List a connector’s tools for writing a restriction
/restriction/connector/{slug}/tools
Every tool the connector defines — name, person-readable label, description, resource and method — for picking `tools[].tool_name` values in a restriction. Unlike `GET /connector/{slug}/tools`, this answers regardless of the CALLER’S own restrictions: that route asks “which of these may I call” and `403`s a connector the caller is blocked from, which left a member unable to narrow a rule that blocks them to specific tools. Reading the catalog grants nothing: execution, connection and toolbox pinning each still apply the caller’s restrictions, and the write routes still decide whether the caller may write the rule. Requires `restriction:manage` and `connector:view` — the second is what browsing the catalog costs everywhere else; this route drops only the caller’s use-side restriction. Cursor-paged by `name`. For an organization’s remote MCP connector the rows are the org’s registry of names (turned-off ones included, with `status`, `tier` and `title`), `q` is a name or title search done server-side, `resource` is `mcp`, `method` the upstream tool name, and `operation_counts` is not returned.
Path Parameters
Connector slug.
Query Parameters
Case-insensitive substring match on tool_label, name, description and resource. LIKE wildcards are matched literally. Max 200 characters.
Comma-separated CRUD buckets to keep: read, create, update, delete, other. Unknown values 400. Applied before paging, so the cursor never counts a row the filter would have hidden.
Response Body
How many tools of each CRUD bucket the q filter alone leaves — never narrowed further by operation itself, so the count beside an unselected filter chip stays honest. Repeated on every page.
remote_mcp for a tool from an organization's remote MCP connector, else catalog.
catalogremote_mcp
Exact tool name — what tools[].tool_name must contain.
Same server-computed CRUD bucket as GET /connector/{slug}/tools (src/connector/toolOperation.ts). Filter with ?operation=.
readcreateupdatedeleteother
Whether a remote MCP tool is on in the organization's registry (disabled: a manager turned it off). Present only on a remote MCP tool, where operation_counts is not returned; absent on a catalog tool.
activedisabled
Always present, as on GET /connector/{slug}/tools: what the approval gate and the MCP scope ladder treat this tool as (classifyToolMethod). For a remote MCP tool, the server's label. Read kind to tell a remote MCP tool, never this field.
readwritedestructive
The remote MCP server's human title for the tool, as on GET /connector/{slug}/tools. Present only on a remote MCP tool that has one.
The same server-computed phrase a saved rule’s tools[].tool_label carries for this tool, so a tool reads the same in the picker as on the saved rule.
curl -X GET 'https://api.elaichi.ai/restriction/connector/<slug>/tools' \
-H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
-H 'Content-Type: application/json'const response = await fetch('https://api.elaichi.ai/restriction/connector/<slug>/tools', {
method: 'GET',
headers: {
'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
'Content-Type': 'application/json',
},
});
const data = await response.json();
console.log(data);import os
import requests
url = "https://api.elaichi.ai/restriction/connector/<slug>/tools"
headers = {
"Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
"Content-Type": "application/json",
}
response = requests.get(url, headers=headers)
print(response.json())