they are given the new one, and running this tool again cannot restore the old password because WHM does not store it in a readable form. - `whm_configure_service` [write, off by default] — Enable or disable a service, and turn WHM's monitoring of it on or off. Disabling a service stops it for every account on the server; turning off monitoring means WHM will no longer restart it automatically when it fails. At least one of enabled or monitored must be supplied. - `whm_create_account` [write, off by default] — Provision a new cPanel account on the server. This creates a live Unix account, home directory, DNS zone and mail configuration, and consumes a licence slot. Nothing existing is lost, but the account is real and billable the moment this returns. - `whm_create_package` [write, off by default] — Create a new hosting package (plan) on the server. Creating a package does not change any existing account -- it only makes a new set of limits available to assign. - `whm_delete_dns_zone` [write, destructive, off by default] — Permanently delete a domain's entire DNS zone and every record in it. The domain stops resolving as soon as the change propagates. This does not remove the cPanel account or its files -- the site simply becomes unreachable by name. There is no undo and no backup taken. - `whm_delete_package` [write, destructive, off by default] — Permanently delete a hosting package. The package definition is gone and cannot be recovered without recreating it by hand from its exact settings. Accounts currently assigned to the package are not deleted, but they are left referencing a plan that no longer exists, which breaks package-based reporting and blocks any later attempt to re-apply their plan's limits. - `whm_delete_ssl_certificate` [write, destructive, off by default] — Delete a hostname's SSL virtual host, removing its HTTPS configuration. The site stops serving on port 443 immediately -- visitors on https:// get a connection failure, not a redirect to http://. This does not delete the cPanel account or its files. - `whm_domain_user_data` [read-only] — Map a domain to the cPanel account that owns it, along with that domain's virtual host configuration (document root, server name, IP). This is the way to find out which account a site belongs to. - `whm_edit_package` [write, off by default] — Change the settings on an existing hosting package. Only the fields provided are changed. Note that this reaches beyond the package itself: accounts already assigned to it have the new limits applied, so lowering a quota or bandwidth limit here can put live accounts over their limit immediately. - `whm_edit_zone_record` [write, off by default] — Replace the DNS record at a given line number. Read the line number from whm_get_dns_zone immediately before calling, and ideally confirm it with whm_get_zone_record first -- line numbers shift whenever any record is added or removed, and this call overwrites whatever currently sits on that line without checking it is the record you meant. - `whm_get_backup_config` [read-only] — Return the server's backup configuration -- whether backups are enabled, the schedule, retention, and the configured destinations. - `whm_get_dns_zone` [read-only] — Return a domain's full DNS zone as parsed records. Each record carries a `Line` value -- that is the line number the edit and remove tools require, and it is only valid until the next change to the zone. - `whm_get_package` [read-only] — Return the full configuration of one hosting package: its disk quota, bandwidth limit, domain and mailbox limits, feature list, and shell and CGI settings. - `whm_get_ssl_info` [read-only] — Inspect an SSL certificate: its covered domains, CA bundle, expiry, and associated IP. Pass a domain to look up what the server holds for it, or pass certificate text to parse a certificate you already have. Note that cPanel reports the certificate it considers AVAILABLE for the domain, which is not always the one currently serving traffic. - `whm_get_zone_record` [read-only] — Return the single zone record at a given line number. Use this to confirm a line still holds the record you expect before editing or removing it. - `whm_install_ssl_certificate` [write, destructive, off by default] — Install an SSL certificate and private key on a domain, replacing whatever certificate is currently serving it. The previous certificate and key are overwritten and cannot be recovered through the API, and a mismatched certificate and key will break HTTPS on a live site immediately. Always supply the CA bundle unless the certificate is self-signed -- omitting it leaves an incomplete chain that many clients reject. Pass the PEM text exactly as issued; do not URI-encode it. - `whm_list_account_domains` [read-only] — List every domain on one cPanel account -- primary, addon, parked and subdomains -- with each domain's type and document root. Use this rather than the account summary when addon and parked domains matter, since the summary reports only the primary domain. - `whm_list_accounts` [read-only] — List the cPanel accounts on the server, optionally filtered by a search. If this connection has an account allowlist, only allowed accounts are returned. - `whm_list_backup_sets` [read-only] — List the backup files held on the server's local disk for its accounts. - `whm_list_backup_users` [read-only] — List the cPanel accounts that have a backup for a given date, on local disk or on an additional backup destination, along with each account's backup status. WHM keys backups by date rather than by account, so a date is required; to find out whether one account is covered, list a date and look for that account. - `whm_list_dns_zones` [read-only] — List every DNS zone the server is authoritative for, across all cPanel accounts. - `whm_list_ips` [read-only] — Return the IP addresses bound to the server. - `whm_list_packages` [read-only] — List the hosting packages (plans) available on the server. These are the plan names accepted by whm_create_account and whm_change_account_package. - `whm_list_resellers` [read-only] — List the reseller accounts on the server. - `whm_list_ssl_certificates` [read-only] — List installed SSL certificates and the domains they cover. Without a username this returns every certificate on the server; pass a username to scope it to one account. If this connection has an allowed-accounts list, a username is required. - `whm_list_suspended_accounts` [read-only] — List the suspended cPanel accounts on the server, with the reason and time recorded for each suspension. If this connection has an account allowlist, only allowed accounts are returned. - `whm_modify_account` [write, off by default] — Change settings on an existing cPanel account: its primary domain, contact email, shell, owner, and its resource limits. Only the fields provided are changed. Changing the domain renames the account's primary domain and rewrites its DNS zone; granting a shell gives the account SSH access to the server. - `whm_remove_zone_record` [write, destructive, off by default] — Permanently delete the DNS record at a given line number. Read the line number from whm_get_dns_zone immediately before calling and confirm it with whm_get_zone_record -- line numbers shift whenever any record is added or removed, so a stale number deletes a different record than intended, with no undo. Removing a record can break mail delivery or take a hostname offline. - `whm_reseller_stats` [read-only] — Return a reseller's information, including the accounts they own and their usage. - `whm_reset_dns_zone` [write, destructive, off by default] — Discard a zone's customisations and rebuild it from WHM's default template. Valid TXT records are preserved; every other custom record -- added A records, CNAMEs, MX changes, SRV, CAA -- is lost. Intended for repairing a corrupted zone, not for routine edits. - `whm_restart_service` [write, destructive, off by default] — Restart a service on the server. This drops every live connection to that service across every account on the machine -- restarting httpd interrupts in-flight requests to every hosted site, restarting exim interrupts mail delivery for every account, restarting mysql drops every open database connection. The effect is server-wide, not scoped to one account, and it cannot be limited by the connection's allowed-accounts list. - `whm_restore_account_backup` [write, destructive, off by default] — Add a cPanel account to WHM's restoration queue, to be restored from the backup taken on a given date. Restoring overwrites the account's current live data -- files, databases and mail -- with the older contents of that backup, and anything created since the backup was taken is lost. This call only QUEUES the restoration; it does not carry it out and it does not report on one. The queue must be started separately from WHM's Backup Restoration interface, so a successful result here means the account is scheduled, not that its data has been replaced. - `whm_server_hostname` [read-only] — Return the server's hostname. - `whm_server_version` [read-only] — Return the cPanel & WHM version running on the server. - `whm_service_status` [read-only] — Return the running state of the server's services -- which are up, which are down, and which are monitored. - `whm_set_account_quota` [write, off by default] — Set the disk quota for a cPanel account. Lowering it below the account's current usage does not delete anything, but the account can no longer write -- uploads, mail delivery and database writes start failing until usage is brought back under the limit. - `whm_setup_reseller` [write, off by default] — Grant a cPanel account reseller privileges. This is a privilege escalation: the account gains the ability to create, suspend and terminate other cPanel accounts, subject to the limits and package permissions set for it afterwards. It does not by itself grant any account quota. - `whm_suspend_account` [write, destructive, off by default] — Suspend a cPanel account. Every website on the account goes offline immediately and starts serving a suspension page, mail delivery stops, and the account holder can no longer log in. Reversible with whm_unsuspend_account, but the outage between the two is real and visible to the account's visitors. - `whm_system_load_avg` [read-only] — Return the server's 1, 5, and 15 minute load averages. - `whm_terminate_account` [write, destructive, off by default] — Permanently delete a cPanel account. This removes the Unix account, its entire home directory and every website file in it, all of its databases and database users, all of its email accounts and stored mail, its FTP accounts, its cron jobs, and its DNS zone. It cannot be undone: the only way back is a restore from a backup taken before this ran, and if no such backup exists the data is gone. - `whm_unsetup_reseller` [write, destructive, off by default] — Revoke a cPanel account's reseller privileges. The accounts it owns are not deleted, but the account loses its control over them -- anyone relying on that reseller login to manage their customers' accounts will lose access until the status is granted again. - `whm_unsuspend_account` [write, off by default] — Lift the suspension on a cPanel account, bringing its websites, email and logins back online. ## Amazon Ads Sponsored Products, Sponsored Brands, and Sponsored Display campaign management, plus async reporting and read-only performance analytics (ROAS root-cause diagnosis, seasonality, period/YoY comparison, campaign-config change history). Ships disabled. 52 tools: 25 read-only, 27 write. - `amazon_ads_config_change_history` [read-only] — Reads previously-recorded configuration changes for a profile (from amazon_ads_snapshot_config_history runs). Only covers the period since snapshotting started for this connection -- Amazon exposes no way to reconstruct history from before the first snapshot. Read-only. - `amazon_ads_create_report` [write, off by default] — Request a performance report across Sponsored Products, Brands, or Display. Returns a report_id -- call amazon_ads_get_report_status to check when it's ready, then amazon_ads_get_report_result to fetch it. Report generation is asynchronous and can take minutes; this call returns immediately. - `amazon_ads_get_profile` [read-only] — Retrieve an authorized profile's account details (country, currency, account type). - `amazon_ads_get_report_result` [read-only] — Fetch and parse a completed report's data. Returns 'not ready' if the report hasn't finished -- call amazon_ads_get_report_status first to check. Large reports are truncated to the first 2000 rows; check the returned total_rows/truncated fields. - `amazon_ads_get_report_status` [read-only] — Poll a report's generation status. Call amazon_ads_get_report_result once status is COMPLETED. - `amazon_ads_list_accessible_profiles` [read-only] — List every Amazon Ads profile (advertiser account) this connection's token can see, across all three regions (North America, Europe, Far East) -- not filtered to just the ones authorized on this connection. Use this to find profile IDs to authorize from Settings -> Connections -> Manage Profiles. - `amazon_ads_management_transition_analysis` [read-only] — Compares performance before/after a transition date across two campaign cohorts: campaigns with a recorded configuration change at or after the transition (treatment) vs. campaigns with none (control). Both cohorts deteriorating similarly suggests an external cause (seasonality/market demand); only the changed cohort deteriorating points at the changes themselves. REQUIRES prior amazon_ads_snapshot_config_history runs bracketing the transition date -- Amazon exposes no historical config-change API, so without local snapshot history this tool cannot form the cohorts and will say so rather than guess. Fetches one live performance report spanning both windows, which can take longer than one call allows -- see report_id for resuming. - `amazon_ads_performance` [read-only] — Live Sponsored Products performance for a date range -- impressions, clicks, spend, orders, units, sales, plus derived CTR/CPC/CVR/ACOS/ROAS/AOV, aggregated across the profile and broken out per campaign. Runs Amazon's report generation internally (this can take longer than one call allows) -- if the response has status 'processing', call this tool again with the same report_id to resume; do not start a new one. - `amazon_ads_period_comparison` [read-only] — Compares Sponsored Products performance between two arbitrary date ranges (raw counts and derived CTR/CPC/CVR/ACOS/ROAS/AOV, each with before/after/absolute-change/percent-change). Fetches one report spanning both periods, which can take longer than one call allows -- see report_id for resuming. - `amazon_ads_roas_decomposition` [read-only] — Decomposes a ROAS change between two periods into its CPC/CVR/AOV drivers using exact logarithmic decomposition (each driver's contribution sums exactly to the total change -- no residual/interaction term). Fetches one report spanning both periods, which can take longer than one call allows -- see report_id for resuming. - `amazon_ads_roas_root_cause` [read-only] — Diagnoses WHY ROAS changed between two periods -- classifies as seasonality_dominant / management_dominant / retail_dominant / mix_shift / mixed / inconclusive, with evidence and (when supported) a quantitative seasonality-vs-management contribution split. Fetches its own performance data plus, if a sibling Amazon SP-API connection exists in this workspace, retail context (Buy Box change) automatically. For the strongest diagnosis, call amazon_ads_management_transition_analysis, amazon_ads_year_over_year_comparison, and amazon_ads_seasonality_analysis FIRST and pass their raw output back in as management_transition/year_over_year/seasonality -- each is its own bounded Amazon report and can't all be fetched inside this one call. Without them, this tool still runs on ROAS comparison + driver decomposition + retail context alone, with lower confidence and a note on what's missing. Never turns correlation into certainty -- a quantitative contribution split is only produced when the underlying comparisons genuinely support one. - `amazon_ads_sb_create_ad_group` [write, off by default] — Create an ad group within a Sponsored Brands campaign. - `amazon_ads_sb_create_campaign` [write, off by default] — Create a Sponsored Brands campaign with a daily budget. Always created PAUSED. - `amazon_ads_sb_create_keywords` [write, off by default] — Add keywords to a Sponsored Brands ad group. - `amazon_ads_sb_list_ad_groups` [read-only] — List Sponsored Brands ad groups, optionally filtered by campaign. - `amazon_ads_sb_list_campaigns` [read-only] — List Sponsored Brands campaigns on a profile. - `amazon_ads_sb_list_keywords` [read-only] — List keywords, optionally filtered by ad group. - `amazon_ads_sb_update_ad_group` [write, off by default] — Rename or pause/enable a Sponsored Brands ad group. - `amazon_ads_sb_update_campaign` [write, off by default] — Rename, pause/enable, or change a Sponsored Brands campaign's daily budget. Enabling a paused campaign or increasing its budget starts or grows real spend -- requires confirm_spend: true. - `amazon_ads_sb_update_keyword` [write, off by default] — Change a keyword's bid or pause/enable it. - `amazon_ads_sd_create_ad_group` [write, off by default] — Create an ad group within a Sponsored Display campaign. - `amazon_ads_sd_create_campaign` [write, off by default] — Create a Sponsored Display campaign with a daily budget. Always created PAUSED. - `amazon_ads_sd_create_targets` [write, off by default] — Add audience or product targeting clauses to a Sponsored Display ad group. - `amazon_ads_sd_list_ad_groups` [read-only] — List Sponsored Display ad groups, optionally filtered by campaign. - `amazon_ads_sd_list_campaigns` [read-only] — List Sponsored Display campaigns on a profile. - `amazon_ads_sd_list_targets` [read-only] — List audience/product/contextual targeting clauses, optionally filtered by ad group. - `amazon_ads_sd_update_ad_group` [write, off by default] — Rename, pause/enable, or change a Sponsored Display ad group's default bid. - `amazon_ads_sd_update_campaign` [write, off by default] — Rename, pause/enable, or change a Sponsored Display campaign's daily budget. Enabling a paused campaign or increasing its budget starts or grows real spend -- requires confirm_spend: true. - `amazon_ads_sd_update_target` [write, off by default] — Change a target's bid or pause/enable it. - `amazon_ads_seasonality_analysis` [read-only] — Analyzes average ROAS/sales by calendar month across the requested history to surface recurring seasonal patterns. Requires at least 24 months of daily data to produce a conclusion -- with less, returns insufficient_history rather than guessing from one observation. This is the heaviest tool in this connector under ServeMCP's live-fetch model (no local historical warehouse): a multi-year daily report is large and MAY require multiple resumed calls (see report_id) before it completes. - `amazon_ads_snapshot_config_history` [write, off by default] — Fetches this profile's current Sponsored Products campaign/ad-group/target configuration, diffs it against the most recent stored snapshot for this connection, and records what changed. Amazon has no historical config-change API, so this is the ONLY way ServeMCP can answer 'what changed and when' -- and history is only as complete as how often this tool is actually called. Run it regularly (or on a schedule via an external cron calling this tool) for meaningful history. Writes to ServeMCP's own database, not Amazon. - `amazon_ads_sp_archive_negative_keywords` [write, destructive, off by default] — Archive (permanently remove) negative keywords. Amazon has no delete endpoint for these -- archiving via state: ARCHIVED is the only removal path and cannot be undone. - `amazon_ads_sp_create_ad_group` [write, off by default] — Create an ad group within a Sponsored Products campaign. - `amazon_ads_sp_create_campaign` [write, off by default] — Create a Sponsored Products campaign with a daily budget. Always created PAUSED -- use amazon_ads_sp_update_campaign with confirmSpend to activate it once you've reviewed the setup. - `amazon_ads_sp_create_keywords` [write, off by default] — Add keywords to an ad group. - `amazon_ads_sp_create_negative_keywords` [write, off by default] — Add ad-group-level negative keywords to exclude search terms from matching. - `amazon_ads_sp_create_negative_targets` [write, off by default] — Add ad-group-level negative product targets to exclude specific ASINs from matching. - `amazon_ads_sp_create_product_ads` [write, off by default] — Add products (by SKU or ASIN) as ads within an ad group. - `amazon_ads_sp_create_targets` [write, off by default] — Add product or category targeting clauses to an ad group (for MANUAL targeting_type campaigns). - `amazon_ads_sp_list_ad_groups` [read-only] — List Sponsored Products ad groups, optionally filtered by campaign. - `amazon_ads_sp_list_campaigns` [read-only] — List Sponsored Products campaigns on a profile. - `amazon_ads_sp_list_keywords` [read-only] — List keywords, optionally filtered by ad group. - `amazon_ads_sp_list_negative_keywords` [read-only] — List ad-group-level negative keywords, optionally filtered by ad group. - `amazon_ads_sp_list_negative_targets` [read-only] — List ad-group-level negative product targets. - `amazon_ads_sp_list_product_ads` [read-only] — List product ads, optionally filtered by ad group. - `amazon_ads_sp_list_targets` [read-only] — List product/category targeting clauses, optionally filtered by ad group. - `amazon_ads_sp_update_ad_group` [write, off by default] — Rename, pause/enable, or change an ad group's default bid. - `amazon_ads_sp_update_campaign` [write, off by default] — Rename, pause/enable, or change a Sponsored Products campaign's daily budget. Enabling a paused campaign or increasing its budget starts or grows real spend -- requires confirmSpend: true. - `amazon_ads_sp_update_keyword` [write, off by default] — Change a keyword's bid or pause/enable it. - `amazon_ads_sp_update_product_ad_status` [write, destructive, off by default] — Pause, enable, or archive a product ad. - `amazon_ads_sp_update_target` [write, off by default] — Change a target's bid or pause/enable it. - `amazon_ads_year_over_year_comparison` [read-only] — Compares Sponsored Products performance for a date range against the same calendar dates exactly one year earlier. Fetches one report spanning both years, which can take longer than one call allows -- see report_id for resuming. ## Printify Print-on-demand product/order/catalog management. 34 tools: 17 read-only, 17 write. - `printify_archive_upload` [write, destructive, off by default] — Archive a previously uploaded image. IRREVERSIBLE -- an archived upload can no longer be used in new print areas. - `printify_calculate_order_shipping` [read-only] — Calculate shipping cost options for a set of line items and an address, without creating an order. - `printify_cancel_order` [write, destructive, off by default] — Cancel an order that has not yet been sent to production. IRREVERSIBLE once accepted -- an order already in production cannot be canceled this way. - `printify_create_product` [write, off by default] — Create a new product in a shop from a blueprint, print provider, and variant/pricing list. - `printify_create_webhook` [write, off by default] — Register a new webhook on a shop for a given event topic. - `printify_delete_product` [write, destructive, off by default] — Permanently delete a product from a shop. IRREVERSIBLE. - `printify_delete_webhook` [write, destructive, off by default] — Permanently remove a webhook from a shop. IRREVERSIBLE. - `printify_disconnect_shop` [write, destructive, off by default] — Permanently disconnect a shop's sales-channel connection from this Printify account. IRREVERSIBLE -- the shop stops syncing and would need to be reconnected from Printify's own UI. - `printify_get_blueprint` [read-only] — Get full details of one product blueprint. - `printify_get_blueprint_print_providers` [read-only] — List the print providers available for one blueprint. - `printify_get_blueprint_variants` [read-only] — List the variants (size/color combinations) a specific print provider offers for a blueprint. - `printify_get_order` [read-only] — Get full details of one order, including its line items, shipping, and production status. - `printify_get_print_provider` [read-only] — Get full details of one print provider (location, its full blueprint list). - `printify_get_product` [read-only] — Get full details of one product, including its variants and print areas. - `printify_get_shipping_costs` [read-only] — Get the v2 shipping-cost breakdown (economy/express/priority/standard) for a blueprint+print-provider combination. Optionally scope to a single shipping method. - `printify_get_upload` [read-only] — Get details of one previously uploaded image. - `printify_get_variant_shipping` [read-only] — Get the v1 shipping-cost table for a blueprint+print-provider combination. - `printify_list_blueprints` [read-only] — List every product blueprint (e.g. "Unisex Heavy Cotton Tee") in Printify's catalog. - `printify_list_orders` [read-only] — List orders in a shop. - `printify_list_print_providers` [read-only] — List every print provider in Printify's catalog, independent of any one blueprint. Missing from the community printify-mcp server this was scoped from -- only the blueprint-scoped lookup existed there. - `printify_list_products` [read-only] — List products in a shop. - `printify_list_shops` [read-only] — List every shop visible to this Printify account's token. Use this to discover shopId values for every other shop-scoped tool. - `printify_list_uploads` [read-only] — List previously uploaded images on this account. - `printify_list_webhooks` [read-only] — List webhooks configured on a shop. - `printify_publish_product` [write, off by default] — Push a product live to its shop's connected sales channel. Publishes the fields requested (title/description/images/variants/tags default to true). - `printify_send_order_to_production` [write, destructive, off by default] — Send a draft order to production -- this starts real fulfillment and charges the shop's payment method. Requires confirm: true. - `printify_set_product_publish_failed` [write, off by default] — Complete Printify's publish handshake by reporting that publishing this product to the external sales channel failed, with a reason. Only meaningful if this connection is itself acting as a custom Printify sales-channel integration. - `printify_set_product_publish_succeeded` [write, off by default] — Complete Printify's publish handshake by reporting that this product was successfully created on the external sales channel, with the channel's own product/variant IDs. Only meaningful if this connection is itself acting as a custom Printify sales-channel integration. - `printify_submit_express_order` [write, off by default] — Create and immediately send an order to production in one call, bypassing the draft/review step. Use printify_submit_order instead when you want to review before production. - `printify_submit_order` [write, off by default] — Create a draft order from existing products' variants and a shipping address. Does not send to production -- call printify_send_order_to_production once reviewed. - `printify_unpublish_product` [write, off by default] — Remove a previously published product from its shop's connected sales channel. - `printify_update_product` [write, off by default] — Update an existing product's title, description, variant pricing/enablement, or print areas. - `printify_update_webhook` [write, off by default] — Change the delivery URL of an existing webhook. - `printify_upload_image` [write, off by default] — Upload an image for use in print areas, either from a remote URL or base64-encoded content. Provide exactly one of url or contentsBase64. ## Microsoft Advertising Campaign/ad group/ad/keyword management and async reporting against the Microsoft Advertising API v13 (bingads-13). 29 tools: 15 read-only, 14 write. - `microsoft_ads_add_negative_keywords` [write, off by default] — Add negative keywords to a campaign or ad group to exclude search terms from matching. Negative keywords only restrict spend, never grow it, so this doesn't require confirmSpend. - `microsoft_ads_create_ad` [write, off by default] — Create a Responsive Search Ad in an ad group -- Microsoft requires 3-15 headlines (<=30 chars each) and 2-4 descriptions (<=90 chars each). Always created Paused so it never spends before review. - `microsoft_ads_create_ad_group` [write, off by default] — Create a Search ad group under an existing campaign. Always created PAUSED. - `microsoft_ads_create_campaign` [write, off by default] — Create a Search campaign with a new daily budget. Always created PAUSED -- use microsoft_ads_update_campaign with confirmSpend to activate it once you've reviewed the setup. - `microsoft_ads_create_keyword` [write, off by default] — Add a keyword to an ad group. Always created Paused so it never spends before review. - `microsoft_ads_create_report` [write, off by default] — Request an Account Performance or Keyword Performance report. Returns a reportRequestId -- call microsoft_ads_get_report_status to check when it's ready, then microsoft_ads_get_report_result to fetch it. Report generation is asynchronous and can take minutes; this call returns immediately. - `microsoft_ads_delete_ad` [write, destructive, off by default] — Permanently delete an ad. This cannot be undone. - `microsoft_ads_delete_ad_group` [write, destructive, off by default] — Permanently delete an ad group and everything under it (ads, keywords). IRREVERSIBLE. - `microsoft_ads_delete_campaign` [write, destructive, off by default] — Permanently delete a campaign and everything under it (ad groups, ads, keywords). IRREVERSIBLE. - `microsoft_ads_delete_keyword` [write, destructive, off by default] — Permanently delete a keyword. This cannot be undone. - `microsoft_ads_get_account` [read-only] — Get full details of one AdvertiserAccount -- currency, time zone, pause reason, and parent customer. - `microsoft_ads_get_ad` [read-only] — Get a single ad by ID, with its full headline/description set, final URL, and status. - `microsoft_ads_get_ad_group` [read-only] — Get full details of one ad group by ID. - `microsoft_ads_get_campaign` [read-only] — Get full details of one campaign by ID. - `microsoft_ads_get_keyword` [read-only] — Get a single keyword by ID, with its match type, bid, and status. - `microsoft_ads_get_report_result` [read-only] — Fetch and parse a completed report's data. Returns an error if the report hasn't finished -- call microsoft_ads_get_report_status first to check. Large reports are truncated to the first 2000 rows; check the returned total_rows/truncated fields. - `microsoft_ads_get_report_status` [read-only] — Poll a report's generation status. Call microsoft_ads_get_report_result once status is Success. - `microsoft_ads_list_accounts` [read-only] — List the AdvertiserAccounts under a Customer (Manager account). - `microsoft_ads_list_account_users` [read-only] — List the users associated with the Customer that owns this account, with their roles. Useful for confirming who has access before making changes on an account's behalf. - `microsoft_ads_list_ad_group_negative_keywords` [read-only] — Negative keywords excluded at the ad group level, with match type. - `microsoft_ads_list_ad_groups` [read-only] — Ad groups under a campaign, with status and bid. - `microsoft_ads_list_ads` [read-only] — List the ads in an ad group, with their headlines, descriptions, final URL, and status. - `microsoft_ads_list_campaigns` [read-only] — Search campaigns on this account, with status, budget, and bidding strategy. - `microsoft_ads_list_customers` [read-only] — List the Customers (Manager accounts) the authenticated user can access. This is the entry point for discovering customerId/accountId values -- call this before any other Microsoft Ads tool if you don't already have them. - `microsoft_ads_list_keywords` [read-only] — List the keywords in an ad group, with match type, bid, and status. - `microsoft_ads_update_ad` [write, off by default] — Pause or enable an ad, or edit its headlines/descriptions/final URL. Enabling an ad under an active ad group resumes its spend -- requires confirmSpend: true. - `microsoft_ads_update_ad_group` [write, off by default] — Rename, pause/enable, or change an ad group's CPC bid. Enabling one under an active campaign resumes its spend -- requires confirmSpend: true. - `microsoft_ads_update_campaign` [write, off by default] — Rename, pause/enable, or change a campaign's daily budget. Enabling a paused campaign or increasing its budget starts or grows real spend -- requires confirmSpend: true. - `microsoft_ads_update_keyword` [write, off by default] — Change a keyword's bid, match type, or pause/enable it. Enabling a keyword under an active ad group, or raising its bid, both increase spend -- requires confirmSpend: true. Because the current bid isn't read back before this call, any bid value provided is treated as a possible increase and gated the same way. ## Cloudflare DNS, zone/security settings, WAF, Workers, and analytics. Customers supply their own scoped API Token per connection. 27 tools: 14 read-only, 13 write. - `cloudflare_create_dns_record` [write, off by default] — Create a DNS record in a zone. - `cloudflare_create_firewall_rule` [write, off by default] — Add a rule to a zone's custom WAF ruleset. `expression` uses Cloudflare's Wireshark-inspired rules language, e.g. `(http.request.uri.path contains "/admin") and not ip.src in {1.2.3.4}`. - `cloudflare_create_workers_route` [write, off by default] — Bind a URL pattern (e.g. 'sub.example.com/*') in this zone to a Worker script. - `cloudflare_delete_dns_record` [write, destructive, off by default] — Permanently delete a DNS record. This is destructive -- confirm the record_id first with cloudflare_get_dns_record. - `cloudflare_delete_firewall_rule` [write, destructive, off by default] — Permanently remove a rule from a zone's custom WAF ruleset. Confirm rule_id first with cloudflare_get_firewall_ruleset. - `cloudflare_delete_workers_route` [write, destructive, off by default] — Remove a route binding. Requests matching its pattern will stop reaching the Worker. - `cloudflare_delete_workers_script` [write, destructive, off by default] — Permanently delete a Worker script. Any routes still pointing at it will start failing. - `cloudflare_deploy_workers_script` [write, destructive, off by default] — Upload/overwrite a Worker script's live code. This takes effect immediately with no rollback -- confirm the script name and content are correct before calling. - `cloudflare_get_dns_analytics` [read-only] — DNS query analytics for a zone over a date range: query volume by type and response code. - `cloudflare_get_dns_record` [read-only] — Get a single DNS record by ID. - `cloudflare_get_firewall_ruleset` [read-only] — Read a zone's custom WAF ruleset, including every rule in it (expression, action, enabled state). - `cloudflare_get_security_events` [read-only] — Recent WAF/firewall events for a zone: what was blocked/challenged/logged, and by which rule. - `cloudflare_get_workers_cron_triggers` [read-only] — Get a Worker script's cron trigger schedule. - `cloudflare_get_workers_script_content` [read-only] — Get a Worker script's raw source code. This is not structured JSON -- large scripts may be truncated by the MCP client transport; prefer cloudflare_get_workers_script_metadata when source isn't needed. - `cloudflare_get_workers_script_metadata` [read-only] — Get a Worker script's metadata (size, modified date, usage model). Does not return source code. - `cloudflare_get_zone` [read-only] — Get a zone's status, plan, and name servers. - `cloudflare_get_zone_analytics` [read-only] — Traffic analytics for a zone over a date range: requests, bandwidth, threats blocked, cached vs. uncached. - `cloudflare_get_zone_settings` [read-only] — Bulk-read all of a zone's settings (SSL mode, security level, cache level, etc.). - `cloudflare_list_dns_records` [read-only] — List DNS records for a zone, optionally filtered by type or name. - `cloudflare_list_workers_routes` [read-only] — List URL-pattern-to-script route bindings for a zone. - `cloudflare_list_workers_scripts` [read-only] — List Worker scripts in this connection's account. - `cloudflare_list_zones` [read-only] — List the zones (domains) visible to this connection's API token. - `cloudflare_purge_cache` [write, destructive, off by default] — Purge cached content for a zone -- by specific file URLs, cache tags, hostnames, or everything. A full purge is a real operational event: it forces every cached asset to be re-fetched from origin, which can spike origin traffic. Prefer scoping to files/tags/hosts over purge_everything when possible. - `cloudflare_update_dns_record` [write, off by default] — Update an existing DNS record. - `cloudflare_update_firewall_rule` [write, off by default] — Update an existing rule in a zone's custom WAF ruleset. Confirm rule_id first with cloudflare_get_firewall_ruleset. - `cloudflare_update_workers_cron_triggers` [write, off by default] — Replace a Worker script's full cron trigger schedule (this is a full replace, not an incremental add). - `cloudflare_update_zone_setting` [write, destructive, off by default] — Update one zone setting. Only a vetted allowlist of settings can be changed through this tool -- a wrong SSL mode or security level can take a zone offline, so this deliberately does not accept arbitrary Cloudflare setting IDs. ## UniFi Network Read-only site, device, and client visibility. Customers supply their own controller credentials per connection. 25 tools: 23 read-only, 2 write. - `unifi_confirm_radio_config` [read-only] — [API: Local] Cancels the pending auto-revert for a radio config change made with unifi_set_radio_config and marks it permanent. Errors if the revision has no pending auto-revert (already confirmed, already reverted, or auto_revert was false when it was made) or if the auto-revert already fired. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. - `unifi_find_client` [read-only] — [API: Integration] Find a client by name, MAC address, or IP address on a UniFi site. - `unifi_get_alarms` [read-only] — [API: Local] Get system-generated alarms for a UniFi site over a time range (distinct from the general event log — alarms are explicit alerts like WAN disconnects) via local controller API access. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. Returns a clear error if local API access hasn't been set up, and also returns UNIFI_UNSUPPORTED_OPERATION on some newer Network application versions where this endpoint has been relocated or removed. - `unifi_get_client` [read-only] — [API: Integration] Get details for a single client device on a UniFi site. - `unifi_get_device` [read-only] — [API: Integration] Get details for a single UniFi device. - `unifi_get_firmware_status` [read-only] — [API: Integration] Get firmware version and update-available status for devices on a UniFi site. Requires the read-advanced permission profile. - `unifi_get_offline_devices` [read-only] — [API: Integration] List devices on a UniFi site that are currently offline. - `unifi_get_port_stats` [read-only] — [API: Local] Get port-level statistics for a UniFi device — link speed, duplex, up/down state, rx/tx error counters, and device uptime (so error counts can be read as a rate, not just a raw total) — including which port is WAN-facing on a gateway, if determinable. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection (a separate, higher-privilege credential from the main connection — see the connection's settings). Returns a clear error if local API access hasn't been set up. - `unifi_get_radio_config` [read-only] — [API: Local] Read-only. Current channel, channel width, and tx power mode/value for every radio on a UniFi AP (or every AP on a site if device_mac is omitted), with device names resolved. Use this to plan a change before calling unifi_set_radio_config, and to verify one afterward without a mutating call. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. - `unifi_get_recent_events` [read-only] — [API: Local] Get recent events (WAN transitions, link flaps, reconnects, and more) for a UniFi site over a time range, via local controller API access. The Integration API has no events endpoint at all, so this returns UNIFI_UNSUPPORTED_OPERATION if local API access isn't configured for this connection — requires the read-advanced permission profile. Also returns UNIFI_UNSUPPORTED_OPERATION on some newer Network application versions where this endpoint has been relocated or removed. - `unifi_get_site_health` [read-only] — [API: Integration (derived)] Get a ServeMCP-computed health rollup for a UniFi site (online/offline device counts, connected client count) derived from device and client inventory — the UniFi Integration API has no native site-health endpoint, so this is not a raw controller-reported score. - `unifi_get_throughput_history` [read-only] — [API: Local] Get historical throughput (bytes transferred over time, at 5-minute or daily granularity) for a UniFi site or a single device, via local controller API access. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. Device-level queries can return two rows per timestamp — one labeled 'device' (general/aggregate counters) and one labeled 'wan' (specifically the WAN interface) — this is intentional interface-level detail, not duplicated data. Field names for the underlying report are the least-documented part of the UniFi local API — returns whatever throughput-shaped metrics the controller actually provides rather than a fixed set. Returns a clear error if local API access hasn't been set up. - `unifi_get_top_bandwidth_clients` [read-only] — [API: Integration (derived)] Get the highest-bandwidth-consuming clients on a UniFi site based on current-session traffic counters (the UniFi Integration API has no historical time-range query, so this reflects current usage, not a bounded past window). Requires the read-advanced permission profile. Returns UNIFI_UNSUPPORTED_OPERATION if the controller doesn't expose per-client traffic counters — if that happens, try unifi_get_throughput_history instead, which uses local API access and does have historical data. - `unifi_get_wan_health` [read-only] — [API: Local] Get a real WAN health summary (ISP name, WAN IP, latency, availability, uptime, current throughput, and per-monitor ping/DNS results) for a UniFi site via local controller API access. The Integration API has no equivalent endpoint at all, so this returns UNIFI_UNSUPPORTED_OPERATION if local API access isn't configured for this connection — requires the read-advanced permission profile. Dropped-packet count is not available from this endpoint and is always null. - `unifi_get_wifi_health` [read-only] — [API: Local] Get a real Wi-Fi health summary (access point counts, connected/guest client counts, status) for a UniFi site via local controller API access. The Integration API has no equivalent endpoint at all, so this returns UNIFI_UNSUPPORTED_OPERATION if local API access isn't configured for this connection — requires the read-advanced permission profile. - `unifi_get_wireless_client_stats` [read-only] — [API: Local] Per-client wireless RF telemetry via local controller API access — which AP each client is actually on, band and channel, signal strength, and connection rate. The Integration API's client list has no equivalent data (ap_mac and ssid are always null there, and it has no signal field at all) — this is the only way to answer 'is this device on a weak signal / is this a coverage gap / which AP is over-loaded'. IMPORTANT — signal vs rssi are NOT the same scale and are commonly confused: `signal` is the actual measured strength in dBm (e.g. -62, more negative is weaker) — use this for any single dBm figure. `rssi` is a UniFi-computed value in dB ABOVE A NOMINAL NOISE FLOOR (e.g. 44, higher is stronger) and is not comparable to `signal` or to the separately-reported `noise` field. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. Snapshot semantics: the underlying stat/sta endpoint reports only currently-associated clients, polled at call time — it is not a stable census, and a site with clients that connect/disconnect frequently (motion-triggered cameras, phones leaving a building) will show a different total on every call; do not treat one sample as authoritative, and it will often diverge from unifi_list_clients's Integration-API inventory count, which is expected rather than a bug. With include_summary=true, adds a derived rollup: client count per AP (resolved to AP name when available), client count per band, an RSSI histogram in 10dBm buckets from -90 to -30 using `signal`, and a count of clients at or below -75dBm (roaming/coverage-gap candidates). Returns a clear error if local API access hasn't been set up. - `unifi_list_clients` [read-only] — [API: Integration] List client devices connected to a UniFi site, optionally filtered by connection type or online status. Inventory only — this always returns ap_mac: null, ssid: null, and no signal/RSSI field at all (confirmed against the live API), so it cannot answer which AP a client is on or how strong its signal is. For per-client RF telemetry (AP association, band, channel, signal strength), use unifi_get_wireless_client_stats instead, which requires local API access. - `unifi_list_devices` [read-only] — [API: Integration] List network devices (APs, switches, gateways) at a UniFi site. - `unifi_list_pending_reverts` [read-only] — [API: Local] Lists every armed auto-revert, still-retrying revert failure, and drift-skipped revert across the connection (or one site, if site_id is given) — device, radio, what changed, when it reverts, and the retry state of any failure. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. - `unifi_list_radio_revisions` [read-only] — [API: Local] Newest-first history of radio config changes for a site (or one device, if device_mac is given) — what changed, when, whether the post-write readback confirmed it took effect, and its current state (armed / confirmed / auto_reverted / manually_reverted / revert_failed / revert_skipped_drift). A revert is its own revision here too, cross-linked to the one it restored, so the full chain of a device's radio history is visible in one list. Requires the read-advanced permission profile AND local API access to be explicitly configured for this connection. - `unifi_list_sites` [read-only] — [API: Integration] List UniFi sites authorized for this connection. - `unifi_list_switch_ports` [read-only] — [API: Unsupported] Attempts to list switch ports for a UniFi switch device. Not currently supported regardless of credentials — the per-device endpoint it depends on requires an identifier the device list never exposes, on either API. This tool always returns UNIFI_UNSUPPORTED_OPERATION and is kept for forward compatibility if Ubiquiti exposes device IDs in a future API version. Use unifi_get_port_stats instead, which gets the same data via a different local-API endpoint that does work. - `unifi_revert_radio_config` [write, destructive, off by default] — [API: Local] MUTATING. Restores a radio to the state recorded in a prior revision — the same deauth side effect as unifi_set_radio_config, since it is itself a radio config write. Reverting creates a NEW revision capturing what the radio looked like immediately before the revert, so a revert can itself be undone; the original revision is marked reverted and cross-linked to the new one. Refuses if the radio's live config has drifted from what that revision recorded as its result — e.g. someone changed it in the UniFi UI since — and names the drifted fields; pass force: true to override and revert anyway, which will discard that drift. Requires confirm: true, the read-advanced permission profile, and local API access to be explicitly configured for this connection. - `unifi_search` [read-only] — [API: Integration] Search devices and/or clients on a UniFi site by name, MAC, or IP address. Requires the read-advanced permission profile. - `unifi_set_radio_config` [write, destructive, off by default] — [API: Local] MUTATING. Changes an AP radio's channel, channel width, and/or tx power — restricted to exactly those fields; enabling/disabling a radio, SSID/WLAN config, and anything on a gateway or switch are out of scope and refused. The radio restarts to apply the change: every client on it deauthenticates and re-associates, which can take several minutes for battery-powered or sleeping devices (cameras, sensors) to complete — an immediate client count afterward is not a reliable health signal. Every prior state is snapshotted to a revision BEFORE any write is attempted, and by default (auto_revert: true, auto_revert_minutes: 10) the change automatically reverts unless confirmed within that window with unifi_confirm_radio_config — pass auto_revert: false only when you mean the change to be permanent immediately with no safety net. Refuses if this device+radio already has an unresolved pending change (names the blocking revision). Requires confirm: true (a bare call with confirm omitted or false is refused, precisely because of the deauth side effect) and the read-advanced permission profile AND local API access to be explicitly configured for this connection. ## Shopify Order, product, customer, and inventory management. Customers supply their own Dev Dashboard app credentials per connection. 24 tools: 14 read-only, 10 write. - `shopify_add_to_collection` [write, off by default] — Add one or more products to an existing manual collection. - `shopify_bulk_update_product_status` [write, destructive, off by default] — Update the status of multiple products at once, up to 25 per call. Setting status to ARCHIVED hides products from the storefront. There is no dedicated bulk-status mutation on Shopify's API -- this sends one GraphQL request containing an aliased productUpdate call per product, rather than one HTTP round trip per product. - `shopify_create_collection` [write, off by default] — Create a new collection. Pass product_ids for a manual collection of specific products, or rules for a smart collection that auto-populates from conditions (tag, vendor, type, title, or price). Exactly one of product_ids or rules. - `shopify_create_discount` [write, off by default] — Create a price rule and discount code in your Shopify store. - `shopify_create_product` [write, off by default] — Create a new product in your Shopify store (saved as draft by default). - `shopify_fulfill_order` [write, off by default] — Mark a Shopify order as fulfilled and optionally add tracking information. - `shopify_get_collection` [read-only] — Retrieve one Shopify collection by ID: title, description, handle, and product count. - `shopify_get_inventory_levels` [read-only] — Inventory levels for every variant of a product, across all locations. Call this before shopify_update_inventory when passing compare_quantity, to get the current value to compare against. - `shopify_get_order` [read-only] — Retrieve a specific Shopify order by ID. - `shopify_get_product` [read-only] — Get detailed information about a specific Shopify product. - `shopify_get_shop_info` [read-only] — Basic information about the connected Shopify store: name, domain, email, plan, currency, timezone, and country. - `shopify_graphql_mutation` [write, destructive, off by default] — Execute a GraphQL mutation against the Shopify Admin API, for writes with no dedicated tool (metafields, metaobjects, pages, blogs, translations, publications, non-live theme files, etc.). Some mutations are always blocked for safety: refunds, gift card writes, staff/collaborator management, and theme deletion/publishing. Theme file writes are allowed only on a non-live theme -- pass themeId as a $themeId variable, never inlined, so it can be checked first. Use shopify_graphql_schema to look up the exact mutation name and input fields before calling. - `shopify_graphql_query` [read-only, off by default] — Execute a read-only GraphQL query against the Shopify Admin API, for data with no dedicated tool (metafields, metaobjects, pages, blogs, markets, translations, publications, gift cards, etc.). Use shopify_graphql_schema first to look up the correct types and fields. Can only reach whatever this connection's granted scopes already cover. - `shopify_graphql_schema` [read-only, off by default] — Look up a type, query, or mutation on the Shopify Admin GraphQL schema: its fields, arguments, and (for input types) input fields. Use before shopify_graphql_query/shopify_graphql_mutation to confirm exact names rather than guessing. Pass 'QueryRoot' or 'Mutation' to list everything available. - `shopify_list_customers` [read-only] — List customers from your Shopify store. - `shopify_list_orders` [read-only] — List recent orders from Shopify with filtering by status and date. - `shopify_list_products` [read-only] — List products from your Shopify store. - `shopify_run_analytics_query` [read-only, off by default] — Run a ShopifyQL analytics query against the store. Always use FROM...SHOW syntax. Examples: "FROM sales SHOW gross_sales, orders TIMESERIES day SINCE -30d UNTIL today", "FROM sales SHOW gross_sales, orders GROUP BY product_title ORDER BY gross_sales DESC LIMIT 10", "FROM sessions SHOW sessions, conversion_rate TIMESERIES day SINCE -30d UNTIL today". - `shopify_search_collections` [read-only] — Search or list the store's collections by title, handle, or type. Results capped at 50 per call. - `shopify_search_products` [read-only] — Search the store's products with Shopify's query syntax (e.g. 'status:active AND vendor:Nike', 'price:<=25'), cursor pagination, and sorting. Richer than shopify_list_products, which only filters by status/title. - `shopify_update_collection` [write, off by default] — Update a collection's title or description. - `shopify_update_inventory` [write, off by default] — Set the available inventory quantity for a product variant at a specific location. - `shopify_update_product` [write, off by default] — Update an existing Shopify product's title, description, status, or other fields. - `shopify_validate_graphql` [read-only, off by default] — Validate a GraphQL query or mutation against the Shopify Admin schema before executing it with shopify_graphql_query/shopify_graphql_mutation -- catches hallucinated fields, wrong types, and syntax errors early. ## Brevo Email campaigns, contacts, and marketing automation. 12 tools: 7 read-only, 5 write. - `brevo_create_campaign` [write, off by default] — Create a new email campaign in Brevo (saved as draft). Provide HTML content, sender, subject, and optionally schedule it. - `brevo_create_contact` [write, off by default] — Add a new contact to Brevo or update an existing one. Can assign to lists. - `brevo_create_email_template` [write, off by default] — Create a reusable email template in Brevo for use in campaigns or automation. - `brevo_get_account` [read-only] — Get your Brevo account details including plan and usage. - `brevo_get_campaign_stats` [read-only] — Get detailed statistics for a specific email campaign. - `brevo_get_contact` [read-only] — Get details for a specific contact by email address. - `brevo_list_campaigns` [read-only] — List email campaigns with optional status filter. - `brevo_list_contacts` [read-only] — List contacts in your Brevo account, optionally filtered by list. - `brevo_list_lists` [read-only] — List all contact lists in your Brevo account. - `brevo_list_templates` [read-only] — List all email templates in your Brevo account. - `brevo_send_transactional_email` [write, off by default] — Send a one-off transactional email to a specific recipient immediately. - `brevo_update_email_template` [write, off by default] — Update an existing Brevo email template's content, subject, or sender. ## cPanel Hosting Hosting account info, real backups, DNS, SSL and system cron on any cPanel host. Works standalone. 7 tools: 6 read-only, 1 write. - `cpanel_account_info` [read-only] — Disk usage and quota, bandwidth, and the limits the host has set on this cPanel account (databases, email accounts, subdomains, inodes). This is the account-level view a site-level tool cannot see: a site can be perfectly healthy while the account hosting it is at its disk or inode cap, which produces failures that look like application bugs. Always account-wide, even on a scoped connection. Read-only. - `cpanel_create_backup` [write, destructive, off by default] — Asks cPanel to create a full account backup into the account's home directory. A REAL backup, unlike a ServeMCP checkpoint. REFUSED on a scoped connection: a full backup archives every site on the account, so running it from a connection labelled for one client would do something much larger than that connection claims to cover. It also consumes disk roughly equal to the account's own size, which on a near-full account causes its own failures — check cpanel_account_info first. The backup runs asynchronously; this returns once cPanel accepts the request, not once it exists. - `cpanel_dns_records` [read-only] — Lists the DNS zone records cPanel manages for a domain: A, CNAME, MX, TXT and the rest. Useful for confirming where a domain points and for checking SPF and DKIM when email is not delivering. Read-only. Note this shows the zone as cPanel holds it, which is NOT authoritative if the domain's nameservers point elsewhere, such as at Cloudflare — in that case the live answers come from there and this zone is ignored entirely. - `cpanel_list_backups` [read-only] — Lists the backups cPanel holds for the hosting account, with dates and types. This is the real backup story: unlike a ServeMCP checkpoint, which is scoped, short-lived and dies with the server, these are the account's own restore points. Check here before any risky change. Always account-wide. Read-only. - `cpanel_list_cron_jobs` [read-only] — Lists the real system cron jobs on the hosting account, which is different from WordPress's own WP-Cron. This is how you confirm whether a site with DISABLE_WP_CRON set actually has a system cron calling wp-cron.php — that combination with no system cron means scheduled work never runs at all, silently. On a scoped connection the list is filtered to jobs mentioning the scope path. Read-only. - `cpanel_list_databases` [read-only] — Lists the MySQL databases on the hosting account with their sizes, and the users granted access to each. Useful for confirming which database a site actually uses and for spotting abandoned databases still consuming the account's quota. On a scoped connection the list is filtered to databases whose name mentions the scope, which is a convenience rather than a restriction — the token can still see every database on the account. Read-only. - `cpanel_ssl_status` [read-only] — Lists the SSL certificates cPanel has installed, with their domains, issuer and expiry. An expiring or mismatched certificate breaks a site for every visitor at once, with no warning from the application itself. On a scoped connection the list is filtered to the scope domain. Read-only. ## Threads Also by Meta, but a separate app and login. 7 tools: 5 read-only, 2 write. - `threads_create_post` [write, off by default] — Publish a text, image, or video post to the connected Threads account. - `threads_get_post` [read-only] — Get details of a single Threads post. - `threads_get_post_insights` [read-only] — Get engagement metrics (views, likes, replies, reposts, quotes) for a Threads post. - `threads_get_profile` [read-only] — Get the connected Threads account's profile (username, bio, profile picture). - `threads_list_posts` [read-only] — List recent posts from the connected Threads account. - `threads_list_replies` [read-only] — List replies to a Threads post. - `threads_reply_to_post` [write, off by default] — Post a reply to a Threads post. ## Amazon Selling Partner API Read-only retail analytics. 5 tools: 5 read-only, 0 write. - `amazon_spapi_inventory_status` [read-only] — FBA inventory levels for this marketplace -- fulfillable/inbound/reserved quantities per SKU. Synchronous, no polling needed. - `amazon_spapi_list_marketplace_participations` [read-only] — List every marketplace this connection's token can see, across all three regions (North America, Europe, Far East) -- not filtered to just the ones authorized on this connection. Use this to find marketplace IDs to authorize from Settings -> Connections -> Manage Marketplaces. - `amazon_spapi_pricing` [read-only] — Current competitive pricing and offers for up to 20 ASINs in this marketplace, including Buy Box status. Synchronous, no polling needed. - `amazon_spapi_retail_context_analysis` [read-only] — Retail-side signals (Buy Box percentage change) for two periods, in the shape amazon_ads_roas_root_cause's retailContext input expects. Fetches one report spanning both periods, which can take longer than one call allows -- see report_id for resuming. newStockouts and priceChanges are always empty under ServeMCP's live-fetch model -- FBA Inventory and Product Pricing are current-state-only APIs with no historical endpoint, so there is nothing to diff against period1. Not a bug: documented here rather than fabricated. - `amazon_spapi_retail_performance` [read-only] — Live retail sales and traffic (sessions, page views, units ordered, ordered sales, plus derived unit session % and average selling price) for a date range, aggregated and broken out by day. Runs Amazon's report generation internally (this can take longer than one call allows) -- if the response has status 'processing', call this tool again with the same report_id to resume; do not start a new one. ## PostgreSQL Read-only database queries. Customers supply their own connection details per connection. 3 tools: 3 read-only, 0 write. - `postgres_describe_table` [read-only] — Get column definitions and metadata for a specific table. - `postgres_list_tables` [read-only] — List all tables in the connected PostgreSQL database. - `postgres_run_readonly_query` [read-only] — Execute a read-only SELECT query against the connected PostgreSQL database. Only SELECT statements are allowed.