MCP

Actions (list_actions / call_action)

Let an agent change data safely through the REST pipeline.

The two action tools give an agent the reach of the REST API without a second set of rules.

list_actions

Returns every console action the credential may call, with its method, route, path parameters and body fields.

{ "module": "inventory", "search": "transfer", "includeReads": false }

All parameters are optional. Actions closed to machines — sign-in and auth flows, minting keys and OAuth clients, the vendor platform — are never listed.

call_action

{
  "method": "POST",
  "path": "/api/v1/console/central-kitchen/transfers",
  "body": { "sourceLocationId": "…", "destLocationId": "…", "lines": [] },
  "idempotencyKey": "7f3c2a9e-1b4d-4c1e-9a53-0e2b6d1f8a44"
}
  • path is a concrete console path, starting /api/v1/console/.
  • body is for POST, PUT and PATCH.
  • idempotencyKey — a fresh value for each write. Reuse it only to retry the identical request.

The result is the action's normal response: the { success, data, message, code, errors } envelope (see Responses & Errors).

What still applies

call_action runs in-process through the application's own pipeline, as the calling credential, with its real address:

  • scope AND role capability, and [SessionOnly] refusals;
  • the key's rate limit, quota, IP and origin allow-lists;
  • validation, separation of duties and period locks;
  • idempotency and the audit chain — every write is audited, and emits its webhook event like any other change.

Keeping an agent safe

  • Give the key only the module presets it needs.
  • The tool is annotated destructive, and the server tells the model to confirm money and stock movements with the user before calling it. Keep your client's tool-approval prompt on for call_action.
  • Review the agent's changes in the audit log like any other user's.