List tools for one connection
/connection/{id}/tools
What this authenticated account can run: the connector's tools, each flagged `restricted`/`restricted_by` for the caller rather than filtered out — this is where a PARTIALLY restricted connection says so, since the connection row's own `restricted_by` asserts the whole connector is blocked. Contrast `GET /connector/{slug}/tools`, which is the catalog capability with no account behind it. A restricted connector answers 403. Resolves the same access as `GET /connection/{id}`: a connection the caller holds no grant on is `404`, with no oversight opt-in of any kind — a `visibility` query parameter is not accepted. `q` and `operation` are both applied before paging, and `operation_counts` describes the `q`-filtered set (never narrowed further by `operation` itself), same as `GET /connector/{slug}/tools`. For a REMOTE MCP connection ("bring your own") the rows are the tools THIS connection's own credentials listed, from per-connection discovery: `name`, `upstream_name`, `title`, the whole `description` of this connection's definition, `status` (`active` | `disabled`, the connector-wide on/off), the `tier` (the server's label), `tier_source` (`server` | `default`), `operation` (the tier as `read` | `other` | `delete`, computed here for the access picker) and `last_seen_at`, plus the same restriction flags. `q` and `status` are applied before paging, on the server. A caller who manages the connection may filter by either `status` and sees tools that are turned off; everyone else with access is shown `active` tools only, whatever `status` they send. When the connection's connector is gone from the catalog (staff unpublished or deleted it) the answer is `409 connector_unavailable` with a message a person can read; the connection itself is kept.
Path Parameters
Connection id (conn_…).
Query Parameters
Case-insensitive substring match on name, description and resource. LIKE wildcards are matched literally. Max 200 characters.
Comma-separated CRUD buckets to keep: read, create, update, delete, other. Unknown values 400. Applied before paging, so the cursor never counts a row the filter would have hidden.
Response Body
How many tools of each CRUD bucket the q filter alone leaves — never narrowed further by operation itself, so the count beside an unselected filter chip stays honest. Repeated on every page.
JSON Schema for the tool arguments.
remote_mcp for a tool from a remote MCP connector (its resource is the constant mcp, its method the upstream name, and title may be set), catalog for every other tool.
catalogremote_mcp
Exact tool name — what a toolbox entry's tool_name must contain.
The CRUD bucket this tool falls into, computed server-side from its resolved HTTP verb (src/connector/toolOperation.ts) — never re-derive it client-side. Filter with ?operation=.
readcreateupdatedeleteother
True when the caller's restrictions block THIS tool. Blocked tools are returned flagged, never omitted — a shorter list is no signal, because nobody knows the length it should have been. Presence is not permission: execution still refuses it. The connector-level 403 is a separate question and is unchanged.
Which precedence layer's rule blocks this tool, null when none does. Same field, union and meaning as on connector and connection rows: adds which to restricted's whether and nothing else — no rule id, author, reason or coverage. restricted === (restricted_by !== null) always.
roleusernull
"connector" when the tool is refused because its WHOLE connector is restricted for the caller, "tool" for a rule about the tool itself, null exactly when restricted_by is. Decides which ask can succeed: a tool request on a connector restricted whole is refused (409 tool_request_connector_blocked), so ask for the connector. On this listing it is only ever "tool" when set, since a connector restricted whole 403s the route; toolbox entries carry the same field and can say "connector".
connectortoolnull
Always present. What the approval gate and the MCP scope ladder treat this tool as — classifyToolMethod, the one function they share, so a badge can never disagree with the gate. A remote MCP tool's is derived from the server's annotations (unannotated means destructive) and always follows it, up or down, on a refresh. A system-catalog tool whose method documents mcp_annotations takes the tier those give (an HTTP DELETE is always destructive); any other catalog tool, including every custom connector and fork tool, takes it from its method and HTTP verb. Never infer a remote MCP tool from it: read kind.
readwritedestructive
Why a remote MCP tool's tier is what it is: server (the MCP server's own annotations decided it) or default (the server labeled the tool neither way, so the MCP safe default destructive applies). Lets a client say "Not labeled" rather than show a tier nobody chose. Present only on a remote MCP tool.
serverdefault
The upstream server's human title for the tool. Present only on a remote MCP tool that has one.
curl -X GET 'https://api.elaichi.ai/connection/<id>/tools' \
-H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
-H 'Content-Type: application/json'const response = await fetch('https://api.elaichi.ai/connection/<id>/tools', {
method: 'GET',
headers: {
'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
'Content-Type': 'application/json',
},
});
const data = await response.json();
console.log(data);import os
import requests
url = "https://api.elaichi.ai/connection/<id>/tools"
headers = {
"Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
"Content-Type": "application/json",
}
response = requests.get(url, headers=headers)
print(response.json())