# List tools for one connection

> Source: https://elaichi.ai/docs/api-reference/connections/connection/listconnectiontools/

`GET /connection/{id}/tools`

Resource: **Connection** · API: **Connections**

## Path parameters

- **`id`** _(string, required)_
  Connection id (`conn_…`).

## Query parameters

- **`q`** _(string)_
  Case-insensitive substring match on `name`, `description` and `resource`. LIKE wildcards are matched literally. Max 200 characters.
- **`operation`** _(string)_
  Comma-separated CRUD buckets to keep: read, create, update, delete, other. Unknown values 400. Applied before paging, so the cursor never counts a row the filter would have hidden.

## Response body

- **`result`** _(array<object>)_
  - **`name`** _(string)_
    Exact tool name — what a toolbox entry's `tool_name` must contain.
  - **`description`** _(string)_
  - **`resource`** _(string)_
  - **`method`** _(string)_
  - **`input_schema`** _(object)_
    JSON Schema for the tool arguments.
  - **`title`** _(string)_
    The upstream server's human title for the tool. Present only on a remote MCP tool that has one.
  - **`tier`** _(string)_
    Always present. What the approval gate and the MCP scope ladder treat this tool as — `classifyToolMethod`, the one function they share, so a badge can never disagree with the gate. A remote MCP tool's is derived from the server's annotations (unannotated means `destructive`) and always follows it, up or down, on a refresh. A system-catalog tool whose method documents `mcp_annotations` takes the tier those give (an HTTP DELETE is always `destructive`); any other catalog tool, including every custom connector and fork tool, takes it from its method and HTTP verb. Never infer a remote MCP tool from it: read `kind`.
    Allowed: `read`, `write`, `destructive`
  - **`kind`** _(string)_
    `remote_mcp` for a tool from a remote MCP connector (its `resource` is the constant `mcp`, its `method` the upstream name, and `title` may be set), `catalog` for every other tool.
    Allowed: `catalog`, `remote_mcp`
  - **`tier_source`** _(string)_
    Why a remote MCP tool's `tier` is what it is: `server` (the MCP server's own annotations decided it) or `default` (the server labeled the tool neither way, so the MCP safe default `destructive` applies). Lets a client say "Not labeled" rather than show a tier nobody chose. Present only on a remote MCP tool.
    Allowed: `server`, `default`
  - **`restricted`** _(boolean)_
    True when the caller's restrictions block THIS tool. Blocked tools are returned flagged, never omitted — a shorter list is no signal, because nobody knows the length it should have been. Presence is not permission: execution still refuses it. The connector-level 403 is a separate question and is unchanged.
  - **`restricted_by`** _(string,null)_
    Which precedence layer's rule blocks this tool, null when none does. Same field, union and meaning as on connector and connection rows: adds *which* to `restricted`'s *whether* and nothing else — no rule id, author, reason or coverage. `restricted === (restricted_by !== null)` always.
    Allowed: `role`, `user`, `null`
  - **`restricted_scope`** _(string,null)_
    `"connector"` when the tool is refused because its WHOLE connector is restricted for the caller, `"tool"` for a rule about the tool itself, null exactly when `restricted_by` is. Decides which ask can succeed: a tool request on a connector restricted whole is refused (`409 tool_request_connector_blocked`), so ask for the connector. On this listing it is only ever `"tool"` when set, since a connector restricted whole 403s the route; toolbox entries carry the same field and can say `"connector"`.
    Allowed: `connector`, `tool`, `null`
  - **`operation`** _(string)_
    The CRUD bucket this tool falls into, computed server-side from its resolved HTTP verb (`src/connector/toolOperation.ts`) — never re-derive it client-side. Filter with `?operation=`.
    Allowed: `read`, `create`, `update`, `delete`, `other`
- **`next_cursor`** _(string,null)_
- **`prev_cursor`** _(string,null)_
- **`operation_counts`** _(object, required)_
  How many tools of each CRUD bucket the `q` filter alone leaves — never narrowed further by `operation` itself, so the count beside an unselected filter chip stays honest. Repeated on every page.
  - **`read`** _(integer)_
  - **`create`** _(integer)_
  - **`update`** _(integer)_
  - **`delete`** _(integer)_
  - **`other`** _(integer)_

## Code examples

### curl

```bash
curl -X GET 'https://api.elaichi.ai/connection/<id>/tools' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json'
```

### JavaScript

```javascript
const response = await fetch('https://api.elaichi.ai/connection/<id>/tools', {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Python

```python
import os
import requests

url = "https://api.elaichi.ai/connection/<id>/tools"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}

response = requests.get(url, headers=headers)
print(response.json())
```
