MCP
Tools
Every tool on the Graphon MCP server, grouped by toolset, with the role that each tool needs.
The Graphon MCP server has 47 tools in 9 toolsets. A connection lists only the tools that its role covers. See Connect for how to pick the role.
- Role is the lowest role that can call the tool: Viewer, then Editor, then Admin.
- A read-only tool does not change your data.
- A destructive tool can delete or overwrite data.
Context
| Tool | Role | Description |
|---|---|---|
get_meGet the callerRead-only | Viewer | Returns the signed-in user, or the API key workspace when the caller is a key. |
list_workspacesList workspacesRead-only | Viewer | Lists workspaces for the signed-in user. An API key cannot call this route. Call this first when a tool asks for workspaceId. |
get_workspaceGet a workspaceRead-only | Viewer | Confirms that the caller can access the workspace. The response includes the workspace id. |
API keys
| Tool | Role | Description |
|---|---|---|
list_api_keysList API keysRead-only | Viewer | Lists API keys. owner=me returns the caller's personal keys and needs the viewer role. owner=workspace returns the workspace keys and requires the admin role. Keys are never returned, only masked keys. |
create_api_keyCreate an API key | Viewer | Creates a personal API key for the caller, or a workspace key when owner is workspace. A viewer can create a personal key. An admin is required for a workspace key. The key works on the API, the storage API, and S3 tools. It appears once. The new key appears once, in this result, so it enters your context. It works on the API, on storage, and in S3 tools; the server instructions give the S3 settings. |
get_api_keyGet an API keyRead-only | Viewer | Returns one API key without the key itself. The owner can read a personal key. An admin can read any key in the workspace. |
update_api_keyUpdate an API key | Viewer | Edits the name or role. The key stays the same. |
revoke_api_keyRevoke an API keyDestructive | Viewer | Revokes an API key. The owner can revoke their own personal key. An admin can revoke any key in the workspace. Storage rejects the key when this call returns. |
Members
| Tool | Role | Description |
|---|---|---|
list_membersList membersRead-only | Viewer | Lists active members in the workspace. Requires the viewer role. Use query to filter by display name or email. |
update_memberUpdate a member role | Admin | Changes a member's role. Requires the admin role. The last admin cannot become a viewer or editor. |
remove_memberRemove a memberDestructive | Admin | Removes a member from the workspace. Requires the admin role. The last admin cannot be removed. Self-leave at /members/me is not available on this API. |
list_member_api_keysList a member's API keysRead-only | Admin | Lists personal API keys for another member. Requires the admin role. Secrets are never returned. |
Invitations
| Tool | Role | Description |
|---|---|---|
list_invitationsList invitationsRead-only | Admin | Lists pending invitations for the workspace. Requires the admin role. |
create_invitationsInvite members | Admin | Invites one or more email addresses with the same role. Requires the admin role. Send between 1 and 50 addresses. Each address returns its own outcome. |
resend_invitationResend an invitation | Admin | Sends the invitation email again. Requires the admin role. The invitation must still be pending. |
update_invitationUpdate an invitation role | Admin | Changes the role on a pending invitation. Requires the admin role. |
revoke_invitationRevoke an invitationDestructive | Admin | Revokes a pending invitation. Requires the admin role. This does not remove an accepted member. |
Buckets
| Tool | Role | Description |
|---|---|---|
list_bucketsList bucketsRead-only | Viewer | Lists the buckets in the workspace. Pass name to find one bucket by its exact name. Role: viewer or higher. |
check_bucket_nameCheck a bucket nameRead-only | Viewer | Returns whether a bucket name is valid and free. Bucket names are unique across all workspaces. Role: viewer or higher. |
create_bucketCreate a bucket | Editor | Creates a bucket and returns it when it is active. Search is enabled unless you send search disabled, and it cannot change later. Role: editor or higher. |
get_bucketGet a bucketRead-only | Viewer | Returns one bucket with its settings and usage. Role: viewer or higher. |
update_bucketUpdate a bucket | Editor | Changes the permission, availability, or policy of a bucket. A missing field keeps its value. Role: editor or higher. |
retry_bucket_provisioningRetry bucket provisioning | Editor | Provisions a bucket again after it failed, and returns it when it is active. Role: editor or higher. |
empty_bucketEmpty a bucketDestructive | Editor | Deletes every object in the bucket. Send the exact bucket name as confirmName. Objects under retention stay, and the call returns object_locked with their keys. Role: editor or higher. |
delete_bucketDelete a bucketDestructive | Editor | Deletes an empty bucket. Send the exact bucket name as confirmName. The bucket stays restorable for seven days. Role: editor or higher. |
restore_bucketRestore a bucket | Editor | Restores a deleted bucket within its recovery window. Role: editor or higher. |
get_jobGet a jobRead-only | Viewer | Returns the status of background work, such as an empty or a copy. Role: viewer or higher. |
Objects
| Tool | Role | Description |
|---|---|---|
list_objectsList objectsRead-only | Viewer | Lists live objects in key order, one page at a time. Pass delimiter "/" to group keys into prefixes. Role: viewer or higher. |
get_object_metadataGet object metadataRead-only | Viewer | Returns the metadata of the live version of one object, without its bytes. Role: viewer or higher. |
list_object_versionsList object versionsRead-only | Viewer | Lists the live versions and delete markers of one object, newest first. Role: viewer or higher. |
delete_objectDelete an objectDestructive | Editor | Deletes one object. The deleted version stays recoverable for the bucket recovery window. Role: editor or higher. |
restore_objectRestore an object | Editor | Restores a deleted or replaced version from recovery. Get the recoveryId from GET …/recovery. Role: editor or higher. |
copy_objectCopy an object | Editor | Copies an object to another key in the same bucket. Role: editor or higher. |
read_objectRead an objectRead-only | Viewer | Reads one object. Text content up to maxBytes returns as text, and a PNG, JPEG, GIF, or WebP image returns as an image. Anything else, or anything larger, returns its metadata and a download URL that lasts 15 minutes. |
create_object_download_urlCreate an object download URLRead-only | Viewer | Returns a presigned GET URL for one object. It lasts up to 15 minutes. Use it to download a file with curl instead of reading it into the conversation. |
write_objectWrite a new object | Editor | Creates an object from content that you produce, such as generated text or JSON, up to 1 MiB. Do not use it for a file on disk: call create_object_upload_url. It fails with object_exists when the key exists; to overwrite, call replace_object. |
create_object_upload_urlCreate an object upload URL | Editor | Uploads a file from disk without passing it through the model. Returns a presigned PUT URL and a ready curl command. The URL creates only: storage rejects the PUT when the key exists. For files over 200 MiB, or many files, use graphon objects put. |
replace_objectReplace an objectDestructive | Editor | Writes an object from content that you produce, up to 1 MiB, and overwrites the key when it exists. The previous version stays as an older version; list_object_versions lists it. |
create_object_replace_urlCreate an object replace URLDestructive | Editor | Like create_object_upload_url, but the PUT overwrites the key when it exists. The previous version stays as an older version. For files over 200 MiB, or many files, use graphon objects put. |
Insights
| Tool | Role | Description |
|---|---|---|
get_bucket_usageGet bucket usageRead-only | Viewer | Returns the bytes and objects that one bucket stores. Role: viewer or higher. |
list_bucket_recoveryList bucket recoveryRead-only | Viewer | Lists deleted or replaced versions that can still be restored. Role: viewer or higher. |
list_bucket_activityList bucket activityRead-only | Viewer | Lists recent changes in one bucket, newest first. Role: viewer or higher. |
get_bucket_metricsGet bucket metricsRead-only | Viewer | Returns storage metrics for one bucket. Role: viewer or higher. |
Workspace admin
| Tool | Role | Description |
|---|---|---|
delete_workspaceDelete a workspaceDestructive | Admin | Marks the workspace deleted and starts a seven-day recovery window. Requires the admin role. Every bucket must already be deleted. Members stay retained for restore. |
restore_workspaceRestore a workspace | Admin | Restores a deleted workspace within its recovery window. Requires a human session that was an Admin at deletion. Returns the same workspace id. API keys cannot call this route. |
Account
| Tool | Role | Description |
|---|---|---|
get_notification_preferencesGet notification preferencesRead-only | Viewer | Returns personal notification preferences for the signed-in user. An API key cannot call this route. |
update_notification_preferencesUpdate notification preferences | Viewer | Updates personal notification preferences for the signed-in user. An API key cannot call this route. |
Was this page helpful?