FruxonDocs
IntegrationsTools

Reviews what a workspace tool does.

Records that a signed-in person checked the tool and chose its classification — `READ_ONLY`, `REVERSIBLE` or `IRREVERSIBLE` — which becomes its `actionType`. The review names the `definitionVersion` the reviewer saw, and stops applying as soon as the tool's definition or classification changes (`actionTypeReviewState` then reads `CHANGED_SINCE_REVIEW`). API keys and service accounts cannot review: a review has to come from a person. Built-in tools cannot be reviewed.

POST
/v1/tenants/{tenant}/integrations/{integration}/tools/{tool}:review
AuthorizationBearer <token>

JWT Authorization header using the Bearer scheme. Enter 'Bearer' [space] and then your token.

In: header

Path Parameters

integration*string

The integration identifier.

tool*string

The unique identifier of the AI Tool.

tenant*string

The tenant identifier

The chosen classification and the definition version it applies to.

actionType?string

What the tool does: READ_ONLY, REVERSIBLE or IRREVERSIBLE. Becomes the tool's actionType.

Value in"UNSPECIFIED" | "READ_ONLY" | "REVERSIBLE" | "IRREVERSIBLE"
definitionVersion?integer

The tool's definitionVersion as the reviewer saw it. A tool whose definition has moved on since answers 409, so a review can only ever approve a definition its reviewer saw.

Formatint32
[key: string]?never

Response Body

curl -X POST "https://api.fruxon.com/v1/tenants/string/integrations/string/tools/string:review" \  -H "Content-Type: application/json" \  -d '{}'
{
  "descriptor": {
    "apiTool": {
      "headers": {},
      "httpMethod": "string",
      "url": "string",
      "queryParameters": {},
      "body": "string",
      "bodyContentType": "string",
      "formParameters": {},
      "resultType": "STRING",
      "resultTransformExpression": "string",
      "pagination": {
        "cursorPath": "string",
        "hasMorePath": "string",
        "offset": null,
        "linkHeader": null
      },
      "successStatusCodes": [
        0
      ],
      "multipart": {
        "parts": []
      },
      "timeoutMs": 0,
      "responseSchema": null
    },
    "predefinedTool": {
      "resultType": "STRING"
    },
    "mcpTool": {
      "serverUrl": "string",
      "mcpToolName": "string",
      "annotations": {
        "readOnlyHint": null,
        "destructiveHint": null,
        "idempotentHint": null,
        "openWorldHint": null
      },
      "resultType": "STRING"
    },
    "codeTool": {
      "code": "string",
      "timeoutSeconds": 0,
      "packages": [
        "string"
      ],
      "resultType": "STRING"
    }
  },
  "isInternal": false,
  "isDeprecated": false,
  "isAsync": false,
  "createdAt": 0,
  "id": "string",
  "modifiedAt": 0,
  "integrationId": "string",
  "displayName": "string",
  "description": "string",
  "toolType": "API",
  "isModifiable": true,
  "actionType": "READ_ONLY",
  "definitionVersion": 0,
  "actionTypeReview": {
    "actionType": "READ_ONLY",
    "definitionVersion": 0,
    "reviewedAt": 0,
    "reviewedBy": "string"
  },
  "actionTypeReviewState": "REVIEWED",
  "messagingRole": "CHANNEL_SEND",
  "resultType": "STRING",
  "parametersMetadata": [
    {
      "name": "string",
      "index": 0,
      "type": "STRING",
      "typeName": "STRING",
      "integerRange": {
        "min": 0,
        "max": 0
      },
      "floatRange": {
        "min": 0,
        "max": 0
      },
      "options": [],
      "asset": {
        "providers": null,
        "contentTypes": null,
        "vectorized": false
      },
      "displayName": "string",
      "description": "string",
      "required": false,
      "secret": false,
      "secretResolvable": false,
      "defaultValue": "string",
      "jsonSchema": null,
      "minLength": 0,
      "maxLength": 0,
      "pattern": "string",
      "validator": "string",
      "uiHint": "CODE",
      "rules": []
    }
  ],
  "authSettings": {
    "supportsOAuth": false,
    "oAuth": [
      {
        "scopeSize": 0,
        "scopes": [],
        "userScopes": [],
        "allScopes": [],
        "requiresResourceAuth": false,
        "successfulOAuthRedirect": "string"
      }
    ]
  }
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}
Empty
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}

Updates an existing Python script tool.

Replaces the Python-script tool definition at `(integration, tool)`; the script body and its input schema are validated together before the write commits, so a malformed script or schema returns 400 without modifying the stored definition. This is the script-tool counterpart to `PUT /integrations/{integration}/tools/{tool}` and must be used for tools whose execution is sandboxed Python rather than an HTTP call.

Runs a tool with the provided parameters.

Resolves the tool by ID within the integration and executes it. When `configId` is set the tool runs against that config's currently published revision — the server resolves its (encrypted) credentials internally, so no secret ever travels in the request. Omit `configId` for SYSTEM / no-auth tools (e.g. File Tools), which run against an empty placeholder config. An optional `resultSelect` previews the agent runtime's `result_select` field projection over a JSON result; it is preview-only and never persisted. Every value in `parameters` must be sent as a JSON <b>string</b>, whatever the parameter's declared type — `"count": "3"`, `"dryRun": "true"`, `"rows": "[[1,2]]"`. The bag is typed server-side against the tool's declared parameters; sending a bare number, boolean or object fails model binding with 400 `"The JSON value could not be converted to System.String"`. The result comes back both ways: `response` is the flattened string form (unchanged), and `resultType` / `jsonValue` / `fileLink` carry the shape the tool actually returned, so a caller need not sniff `response` nor fetch the tool's metadata to learn its type.