MCP

Tools

Every tool on the Graphon MCP server, grouped by toolset, with the role that each tool needs.

The Graphon MCP server has 47 tools in 9 toolsets. A connection lists only the tools that its role covers. See Connect for how to pick the role.

  • Role is the lowest role that can call the tool: Viewer, then Editor, then Admin.
  • A read-only tool does not change your data.
  • A destructive tool can delete or overwrite data.

Context

ToolRoleDescription
get_meGet the callerRead-only
ViewerReturns the signed-in user, or the API key workspace when the caller is a key.
list_workspacesList workspacesRead-only
ViewerLists workspaces for the signed-in user. An API key cannot call this route. Call this first when a tool asks for workspaceId.
get_workspaceGet a workspaceRead-only
ViewerConfirms that the caller can access the workspace. The response includes the workspace id.

API keys

ToolRoleDescription
list_api_keysList API keysRead-only
ViewerLists API keys. owner=me returns the caller's personal keys and needs the viewer role. owner=workspace returns the workspace keys and requires the admin role. Keys are never returned, only masked keys.
create_api_keyCreate an API key
ViewerCreates a personal API key for the caller, or a workspace key when owner is workspace. A viewer can create a personal key. An admin is required for a workspace key. The key works on the API, the storage API, and S3 tools. It appears once. The new key appears once, in this result, so it enters your context. It works on the API, on storage, and in S3 tools; the server instructions give the S3 settings.
get_api_keyGet an API keyRead-only
ViewerReturns one API key without the key itself. The owner can read a personal key. An admin can read any key in the workspace.
update_api_keyUpdate an API key
ViewerEdits the name or role. The key stays the same.
revoke_api_keyRevoke an API keyDestructive
ViewerRevokes an API key. The owner can revoke their own personal key. An admin can revoke any key in the workspace. Storage rejects the key when this call returns.

Members

ToolRoleDescription
list_membersList membersRead-only
ViewerLists active members in the workspace. Requires the viewer role. Use query to filter by display name or email.
update_memberUpdate a member role
AdminChanges a member's role. Requires the admin role. The last admin cannot become a viewer or editor.
remove_memberRemove a memberDestructive
AdminRemoves a member from the workspace. Requires the admin role. The last admin cannot be removed. Self-leave at /members/me is not available on this API.
list_member_api_keysList a member's API keysRead-only
AdminLists personal API keys for another member. Requires the admin role. Secrets are never returned.

Invitations

ToolRoleDescription
list_invitationsList invitationsRead-only
AdminLists pending invitations for the workspace. Requires the admin role.
create_invitationsInvite members
AdminInvites one or more email addresses with the same role. Requires the admin role. Send between 1 and 50 addresses. Each address returns its own outcome.
resend_invitationResend an invitation
AdminSends the invitation email again. Requires the admin role. The invitation must still be pending.
update_invitationUpdate an invitation role
AdminChanges the role on a pending invitation. Requires the admin role.
revoke_invitationRevoke an invitationDestructive
AdminRevokes a pending invitation. Requires the admin role. This does not remove an accepted member.

Buckets

ToolRoleDescription
list_bucketsList bucketsRead-only
ViewerLists the buckets in the workspace. Pass name to find one bucket by its exact name. Role: viewer or higher.
check_bucket_nameCheck a bucket nameRead-only
ViewerReturns whether a bucket name is valid and free. Bucket names are unique across all workspaces. Role: viewer or higher.
create_bucketCreate a bucket
EditorCreates a bucket and returns it when it is active. Search is enabled unless you send search disabled, and it cannot change later. Role: editor or higher.
get_bucketGet a bucketRead-only
ViewerReturns one bucket with its settings and usage. Role: viewer or higher.
update_bucketUpdate a bucket
EditorChanges the permission, availability, or policy of a bucket. A missing field keeps its value. Role: editor or higher.
retry_bucket_provisioningRetry bucket provisioning
EditorProvisions a bucket again after it failed, and returns it when it is active. Role: editor or higher.
empty_bucketEmpty a bucketDestructive
EditorDeletes every object in the bucket. Send the exact bucket name as confirmName. Objects under retention stay, and the call returns object_locked with their keys. Role: editor or higher.
delete_bucketDelete a bucketDestructive
EditorDeletes an empty bucket. Send the exact bucket name as confirmName. The bucket stays restorable for seven days. Role: editor or higher.
restore_bucketRestore a bucket
EditorRestores a deleted bucket within its recovery window. Role: editor or higher.
get_jobGet a jobRead-only
ViewerReturns the status of background work, such as an empty or a copy. Role: viewer or higher.

Objects

ToolRoleDescription
list_objectsList objectsRead-only
ViewerLists live objects in key order, one page at a time. Pass delimiter "/" to group keys into prefixes. Role: viewer or higher.
get_object_metadataGet object metadataRead-only
ViewerReturns the metadata of the live version of one object, without its bytes. Role: viewer or higher.
list_object_versionsList object versionsRead-only
ViewerLists the live versions and delete markers of one object, newest first. Role: viewer or higher.
delete_objectDelete an objectDestructive
EditorDeletes one object. The deleted version stays recoverable for the bucket recovery window. Role: editor or higher.
restore_objectRestore an object
EditorRestores a deleted or replaced version from recovery. Get the recoveryId from GET …/recovery. Role: editor or higher.
copy_objectCopy an object
EditorCopies an object to another key in the same bucket. Role: editor or higher.
read_objectRead an objectRead-only
ViewerReads one object. Text content up to maxBytes returns as text, and a PNG, JPEG, GIF, or WebP image returns as an image. Anything else, or anything larger, returns its metadata and a download URL that lasts 15 minutes.
create_object_download_urlCreate an object download URLRead-only
ViewerReturns a presigned GET URL for one object. It lasts up to 15 minutes. Use it to download a file with curl instead of reading it into the conversation.
write_objectWrite a new object
EditorCreates an object from content that you produce, such as generated text or JSON, up to 1 MiB. Do not use it for a file on disk: call create_object_upload_url. It fails with object_exists when the key exists; to overwrite, call replace_object.
create_object_upload_urlCreate an object upload URL
EditorUploads a file from disk without passing it through the model. Returns a presigned PUT URL and a ready curl command. The URL creates only: storage rejects the PUT when the key exists. For files over 200 MiB, or many files, use graphon objects put.
replace_objectReplace an objectDestructive
EditorWrites an object from content that you produce, up to 1 MiB, and overwrites the key when it exists. The previous version stays as an older version; list_object_versions lists it.
create_object_replace_urlCreate an object replace URLDestructive
EditorLike create_object_upload_url, but the PUT overwrites the key when it exists. The previous version stays as an older version. For files over 200 MiB, or many files, use graphon objects put.

Insights

ToolRoleDescription
get_bucket_usageGet bucket usageRead-only
ViewerReturns the bytes and objects that one bucket stores. Role: viewer or higher.
list_bucket_recoveryList bucket recoveryRead-only
ViewerLists deleted or replaced versions that can still be restored. Role: viewer or higher.
list_bucket_activityList bucket activityRead-only
ViewerLists recent changes in one bucket, newest first. Role: viewer or higher.
get_bucket_metricsGet bucket metricsRead-only
ViewerReturns storage metrics for one bucket. Role: viewer or higher.

Workspace admin

ToolRoleDescription
delete_workspaceDelete a workspaceDestructive
AdminMarks the workspace deleted and starts a seven-day recovery window. Requires the admin role. Every bucket must already be deleted. Members stay retained for restore.
restore_workspaceRestore a workspace
AdminRestores a deleted workspace within its recovery window. Requires a human session that was an Admin at deletion. Returns the same workspace id. API keys cannot call this route.

Account

ToolRoleDescription
get_notification_preferencesGet notification preferencesRead-only
ViewerReturns personal notification preferences for the signed-in user. An API key cannot call this route.
update_notification_preferencesUpdate notification preferences
ViewerUpdates personal notification preferences for the signed-in user. An API key cannot call this route.
Was this page helpful?