# List a connector’s tools for writing a restriction

> Source: https://elaichi.ai/docs/api-reference/restrictions/restriction/listrestrictioncatalogtools/

`GET /restriction/connector/{slug}/tools`

Resource: **Restriction** · API: **Restrictions**

## Path parameters

- **`slug`** _(string, required)_
  Connector slug.

## Query parameters

- **`q`** _(string)_
  Case-insensitive substring match on `tool_label`, `name`, `description` and `resource`. LIKE wildcards are matched literally. Max 200 characters.
- **`operation`** _(string)_
  Comma-separated CRUD buckets to keep: read, create, update, delete, other. Unknown values 400. Applied before paging, so the cursor never counts a row the filter would have hidden.

## Response body

- **`result`** _(array<object>)_
  - **`name`** _(string)_
    Exact tool name — what `tools[].tool_name` must contain.
  - **`tool_label`** _(string)_
    The same server-computed phrase a saved rule’s `tools[].tool_label` carries for this tool, so a tool reads the same in the picker as on the saved rule.
  - **`description`** _(string)_
  - **`resource`** _(string)_
  - **`method`** _(string)_
  - **`operation`** _(string)_
    Same server-computed CRUD bucket as `GET /connector/{slug}/tools` (`src/connector/toolOperation.ts`). Filter with `?operation=`.
    Allowed: `read`, `create`, `update`, `delete`, `other`
  - **`title`** _(string)_
    The remote MCP server's human title for the tool, as on `GET /connector/{slug}/tools`. Present only on a remote MCP tool that has one.
  - **`tier`** _(string)_
    Always present, as on `GET /connector/{slug}/tools`: what the approval gate and the MCP scope ladder treat this tool as (`classifyToolMethod`). For a remote MCP tool, the server's label. Read `kind` to tell a remote MCP tool, never this field.
    Allowed: `read`, `write`, `destructive`
  - **`kind`** _(string)_
    `remote_mcp` for a tool from an organization's remote MCP connector, else `catalog`.
    Allowed: `catalog`, `remote_mcp`
  - **`status`** _(string)_
    Whether a remote MCP tool is on in the organization's registry (`disabled`: a manager turned it off). Present only on a remote MCP tool, where `operation_counts` is not returned; absent on a catalog tool.
    Allowed: `active`, `disabled`
- **`next_cursor`** _(string,null)_
- **`prev_cursor`** _(string,null)_
- **`operation_counts`** _(object, required)_
  How many tools of each CRUD bucket the `q` filter alone leaves — never narrowed further by `operation` itself, so the count beside an unselected filter chip stays honest. Repeated on every page.
  - **`read`** _(integer)_
  - **`create`** _(integer)_
  - **`update`** _(integer)_
  - **`delete`** _(integer)_
  - **`other`** _(integer)_

## Code examples

### curl

```bash
curl -X GET 'https://api.elaichi.ai/restriction/connector/<slug>/tools' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json'
```

### JavaScript

```javascript
const response = await fetch('https://api.elaichi.ai/restriction/connector/<slug>/tools', {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Python

```python
import os
import requests

url = "https://api.elaichi.ai/restriction/connector/<slug>/tools"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}

response = requests.get(url, headers=headers)
print(response.json())
```
