---
title: Tools
description: Every tool on the Graphon MCP server, grouped by toolset, with the role that each tool needs.
doc_version: 0.1.0-preview
last_updated: 2026-09-14
---

# Tools

Every tool on the Graphon MCP server, grouped by toolset, with the role that each tool needs.

The server has 47 tools. A connection lists only the tools that its role
covers. Role is the lowest role that can call the tool: Viewer, then Editor,
then Admin. A read-only tool does not change data. A destructive tool can
delete or overwrite data.

## Context

- `get_me` (Get the caller). Role: Viewer. Read-only. Returns the signed-in user, or the API key workspace when the caller is a key.
- `list_workspaces` (List workspaces). Role: Viewer. Read-only. Lists workspaces for the signed-in user. An API key cannot call this route. Call this first when a tool asks for workspaceId.
- `get_workspace` (Get a workspace). Role: Viewer. Read-only. Confirms that the caller can access the workspace. The response includes the workspace id.

## API keys

- `list_api_keys` (List API keys). Role: Viewer. Read-only. Lists API keys. owner=me returns the caller's personal keys and needs the viewer role. owner=workspace returns the workspace keys and requires the admin role. Keys are never returned, only masked keys.
- `create_api_key` (Create an API key). Role: Viewer. Creates a personal API key for the caller, or a workspace key when owner is workspace. A viewer can create a personal key. An admin is required for a workspace key. The key works on the API, the storage API, and S3 tools. It appears once. The new key appears once, in this result, so it enters your context. It works on the API, on storage, and in S3 tools; the server instructions give the S3 settings.
- `get_api_key` (Get an API key). Role: Viewer. Read-only. Returns one API key without the key itself. The owner can read a personal key. An admin can read any key in the workspace.
- `update_api_key` (Update an API key). Role: Viewer. Edits the name or role. The key stays the same.
- `revoke_api_key` (Revoke an API key). Role: Viewer. Destructive. Revokes an API key. The owner can revoke their own personal key. An admin can revoke any key in the workspace. Storage rejects the key when this call returns.

## Members

- `list_members` (List members). Role: Viewer. Read-only. Lists active members in the workspace. Requires the viewer role. Use query to filter by display name or email.
- `update_member` (Update a member role). Role: Admin. Changes a member's role. Requires the admin role. The last admin cannot become a viewer or editor.
- `remove_member` (Remove a member). Role: Admin. Destructive. Removes a member from the workspace. Requires the admin role. The last admin cannot be removed. Self-leave at /members/me is not available on this API.
- `list_member_api_keys` (List a member's API keys). Role: Admin. Read-only. Lists personal API keys for another member. Requires the admin role. Secrets are never returned.

## Invitations

- `list_invitations` (List invitations). Role: Admin. Read-only. Lists pending invitations for the workspace. Requires the admin role.
- `create_invitations` (Invite members). Role: Admin. Invites one or more email addresses with the same role. Requires the admin role. Send between 1 and 50 addresses. Each address returns its own outcome.
- `resend_invitation` (Resend an invitation). Role: Admin. Sends the invitation email again. Requires the admin role. The invitation must still be pending.
- `update_invitation` (Update an invitation role). Role: Admin. Changes the role on a pending invitation. Requires the admin role.
- `revoke_invitation` (Revoke an invitation). Role: Admin. Destructive. Revokes a pending invitation. Requires the admin role. This does not remove an accepted member.

## Buckets

- `list_buckets` (List buckets). Role: Viewer. Read-only. Lists the buckets in the workspace. Pass name to find one bucket by its exact name. Role: viewer or higher.
- `check_bucket_name` (Check a bucket name). Role: Viewer. Read-only. Returns whether a bucket name is valid and free. Bucket names are unique across all workspaces. Role: viewer or higher.
- `create_bucket` (Create a bucket). Role: Editor. Creates a bucket and returns it when it is active. Search is enabled unless you send search disabled, and it cannot change later. Role: editor or higher.
- `get_bucket` (Get a bucket). Role: Viewer. Read-only. Returns one bucket with its settings and usage. Role: viewer or higher.
- `update_bucket` (Update a bucket). Role: Editor. Changes the permission, availability, or policy of a bucket. A missing field keeps its value. Role: editor or higher.
- `retry_bucket_provisioning` (Retry bucket provisioning). Role: Editor. Provisions a bucket again after it failed, and returns it when it is active. Role: editor or higher.
- `empty_bucket` (Empty a bucket). Role: Editor. Destructive. Deletes every object in the bucket. Send the exact bucket name as confirmName. Objects under retention stay, and the call returns object_locked with their keys. Role: editor or higher.
- `delete_bucket` (Delete a bucket). Role: Editor. Destructive. Deletes an empty bucket. Send the exact bucket name as confirmName. The bucket stays restorable for seven days. Role: editor or higher.
- `restore_bucket` (Restore a bucket). Role: Editor. Restores a deleted bucket within its recovery window. Role: editor or higher.
- `get_job` (Get a job). Role: Viewer. Read-only. Returns the status of background work, such as an empty or a copy. Role: viewer or higher.

## Objects

- `list_objects` (List objects). Role: Viewer. Read-only. Lists live objects in key order, one page at a time. Pass delimiter "/" to group keys into prefixes. Role: viewer or higher.
- `get_object_metadata` (Get object metadata). Role: Viewer. Read-only. Returns the metadata of the live version of one object, without its bytes. Role: viewer or higher.
- `list_object_versions` (List object versions). Role: Viewer. Read-only. Lists the live versions and delete markers of one object, newest first. Role: viewer or higher.
- `delete_object` (Delete an object). Role: Editor. Destructive. Deletes one object. The deleted version stays recoverable for the bucket recovery window. Role: editor or higher.
- `restore_object` (Restore an object). Role: Editor. Restores a deleted or replaced version from recovery. Get the recoveryId from GET …/recovery. Role: editor or higher.
- `copy_object` (Copy an object). Role: Editor. Copies an object to another key in the same bucket. Role: editor or higher.
- `read_object` (Read an object). Role: Viewer. Read-only. Reads one object. Text content up to maxBytes returns as text, and a PNG, JPEG, GIF, or WebP image returns as an image. Anything else, or anything larger, returns its metadata and a download URL that lasts 15 minutes.
- `create_object_download_url` (Create an object download URL). Role: Viewer. Read-only. Returns a presigned GET URL for one object. It lasts up to 15 minutes. Use it to download a file with curl instead of reading it into the conversation.
- `write_object` (Write a new object). Role: Editor. Creates an object from content that you produce, such as generated text or JSON, up to 1 MiB. Do not use it for a file on disk: call create_object_upload_url. It fails with object_exists when the key exists; to overwrite, call replace_object.
- `create_object_upload_url` (Create an object upload URL). Role: Editor. Uploads a file from disk without passing it through the model. Returns a presigned PUT URL and a ready curl command. The URL creates only: storage rejects the PUT when the key exists. For files over 200 MiB, or many files, use graphon objects put.
- `replace_object` (Replace an object). Role: Editor. Destructive. Writes an object from content that you produce, up to 1 MiB, and overwrites the key when it exists. The previous version stays as an older version; list_object_versions lists it.
- `create_object_replace_url` (Create an object replace URL). Role: Editor. Destructive. Like create_object_upload_url, but the PUT overwrites the key when it exists. The previous version stays as an older version. For files over 200 MiB, or many files, use graphon objects put.

## Insights

- `get_bucket_usage` (Get bucket usage). Role: Viewer. Read-only. Returns the bytes and objects that one bucket stores. Role: viewer or higher.
- `list_bucket_recovery` (List bucket recovery). Role: Viewer. Read-only. Lists deleted or replaced versions that can still be restored. Role: viewer or higher.
- `list_bucket_activity` (List bucket activity). Role: Viewer. Read-only. Lists recent changes in one bucket, newest first. Role: viewer or higher.
- `get_bucket_metrics` (Get bucket metrics). Role: Viewer. Read-only. Returns storage metrics for one bucket. Role: viewer or higher.

## Workspace admin

- `delete_workspace` (Delete a workspace). Role: Admin. Destructive. Marks the workspace deleted and starts a seven-day recovery window. Requires the admin role. Every bucket must already be deleted. Members stay retained for restore.
- `restore_workspace` (Restore a workspace). Role: Admin. Restores a deleted workspace within its recovery window. Requires a human session that was an Admin at deletion. Returns the same workspace id. API keys cannot call this route.

## Account

- `get_notification_preferences` (Get notification preferences). Role: Viewer. Read-only. Returns personal notification preferences for the signed-in user. An API key cannot call this route.
- `update_notification_preferences` (Update notification preferences). Role: Viewer. Updates personal notification preferences for the signed-in user. An API key cannot call this route.

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
