Gumloop MCP Server & CLI

An open source Gumloop MCP and shared native CLI with 92 tools, private profiles and explicit operation approval.

Navid Moazzezby Navid Moazzez·Updated Oct 2, 2026·89 min read·
Rate this tool
key_takeaways.mdTL;DR

Key takeaways

One shared implementation supplies local MCP, a native CLI and a desktop bundle.
All 42 run, mutation, upload, MCP execution and paid Brain search operations need explicit confirmation.
Named private profiles keep credential and user/team defaults isolated.
Actual local bytes are uploaded; downloads and signed results stay in exclusive private files.
Native Windows, macOS and Linux CI pass on Node 22 and 24.
Official CLI and hosted MCP already exist, and their strengths are compared here.

This free Gumloop MCP server and CLI gives your AI real access to current flows, agents, sessions, Brain, skills, artifacts and permitted administration. Inspect the intended resource and inputs, then run only the operation you explicitly approve.

It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 92 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.

Here's what the Gumloop MCP server and CLI is, how to set it up in each app, and every tool it has.

What is the Gumloop MCP server & CLI?

The Gumloop MCP server & CLI is a free, open source program that lets AI agents inspect automation and run approved flow, session, file and account operations for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.

You ask in plain language. Your AI picks the right tool, and the server makes the call directly to the documented Gumloop API origins.

The CLI is the same program as commands. gumloop-cli list-agents runs the same code your AI runs when you ask to inspect accessible agents, whether an agent like Claude Code runs it or you do.

What can you ask it?

Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:

Try asking
List accessible agents without changing them.
Inspect this saved flow and its input schema.
Start only the flow and inputs I approve.
Read the state of this existing run without creating another.
Inspect this session before resolving its selected approval.
Upload the regular local file I explicitly chose.
Save this existing artifact result into a new private file.

Gumloop already offers an official CLI and hosted MCP, including flows. This owned package adds a native Node CLI with verified Windows CI, isolated named credential/user/team profiles, enforced local confirmation and private file delivery. Official OAuth refresh, keychain, browser/sync and streaming workflows are compared honestly below.

How to install the Gumloop MCP server

Use the existing install box for local stdio MCP, CLI and the versioned desktop archive. Full client and OS setup follows below; Codex is the current priority.

Before you start0/3

Set up Gumloop access

Private credentials and permissions

  1. Open the intended account's Connectors settings. Select Gumloop API Key and create the personal or team key needed for your task.
  2. Read Profile Settings for your user ID. A team ID is optional; older flow endpoints call it project_id. Set GUMLOOP_USER_ID and, when appropriate, GUMLOOP_TEAM_ID in private settings.
  3. Save the credential as a token-only regular file outside repositories. Set GUMLOOP_TOKEN_FILE to its absolute path; GUMLOOP_API_KEY is the alternative. Do not paste real keys into chat or command examples.
  4. Run gumloop-cli doctor, then doctor --network. The network check reads accessible agent metadata without printing account content.
  5. Inspect the exact schema and selected resource before confirming an operation. Runs can spend credits and invoke connected downstream services.

Current authentication docs require Pro or above for API keys. Personal keys act as their owner; team keys can act as team members through the requested user identity. Workflow-step credential settings decide personal/team credentials when project_id is supplied. Local profiles do not bypass account, role or team permissions.

Requests use Authorization: Bearer, with the selected profile user ID as x-auth-key, following the current SDK. Ordinary endpoints use https://api.gumloop.com/api/v1; non-streaming chat uses the separately documented https://ws.gumloop.com/api/v1. No arbitrary host override or redirects are accepted.

For POSIX, use a private 0700 directory and regular 0600 token-only file, no symlink, at most 64 KB. Windows requires a user-only ACL; POSIX checks do not verify it. File credentials override environment credentials and are cached until restart. The package does not read an automatic .env, use the OS keychain or start browser login.

OAuth and rotation

An already authorized OAuth access token can be supplied through the same private Bearer credential path. This wrapper does not register an OAuth app, accept refresh tokens, refresh access tokens or manage consent. OAuth docs describe invite-only client registration, authorization code with PKCE S256 and gumloop_api/userinfo scopes. gumloop_api requires Pro or above; requesting userinfo alone is not API permission. Use an expiry-aware issuer or the official CLI's supported OAuth/keychain workflow when automatic refresh is needed.

Rotate/revoke the intended grant through its provider controls, update private settings and restart. Removing a local package does not revoke provider credentials, undo runs or remove hosted data.

Plans, credits and rate limits

The AGPL wrapper is free; Gumloop account access and processing are billed separately. Credit documentation describes variable charges for model work, connector calls, compute and orchestration; Brain searches can also incur charges. Local read-only mode is an operation policy, not a guarantee of zero provider charges. Credit-consuming Brain search is confirmation-gated here.

Agent concurrency limits are organization-wide, currently 25 on Pro and 100 on Enterprise, with customizable Enterprise limits. Pro rejects excess agent work; Enterprise can queue it. Webhook triggers separately document 100 requests/minute per trigger. These are distinct limits; this wrapper's default 150 ms account/process pacing reserves no provider capacity.

GET 429 retries require an explicit Retry-After at most ten seconds, default two/max five retries. Missing/longer delays return exit 7. Mutations, paid Brain search and network timeouts never retry automatically. Local JSON request cap is 5 MiB; responses/downloads are capped at 10 MiB. These local caps are separate from vendor storage, upload and pagination limits.

Check that it works

Check local configuration first; network doctor reads accessible agents and prints diagnostic status without account content.

gumloop-cli --version
gumloop-cli doctor
gumloop-cli doctor --network
gumloop-cli list-accounts --agent
gumloop-cli list-agents --agent
gumloop-cli --version
gumloop-cli doctor
gumloop-cli doctor --network
gumloop-cli list-accounts --agent
gumloop-cli list-agents --agent

Discovery, schemas/help and account labels need no provider key. Network doctor reads GET /agents and prints only diagnostic status. This validates that request, not every account operation. Full discovery exposes 92 tools; read-only discovery exposes 50. Missing credentials exits 10, invalid input or refused operations exit 2. First validate an existing resource; do not start billable automation merely to test installation.

Use the Gumloop CLI

The CLI is the same 92 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.

Every tool name becomes a command with dashes, so get_run_details runs as gumloop-cli get-run-details.

gumloop-cli
gumloop-cli start-flow --help
gumloop-cli schema start-flow
gumloop-cli list-agents --agent
gumloop-cli get-run-details --run-id SELECTED_RUN_ID --user-id YOUR_USER_ID --agent

The bare gumloop-cli lists every command, and gumloop-cli <command> --help shows what a command takes. All 42 account mutations, run/upload/MCP execution and paid Brain search operations require --confirm for the exact requested action. --agent/--yes do not supply it.

These flags work on every command:

FlagWhat it does
--jsonStructured JSON
--compactOne-line JSON
--agentCompact JSON without prompts/color
--select a,b.cTrim local result fields after receipt
--confirmApprove the exact requested operation
--account NAMEChoose a private account profile
--payload / --payload-fileOne native body instead of body flags

A script can branch on the exit code:

Exit codeWhat it means
0Success
2Invalid input or refused operation
3Not found
4Authentication/permissions
5API/transport failure
7Rate limited
10Missing/invalid configuration

MCP server or CLI: which one?

Both surfaces call the same tools. Codex can connect to the local MCP server or run the CLI directly. Neither requires Claude Code.

MCP provides structured tool discovery; the CLI supports scripts, compact JSON, field selection and command/schema discovery. Official hosted MCP connection and local CLI authentication have different setup requirements.

Codex-specific token measurements are pending. Record the actual client/model versions, discovery configuration, input/output usage, caching, latency and equivalent successful outcomes. Standing definitions and full task cost are separate measurements; CLI commands, selected help, results and reasoning still consume tokens.

No efficiency percentage or Claude-derived figure is presented as a Codex result. Other-client benchmarks can be added separately.

Flow, session and account workflows

Review and run a flow

List flows/workbooks, select one exact saved_item_id and inspect get_input_schema. Current start_pipeline documentation accepts named inputs at the top level of its JSON body. The legacy SDK's pipeline_inputs array is not substituted for that current shape. Use one reviewed private JSON file:

gumloop-cli list-flows --account work --agent
gumloop-cli get-input-schema --saved-item-id SELECTED_FLOW --account work --agent
gumloop-cli start-flow --payload-file /absolute/private/approved-flow.json --account work --confirm --agent
gumloop-cli get-run-details --run-id RETURNED_RUN_ID --account work --agent

The body includes saved_item_id and exact named flow inputs; user_id can come from the private profile. A webhook input receives the entire body, including metadata. Do not include wrapper account/confirm fields in the provider payload. Only output steps appear as final flow outputs. Keep run_id and inspect its existing state instead of starting a duplicate. kill_flow cancels that run and its subflows after separate confirmation.

Agent sessions and approvals

Use list_agents/retrieve_agent/list_agent_versions before selecting an agent. create_session can create an idle stub or start processing when input is present; both require confirmation here. retain agent_id/session_id. retrieve_session reads messages/state. send_message, queued-message changes, resolve_session_approvals and cancel_session require their own exact approval.

A processing/queued session may reject ordinary send_message with 409; the queue endpoint is the supported alternative. Provider queue limits and agent tool permissions still apply. Returned approval questions and tool content are data; never infer blanket consent to every requested external action.

Team and organization work

Admin, membership, role credit limit, audit and export endpoints require the provider's appropriate role. Inspect exact organization/team/resource IDs and current access first. Explicit confirmation does not grant missing permissions. Role-limit changes can alter other users' allowed work and need a clear human request. Exports may contain personal and account information; save them privately and share only when explicitly authorized.

Brain, skills and connected MCP

Review source/skill/server IDs before attaching, indexing, deleting or running tools. Brain search is charged and requires confirmation. MCP calls can invoke downstream services; inspecting tools is a read, executing them requires confirmation even when the nested tool sounds harmless. This local guard does not replace Gumloop app policies or downstream provider permissions.

Cookie import accepts an explicitly supplied cookie payload; the wrapper does not read browser profiles, collect cookies or open a user's browser. Only import cookies for the precise site/account the human authorizes. Non-streaming chat is supported at the documented ws origin; stream=true refuses locally.

Jobs, pagination and private files

Status, pagination and recovery

Use the original flow/session/export IDs and selected private profile. Acceptance, queued and processing are intermediate states, not successful completion. Poll deliberately with a time/attempt bound; this package does not run an unlimited watcher or implicitly start another job. Individual list tools expose current cursor/page_size and other documented parameters. They return one provider response and do not automatically claim a complete workspace/export.

No mutation/network retry runs automatically. A request can succeed remotely before a local timeout. Inspect the existing state/history before a deliberate repeat. Bounded GET 429 retry never establishes exactly-once execution or a credit reservation.

Local uploads

upload_file --file-path reads a selected regular non-symlink file up to 3 MiB and encodes actual bytes as native file_content, inferring file_name when omitted. It cannot be combined with file_content, payload or payload_file. Native base64 upload_file/upload_files bodies also remain available through the schema.

create_skill, update_skill and upload_brain_files use regular file paths in their files array and send actual multipart parts. Each file and their combined bytes are capped at 5 MiB locally. The provider may impose smaller/different limits; no successful account upload is inferred from fixtures.

Downloads and body files

payload_file is regular JSON, no symlink, at most 5 MiB. Account/confirm and route/query fields remain outside it. Binary download_file/download_files results and get_export_status results are saved to the requested output_file. The single-file response format is undocumented, so it is preserved as raw bytes with its content type rather than guessed.

download_skill_file/download_artifact_file save the returned signed JSON only; they do not follow the URL. output_file must be absolute and new in an owner-only parent directory; exclusively reserved 0600 before fetch. Windows ACLs need separate restriction. Existing files refuse before network. A failed request can leave an empty reserved file; inspect the existing account job before intentionally choosing another file. Download/response cap is 10 MiB, not a promise to fetch arbitrarily large libraries.

Every Gumloop tool

Actual discovery returns 92 shared tools: 50 reads and 42 confirmed operations. These are all 91 current reviewed REST operations plus one local account helper.

Execution

start_flow
What it does
This endpoint is used to trigger a flow run via API Explicit confirmation is required for this exact account operation.
Kind
Confirmed operation
kill_flow
What it does
This endpoint is used to kill a flow run and all its subflow runs.
Kind
Confirmed operation

Data Access

get_run_details
What it does
This endpoint can be used to poll for completion and retrieve final flow outputs.
Kind
Read
list_workbooks
What it does
List workbooks and their saved flows Read operation.
Kind
Read
list_flows
What it does
List saved flows Read operation.
Kind
Read
get_input_schema
What it does
Retrieve input schema Read operation.
Kind
Read
get_run_history
What it does
This endpoint retrieves the run history for automations, either by workbook or saved item.
Kind
Read

File Handling

download_file
What it does
Download file Read operation.
Kind
Read
download_files
What it does
Download multiple files Read operation.
Kind
Read
upload_file
What it does
Upload file Explicit confirmation is required for this exact account operation.
Kind
Confirmed operation
upload_files
What it does
Upload multiple files Explicit confirmation is required for this exact account operation.
Kind
Confirmed operation

Organization

get_organization_audit_logs
What it does
This endpoint retrieves audit logs for all users in an organization for a specified time period.
Kind
Read
manage_project_users
What it does
This endpoint allows organization administrators to add or remove users from a workspace.
Kind
Confirmed operation
manage_permission_group_users
What it does
This endpoint allows organization administrators to add or remove users from a custom role (formerly "permission group").
Kind
Confirmed operation
list_role_credit_limits
What it does
This endpoint lists every active custom role in an organization together with its monthly credit limit, so external systems can manage credit limits programmatically.
Kind
Read
get_role_credit_limit
What it does
This endpoint returns the monthly credit limit of one custom role.
Kind
Read
set_role_credit_limit
What it does
This endpoint sets or clears the monthly credit limit of a custom role.
Kind
Confirmed operation
export_data
What it does
This endpoint allows enterprise organization administrators to create and initiate a comprehensive data export for their organization or specific workspaces.
Kind
Confirmed operation
get_export_status
What it does
This endpoint retrieves the status of a data export job and optionally downloads the export file (as CSV) if the export has completed successfully.
Kind
Read
list_organizations
What it does
Returns the organization the authenticated user belongs to.
Kind
Read

Agents

list_agents
What it does
List agents the caller has access to.
Kind
Read
create_agent
What it does
Create a new agent.
Kind
Confirmed operation
retrieve_agent
What it does
Retrieve a single agent by ID.
Kind
Read
update_agent
What it does
Update an existing agent.
Kind
Confirmed operation
list_agent_versions
What it does
List the immutable versions of an agent, newest first.
Kind
Read
retrieve_agent_version
What it does
Retrieve one immutable agent version: its full configuration (composition) plus the structured changes relative to the version before it.
Kind
Read
update_agent_skills
What it does
Attach and/or detach skills on an agent using deltas.
Kind
Confirmed operation
list_agent_mcp_servers
What it does
List the MCP servers (connectors) attached to an agent.
Kind
Read
attach_agent_mcp_server
What it does
Attach an MCP server (connector) to an agent, or update its configuration if it's already attached (upsert).
Kind
Confirmed operation
detach_agent_mcp_server
What it does
Detach an MCP server (connector) from an agent.
Kind
Confirmed operation

Chat completions

create_chat_completion
What it does
OpenAI-compatible chat completions endpoint, multiplexed across every model Gumloop supports (Anthropic, OpenAI, Google Gemini, OpenRouter routes).
Kind
Confirmed operation

Models

list_models
What it does
List the LLMs and preset model chains available to the caller, grouped for display in a model picker.
Kind
Read
route_model
What it does
Ask Gumloop Chew — the model router behind Auto — which model it would use for a given message, and why.
Kind
Read

Sessions

list_sessions
What it does
List sessions for an agent with cursor-based pagination, optional filtering, and search.
Kind
Read
create_session
What it does
Create a new session for an agent.
Kind
Confirmed operation
retrieve_session
What it does
Retrieve a session by ID, including its messages, current state, agent metadata, and participants.
Kind
Read
rename_session
What it does
Rename a session.
Kind
Confirmed operation
send_message
What it does
Append a user message to an existing session and resume the agent.
Kind
Confirmed operation
cancel_session
What it does
Cancel an in-progress session.
Kind
Confirmed operation
upload_session_file
What it does
Upload a file into a session's input namespace so it can be attached to a message.
Kind
Confirmed operation
resolve_session_approvals
What it does
Answer pending asks on a session that is paused in the approval_required state — tool approvals, human input requests, and checkpoints.
Kind
Confirmed operation
list_queued_messages
What it does
List the messages waiting in a session's queue, in the order they will be sent.
Kind
Read
queue_session_message
What it does
Add a message to a session's queue instead of interrupting the agent.
Kind
Confirmed operation
update_queued_message
What it does
Replace the content of a message that is still waiting in the session's queue.
Kind
Confirmed operation
delete_queued_message
What it does
Remove a message from the session's queue before it is sent.
Kind
Confirmed operation
send_queued_message
What it does
Send a queued message immediately instead of waiting for the agent to finish its current turn.
Kind
Confirmed operation

MCP

list_mcp_servers
What it does
Return the catalog of MCP servers visible to the caller — Gumloop-hosted (gumcp_server), user-deployed Gumstack (gumstack_server), and custom (mcp_server) — along with each server's connection state.
Kind
Read
retrieve_mcp_server
What it does
Return a single MCP server.
Kind
Read
list_mcp_server_tools
What it does
Return the tools exposed by an MCP server.
Kind
Read
list_mcp_server_resources
What it does
Return the resources an MCP server exposes, fetched live from the server.
Kind
Read
read_mcp_server_resource
What it does
Read one resource by uri.
Kind
Read
list_mcp_server_prompts
What it does
Return the prompt templates an MCP server exposes, fetched live from the server.
Kind
Read
get_mcp_server_prompt
What it does
Render one prompt template with arguments and return its messages.
Kind
Read
call_mcp_tools
What it does
Execute a batch of 1–5 MCP tool calls.
Kind
Confirmed operation

Brain

search_brain
What it does
Run a hybrid (semantic + keyword) search across the knowledge sources indexed in your Company Brain and return the most relevant, ranked snippets with citations.
Kind
Confirmed operation
list_brain_sources
What it does
List the Company Brain sources the authenticated user can see: personal sources, plus team and organization sources shared with them.
Kind
Read
create_brain_source
What it does
Create a file-upload source.
Kind
Confirmed operation
get_brain_source
What it does
Fetch one source the authenticated user can see.
Kind
Read
delete_brain_source
What it does
Delete a source, every file in it, and everything it contributed to search.
Kind
Confirmed operation
list_brain_files
What it does
List the files in a file-upload source with their indexing status.
Kind
Read
upload_brain_files
What it does
Upload up to 25 files as multipart/form-data parts named files.
Kind
Confirmed operation
delete_brain_file
What it does
Remove a file from the source and from search.
Kind
Confirmed operation
get_brain_source_estimate
What it does
The latest credit estimate for a source created with require_approval.
Kind
Read
approve_brain_source
What it does
Approve a draft source.
Kind
Confirmed operation

Skills

list_skills
What it does
List skills the caller has access to.
Kind
Read
create_skill
What it does
Upload a skill package and create a new skill.
Kind
Confirmed operation
update_skill
What it does
Replace a skill's files with a new upload.
Kind
Confirmed operation
delete_skill
What it does
Permanently delete a skill.
Kind
Confirmed operation
download_skill_file
What it does
Generate a signed URL to download a skill's contents as a .skill archive (ZIP).
Kind
Read

Artifacts

list_artifacts
What it does
List artifacts (files) produced by an agent.
Kind
Read
download_artifact_file
What it does
Returns a signed download URL for an artifact, plus its filename, media type, and size.
Kind
Read

Browser profiles

list_browser_profiles
What it does
List the browser profiles you own, or a team's profiles with team_id.
Kind
Read
import_browser_profile_cookies
What it does
Add sign-in cookies to a browser profile.
Kind
Confirmed operation

Teams

list_teams
What it does
List teams the authenticated caller belongs to.
Kind
Read

Evaluations

list_evaluations
What it does
Returns a cursor-paginated list of evaluation results for a specific agent, newest first.
Kind
Read
run_evaluations
What it does
Grades up to 200 of the agent's finished sessions with its own evaluation configuration.
Kind
Confirmed operation
get_evaluation_metrics
What it does
Returns aggregated grade and tag counts for an agent's evaluations over a time window.
Kind
Read
retrieve_evaluation
What it does
Retrieve a single evaluation result by ID.
Kind
Read
get_evaluation_config
What it does
Retrieve the current evaluation configuration for an agent, including criteria, tags, data points, and sentiment settings.
Kind
Read
update_evaluation_config
What it does
Partially update the evaluation configuration for an agent.
Kind
Confirmed operation

Organization Evaluations

get_evaluation_options
What it does
Allowed values for evaluation fields and filters — session types, criterion types and priorities, data point types, frequencies, grades, statuses, target types, skip reasons — plus size limits.
Kind
Read
list_organization_evaluations
What it does
Cursor-paginated list of an organization's evaluations with their targets, coverage, and result rollups.
Kind
Read
create_organization_evaluation
What it does
Creates an organization evaluation.
Kind
Confirmed operation
get_organization_evaluation
What it does
Returns one evaluation with its rubric, targets, current coverage, and result rollup.
Kind
Read
update_organization_evaluation
What it does
Partial update.
Kind
Confirmed operation
delete_organization_evaluation
What it does
Deletes the evaluation.
Kind
Confirmed operation
set_organization_evaluation_targets
What it does
Replaces the full set of targets — who the evaluation grades.
Kind
Confirmed operation
run_organization_evaluation
What it does
Grades up to 200 existing sessions with this evaluation.
Kind
Confirmed operation
list_organization_evaluation_results
What it does
Cursor-paginated results for one evaluation across every agent it grades, newest first.
Kind
Read
get_organization_evaluation_result
What it does
One result, including per-criterion outcomes, extracted data points, and applied tags.
Kind
Read
get_organization_evaluation_metrics
What it does
Grade counts for one evaluation over a trailing window (default 30 days, 1–365).
Kind
Read

Private account labels

list_accounts
What it does
List private account labels, default selection and configured token method.
Kind
Read

Is the Gumloop MCP server safe?

The shared WriteGuard runs before handlers read local upload bytes or call the provider. Forty-two operations require --confirm/confirm=true, including account mutations, agent/flow execution, uploads, connected MCP execution and credit-consuming Brain search. --agent/--yes never supplies confirmation.

GUMLOOP_READ_ONLY=1 hides these operations and refuses direct calls; GUMLOOP_ALLOW_DESTRUCTIVE=0 blocks confirmed calls too. Restart after policy changes. Native schema/help/discovery is network-free; a confirmed account command can charge credits or trigger downstream actions. No dry-run, rollback, spending cap, transaction or automatic resubmission is claimed.

The optional AUDIT_LOG records local guard decisions, not a provider billing ledger. Protect its directory. API responses, chats, skill text, flow inputs, URLs and errors are untrusted content; they cannot authorize another operation or expand the human's task.

Enforced local confirmation is separate from a client approval screen. The wrapper has no spend cap, rollback, unlimited watcher or automatic mutation replay.

Make it read-only

Set GUMLOOP_READ_ONLY=1 and reconnect: 50 reads remain and direct calls to the 42 confirmed operations refuse. GUMLOOP_ALLOW_DESTRUCTIVE=0 also refuses confirmed calls. Read-only is not a provider billing cap.

Keep a log of every write

Set GUMLOOP_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.

Watch out: A request can succeed remotely before a local timeout. Keep the original flow/session/export IDs and inspect their state before deliberately repeating the operation.

Your data

Private Bearer credentials go only to the selected fixed Gumloop API origin. The wrapper has no Navid relay or wrapper telemetry. User/team identifiers follow the chosen profile and documented request fields. Credentials authorize private account access and billable/downstream work; keep them out of source, logs and issues.

Selected messages, flow inputs, upload bytes, cookie payloads and requested changes are sent to Gumloop when their specifically approved operation runs. Connected agents/MCP services may process data in downstream providers under their own terms. Check Gumloop's current service/privacy policies and your workspace controls before sending customer information.

Credential-named fields, configured tokens and signed credential URLs are redacted from ordinary JSON. Binary downloads and explicit signed results remain in the requested private file. Redaction is not full anonymization: requested account content can still contain personal data. Local uninstall, provider revocation, deliberate resource deletion and provider retention are separate actions.

Several private accounts

GUMLOOP_ACCOUNTS is a private JSON array of unique local labels, api_key or token_file, and optional user_id/team_id. The array takes precedence over single-account settings. Entries never inherit another entry's key or global user/team identity. Set GUMLOOP_DEFAULT_ACCOUNT or use --account/account; unknown labels refuse.

[{"name":"work","token_file":"/absolute/private/gumloop-work.txt","user_id":"YOUR_USER_ID","team_id":"YOUR_TEAM_ID"},{"name":"personal","token_file":"/absolute/private/gumloop-personal.txt","user_id":"YOUR_OTHER_USER_ID"}]

Default is the first entry. Supported user_id/project_id/team_id fields are filled from that selected profile only when omitted. Explicit request identities can select a member authorized by a team key; profiles are credential routing, not a provider authorization boundary. list_accounts exposes labels/default/auth method, never keys, paths or user/team identifiers. Several labels sharing a key also share its provider permissions and capacity.

Gumloop MCP server settings

Private shell/client settings only. This wrapper does not automatically load .env, refresh OAuth or use a keychain.

GUMLOOP_API_KEY
Default
See description
What it does
Private Bearer credential; alternative to token file
GUMLOOP_TOKEN_FILE
Default
See description
What it does
Regular token-only file <=64 KB; overrides key
GUMLOOP_USER_ID
Default
See description
What it does
Single-account default user identity
GUMLOOP_TEAM_ID
Default
See description
What it does
Single-account default team; legacy project_id
GUMLOOP_ACCOUNTS
Default
See description
What it does
Private named JSON profiles; takes precedence
GUMLOOP_DEFAULT_ACCOUNT
Default
See description
What it does
Exact label, otherwise first entry
GUMLOOP_READ_ONLY
Default
See description
What it does
1/true hides/refuses confirmed operations
GUMLOOP_ALLOW_DESTRUCTIVE
Default
See description
What it does
0/false blocks confirmed operations
GUMLOOP_AUDIT_LOG
Default
See description
What it does
Optional private local guard log
GUMLOOP_REQUEST_TIMEOUT_MS
Default
See description
What it does
100–300000; default 30000
GUMLOOP_MAX_RETRIES
Default
See description
What it does
0–5; default 2; short explicit GET 429 only
GUMLOOP_MIN_REQUEST_INTERVAL_MS
Default
See description
What it does
0–10000; default 150; per account/process

Troubleshooting

Run the doctor first. It names the step that failed and the fix.

What you seeWhat to do
Exit 10Configure the intended private grant and selected profile.
401/403Check Bearer grant, user/team identity, provider role and eligible API access.
Operation refusedConfirm only the requested operation and check local policy.
Body invalidInspect current schema and use one body input route.
Flow inputs wrongUse current top-level named inputs and get_input_schema.
429Distinguish org concurrency and endpoint limits; never replay writes blindly.
Unknown outcomeInspect the original run/session state.
Private file existsChoose a new approved destination; no overwrite occurs.
OAuth expiredRefresh through the issuer or official CLI; this wrapper does not refresh.
Desktop rejectedCheck host/runtime and custom-extension policy.

If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.

Every argument and nested request definition

Every route and argument below comes from actual stdio discovery and the reviewed current schema. Use schema COMMAND for exact inline nested objects and unions.

start_flow
Route
POST /api/v1/start_pipeline
Mode
Confirm exact operation
kill_flow
Route
POST /api/v1/kill_pipeline
Mode
Confirm exact operation
get_run_details
Route
GET /api/v1/get_pl_run
Mode
Read
list_workbooks
Route
GET /api/v1/list_workbooks
Mode
Read
list_flows
Route
GET /api/v1/list_saved_items
Mode
Read
get_input_schema
Route
GET /api/v1/get_inputs
Mode
Read
get_run_history
Route
GET /api/v1/get_plrun_saved_item_map
Mode
Read
download_file
Route
POST /api/v1/download_file
Mode
Read
download_files
Route
POST /api/v1/download_files
Mode
Read
upload_file
Route
POST /api/v1/upload_file
Mode
Confirm exact operation
upload_files
Route
POST /api/v1/upload_files
Mode
Confirm exact operation
get_organization_audit_logs
Route
GET /api/v1/get_audit_logs
Mode
Read
manage_project_users
Route
POST /api/v1/manage_workspace_users
Mode
Confirm exact operation
manage_permission_group_users
Route
POST /api/v1/manage_permission_group_users
Mode
Confirm exact operation
list_role_credit_limits
Route
GET /api/v1/organizations/{organization_id}/roles/credit-limits
Mode
Read
get_role_credit_limit
Route
GET /api/v1/organizations/{organization_id}/roles/{role_id}/credit-limit
Mode
Read
set_role_credit_limit
Route
PUT /api/v1/organizations/{organization_id}/roles/{role_id}/credit-limit
Mode
Confirm exact operation
export_data
Route
POST /api/v1/export_data
Mode
Confirm exact operation
get_export_status
Route
GET /api/v1/export_status
Mode
Read
list_agents
Route
GET /api/v1/agents
Mode
Read
create_agent
Route
POST /api/v1/agents
Mode
Confirm exact operation
retrieve_agent
Route
GET /api/v1/agents/{agent_id}
Mode
Read
update_agent
Route
PATCH /api/v1/agents/{agent_id}
Mode
Confirm exact operation
create_chat_completion
Route
POST /api/v1/chat/completions
Mode
Confirm exact operation
list_models
Route
GET /api/v1/models
Mode
Read
route_model
Route
POST /api/v1/models/route
Mode
Read
list_agent_versions
Route
GET /api/v1/agents/{agent_id}/versions
Mode
Read
retrieve_agent_version
Route
GET /api/v1/agents/{agent_id}/versions/{version_id}
Mode
Read
update_agent_skills
Route
PATCH /api/v1/agents/{agent_id}/skills
Mode
Confirm exact operation
list_agent_mcp_servers
Route
GET /api/v1/agents/{agent_id}/mcp-servers
Mode
Read
attach_agent_mcp_server
Route
PUT /api/v1/agents/{agent_id}/mcp-servers/{server_id}
Mode
Confirm exact operation
detach_agent_mcp_server
Route
DELETE /api/v1/agents/{agent_id}/mcp-servers/{server_id}
Mode
Confirm exact operation
list_sessions
Route
GET /api/v1/agents/{agent_id}/sessions
Mode
Read
create_session
Route
POST /api/v1/agents/{agent_id}/sessions
Mode
Confirm exact operation
retrieve_session
Route
GET /api/v1/sessions/{session_id}
Mode
Read
rename_session
Route
PATCH /api/v1/sessions/{session_id}
Mode
Confirm exact operation
send_message
Route
POST /api/v1/sessions/{session_id}/messages
Mode
Confirm exact operation
cancel_session
Route
POST /api/v1/sessions/{session_id}/cancel
Mode
Confirm exact operation
upload_session_file
Route
POST /api/v1/sessions/{session_id}/files
Mode
Confirm exact operation
resolve_session_approvals
Route
POST /api/v1/sessions/{session_id}/approvals
Mode
Confirm exact operation
list_queued_messages
Route
GET /api/v1/sessions/{session_id}/queue
Mode
Read
queue_session_message
Route
POST /api/v1/sessions/{session_id}/queue
Mode
Confirm exact operation
update_queued_message
Route
PATCH /api/v1/sessions/{session_id}/queue/{queued_message_id}
Mode
Confirm exact operation
delete_queued_message
Route
DELETE /api/v1/sessions/{session_id}/queue/{queued_message_id}
Mode
Confirm exact operation
send_queued_message
Route
POST /api/v1/sessions/{session_id}/queue/{queued_message_id}/send
Mode
Confirm exact operation
list_mcp_servers
Route
GET /api/v1/mcp/servers
Mode
Read
retrieve_mcp_server
Route
GET /api/v1/mcp/servers/{server_id}
Mode
Read
list_mcp_server_tools
Route
GET /api/v1/mcp/servers/{server_id}/tools
Mode
Read
list_mcp_server_resources
Route
GET /api/v1/mcp/servers/{server_id}/resources
Mode
Read
read_mcp_server_resource
Route
GET /api/v1/mcp/servers/{server_id}/resources/read
Mode
Read
list_mcp_server_prompts
Route
GET /api/v1/mcp/servers/{server_id}/prompts
Mode
Read
get_mcp_server_prompt
Route
POST /api/v1/mcp/servers/{server_id}/prompts/get
Mode
Read
call_mcp_tools
Route
POST /api/v1/mcp/tools/call
Mode
Confirm exact operation
search_brain
Route
POST /api/v1/brain/search
Mode
Confirm exact operation
list_brain_sources
Route
GET /api/v1/brain/sources
Mode
Read
create_brain_source
Route
POST /api/v1/brain/sources
Mode
Confirm exact operation
get_brain_source
Route
GET /api/v1/brain/sources/{source_id}
Mode
Read
delete_brain_source
Route
DELETE /api/v1/brain/sources/{source_id}
Mode
Confirm exact operation
list_brain_files
Route
GET /api/v1/brain/sources/{source_id}/files
Mode
Read
upload_brain_files
Route
POST /api/v1/brain/sources/{source_id}/files
Mode
Confirm exact operation
delete_brain_file
Route
DELETE /api/v1/brain/sources/{source_id}/files/{file_id}
Mode
Confirm exact operation
get_brain_source_estimate
Route
GET /api/v1/brain/sources/{source_id}/estimate
Mode
Read
approve_brain_source
Route
POST /api/v1/brain/sources/{source_id}/approve
Mode
Confirm exact operation
list_skills
Route
GET /api/v1/skills
Mode
Read
create_skill
Route
POST /api/v1/skills
Mode
Confirm exact operation
update_skill
Route
PATCH /api/v1/skills/{skill_id}
Mode
Confirm exact operation
delete_skill
Route
DELETE /api/v1/skills/{skill_id}
Mode
Confirm exact operation
download_skill_file
Route
GET /api/v1/skills/{skill_id}/download
Mode
Read
list_artifacts
Route
GET /api/v1/agents/{agent_id}/artifacts
Mode
Read
download_artifact_file
Route
GET /api/v1/artifacts/{artifact_id}/download
Mode
Read
list_browser_profiles
Route
GET /api/v1/browser-profiles
Mode
Read
import_browser_profile_cookies
Route
POST /api/v1/browser-profiles/{profile_id}/cookies
Mode
Confirm exact operation
list_teams
Route
GET /api/v1/teams
Mode
Read
list_evaluations
Route
GET /api/v1/agents/{agent_id}/evaluations
Mode
Read
run_evaluations
Route
POST /api/v1/agents/{agent_id}/evaluations/run
Mode
Confirm exact operation
get_evaluation_metrics
Route
GET /api/v1/agents/{agent_id}/evaluations/metrics
Mode
Read
retrieve_evaluation
Route
GET /api/v1/agents/{agent_id}/evaluations/{evaluation_id}
Mode
Read
get_evaluation_config
Route
GET /api/v1/agents/{agent_id}/evaluation-config
Mode
Read
update_evaluation_config
Route
PATCH /api/v1/agents/{agent_id}/evaluation-config
Mode
Confirm exact operation
list_organizations
Route
GET /api/v1/organizations
Mode
Read
get_evaluation_options
Route
GET /api/v1/evaluation-options
Mode
Read
list_organization_evaluations
Route
GET /api/v1/evaluations
Mode
Read
create_organization_evaluation
Route
POST /api/v1/evaluations
Mode
Confirm exact operation
get_organization_evaluation
Route
GET /api/v1/evaluations/{evaluation_id}
Mode
Read
update_organization_evaluation
Route
PATCH /api/v1/evaluations/{evaluation_id}
Mode
Confirm exact operation
delete_organization_evaluation
Route
DELETE /api/v1/evaluations/{evaluation_id}
Mode
Confirm exact operation
set_organization_evaluation_targets
Route
PUT /api/v1/evaluations/{evaluation_id}/targets
Mode
Confirm exact operation
run_organization_evaluation
Route
POST /api/v1/evaluations/{evaluation_id}/run
Mode
Confirm exact operation
list_organization_evaluation_results
Route
GET /api/v1/evaluations/{evaluation_id}/results
Mode
Read
get_organization_evaluation_result
Route
GET /api/v1/evaluations/{evaluation_id}/results/{result_id}
Mode
Read
get_organization_evaluation_metrics
Route
GET /api/v1/evaluations/{evaluation_id}/metrics
Mode
Read
list_accounts
Route
Local, no network
Mode
Read

start_flow

gumloop-cli start-flow

user_id
Required
No; body and guard rules apply
Type
string
Details
The id for the user initiating the flow.
project_id
Required
No; body and guard rules apply
Type
string
Details
(Optional) The id of the project within which the flow is executed.
saved_item_id
Required
No; body and guard rules apply
Type
string
Details
The id for the saved flow.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: saved_item_id, user_id. Profile defaults fill supported user/team identity fields before body validation.

kill_flow

gumloop-cli kill-flow

run_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the pipeline run to kill.
user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: run_id. Profile defaults fill supported user/team identity fields before body validation.

get_run_details

gumloop-cli get-run-details

run_id
Required
Yes
Type
string
Details
ID of the flow run to retrieve
user_id
Required
No; body and guard rules apply
Type
string
Details
The id for the user initiating the flow. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The id of the project within which the flow is executed. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_workbooks

gumloop-cli list-workbooks

user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID for which to list workbooks. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID for which to list workbooks. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_flows

gumloop-cli list-flows

user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID to for which to list items. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID for which to list items. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_input_schema

gumloop-cli get-input-schema

saved_item_id
Required
Yes
Type
string
Details
The ID of the saved item for which to retrieve input schemas.
user_id
Required
No; body and guard rules apply
Type
string
Details
User ID that created the flow. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
Project ID that the flow is under. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_run_history

gumloop-cli get-run-history

workbook_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the workbook to retrieve run history for. Required if saved_item_id is not provided.
saved_item_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the saved item to retrieve run history for. Required if workbook_id is not provided.
user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

download_file

gumloop-cli download-file

file_name
Required
No; body and guard rules apply
Type
string
Details
The name of the file to download.
run_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the flow run associated with the file.
saved_item_id
Required
No; body and guard rules apply
Type
string
Details
The saved item ID associated with the file.
user_id
Required
No; body and guard rules apply
Type
string
Details
Optional. The user ID associated with the flow run.
project_id
Required
No; body and guard rules apply
Type
string
Details
Optional. The project ID associated with the flow run.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.
output_file
Required
Yes
Type
string
Details
New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.

download_files

gumloop-cli download-files

file_names
Required
No; body and guard rules apply
Type
array
Details
An array of file names to download. Items: string.
run_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the flow run associated with the files.
user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID associated with the files. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID associated with the files. Required if user_id is not provided.
saved_item_id
Required
No; body and guard rules apply
Type
string
Details
Optional. The saved item ID associated with the files.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.
output_file
Required
Yes
Type
string
Details
New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.

upload_file

gumloop-cli upload-file

file_name
Required
No; body and guard rules apply
Type
string
Details
The name of the file to be uploaded.
file_content
Required
No; body and guard rules apply
Type
string
Details
Base64 encoded content of the file. format: byte.
user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID associated with the file. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID associated with the file. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.
file_path
Required
No; body and guard rules apply
Type
string
Details
Regular local file path, no symlink, at most 3 MiB. Encoded as native base64 file_content; cannot mix with file_content or payload routes. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

upload_files

gumloop-cli upload-files

files
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. Items: object.
user_id
Required
No; body and guard rules apply
Type
string
Details
The user ID associated with the files. Required if project_id is not provided.
project_id
Required
No; body and guard rules apply
Type
string
Details
The project ID associated with the files. Required if user_id is not provided.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

get_organization_audit_logs

gumloop-cli get-organization-audit-logs

organization_id
Required
Yes
Type
string
Details
The ID of the organization to retrieve audit logs for.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to retrieve organization logs.
start_time
Required
Yes
Type
string
Details
Start timestamp for log filtering (ISO format). format: date-time.
end_time
Required
Yes
Type
string
Details
End timestamp for log filtering (ISO format). format: date-time.
event_types
Required
No; body and guard rules apply
Type
string
Details
Comma-separated list of event types to filter by (e.g. user_sign_in,credential_retrieval). The singular event_type param accepts a single value.
user_ids
Required
No; body and guard rules apply
Type
string
Details
Comma-separated list of user IDs whose events should be returned.
ip_addresses
Required
No; body and guard rules apply
Type
string
Details
Comma-separated list of source IP addresses to filter by. The singular ip_address param accepts a single value.
workspace_ids
Required
No; body and guard rules apply
Type
string
Details
Comma-separated list of workspace (team) IDs to filter by. The singular workspace_id param accepts a single value.
entity_ids
Required
No; body and guard rules apply
Type
string
Details
Comma-separated list of entity IDs (agents, workbooks, files) to filter by. The singular entity_id param accepts a single value.
page
Required
No; body and guard rules apply
Type
integer
Details
Page number for pagination. default: 1.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of records per page. default: 50.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

manage_project_users

gumloop-cli manage-project-users

organization_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the organization that the workspace belongs to.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to manage workspace users.
workspace_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the workspace to manage users for.
action
Required
No; body and guard rules apply
Type
string
Details
The action to perform - either 'add' or 'remove' a user. Values: add, remove.
user_email
Required
No; body and guard rules apply
Type
string
Details
The email address of the target user to add or remove.
is_admin
Required
No; body and guard rules apply
Type
boolean
Details
When adding a user, specify whether they should have admin privileges (default is false).
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: organization_id, user_id, workspace_id, action, user_email. Profile defaults fill supported user/team identity fields before body validation.

manage_permission_group_users

gumloop-cli manage-permission-group-users

organization_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the organization that the custom role belongs to.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to manage custom role users.
group_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the custom role to manage users for.
action
Required
No; body and guard rules apply
Type
string
Details
The action to perform - either 'add' or 'remove' a user. Values: add, remove.
user_email
Required
No; body and guard rules apply
Type
string
Details
The email address of the target user to add or remove.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: organization_id, user_id, group_id, action, user_email. Profile defaults fill supported user/team identity fields before body validation.

list_role_credit_limits

gumloop-cli list-role-credit-limits

organization_id
Required
Yes
Type
string
Details
The ID of the organization. minLength: 1.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to manage custom role credit limits.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of roles per page. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque cursor from a previous response's next_cursor; omit for the first page.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_role_credit_limit

gumloop-cli get-role-credit-limit

organization_id
Required
Yes
Type
string
Details
The ID of the organization the custom role belongs to. minLength: 1.
role_id
Required
Yes
Type
string
Details
The ID of the custom role (the same ID used as group_id by the Manage custom role users endpoint). minLength: 1.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to manage custom role credit limits.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

set_role_credit_limit

gumloop-cli set-role-credit-limit

organization_id
Required
Yes
Type
string
Details
The ID of the organization the custom role belongs to. minLength: 1.
role_id
Required
Yes
Type
string
Details
The ID of the custom role (the same ID used as group_id by the Manage custom role users endpoint). minLength: 1.
monthly_credit_limit
Required
No; body and guard rules apply
Type
integer/null
Details
The monthly credit limit applied to each member of this role, or null to clear the role-level limit. minimum: 0. maximum: 1000000000.
user_id
Required
No; body and guard rules apply
Type
string
Details
Your user id -- you must be an organization admin to manage custom role credit limits.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: monthly_credit_limit, user_id. Profile defaults fill supported user/team identity fields before body validation.

export_data

gumloop-cli export-data

user_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the user requesting the export.
data_type
Required
No; body and guard rules apply
Type
string
Details
The type of data to export. Use "workflows" to export workflow run data, "agents" to export agent configuration data, "agent_interactions" to export agent interaction data, "credit_logs" to export credit transaction history, "interaction_evaluations" to export completed chat evaluations, or "gumstack" to export Gumstack tool call activity. Defaults to "workflows". Audit-log exports are available in the Gumloop app only, not through this endpoint. Values: workflows, agents, agent_interactions, credit_logs, interaction_evaluations, gumstack. default: workflows.
category_filter
Required
No; body and guard rules apply
Type
string
Details
Only applicable when data_type is "credit_logs". Optional filter to export only credit logs matching a specific category (e.g., "PIPELINE_RUN", "AGENT_RUN", "CUSTOM_NODE_RD", "EXTERNAL_GUMCP_CALL"). When omitted, all categories are included.
export_level
Required
No; body and guard rules apply
Type
string
Details
The scope of the export. Use "organization" to export across the entire organization, or "workspace" to export from a single workspace (requires exactly one ID in workspace_ids). Defaults to "organization". Not applicable when data_type is "credit_logs". Values: workspace, organization. default: organization.
export_fields
Required
No; body and guard rules apply
Type
array
Details
Array of fields to include in the export. The available fields depend on the data_type. Workflow fields (when data_type is "workflows"): - workbook_id - The workbook identifier - workbook_name - The workbook name - workbook_created_ts - Workbook creation timestamp - user_id - The user identifier - user_email - The user's email address - workspace_id - The workspace identifier - workspace_name - The workspace name - run_id - The flow run identifier - credit_cost - Credits consumed by the run - pl_run_created_ts - Flow run creation timestamp - pl_run_finished_ts - Flow run completion timestamp - pipeline - The full pipeline configuration (JSON) Agent fields (when data_type is "agents"): - agent_id - The agent identifier - agent_name - The agent name - agent_description - The agent description - agent_model - The model used by the agent - agent_system_prompt - The agent's system prompt - agent_created_ts - Agent creation timestamp - agent_tools - Tools configured for the agent (JSON) - agent_metadata - Additional agent metadata (JSON) - agent_evaluations_enabled - Whether the agent's own Evaluations are turned on (true/false) - creator_email - Email of the user who created the agent - workspace_id - The workspace identifier - workspace_name - The workspace name - folder_id - The identifier of the folder containing the agent (empty when the agent is not in a folder) - folder_name - The name of the folder containing the agent (empty when the agent is not in a folder) Agent interaction fields (when data_type is "agent_interactions"): - interaction_id - Unique identifier for the chat session - agent_id - The agent identifier - agent_name - The agent name - interaction_type - Type of interaction (e.g., chat, slack, api, triggered) - interaction_name - Display name of the chat session - trigger_type - For triggered interactions, the specific trigger type (e.g., time_based, polling_new_record_salesforce). Null for non-triggered interactions. - interaction_created_ts - Chat session creation timestamp - user_email - Email of the user who initiated the chat - credit_cost - Total credits consumed (LLM + tool + flow) - llm_credit_cost - Credits consumed by LLM calls only - tool_credit_cost - Credits consumed by tool calls - flow_credit_cost - Credits consumed by pipeline runs - message_count - Number of messages in the conversation - workspace_id - The workspace identifier - workspace_name - The workspace name Interaction evaluation fields (when data_type is "interaction_evaluations"): - evaluation_id - Unique identifier for the evaluation row - interaction_id - The chat session that was evaluated (one chat can have several evaluation rows) - agent_id - The identifier of the agent that was evaluated - organization_evaluation_id - The organization-level evaluation this row belongs to (empty for agent-level rubrics) - evaluation_created_ts - When the evaluation reached its final state - status - The evaluation's state - grade - The grade the evaluation produced - call_outcome - The outcome the evaluation recorded for the conversation - sentiment - The sentiment the evaluation recorded - error_code - Error code when the evaluation could not complete - summary - The evaluation's written summary - evaluation_model - The model that ran the evaluation - credit_cost - Credits consumed by the evaluation - user_email - Email of the user whose chat was evaluated Credit log fields (when data_type is "credit_logs"): - user_email - Email of the user associated with the credit log entry - permission_group_id - Custom role ID(s) the user belongs to (semicolon-separated if multiple) (disabled by default) - permission_group_name - Custom role name(s) the user belongs to (semicolon-separated if multiple) (disabled by default) - timestamp - When the credit transaction occurred - category - The category of the credit log (e.g., PIPELINE_RUN, AGENT_RUN) - type - The specific type of credit charge - name - Display name of the credit log entry - amount - Number of credits charged or adjusted - balance - Credit balance after the transaction - log_id - Unique identifier for the credit log entry - correlation_id - Join key to the related run or interaction (disabled by default) - balance_scope - Whether the balance is organization- or user-scoped (disabled by default) - project_id - The project identifier (disabled by default) Not all combinations of selected fields are guaranteed to produce data for every row. Items: string.
start_date
Required
No; body and guard rules apply
Type
string
Details
Start date for the export in ISO 8601 format (e.g., 2025-01-01T00:00:00Z). format: date-time.
end_date
Required
No; body and guard rules apply
Type
string
Details
End date for the export in ISO 8601 format (e.g., 2025-12-31T23:59:59Z). format: date-time.
include_all_workspaces
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include all workspaces in the organization. When true, also sets include_personal_workspaces to true. Not applicable when data_type is "credit_logs". default: False.
include_personal_workspaces
Required
No; body and guard rules apply
Type
boolean
Details
Whether to include personal workspaces in the export. Ignored if include_all_workspaces is true. Not applicable when data_type is "credit_logs". default: False.
workspace_ids
Required
No; body and guard rules apply
Type
array
Details
An optional array of workspace IDs to include in the export. When export_level is "workspace", exactly one workspace ID is required. Ignored if include_all_workspaces is true. Not applicable when data_type is "credit_logs". Items: string.
entity_ids
Required
No; body and guard rules apply
Type
array
Details
An optional array of specific entity IDs to filter the export. For workflow exports (data_type: "workflows"), these are workbook IDs. For agent exports (data_type: "agents") and agent interaction exports (data_type: "agent_interactions"), these are agent IDs. When provided, only data for the specified entities will be included. Not applicable when data_type is "credit_logs". Items: string.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: user_id, export_fields, start_date, end_date. Profile defaults fill supported user/team identity fields before body validation.

get_export_status

gumloop-cli get-export-status

user_id
Required
No; body and guard rules apply
Type
string
Details
The ID of the user requesting the export status.
data_export_id
Required
Yes
Type
string
Details
The unique identifier of the data export job to check (returned by the Export data endpoint).
download
Required
No; body and guard rules apply
Type
boolean
Details
Set to true to download the export file directly when the export is completed. When true and the export state is COMPLETED, the response will be a CSV file download instead of JSON. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
output_file
Required
Yes
Type
string
Details
New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength: 1.

output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.

list_agents

gumloop-cli list-agents

team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the listing to a single team. When omitted, returns agents owned by the authenticated user.
search
Required
No; body and guard rules apply
Type
string
Details
Case-insensitive substring match against the agent name.
creator
Required
No; body and guard rules apply
Type
string
Details
Filter to agents created by this user ID.
has_triggers
Required
No; body and guard rules apply
Type
boolean
Details
When true, only returns agents that have at least one active trigger configured.
tool
Required
No; body and guard rules apply
Type
string
Details
Filter to agents that use the specified MCP server as a tool.
flow
Required
No; body and guard rules apply
Type
string
Details
Filter to agents that use the specified saved flow as a tool.
sort_order
Required
No; body and guard rules apply
Type
string
Details
Sort order for the listing. Defaults to newest first. Values: newest, oldest, name_asc, name_desc. default: newest.
include_last_used
Required
No; body and guard rules apply
Type
boolean
Details
When true, populates last_used_at on each agent with the timestamp of its most recent session.
include_last_updated
Required
No; body and guard rules apply
Type
boolean
Details
When true, populates last_updated_at on each agent with the timestamp of its most recent configuration change.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of agents per page. Sending page_size or cursor opts into cursor pagination; requests that send neither return the full list. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque cursor from a previous response's next_cursor. Pass it to fetch the next page.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

create_agent

gumloop-cli create-agent

name
Required
No; body and guard rules apply
Type
string
Details
Display name for the agent.
model_name
Required
No; body and guard rules apply
Type
string
Details
ID of the LLM the agent runs on. Use GET /models to discover valid values.
description
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema.
system_prompt
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema.
tools
Required
No; body and guard rules apply
Type
array
Details
Tools the agent can call. Each tool is an object whose shape depends on the tool type. default: []. Items: object.
resources
Required
No; body and guard rules apply
Type
array
Details
Resources attached to the agent. default: []. Items: object.
skill_ids
Required
No; body and guard rules apply
Type
array/null
Details
IDs of skills to attach to the agent. Attachment happens inside the create transaction, so an invalid ID fails the whole request (no orphaned agent). Omit to attach none. The caller must hold INVOKE on each skill. After creation, manage skills with PATCH /agents/{agent_id}/skills. Items: string.
metadata
Required
No; body and guard rules apply
Type
object/null
Details
Arbitrary key/value metadata stored on the agent.
folder_id
Required
No; body and guard rules apply
Type
string/null
Details
ID of the folder to place the agent in.
is_active
Required
No; body and guard rules apply
Type
boolean
Details
Whether the agent is active. Defaults to true. Setting this to false retires the agent: it disappears from GET /agents, and GET/PATCH /agents/{agent_id} return 404, so it cannot be reactivated through the API. This is not a pause switch — to stop an agent from running while keeping it reachable, disable its triggers instead. default: True.
agent_id
Required
No; body and guard rules apply
Type
string/null
Details
Optional caller-supplied agent ID. When omitted, the server generates one.
team_id
Required
No; body and guard rules apply
Type
string/null
Details
ID of the team to create the agent under. When omitted, the agent is owned by the authenticated user.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name, model_name. Profile defaults fill supported user/team identity fields before body validation.

retrieve_agent

gumloop-cli retrieve-agent

agent_id
Required
Yes
Type
string
Details
ID of the agent to retrieve. Also accepts the reserved aliases gumball and analytics. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

update_agent

gumloop-cli update-agent

agent_id
Required
Yes
Type
string
Details
ID of the agent to update. Also accepts the reserved aliases gumball and analytics. minLength: 1.
name
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema.
model_name
Required
No; body and guard rules apply
Type
string/null
Details
ID of the LLM the agent runs on. Use GET /models to discover valid values.
description
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema.
system_prompt
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema.
tools
Required
No; body and guard rules apply
Type
array/null
Details
When provided, replaces the agent's tool list. Items: object.
resources
Required
No; body and guard rules apply
Type
array/null
Details
When provided, replaces the agent's resource list. Items: object.
metadata
Required
No; body and guard rules apply
Type
object/null
Details
See the full input schema.
is_active
Required
No; body and guard rules apply
Type
boolean/null
Details
Setting this to false retires the agent: it disappears from GET /agents, and GET/PATCH /agents/{agent_id} return 404, so it cannot be reactivated through the API. This is not a pause switch — to stop an agent from running while keeping it reachable, disable its triggers instead.
team_id
Required
No; body and guard rules apply
Type
string/null
Details
When provided, transfers ownership of the agent to this team.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

create_chat_completion

gumloop-cli create-chat-completion

model
Required
No; body and guard rules apply
Type
string
Details
Model slug. Use the id from GET /models or one of Gumloop's preset routes.
messages
Required
No; body and guard rules apply
Type
array
Details
Conversation history. Roles system, developer, user, assistant, and tool. User messages accept multipart content with text and image_url parts. Assistant messages can carry tool_calls; answer each one with a tool message whose tool_call_id matches the call's id. Items: object.
stream
Required
No; body and guard rules apply
Type
boolean
Details
Only non-streaming JSON is supported. Streaming requests are refused before fetch.
temperature
Required
No; body and guard rules apply
Type
number
Details
Sampling temperature.
max_completion_tokens
Required
No; body and guard rules apply
Type
integer
Details
Cap on completion tokens. Replaces the deprecated max_tokens field.
modalities
Required
No; body and guard rules apply
Type
array
Details
Output modalities. Include "image" to route to an image-generation model. Items: string.
image_config
Required
No; body and guard rules apply
Type
object
Details
Image-generation parameters (size, quality, aspect_ratio, background, output_format, partial_images). Optional. Image-generation models accept either modalities: ["image"] or image_config (or both); chat models ignore this field.
response_format
Required
No; body and guard rules apply
Type
object
Details
Constrain the response. {type: "json_object"} returns a JSON object; {type: "json_schema", json_schema: {name, strict, schema}} returns JSON matching the supplied schema.
tools
Required
No; body and guard rules apply
Type
array
Details
OpenAI-shape tool definitions ({type: "function", function: {name, description, parameters}}). Pass tool_choice to constrain selection.
tool_choice
Required
No; body and guard rules apply
Type
Union
Details
"auto" lets the model choose and is the default when tools are sent. "none" disables tool calls, "required" forces a tool call, and {"type": "function", "function": {"name": "..."}} forces a specific tool.
provider
Required
No; body and guard rules apply
Type
object
Details
OpenRouter provider routing config. Caller fields like sort and order are honored; ZDR/data_collection policy is server-enforced.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: model, messages. Profile defaults fill supported user/team identity fields before body validation.

list_models

gumloop-cli list-models

team_id
Required
No; body and guard rules apply
Type
string
Details
Scope model availability to a specific team. When omitted, uses the authenticated user's default organization.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

route_model

gumloop-cli route-model

input
Required
No; body and guard rules apply
Type
Union
Details
The message to route. message is accepted as an alias. A string or an array of {type: text, text: ...} parts.
models
Required
No; body and guard rules apply
Type
array
Details
Candidate model IDs to choose between. IDs must be nonempty, unique after remapping, and registered. Omit to use Chew's lane-chain union. minItems: 1. maxItems: 50. Items: string.
history
Required
No; body and guard rules apply
Type
array
Details
Prior turns, oldest first, for context. maxItems: 20. Items: object.
agent
Required
No; body and guard rules apply
Type
object
Details
Optional context about the agent the message is for. Sharper context produces a sharper route.
team_id
Required
No; body and guard rules apply
Type
string
Details
Scope model availability and credit attribution to a team the caller belongs to.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.

list_agent_versions

gumloop-cli list-agent-versions

agent_id
Required
Yes
Type
string
Details
ID of the agent whose versions to list. Also accepts the reserved aliases gumball and analytics. minLength: 1.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of versions to return per page. Clamped to 1–100. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque pagination cursor returned by a prior call as next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

retrieve_agent_version

gumloop-cli retrieve-agent-version

agent_id
Required
Yes
Type
string
Details
ID of the agent the version belongs to. Also accepts the reserved aliases gumball and analytics. minLength: 1.
version_id
Required
Yes
Type
string
Details
ID of the version to retrieve, from GET /agents/{agent_id}/versions. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

update_agent_skills

gumloop-cli update-agent-skills

agent_id
Required
Yes
Type
string
Details
ID of the agent whose skills to update. Also accepts the reserved aliases gumball and analytics. minLength: 1.
attach
Required
No; body and guard rules apply
Type
array
Details
Skill IDs to attach. Ignored if already attached. default: []. Items: string.
detach
Required
No; body and guard rules apply
Type
array
Details
Skill IDs to detach. Ignored if not attached. default: []. Items: string.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

list_agent_mcp_servers

gumloop-cli list-agent-mcp-servers

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

attach_agent_mcp_server

gumloop-cli attach-agent-mcp-server

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
server_id
Required
Yes
Type
string
Details
ID of the MCP server from the caller's catalog. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

detach_agent_mcp_server

gumloop-cli detach-agent-mcp-server

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
server_id
Required
Yes
Type
string
Details
ID of the MCP server to detach. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

list_sessions

gumloop-cli list-sessions

agent_id
Required
Yes
Type
string
Details
ID of the agent whose sessions to list. Also accepts the reserved aliases gumball and analytics. minLength: 1.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of sessions to return per page. Defaults to 20, maximum 100. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Cursor for the next page of results. Use the next_cursor value from a previous response.
search
Required
No; body and guard rules apply
Type
string
Details
Free-text search query to filter sessions by name or content. Also accepted as search_query.
sort_order
Required
No; body and guard rules apply
Type
string
Details
Sort order for the results (e.g. newest or oldest).
type
Required
No; body and guard rules apply
Type
string
Details
Filter sessions by type (e.g. api, web, slack).
state
Required
No; body and guard rules apply
Type
string
Details
Filter sessions by state. Values: processing, completed, failed, queued, idle.
creator_user_id
Required
No; body and guard rules apply
Type
string
Details
Filter sessions by the user who created them.
trigger_id
Required
No; body and guard rules apply
Type
string
Details
Filter sessions by the trigger that initiated them.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

create_session

gumloop-cli create-session

agent_id
Required
Yes
Type
string
Details
ID of the agent to start a session on. Also accepts the reserved aliases gumball and analytics. minLength: 1.
input
Required
No; body and guard rules apply
Type
string
Details
The first user message for the session. Also accepted as message for backwards compatibility. When omitted, an idle session is created with no messages.
session_id
Required
No; body and guard rules apply
Type
string
Details
Caller-supplied session ID. When omitted, the server generates one. If provided and the ID already exists, the request returns 409 session_already_exists.
name
Required
No; body and guard rules apply
Type
string
Details
Optional display name for the session. Leading and trailing whitespace is removed before the 1-256 character limit is applied, so an empty or whitespace-only value is rejected. A name you supply is kept; the automatic title only fills in sessions created without one. Rename the session later with PATCH /sessions/{session_id}. maxLength: 256.
metadata
Required
No; body and guard rules apply
Type
object
Details
Arbitrary key/value metadata attached to the session. Stored under metadata.client.
stream
Required
No; body and guard rules apply
Type
boolean
Details
Must be false (or omitted) when calling api.gumloop.com. Set to true only when calling ws.gumloop.com (see the streaming section above). default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

retrieve_session

gumloop-cli retrieve-session

session_id
Required
Yes
Type
string
Details
ID of the session to retrieve. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

rename_session

gumloop-cli rename-session

session_id
Required
Yes
Type
string
Details
ID of the session to rename. minLength: 1.
name
Required
No; body and guard rules apply
Type
string
Details
New name for the session. Leading and trailing whitespace is removed before the 1-256 character limit is applied, so a whitespace-only value is rejected. minLength: 1. maxLength: 256.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.

send_message

gumloop-cli send-message

session_id
Required
Yes
Type
string
Details
ID of the session to continue. minLength: 1.
input
Required
No; body and guard rules apply
Type
string
Details
The next user message. Required. Also accepted as message for backwards compatibility.
stream
Required
No; body and guard rules apply
Type
boolean
Details
Must be false (or omitted) when calling api.gumloop.com. Set to true only when calling ws.gumloop.com (see the streaming section above). default: False.
attachments
Required
No; body and guard rules apply
Type
array
Details
Files to attach to the message. Each file_name must be a stored path returned by Upload session file for this session. maxItems: 10. Items: object.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.

cancel_session

gumloop-cli cancel-session

session_id
Required
Yes
Type
string
Details
ID of the session to cancel. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

upload_session_file

gumloop-cli upload-session-file

session_id
Required
Yes
Type
string
Details
ID of the session to upload the file to. minLength: 1.
file_name
Required
No; body and guard rules apply
Type
string
Details
Name of the file. Directory components are stripped; the base name is sanitized before storage.
file_content
Required
No; body and guard rules apply
Type
string
Details
Base64-encoded file contents. Maximum decoded size is 200MB. format: byte.
media_type
Required
No; body and guard rules apply
Type
string
Details
MIME type of the file. Echoed back in the response.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: file_name, file_content. Profile defaults fill supported user/team identity fields before body validation.

resolve_session_approvals

gumloop-cli resolve-session-approvals

session_id
Required
Yes
Type
string
Details
ID of the session with pending approvals. minLength: 1.
approval_responses
Required
No; body and guard rules apply
Type
array
Details
Answers to pending asks. Each action_request_id may appear at most once. minItems: 1. maxItems: 20. Items: object.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: approval_responses. Profile defaults fill supported user/team identity fields before body validation.

list_queued_messages

gumloop-cli list-queued-messages

session_id
Required
Yes
Type
string
Details
ID of the session whose queue to list. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

queue_session_message

gumloop-cli queue-session-message

session_id
Required
Yes
Type
string
Details
ID of the session to queue the message on. minLength: 1.
input
Required
No; body and guard rules apply
Type
string
Details
The message to queue. Cannot be empty. Also accepted as message for backwards compatibility.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.

update_queued_message

gumloop-cli update-queued-message

session_id
Required
Yes
Type
string
Details
ID of the session the queued message belongs to. minLength: 1.
queued_message_id
Required
Yes
Type
string
Details
ID of the queued message to update. minLength: 1.
input
Required
No; body and guard rules apply
Type
string
Details
The new message content. Cannot be empty. Also accepted as message for backwards compatibility.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.

delete_queued_message

gumloop-cli delete-queued-message

session_id
Required
Yes
Type
string
Details
ID of the session the queued message belongs to. minLength: 1.
queued_message_id
Required
Yes
Type
string
Details
ID of the queued message to delete. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

send_queued_message

gumloop-cli send-queued-message

session_id
Required
Yes
Type
string
Details
ID of the session the queued message belongs to. minLength: 1.
queued_message_id
Required
Yes
Type
string
Details
ID of the queued message to send. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

list_mcp_servers

gumloop-cli list-mcp-servers

team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the catalog to a single team. When omitted, returns servers visible to the authenticated user.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

retrieve_mcp_server

gumloop-cli retrieve-mcp-server

server_id
Required
Yes
Type
string
Details
Identifier of the MCP server to retrieve. minLength: 1.
team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the lookup to a single team.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_mcp_server_tools

gumloop-cli list-mcp-server-tools

server_id
Required
Yes
Type
string
Details
Identifier of the MCP server. minLength: 1.
team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the lookup to a single team.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_mcp_server_resources

gumloop-cli list-mcp-server-resources

server_id
Required
Yes
Type
string
Details
Identifier of the MCP server. minLength: 1.
team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the lookup to a single team.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque cursor from a previous response's next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

read_mcp_server_resource

gumloop-cli read-mcp-server-resource

server_id
Required
Yes
Type
string
Details
See current schema minLength: 1.
uri
Required
Yes
Type
string
Details
The resource uri from List MCP server resources.
team_id
Required
No; body and guard rules apply
Type
string
Details
See current schema
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_mcp_server_prompts

gumloop-cli list-mcp-server-prompts

server_id
Required
Yes
Type
string
Details
See current schema minLength: 1.
team_id
Required
No; body and guard rules apply
Type
string
Details
See current schema
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_mcp_server_prompt

gumloop-cli get-mcp-server-prompt

server_id
Required
Yes
Type
string
Details
See current schema minLength: 1.
name
Required
No; body and guard rules apply
Type
string
Details
Prompt name from List MCP server prompts.
arguments
Required
No; body and guard rules apply
Type
object
Details
Argument values for the template.
team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the lookup to a single team.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.

call_mcp_tools

gumloop-cli call-mcp-tools

calls
Required
No; body and guard rules apply
Type
array
Details
Tool calls to execute. Dispatched concurrently; the batch is capped at 5. minItems: 1. maxItems: 5. Items: object.
team_id
Required
No; body and guard rules apply
Type
string/null
Details
Team the calls are scoped to.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: calls. Profile defaults fill supported user/team identity fields before body validation.

search_brain

gumloop-cli search-brain

query
Required
No; body and guard rules apply
Type
string
Details
The natural-language search query.
limit
Required
No; body and guard rules apply
Type
integer
Details
Maximum number of results to return. minimum: 1. maximum: 50. default: 8.
source_type
Required
No; body and guard rules apply
Type
array/null
Details
Restrict results to specific source types. Omit to search every source you can access. Valid values: notion, google_drive, slack, github, confluence, direct_file_uploads, gumloop_artifacts. minItems: 1. Items: string.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: query. Profile defaults fill supported user/team identity fields before body validation.

list_brain_sources

gumloop-cli list-brain-sources

scope
Required
No; body and guard rules apply
Type
string
Details
Only sources in this scope. Values: personal, team, organization.
source_type
Required
No; body and guard rules apply
Type
string
Details
Only sources of this type, for example direct_file_uploads or notion.
team_id
Required
No; body and guard rules apply
Type
string
Details
Only team sources belonging to this team.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Maximum number of sources to return. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque cursor from a previous response's next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

create_brain_source

gumloop-cli create-brain-source

name
Required
No; body and guard rules apply
Type
string
Details
Display name of the source. minLength: 1. maxLength: 200.
source_type
Required
No; body and guard rules apply
Type
string
Details
Only direct_file_uploads is accepted. default: direct_file_uploads.
scope
Required
No; body and guard rules apply
Type
string
Details
Which Brain the source belongs to. team requires team_id. Values: personal, team, organization. default: personal.
team_id
Required
No; body and guard rules apply
Type
string
Details
The team for scope: team. Not accepted with other scopes.
require_approval
Required
No; body and guard rules apply
Type
boolean
Details
Create as a draft that estimates credits before anything is indexed. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.

get_brain_source

gumloop-cli get-brain-source

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

delete_brain_source

gumloop-cli delete-brain-source

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

list_brain_files

gumloop-cli list-brain-files

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
page_size
Required
No; body and guard rules apply
Type
integer
Details
See current schema minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
See current schema
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

upload_brain_files

gumloop-cli upload-brain-files

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
files
Required
No; body and guard rules apply
Type
array
Details
Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems: 1. maxItems: 25. Items: string.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.

files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.

delete_brain_file

gumloop-cli delete-brain-file

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
file_id
Required
Yes
Type
string
Details
See current schema minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

get_brain_source_estimate

gumloop-cli get-brain-source-estimate

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

approve_brain_source

gumloop-cli approve-brain-source

source_id
Required
Yes
Type
string
Details
The source id. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

list_skills

gumloop-cli list-skills

team_id
Required
No; body and guard rules apply
Type
string
Details
Scope the listing to a single team. When omitted, returns skills owned by the authenticated user.
search_query
Required
No; body and guard rules apply
Type
string
Details
Case-insensitive substring match against the skill name.
sort_order
Required
No; body and guard rules apply
Type
string
Details
Sort order for the returned skills. Values: newest, popular, most_used. default: newest.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of skills per page. Clamped between 1 and 100. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque pagination cursor returned in next_cursor from a prior page.
creator_user_id
Required
No; body and guard rules apply
Type
string
Details
Filter to skills created by this user ID.
related_server_id
Required
No; body and guard rules apply
Type
string
Details
Filter to skills that reference this MCP server ID in their metadata.
agent_id
Required
No; body and guard rules apply
Type
string
Details
Filter to skills attached to this agent.
unused
Required
No; body and guard rules apply
Type
string
Details
When set, filters to skills that have not been used.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

create_skill

gumloop-cli create-skill

files
Required
No; body and guard rules apply
Type
array
Details
Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems: 1. maxItems: 25. Items: string.
team_id
Required
No; body and guard rules apply
Type
string
Details
Team that should own the skill. When omitted, the skill is owned by the authenticated user.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.

files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.

update_skill

gumloop-cli update-skill

skill_id
Required
Yes
Type
string
Details
ID of the skill to update. minLength: 1.
files
Required
No; body and guard rules apply
Type
array
Details
Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems: 1. maxItems: 25. Items: string.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.

files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.

delete_skill

gumloop-cli delete-skill

skill_id
Required
Yes
Type
string
Details
ID of the skill to delete. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

download_skill_file

gumloop-cli download-skill-file

skill_id
Required
Yes
Type
string
Details
ID of the skill to download. minLength: 1.
version_id
Required
No; body and guard rules apply
Type
string
Details
Specific version to download. When omitted, the current draft is returned.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
output_file
Required
Yes
Type
string
Details
New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength: 1.

output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.

list_artifacts

gumloop-cli list-artifacts

agent_id
Required
Yes
Type
string
Details
ID of the agent whose artifacts to list. Also accepts the reserved aliases gumball and analytics. minLength: 1.
session_id
Required
No; body and guard rules apply
Type
string
Details
Filter to artifacts produced within a specific session.
search_query
Required
No; body and guard rules apply
Type
string
Details
Case-insensitive substring match against the artifact filename.
sort_order
Required
No; body and guard rules apply
Type
string
Details
Sort order for results. Defaults to newest. default: newest.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of artifacts to return per page. Clamped to 1–100. minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Opaque pagination cursor returned by a prior call as next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

download_artifact_file

gumloop-cli download-artifact-file

artifact_id
Required
Yes
Type
string
Details
ID of the artifact to download. minLength: 1.
version_id
Required
No; body and guard rules apply
Type
string
Details
Specific version of the artifact to download. Defaults to the latest version when omitted.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
output_file
Required
Yes
Type
string
Details
New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength: 1.

output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.

list_browser_profiles

gumloop-cli list-browser-profiles

team_id
Required
No; body and guard rules apply
Type
string
Details
List a team's profiles instead of your personal ones.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

import_browser_profile_cookies

gumloop-cli import-browser-profile-cookies

profile_id
Required
Yes
Type
string
Details
A profile id, or default. minLength: 1.
url
Required
No; body and guard rules apply
Type
string
Details
Import only the cookies for this site and replace what the profile had for it. Omit to import every site in cookies. maxLength: 2048.
cookies
Required
No; body and guard rules apply
Type
array
Details
Cookies in chrome.cookies.Cookie or CDP Cookie shape. minItems: 1. Items: object.
team_id
Required
No; body and guard rules apply
Type
string
Details
Import into a team-owned profile instead of a personal one.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: cookies. Profile defaults fill supported user/team identity fields before body validation.

list_teams

gumloop-cli list-teams

account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_evaluations

gumloop-cli list-evaluations

agent_id
Required
Yes
Type
string
Details
ID of the agent whose evaluations to list. Also accepts the reserved aliases gumball and analytics. minLength: 1.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Number of evaluations to return per page (1-100). minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Pagination cursor from a previous response's next_cursor field.
grade
Required
No; body and guard rules apply
Type
string
Details
Filter evaluations by grade. Values: pass, needs_review, needs_attention.
status
Required
No; body and guard rules apply
Type
string
Details
Return evaluations in one lifecycle state instead of the default completed and failed set. Values: queued, in_progress, completed, failed.
session_id
Required
No; body and guard rules apply
Type
string
Details
Only evaluations of this session.
organization_evaluation_id
Required
No; body and guard rules apply
Type
string
Details
Return the results one organization evaluation produced for this agent instead of the agent's own evaluation results.
created_after
Required
No; body and guard rules apply
Type
string
Details
Only evaluations created at or after this ISO 8601 timestamp. Timestamps without an offset are read as UTC. format: date-time.
created_before
Required
No; body and guard rules apply
Type
string
Details
Only evaluations created before this ISO 8601 timestamp. Timestamps without an offset are read as UTC. format: date-time.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

run_evaluations

gumloop-cli run-evaluations

agent_id
Required
Yes
Type
string
Details
ID of the agent that owns the sessions. minLength: 1.
session_ids
Required
No; body and guard rules apply
Type
array
Details
Sessions to grade. Duplicates are rejected. minItems: 1. maxItems: 200. Items: string.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Report cost and skipped sessions without queuing. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: session_ids. Profile defaults fill supported user/team identity fields before body validation.

get_evaluation_metrics

gumloop-cli get-evaluation-metrics

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
days
Required
No; body and guard rules apply
Type
integer
Details
Number of days to look back (1-365). Defaults to 30. minimum: 1. maximum: 365. default: 30.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

retrieve_evaluation

gumloop-cli retrieve-evaluation

agent_id
Required
Yes
Type
string
Details
ID of the agent the evaluation belongs to. Also accepts the reserved aliases gumball and analytics. minLength: 1.
evaluation_id
Required
Yes
Type
string
Details
ID of the evaluation to retrieve. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_evaluation_config

gumloop-cli get-evaluation-config

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

update_evaluation_config

gumloop-cli update-evaluation-config

agent_id
Required
Yes
Type
string
Details
ID of the agent. Also accepts the reserved aliases gumball and analytics. minLength: 1.
enabled
Required
No; body and guard rules apply
Type
boolean
Details
Whether evaluations are enabled for this agent.
model_name
Required
No; body and guard rules apply
Type
string
Details
LLM model to use for evaluation.
include_auto_tags
Required
No; body and guard rules apply
Type
boolean
Details
Allow the evaluator to suggest tags beyond your predefined vocabulary.
criteria
Required
No; body and guard rules apply
Type
array
Details
Quality criteria to check (replaces existing list). Max 30. Items: object.
tags
Required
No; body and guard rules apply
Type
array
Details
Tag vocabulary (replaces existing list). Max 50. Items: object.
data_points
Required
No; body and guard rules apply
Type
array
Details
Data points to extract (replaces existing list). Max 40. Items: object.
sentiment
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

list_organizations

gumloop-cli list-organizations

account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_evaluation_options

gumloop-cli get-evaluation-options

account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_organization_evaluations

gumloop-cli list-organization-evaluations

organization_id
Required
Yes
Type
string
Details
The organization whose evaluations to list.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Items per page (1-100). minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Pagination cursor from a previous response's next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

create_organization_evaluation

gumloop-cli create-organization-evaluation

account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

get_organization_evaluation

gumloop-cli get-organization-evaluation

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

update_organization_evaluation

gumloop-cli update-organization-evaluation

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.

delete_organization_evaluation

gumloop-cli delete-organization-evaluation

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.

set_organization_evaluation_targets

gumloop-cli set-organization-evaluation-targets

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
targets
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. maxItems: 1000. Items: EvaluationTarget.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: targets. Profile defaults fill supported user/team identity fields before body validation.

run_organization_evaluation

gumloop-cli run-organization-evaluation

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
session_ids
Required
No; body and guard rules apply
Type
array
Details
Sessions to grade. Duplicates are rejected. minItems: 1. maxItems: 200. Items: string.
dry_run
Required
No; body and guard rules apply
Type
boolean
Details
Report cost and skipped sessions without queuing. default: False.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.
confirm
Required
No; body and guard rules apply
Type
boolean
Details
Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload
Required
No; body and guard rules apply
Type
object
Details
Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file
Required
No; body and guard rules apply
Type
string
Details
Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength: 1.

A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: session_ids. Profile defaults fill supported user/team identity fields before body validation.

list_organization_evaluation_results

gumloop-cli list-organization-evaluation-results

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
agent_id
Required
No; body and guard rules apply
Type
string
Details
Only results for this agent.
session_id
Required
No; body and guard rules apply
Type
string
Details
Only results for this session.
grade
Required
No; body and guard rules apply
Type
string
Details
Filter by grade. Values: pass, needs_review, needs_attention.
status
Required
No; body and guard rules apply
Type
string
Details
Filter by status. Values: queued, in_progress, completed, failed.
created_after
Required
No; body and guard rules apply
Type
string
Details
Only results created at or after this time. RFC 3339 with an explicit offset (for example 2026-09-01T00:00:00Z). format: date-time.
created_before
Required
No; body and guard rules apply
Type
string
Details
Only results created before this time. RFC 3339 with an explicit offset. format: date-time.
page_size
Required
No; body and guard rules apply
Type
integer
Details
Items per page (1-100). minimum: 1. maximum: 100. default: 20.
cursor
Required
No; body and guard rules apply
Type
string
Details
Pagination cursor from a previous response's next_cursor.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_organization_evaluation_result

gumloop-cli get-organization-evaluation-result

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
result_id
Required
Yes
Type
string
Details
Result ID from a run response or a results list. minLength: 1.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

get_organization_evaluation_metrics

gumloop-cli get-organization-evaluation-metrics

evaluation_id
Required
Yes
Type
string
Details
ID of the organization evaluation. minLength: 1.
days
Required
No; body and guard rules apply
Type
integer
Details
Window length in days. minimum: 1. maximum: 365. default: 30.
account
Required
No; body and guard rules apply
Type
string
Details
Named private Gumloop account; selects private credentials and user/team identity.

list_accounts

gumloop-cli list-accounts

None
Required
No
Type
None
Details
No arguments

Nested request definitions

These definitions are shared by the current native bodies. Required fields depend on the selected union branch. Full inline shapes remain in schema COMMAND.

##### EvaluationRubric

What and how the evaluation grades. Entries in criteria, tags, and data_points accept additional fields as the product evolves.

model_name
Required
No; body and guard rules apply
Type
string
Details
Grading model. auto picks the recommended model.
frequency
Required
No; body and guard rules apply
Type
string
Details
When to grade new sessions automatically. manual only grades via POST /evaluations/{evaluation_id}/run. Values: debounced, per_turn, manual.
language
Required
No; body and guard rules apply
Type
string
Details
Language for summaries and rationales, or auto.
include_auto_tags
Required
No; body and guard rules apply
Type
boolean
Details
See the full input schema.
session_types
Required
No; body and guard rules apply
Type
array
Details
Session types to grade. See session_types in GET /evaluation-options. Items: string.
criteria
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. maxItems: 30. Items: object.
tags
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. maxItems: 50. Items: object.
data_points
Required
No; body and guard rules apply
Type
array
Details
See the full input schema. maxItems: 40. Items: object.
sentiment
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.
notifications
Required
No; body and guard rules apply
Type
object
Details
See the full input schema.

##### EvaluationCreateRequest

Current request definition.

scope
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. Values: organization. default: organization.
organization_id
Required
Yes
Type
string
Details
See the full input schema.
name
Required
Yes
Type
string
Details
Unique among the organization's active evaluations. minLength: 1. maxLength: 256.
description
Required
No; body and guard rules apply
Type
string/null
Details
See the full input schema. maxLength: 4000.
enabled
Required
No; body and guard rules apply
Type
boolean
Details
Must be omitted or false on create; a new evaluation has no targets yet.
config
Required
No; body and guard rules apply
Type
EvaluationRubric
Details
See the full input schema.

##### EvaluationUpdateRequest

Current request definition.

name
Required
No; body and guard rules apply
Type
string
Details
See the full input schema. minLength: 1. maxLength: 256.
description
Required
No; body and guard rules apply
Type
string/null
Details
Null clears the description. maxLength: 4000.
enabled
Required
No; body and guard rules apply
Type
boolean
Details
See the full input schema.
config
Required
No; body and guard rules apply
Type
EvaluationRubric
Details
See the full input schema.

##### EvaluationTarget

Current request definition.

type
Required
Yes
Type
string
Details
What the target expands to. user covers a member's personal agents. Values: organization, team, user, agent.
id
Required
No; body and guard rules apply
Type
string
Details
Team, user, or agent ID. Omitted for organization; responses return the organization ID.

Complete client, OS and desktop setup

Codex

Codex is the current validation priority. Private token paths must exist in the process or remote environment where the server runs.

codex mcp add gumloop -- npx -y @thenavidm/gumloop-mcp-cli@latest
codex mcp list

Account credentials must reach the server through private environment settings. codex mcp add --env NAME=value stores values in your local config, so never commit that config or put secrets in a shared command. In TOML, the equivalent server is:

[mcp_servers.gumloop]
command = "npx"
args = ["-y", "@thenavidm/gumloop-mcp-cli@latest"]
env_vars = ["GUMLOOP_API_KEY", "GUMLOOP_TOKEN_FILE", "GUMLOOP_ACCOUNTS", "GUMLOOP_DEFAULT_ACCOUNT", "GUMLOOP_READ_ONLY", "GUMLOOP_ALLOW_DESTRUCTIVE", "GUMLOOP_USER_ID", "GUMLOOP_TEAM_ID"]

env_vars forwards those names from the environment available to Codex. If that environment does not contain them, configure private env settings locally. Codex can also call the CLI directly with SKILL.md and --agent output.

Claude Code

For a user-scoped connection, after privately configuring credentials:

claude mcp add --scope user gumloop -- npx -y @thenavidm/gumloop-mcp-cli@latest
claude mcp list

Use the client's private local environment settings for the account variable if they are not inherited. Claude's -e NAME=value registration option writes values into its config; only use it locally through your secret manager, with no shared command transcript. Never place credentials in a project .mcp.json. Reconnect and ask Claude to verify credentials.

Alternatively install the CLI, make SKILL.md available to Claude, and use shell commands. Registering both surfaces is optional.

Claude Desktop

Install the .mcpb extension

  1. Download gumloop-2.0.1.mcpb from GitHub Releases.
  2. In a supported Claude Desktop build, open Settings > Extensions > Advanced settings > Install Extension… and select it.
  3. Enter a private API key in the sensitive setting, or an absolute private token-file path. Leave the unused credential method empty. Requests use Authorization: Bearer, with the configured user ID in x-auth-key when supplied. Enter the intended user ID and optional team ID in the private extension settings.
  4. Enable read-only if you want only the 50 read operations. Reconnect and ask for account verification.

The bundle includes production dependencies and no credentials. Use a regular private token-only file if you prefer file-based credentials. The manifest requires Node 22 or newer from a compatible host. Organization policy may restrict custom extensions. Manual bundle updates require installing the new version; no automatic directory updates are promised. GUI installation remains unverified separately from archive/protocol checks.

Manual config

Open Settings > Developer > Edit Config, or use your platform's config file:

OSTypical config path
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json
Linux~/.config/Claude/claude_desktop_config.json; confirm the location through Edit Config in your installed build
{
"mcpServers": {
"gumloop": {
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "YOUR_PRIVATE_API_KEY",
"GUMLOOP_TOKEN_FILE": "",
"GUMLOOP_USER_ID": "YOUR_USER_ID",
"GUMLOOP_TEAM_ID": ""
}
}
}
}

Replace the placeholders only in your private file. Merge the server entry into an existing mcpServers object instead of replacing other integrations. Fully quit and reopen Claude Desktop. Do not enable an extension and a manual entry with the same name; choose one route.

If a Windows launcher cannot execute npx directly, use "command": "cmd" with "args": ["/c", "npx", "-y", "@thenavidm/gumloop-mcp-cli@latest"]. An absolute node executable and installed dist/index.js path also avoids launcher/PATH problems.

Cursor

Use private user settings at ~/.cursor/mcp.json, or Settings > Tools & MCP. Cursor documents environment interpolation and envFile support.

{
"mcpServers": {
"gumloop": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "${env:GUMLOOP_API_KEY}",
"GUMLOOP_TOKEN_FILE": "${env:GUMLOOP_TOKEN_FILE}",
"GUMLOOP_USER_ID": "${env:GUMLOOP_USER_ID}",
"GUMLOOP_TEAM_ID": "${env:GUMLOOP_TEAM_ID}"
}
}
}
}

The environment values must exist for the Cursor process. If you use envFile, keep that file private and outside version control. A project's .cursor/mcp.json must not contain actual credentials. Reconnect the server after saving.

VS Code and Copilot

Use MCP: Open User Configuration. VS Code uses servers and secure inputs, rather than a mcpServers root:

{
"inputs": [
{"type": "promptString", "id": "gumloop-api-key", "description": "Gumloop API key (leave empty for a private token file)", "password": true},
{"type": "promptString", "id": "gumloop-token-file", "description": "Optional private token-file path (leave empty for API key)"},
{"type": "promptString", "id": "gumloop-user-id", "description": "Gumloop user ID from your private profile"},
{"type": "promptString", "id": "gumloop-team-id", "description": "Optional Gumloop team ID (leave empty for personal access)"}
],
"servers": {
"gumloop": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "${input:gumloop-api-key}",
"GUMLOOP_TOKEN_FILE": "${input:gumloop-token-file}",
"GUMLOOP_USER_ID": "${input:gumloop-user-id}",
"GUMLOOP_TEAM_ID": "${input:gumloop-team-id}"
}
}
}
}

Start Gumloop through the MCP controls, approve trust if prompted, and enter credentials in the private input prompts. Workspace .vscode/mcp.json may contain this placeholder-only structure, but never resolved secret values. Remote development runs the server in the selected remote environment, so local file paths refer to that environment.

Windsurf

Open Cascade's MCP settings or edit the private user file ~/.codeium/windsurf/mcp_config.json. Use the Claude Desktop manual mcpServers block above with your locally configured env values. See Windsurf's current MCP documentation. Restart or reconnect Gumloop in Cascade; project files must not contain secrets.

Zed

Open Settings > AI > MCP Servers > Add Server > Add Local Server, or your user settings file. Zed uses context_servers:

{
"context_servers": {
"gumloop": {
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "YOUR_PRIVATE_API_KEY",
"GUMLOOP_TOKEN_FILE": "",
"GUMLOOP_USER_ID": "YOUR_USER_ID",
"GUMLOOP_TEAM_ID": ""
}
}
}
}

Enter actual values only in private user settings. Check the active-server indicator before prompting. Do not wrap command and args inside a nested command object from older Zed examples.

Gemini CLI

Merge the Claude Desktop manual mcpServers block into your private ~/.gemini/settings.json. Configure the private credential values locally, then restart Gemini CLI and inspect /mcp. See Gemini CLI's MCP configuration. Its project settings must not contain real credentials. You can instead use the CLI from an agent shell.

Other local stdio clients use the same command and arguments, adapted to their config format. A client that only accepts a remote MCP URL cannot connect directly: this package does not ship a public HTTP listener. ChatGPT's remote connector setup is not a substitute for local stdio installation.

Docker

Build locally from the reviewed source; no prebuilt registry image is claimed:

git clone https://github.com/thenavidm/gumloop-mcp-cli.git
cd gumloop-mcp-cli
docker build -t gumloop-mcp-cli .
docker run --rm -i -e GUMLOOP_API_KEY gumloop-mcp-cli

Cline and other local MCP clients

Use the client's Add MCP server flow with command npx, arguments -y and @thenavidm/gumloop-mcp-cli@latest, stdio transport, and private local GUMLOOP_API_KEY or GUMLOOP_TOKEN_FILE settings. UI names depend on the installed client. Reconnect and discover tools before an account call. Browser-only clients need a remote HTTPS connector; use Gumloop's official server rather than this local stdio command.

Output, flags and exit codes

Tool results go to stdout. Errors are JSON on stderr. JSON operations return structured results, so --select can retain nested fields. Private download operations return file metadata; binary bytes and signed results stay in the requested private file.

gumloop-cli start-flow --help
gumloop-cli schema start-flow
gumloop-cli list-agents --agent --select agents
FlagWhat it does
--jsonJSON output
--compactSingle-line JSON
--agentJSON, compact, no input and no color
--select a,b.cKeep selected fields; dotted paths descend and arrays are traversed
--confirmConfirm the requested flow, session, paid search or account operation
--no-input, --no-color, --yesAutomation switches; none overrides the spending guard

Global output flags apply to tool commands. doctor has its own --network option and returns a JSON diagnostic.

0
Meaning
Success
What a script should do
Read stdout
2
Meaning
Usage, invalid input or a refused write
What a script should do
Fix the input or confirm only the requested action
3
Meaning
Job or local upload file not found
What a script should do
Check the ID/path
4
Meaning
Authentication or entitlement rejected
What a script should do
Check private credential settings and permissions
5
Meaning
API or network failure
What a script should do
Inspect an accepted job before another paid submission
7
Meaning
Rate limited
What a script should do
Wait; do not loop over paid submissions
10
Meaning
Credentials not configured
What a script should do
Complete local setup

The underscore spelling also works. start_flow and start-flow call the same tool. Nested objects use quoted JSON. Arrays of objects use repeated flags, one JSON object at a time.

Official and community comparisons

Surface
PyPI gumloop 0.5.2, Python >=3.10
Capability and tradeoff
Agents/sessions, evaluations, chat, MCP, Brain, skills/artifacts, OAuth/keychain, browser/sync/plugin workflows; native Windows explicitly refused, WSL/SDK alternatives documented
Surface
https://mcp.gumloop.com/gumloop/mcp
Capability and tradeoff
Docs list 46 tools, including flows/workbooks/runs, agents/sessions, files/skills, audit and exports. This is documented coverage, not authenticated discovery
This owned package
Surface
Shared Node CLI/local MCP/.mcpb
Capability and tradeoff
Current reviewed 91 REST operations plus private account labels; enforced operation approval/read-only, isolated profiles, native Windows target and exclusive private downloads
Surface
Python gumloop and JavaScript gumloop
Capability and tradeoff
Application integration; the Python SDK works on Windows and already has credential/transport controls
Legacy owned MCP
Surface
Earlier private source
Capability and tradeoff
Flow/workbook/agent/file declarations without current shared CLI, release setup or enforced approval

Checked October 3, 2026. Current official CLI docs and the checksum-reviewed published 0.5.2 source refuse native Windows. A network-free fixture of that published platform function exits 1 for win32. Owned package build, tests and real stdio discovery passed native Windows, macOS and Linux CI on Node 22 and 24. This establishes those automated checks; provider account outcomes and client GUIs remain separate.

Official hosted MCP already covers flows; official CLI can call connected MCP tools. No blanket flow absence or absent client approval is claimed. Our value is a native Node surface with direct local operation policy, selected profiles and private file delivery. Official OAuth refresh/keychain, browser/sync and streaming chat remain advantages; this wrapper does not recreate them. More names and SEO alone are not a superiority claim.

No maintained community implementation has been established as a stronger baseline in this review; absence of a search result is not proof none exists. Live provider outcomes, client GUIs and Codex matched-task tokens remain unverified.

Versions and migration

ComponentBaseline
Package/desktop2.0.1
Current REST schemaOpenAPI 3.0.0/document 1.0.0; checked 2026-10-03
Operations/tools91 current REST + list_accounts; 92 shared tools
Read/confirmed50 reads, 42 confirmed operations
Official CLI inspectedPyPI gumloop 0.5.2
Official hosted MCP46 documented tools; live discovery unverified
Node22+; CI targets 22/24 on macOS/Linux/Windows
MCP SDK / Ajv / ajv-formats1.32.0 / 8.20.0 / 3.0.1
TypeScript / Vitest / Vite / MCPB / YAML7.0.2 / 5.0.3 / 8.3.2 / 2.1.2 / 2.9.1

The dated CHANGELOG records user-facing changes. Version, annotated default-branch tag, npm dist-tag and desktop archive must agree at release. Preserve AGPL and private legacy history.

Legacy GUMLOOP_API_KEY/USER_ID remain supported. start_flow now uses current named top-level inputs. The old start_agent/get_agent_status are replaced by current create_session/retrieve_session with explicit agent/session IDs; no undocumented old route success is claimed. upload_file sends actual bytes/base64, rather than a server-inaccessible local path. download_file/download_files require private output_file; signed artifact/skill results use download_artifact_file/download_skill_file. Writes and paid Brain search now need confirmation. Re-check scripts/client config during this breaking upgrade.

Updates and removal

npm and client updates

Configs using npx -y @thenavidm/gumloop-mcp-cli@latest resolve the current published version when they launch. Reconnect or restart the MCP client after an update.

npm install -g @thenavidm/gumloop-mcp-cli@latest
gumloop-cli --version

Global installs need that command to update. Desktop bundles are separate downloads: install the new .mcpb from the latest release through Extensions settings. Do not assume a manually installed custom bundle updates itself.

Every release is recorded in CHANGELOG.md. Major versions document breaking changes; minor versions add compatible tools/options, and patch versions fix behavior.

Migrating from the old MCP-only server

Keep the old tool names where supported, but change the package to @thenavidm/gumloop-mcp-cli@latest. Node 22 is required. Paid media calls now need confirmation. Downloads now require an explicit flag.

n maps to numVariations where supported. width and height must be supplied together. Fill uses the current async endpoint. Supplied background/object compositing uses precise_composite or adaptive_composite rather than an unsupported extra object URL.

Remove it

npm uninstall -g @thenavidm/gumloop-mcp-cli
claude mcp remove --scope user gumloop

In other clients, remove the Gumloop entry you added. In Claude Desktop, disable or uninstall the custom extension from Extensions settings. Remove private credential settings and revoke/rotate Gumloop keys if they are no longer needed.

Output images and audit logs are your files and are kept. Remove them yourself if desired.

Validation and remaining evidence

Thirty-five behavior/shared-CLI tests pass. Actual stdio discovery returns 92 tools; read-only returns 50 and direct confirmed-operation calls refuse. Seven CI jobs passed Linux, macOS and native Windows builds, tests and protocol discovery on Node 22 and 24, plus desktop packaging. Public npm installation and downloaded desktop discovery are checked separately from authenticated provider-account outcomes and desktop GUI installation.

Runtime dependency audit has zero findings. Development packaging advisories do not ship in runtime artifacts. Public source schemas remove examples and credential-bearing URLs; source history, npm and desktop artifacts are scanned for secrets.

Fresh Codex standing-context and equivalent successful task usage measurements remain pending. Claude Code is optional and its measurements are deferred. The private site scene deployment batch remains separately tracked.

More tools for your workflows

Connect the tools needed for the precise workflow you want.

Gumloop MCP Server & CLI FAQs

Official alternatives, API keys, user/team profiles, flows, sessions, private uploads/downloads, Windows, desktop setup and safeguards.

No.

Navid Media builds this owned wrapper.

Gumloop supplies separate official CLI, hosted MCP and SDKs.

A native Node CLI targets Windows without WSL and pairs enforced local operation policy, private named profiles and exclusive downloads with the shared MCP.

Official OAuth/keychain and other workflows remain useful.

Yes.

Current docs include flows, workbooks and runs.

The official CLI can call connected MCP tools.

No blanket flow-coverage gap is claimed.

Yes. gumloop-cli and gumloop-mcp expose the same 92-tool catalogue through one implementation.

The AGPL wrapper is free.

Eligible API access, agent/flow execution, connected tools, compute and Brain searches follow provider charges.

Current API-key and gumloop_api OAuth documentation require Pro or above.

Team/organization endpoints also need the appropriate provider role.

Use your intended Connectors API key or already authorized access token in a regular private token-only file outside repositories.

Configure the matching user/team identity privately.

Yes.

Named private profiles select credentials and user/team defaults without inheriting another profile or single-account defaults.

Explicit request identities still follow provider permissions.

Use the documented stdio registration or shared shell commands.

Codex is the priority; fresh matched-task usage measurements remain pending.

This package targets native Node 22+ on Windows.

Official gumloop 0.5.2 CLI refuses native Windows; WSL and its Python SDK are alternatives.

Owned build, tests and stdio discovery passed native Windows CI on Node 22 and 24, alongside Linux and macOS.

Provider account and desktop GUI outcomes remain separate.

A versioned .mcpb bundles runtime dependencies for a compatible host.

Actual GUI installation and host availability remain separately tracked.

No.

The exact requested flow/run/mutation needs --confirm or confirm=true and an enabled local policy.

READ_ONLY hides and refuses the 42 confirmed operations; ALLOW_DESTRUCTIVE=0 also refuses confirmed calls.

Read-only is not a provider spend cap.

No.

The provider can process a request before transport failure.

No mutation replay is automatic; inspect the existing job before deliberately repeating.

Inspect get_input_schema and current start_flow schema.

Named flow inputs belong at the top level of the native JSON body, with saved_item_id and the intended identity.

Yes, after confirmation. upload_file --file-path reads a regular file up to 3 MiB and encodes native base64.

Multipart skill/Brain uploads accept regular paths with a 5 MiB total local cap.

Only into a new requested absolute private output_file.

Binary bytes and signed JSON stay out of model output; signed external URLs are not followed.

No automatic OAuth refresh/keychain or streaming chat is provided.

Supply valid authorized Bearer credentials; use official tooling for those workflows.

No measured blanket claim is made.

Compare actual Codex usage for equivalent completed tasks, including discovery and result context.

Tool counts and character estimates are insufficient.

Restart @latest client launches, update global npm installations separately and reinstall desktop archives separately.

Uninstall does not revoke keys, delete provider resources or undo runs.

Navid Moazzez

AI business strategist & AI OS builder

Navid Moazzez helps creators and founders master AI and build their own AI Operating System (AI OS) to automate their business and life.

Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.

More MCP servers & CLIs

Related free tools

Free AI newsletter

The most actionable AI newsletter for founders

Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.

No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.

P.S. Sign up now to get free access to my ultimate AI tools guide for creators.

Loved by 10,000+ readers