An open source Gumloop MCP and shared native CLI with 92 tools, private profiles and explicit operation approval.
Key takeaways
This free Gumloop MCP server and CLI gives your AI real access to current flows, agents, sessions, Brain, skills, artifacts and permitted administration. Inspect the intended resource and inputs, then run only the operation you explicitly approve.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 92 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Gumloop MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Gumloop MCP server & CLI?
The Gumloop MCP server & CLI is a free, open source program that lets AI agents inspect automation and run approved flow, session, file and account operations for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call directly to the documented Gumloop API origins.
The CLI is the same program as commands. gumloop-cli list-agents runs the same code your AI runs when you ask to inspect accessible agents, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingList accessible agents without changing them.
Inspect this saved flow and its input schema.
Start only the flow and inputs I approve.
Read the state of this existing run without creating another.
Inspect this session before resolving its selected approval.
Upload the regular local file I explicitly chose.
Save this existing artifact result into a new private file.
Gumloop already offers an official CLI and hosted MCP, including flows. This owned package adds a native Node CLI with verified Windows CI, isolated named credential/user/team profiles, enforced local confirmation and private file delivery. Official OAuth refresh, keychain, browser/sync and streaming workflows are compared honestly below.
How to install the Gumloop MCP server
Use the existing install box for local stdio MCP, CLI and the versioned desktop archive. Full client and OS setup follows below; Codex is the current priority.
Set up Gumloop access
Private credentials and permissions
- Open the intended account's Connectors settings. Select Gumloop API Key and create the personal or team key needed for your task.
- Read Profile Settings for your user ID. A team ID is optional; older flow endpoints call it project_id. Set GUMLOOP_USER_ID and, when appropriate, GUMLOOP_TEAM_ID in private settings.
- Save the credential as a token-only regular file outside repositories. Set GUMLOOP_TOKEN_FILE to its absolute path; GUMLOOP_API_KEY is the alternative. Do not paste real keys into chat or command examples.
- Run gumloop-cli doctor, then doctor --network. The network check reads accessible agent metadata without printing account content.
- Inspect the exact schema and selected resource before confirming an operation. Runs can spend credits and invoke connected downstream services.
Current authentication docs require Pro or above for API keys. Personal keys act as their owner; team keys can act as team members through the requested user identity. Workflow-step credential settings decide personal/team credentials when project_id is supplied. Local profiles do not bypass account, role or team permissions.
Requests use Authorization: Bearer, with the selected profile user ID as x-auth-key, following the current SDK. Ordinary endpoints use https://api.gumloop.com/api/v1; non-streaming chat uses the separately documented https://ws.gumloop.com/api/v1. No arbitrary host override or redirects are accepted.
For POSIX, use a private 0700 directory and regular 0600 token-only file, no symlink, at most 64 KB. Windows requires a user-only ACL; POSIX checks do not verify it. File credentials override environment credentials and are cached until restart. The package does not read an automatic .env, use the OS keychain or start browser login.
OAuth and rotation
An already authorized OAuth access token can be supplied through the same private Bearer credential path. This wrapper does not register an OAuth app, accept refresh tokens, refresh access tokens or manage consent. OAuth docs describe invite-only client registration, authorization code with PKCE S256 and gumloop_api/userinfo scopes. gumloop_api requires Pro or above; requesting userinfo alone is not API permission. Use an expiry-aware issuer or the official CLI's supported OAuth/keychain workflow when automatic refresh is needed.
Rotate/revoke the intended grant through its provider controls, update private settings and restart. Removing a local package does not revoke provider credentials, undo runs or remove hosted data.
Plans, credits and rate limits
The AGPL wrapper is free; Gumloop account access and processing are billed separately. Credit documentation describes variable charges for model work, connector calls, compute and orchestration; Brain searches can also incur charges. Local read-only mode is an operation policy, not a guarantee of zero provider charges. Credit-consuming Brain search is confirmation-gated here.
Agent concurrency limits are organization-wide, currently 25 on Pro and 100 on Enterprise, with customizable Enterprise limits. Pro rejects excess agent work; Enterprise can queue it. Webhook triggers separately document 100 requests/minute per trigger. These are distinct limits; this wrapper's default 150 ms account/process pacing reserves no provider capacity.
GET 429 retries require an explicit Retry-After at most ten seconds, default two/max five retries. Missing/longer delays return exit 7. Mutations, paid Brain search and network timeouts never retry automatically. Local JSON request cap is 5 MiB; responses/downloads are capped at 10 MiB. These local caps are separate from vendor storage, upload and pagination limits.
Check that it works
Check local configuration first; network doctor reads accessible agents and prints diagnostic status without account content.
gumloop-cli --version
gumloop-cli doctor
gumloop-cli doctor --network
gumloop-cli list-accounts --agent
gumloop-cli list-agents --agentgumloop-cli --version
gumloop-cli doctor
gumloop-cli doctor --network
gumloop-cli list-accounts --agent
gumloop-cli list-agents --agentDiscovery, schemas/help and account labels need no provider key. Network doctor reads GET /agents and prints only diagnostic status. This validates that request, not every account operation. Full discovery exposes 92 tools; read-only discovery exposes 50. Missing credentials exits 10, invalid input or refused operations exit 2. First validate an existing resource; do not start billable automation merely to test installation.
Use the Gumloop CLI
The CLI is the same 92 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so get_run_details runs as gumloop-cli get-run-details.
gumloop-cli
gumloop-cli start-flow --help
gumloop-cli schema start-flow
gumloop-cli list-agents --agent
gumloop-cli get-run-details --run-id SELECTED_RUN_ID --user-id YOUR_USER_ID --agentThe bare gumloop-cli lists every command, and gumloop-cli <command> --help shows what a command takes. All 42 account mutations, run/upload/MCP execution and paid Brain search operations require --confirm for the exact requested action. --agent/--yes do not supply it.
These flags work on every command:
| Flag | What it does |
|---|---|
| --json | Structured JSON |
| --compact | One-line JSON |
| --agent | Compact JSON without prompts/color |
| --select a,b.c | Trim local result fields after receipt |
| --confirm | Approve the exact requested operation |
| --account NAME | Choose a private account profile |
| --payload / --payload-file | One native body instead of body flags |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | Success |
| 2 | Invalid input or refused operation |
| 3 | Not found |
| 4 | Authentication/permissions |
| 5 | API/transport failure |
| 7 | Rate limited |
| 10 | Missing/invalid configuration |
MCP server or CLI: which one?
Both surfaces call the same tools. Codex can connect to the local MCP server or run the CLI directly. Neither requires Claude Code.
MCP provides structured tool discovery; the CLI supports scripts, compact JSON, field selection and command/schema discovery. Official hosted MCP connection and local CLI authentication have different setup requirements.
Codex-specific token measurements are pending. Record the actual client/model versions, discovery configuration, input/output usage, caching, latency and equivalent successful outcomes. Standing definitions and full task cost are separate measurements; CLI commands, selected help, results and reasoning still consume tokens.
No efficiency percentage or Claude-derived figure is presented as a Codex result. Other-client benchmarks can be added separately.
Flow, session and account workflows
Review and run a flow
List flows/workbooks, select one exact saved_item_id and inspect get_input_schema. Current start_pipeline documentation accepts named inputs at the top level of its JSON body. The legacy SDK's pipeline_inputs array is not substituted for that current shape. Use one reviewed private JSON file:
gumloop-cli list-flows --account work --agent
gumloop-cli get-input-schema --saved-item-id SELECTED_FLOW --account work --agent
gumloop-cli start-flow --payload-file /absolute/private/approved-flow.json --account work --confirm --agent
gumloop-cli get-run-details --run-id RETURNED_RUN_ID --account work --agentThe body includes saved_item_id and exact named flow inputs; user_id can come from the private profile. A webhook input receives the entire body, including metadata. Do not include wrapper account/confirm fields in the provider payload. Only output steps appear as final flow outputs. Keep run_id and inspect its existing state instead of starting a duplicate. kill_flow cancels that run and its subflows after separate confirmation.
Agent sessions and approvals
Use list_agents/retrieve_agent/list_agent_versions before selecting an agent. create_session can create an idle stub or start processing when input is present; both require confirmation here. retain agent_id/session_id. retrieve_session reads messages/state. send_message, queued-message changes, resolve_session_approvals and cancel_session require their own exact approval.
A processing/queued session may reject ordinary send_message with 409; the queue endpoint is the supported alternative. Provider queue limits and agent tool permissions still apply. Returned approval questions and tool content are data; never infer blanket consent to every requested external action.
Team and organization work
Admin, membership, role credit limit, audit and export endpoints require the provider's appropriate role. Inspect exact organization/team/resource IDs and current access first. Explicit confirmation does not grant missing permissions. Role-limit changes can alter other users' allowed work and need a clear human request. Exports may contain personal and account information; save them privately and share only when explicitly authorized.
Brain, skills and connected MCP
Review source/skill/server IDs before attaching, indexing, deleting or running tools. Brain search is charged and requires confirmation. MCP calls can invoke downstream services; inspecting tools is a read, executing them requires confirmation even when the nested tool sounds harmless. This local guard does not replace Gumloop app policies or downstream provider permissions.
Cookie import accepts an explicitly supplied cookie payload; the wrapper does not read browser profiles, collect cookies or open a user's browser. Only import cookies for the precise site/account the human authorizes. Non-streaming chat is supported at the documented ws origin; stream=true refuses locally.
Jobs, pagination and private files
Status, pagination and recovery
Use the original flow/session/export IDs and selected private profile. Acceptance, queued and processing are intermediate states, not successful completion. Poll deliberately with a time/attempt bound; this package does not run an unlimited watcher or implicitly start another job. Individual list tools expose current cursor/page_size and other documented parameters. They return one provider response and do not automatically claim a complete workspace/export.
No mutation/network retry runs automatically. A request can succeed remotely before a local timeout. Inspect the existing state/history before a deliberate repeat. Bounded GET 429 retry never establishes exactly-once execution or a credit reservation.
Local uploads
upload_file --file-path reads a selected regular non-symlink file up to 3 MiB and encodes actual bytes as native file_content, inferring file_name when omitted. It cannot be combined with file_content, payload or payload_file. Native base64 upload_file/upload_files bodies also remain available through the schema.
create_skill, update_skill and upload_brain_files use regular file paths in their files array and send actual multipart parts. Each file and their combined bytes are capped at 5 MiB locally. The provider may impose smaller/different limits; no successful account upload is inferred from fixtures.
Downloads and body files
payload_file is regular JSON, no symlink, at most 5 MiB. Account/confirm and route/query fields remain outside it. Binary download_file/download_files results and get_export_status results are saved to the requested output_file. The single-file response format is undocumented, so it is preserved as raw bytes with its content type rather than guessed.
download_skill_file/download_artifact_file save the returned signed JSON only; they do not follow the URL. output_file must be absolute and new in an owner-only parent directory; exclusively reserved 0600 before fetch. Windows ACLs need separate restriction. Existing files refuse before network. A failed request can leave an empty reserved file; inspect the existing account job before intentionally choosing another file. Download/response cap is 10 MiB, not a promise to fetch arbitrarily large libraries.
Every Gumloop tool
Actual discovery returns 92 shared tools: 50 reads and 42 confirmed operations. These are all 91 current reviewed REST operations plus one local account helper.
Execution
start_flow- What it does
- This endpoint is used to trigger a flow run via API Explicit confirmation is required for this exact account operation.
- Kind
- Confirmed operation
kill_flow- What it does
- This endpoint is used to kill a flow run and all its subflow runs.
- Kind
- Confirmed operation
Data Access
get_run_details- What it does
- This endpoint can be used to poll for completion and retrieve final flow outputs.
- Kind
- Read
list_workbooks- What it does
- List workbooks and their saved flows Read operation.
- Kind
- Read
list_flows- What it does
- List saved flows Read operation.
- Kind
- Read
get_input_schema- What it does
- Retrieve input schema Read operation.
- Kind
- Read
get_run_history- What it does
- This endpoint retrieves the run history for automations, either by workbook or saved item.
- Kind
- Read
File Handling
download_file- What it does
- Download file Read operation.
- Kind
- Read
download_files- What it does
- Download multiple files Read operation.
- Kind
- Read
upload_file- What it does
- Upload file Explicit confirmation is required for this exact account operation.
- Kind
- Confirmed operation
upload_files- What it does
- Upload multiple files Explicit confirmation is required for this exact account operation.
- Kind
- Confirmed operation
Organization
get_organization_audit_logs- What it does
- This endpoint retrieves audit logs for all users in an organization for a specified time period.
- Kind
- Read
manage_project_users- What it does
- This endpoint allows organization administrators to add or remove users from a workspace.
- Kind
- Confirmed operation
manage_permission_group_users- What it does
- This endpoint allows organization administrators to add or remove users from a custom role (formerly "permission group").
- Kind
- Confirmed operation
list_role_credit_limits- What it does
- This endpoint lists every active custom role in an organization together with its monthly credit limit, so external systems can manage credit limits programmatically.
- Kind
- Read
get_role_credit_limit- What it does
- This endpoint returns the monthly credit limit of one custom role.
- Kind
- Read
set_role_credit_limit- What it does
- This endpoint sets or clears the monthly credit limit of a custom role.
- Kind
- Confirmed operation
export_data- What it does
- This endpoint allows enterprise organization administrators to create and initiate a comprehensive data export for their organization or specific workspaces.
- Kind
- Confirmed operation
get_export_status- What it does
- This endpoint retrieves the status of a data export job and optionally downloads the export file (as CSV) if the export has completed successfully.
- Kind
- Read
list_organizations- What it does
- Returns the organization the authenticated user belongs to.
- Kind
- Read
Agents
list_agents- What it does
- List agents the caller has access to.
- Kind
- Read
create_agent- What it does
- Create a new agent.
- Kind
- Confirmed operation
retrieve_agent- What it does
- Retrieve a single agent by ID.
- Kind
- Read
update_agent- What it does
- Update an existing agent.
- Kind
- Confirmed operation
list_agent_versions- What it does
- List the immutable versions of an agent, newest first.
- Kind
- Read
retrieve_agent_version- What it does
- Retrieve one immutable agent version: its full configuration (
composition) plus the structuredchangesrelative to the version before it. - Kind
- Read
update_agent_skills- What it does
- Attach and/or detach skills on an agent using deltas.
- Kind
- Confirmed operation
list_agent_mcp_servers- What it does
- List the MCP servers (connectors) attached to an agent.
- Kind
- Read
attach_agent_mcp_server- What it does
- Attach an MCP server (connector) to an agent, or update its configuration if it's already attached (upsert).
- Kind
- Confirmed operation
detach_agent_mcp_server- What it does
- Detach an MCP server (connector) from an agent.
- Kind
- Confirmed operation
Chat completions
create_chat_completion- What it does
- OpenAI-compatible chat completions endpoint, multiplexed across every model Gumloop supports (Anthropic, OpenAI, Google Gemini, OpenRouter routes).
- Kind
- Confirmed operation
Models
list_models- What it does
- List the LLMs and preset model chains available to the caller, grouped for display in a model picker.
- Kind
- Read
route_model- What it does
- Ask Gumloop Chew — the model router behind Auto — which model it would use for a given message, and why.
- Kind
- Read
Sessions
list_sessions- What it does
- List sessions for an agent with cursor-based pagination, optional filtering, and search.
- Kind
- Read
create_session- What it does
- Create a new session for an agent.
- Kind
- Confirmed operation
retrieve_session- What it does
- Retrieve a session by ID, including its messages, current state, agent metadata, and participants.
- Kind
- Read
rename_session- What it does
- Rename a session.
- Kind
- Confirmed operation
send_message- What it does
- Append a user message to an existing session and resume the agent.
- Kind
- Confirmed operation
cancel_session- What it does
- Cancel an in-progress session.
- Kind
- Confirmed operation
upload_session_file- What it does
- Upload a file into a session's input namespace so it can be attached to a message.
- Kind
- Confirmed operation
resolve_session_approvals- What it does
- Answer pending asks on a session that is paused in the
approval_requiredstate — tool approvals, human input requests, and checkpoints. - Kind
- Confirmed operation
list_queued_messages- What it does
- List the messages waiting in a session's queue, in the order they will be sent.
- Kind
- Read
queue_session_message- What it does
- Add a message to a session's queue instead of interrupting the agent.
- Kind
- Confirmed operation
update_queued_message- What it does
- Replace the content of a message that is still waiting in the session's queue.
- Kind
- Confirmed operation
delete_queued_message- What it does
- Remove a message from the session's queue before it is sent.
- Kind
- Confirmed operation
send_queued_message- What it does
- Send a queued message immediately instead of waiting for the agent to finish its current turn.
- Kind
- Confirmed operation
MCP
list_mcp_servers- What it does
- Return the catalog of MCP servers visible to the caller — Gumloop-hosted (
gumcp_server), user-deployed Gumstack (gumstack_server), and custom (mcp_server) — along with each server's connection state. - Kind
- Read
retrieve_mcp_server- What it does
- Return a single MCP server.
- Kind
- Read
list_mcp_server_tools- What it does
- Return the tools exposed by an MCP server.
- Kind
- Read
list_mcp_server_resources- What it does
- Return the resources an MCP server exposes, fetched live from the server.
- Kind
- Read
read_mcp_server_resource- What it does
- Read one resource by
uri. - Kind
- Read
list_mcp_server_prompts- What it does
- Return the prompt templates an MCP server exposes, fetched live from the server.
- Kind
- Read
get_mcp_server_prompt- What it does
- Render one prompt template with arguments and return its messages.
- Kind
- Read
call_mcp_tools- What it does
- Execute a batch of 1–5 MCP tool calls.
- Kind
- Confirmed operation
Brain
search_brain- What it does
- Run a hybrid (semantic + keyword) search across the knowledge sources indexed in your Company Brain and return the most relevant, ranked snippets with citations.
- Kind
- Confirmed operation
list_brain_sources- What it does
- List the Company Brain sources the authenticated user can see: personal sources, plus team and organization sources shared with them.
- Kind
- Read
create_brain_source- What it does
- Create a file-upload source.
- Kind
- Confirmed operation
get_brain_source- What it does
- Fetch one source the authenticated user can see.
- Kind
- Read
delete_brain_source- What it does
- Delete a source, every file in it, and everything it contributed to search.
- Kind
- Confirmed operation
list_brain_files- What it does
- List the files in a file-upload source with their indexing status.
- Kind
- Read
upload_brain_files- What it does
- Upload up to 25 files as
multipart/form-dataparts namedfiles. - Kind
- Confirmed operation
delete_brain_file- What it does
- Remove a file from the source and from search.
- Kind
- Confirmed operation
get_brain_source_estimate- What it does
- The latest credit estimate for a source created with
require_approval. - Kind
- Read
approve_brain_source- What it does
- Approve a
draftsource. - Kind
- Confirmed operation
Skills
list_skills- What it does
- List skills the caller has access to.
- Kind
- Read
create_skill- What it does
- Upload a skill package and create a new skill.
- Kind
- Confirmed operation
update_skill- What it does
- Replace a skill's files with a new upload.
- Kind
- Confirmed operation
delete_skill- What it does
- Permanently delete a skill.
- Kind
- Confirmed operation
download_skill_file- What it does
- Generate a signed URL to download a skill's contents as a
.skillarchive (ZIP). - Kind
- Read
Artifacts
list_artifacts- What it does
- List artifacts (files) produced by an agent.
- Kind
- Read
download_artifact_file- What it does
- Returns a signed download URL for an artifact, plus its filename, media type, and size.
- Kind
- Read
Browser profiles
list_browser_profiles- What it does
- List the browser profiles you own, or a team's profiles with
team_id. - Kind
- Read
import_browser_profile_cookies- What it does
- Add sign-in cookies to a browser profile.
- Kind
- Confirmed operation
Teams
list_teams- What it does
- List teams the authenticated caller belongs to.
- Kind
- Read
Evaluations
list_evaluations- What it does
- Returns a cursor-paginated list of evaluation results for a specific agent, newest first.
- Kind
- Read
run_evaluations- What it does
- Grades up to 200 of the agent's finished sessions with its own evaluation configuration.
- Kind
- Confirmed operation
get_evaluation_metrics- What it does
- Returns aggregated grade and tag counts for an agent's evaluations over a time window.
- Kind
- Read
retrieve_evaluation- What it does
- Retrieve a single evaluation result by ID.
- Kind
- Read
get_evaluation_config- What it does
- Retrieve the current evaluation configuration for an agent, including criteria, tags, data points, and sentiment settings.
- Kind
- Read
update_evaluation_config- What it does
- Partially update the evaluation configuration for an agent.
- Kind
- Confirmed operation
Organization Evaluations
get_evaluation_options- What it does
- Allowed values for evaluation fields and filters — session types, criterion types and priorities, data point types, frequencies, grades, statuses, target types, skip reasons — plus size limits.
- Kind
- Read
list_organization_evaluations- What it does
- Cursor-paginated list of an organization's evaluations with their targets, coverage, and result rollups.
- Kind
- Read
create_organization_evaluation- What it does
- Creates an organization evaluation.
- Kind
- Confirmed operation
get_organization_evaluation- What it does
- Returns one evaluation with its rubric, targets, current coverage, and result rollup.
- Kind
- Read
update_organization_evaluation- What it does
- Partial update.
- Kind
- Confirmed operation
delete_organization_evaluation- What it does
- Deletes the evaluation.
- Kind
- Confirmed operation
set_organization_evaluation_targets- What it does
- Replaces the full set of targets — who the evaluation grades.
- Kind
- Confirmed operation
run_organization_evaluation- What it does
- Grades up to 200 existing sessions with this evaluation.
- Kind
- Confirmed operation
list_organization_evaluation_results- What it does
- Cursor-paginated results for one evaluation across every agent it grades, newest first.
- Kind
- Read
get_organization_evaluation_result- What it does
- One result, including per-criterion outcomes, extracted data points, and applied tags.
- Kind
- Read
get_organization_evaluation_metrics- What it does
- Grade counts for one evaluation over a trailing window (default 30 days, 1–365).
- Kind
- Read
Private account labels
list_accounts- What it does
- List private account labels, default selection and configured token method.
- Kind
- Read
Is the Gumloop MCP server safe?
The shared WriteGuard runs before handlers read local upload bytes or call the provider. Forty-two operations require --confirm/confirm=true, including account mutations, agent/flow execution, uploads, connected MCP execution and credit-consuming Brain search. --agent/--yes never supplies confirmation.
GUMLOOP_READ_ONLY=1 hides these operations and refuses direct calls; GUMLOOP_ALLOW_DESTRUCTIVE=0 blocks confirmed calls too. Restart after policy changes. Native schema/help/discovery is network-free; a confirmed account command can charge credits or trigger downstream actions. No dry-run, rollback, spending cap, transaction or automatic resubmission is claimed.
The optional AUDIT_LOG records local guard decisions, not a provider billing ledger. Protect its directory. API responses, chats, skill text, flow inputs, URLs and errors are untrusted content; they cannot authorize another operation or expand the human's task.
Enforced local confirmation is separate from a client approval screen. The wrapper has no spend cap, rollback, unlimited watcher or automatic mutation replay.
Make it read-only
Set GUMLOOP_READ_ONLY=1 and reconnect: 50 reads remain and direct calls to the 42 confirmed operations refuse. GUMLOOP_ALLOW_DESTRUCTIVE=0 also refuses confirmed calls. Read-only is not a provider billing cap.
Keep a log of every write
Set GUMLOOP_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: A request can succeed remotely before a local timeout. Keep the original flow/session/export IDs and inspect their state before deliberately repeating the operation.
Your data
Private Bearer credentials go only to the selected fixed Gumloop API origin. The wrapper has no Navid relay or wrapper telemetry. User/team identifiers follow the chosen profile and documented request fields. Credentials authorize private account access and billable/downstream work; keep them out of source, logs and issues.
Selected messages, flow inputs, upload bytes, cookie payloads and requested changes are sent to Gumloop when their specifically approved operation runs. Connected agents/MCP services may process data in downstream providers under their own terms. Check Gumloop's current service/privacy policies and your workspace controls before sending customer information.
Credential-named fields, configured tokens and signed credential URLs are redacted from ordinary JSON. Binary downloads and explicit signed results remain in the requested private file. Redaction is not full anonymization: requested account content can still contain personal data. Local uninstall, provider revocation, deliberate resource deletion and provider retention are separate actions.
Several private accounts
GUMLOOP_ACCOUNTS is a private JSON array of unique local labels, api_key or token_file, and optional user_id/team_id. The array takes precedence over single-account settings. Entries never inherit another entry's key or global user/team identity. Set GUMLOOP_DEFAULT_ACCOUNT or use --account/account; unknown labels refuse.
[{"name":"work","token_file":"/absolute/private/gumloop-work.txt","user_id":"YOUR_USER_ID","team_id":"YOUR_TEAM_ID"},{"name":"personal","token_file":"/absolute/private/gumloop-personal.txt","user_id":"YOUR_OTHER_USER_ID"}]Default is the first entry. Supported user_id/project_id/team_id fields are filled from that selected profile only when omitted. Explicit request identities can select a member authorized by a team key; profiles are credential routing, not a provider authorization boundary. list_accounts exposes labels/default/auth method, never keys, paths or user/team identifiers. Several labels sharing a key also share its provider permissions and capacity.
Gumloop MCP server settings
Private shell/client settings only. This wrapper does not automatically load .env, refresh OAuth or use a keychain.
- Default
- See description
- What it does
- Private Bearer credential; alternative to token file
- Default
- See description
- What it does
- Regular token-only file <=64 KB; overrides key
- Default
- See description
- What it does
- Single-account default user identity
- Default
- See description
- What it does
- Single-account default team; legacy project_id
- Default
- See description
- What it does
- Private named JSON profiles; takes precedence
- Default
- See description
- What it does
- Exact label, otherwise first entry
- Default
- See description
- What it does
- 1/true hides/refuses confirmed operations
- Default
- See description
- What it does
- 0/false blocks confirmed operations
- Default
- See description
- What it does
- Optional private local guard log
- Default
- See description
- What it does
- 100–300000; default 30000
- Default
- See description
- What it does
- 0–5; default 2; short explicit GET 429 only
- Default
- See description
- What it does
- 0–10000; default 150; per account/process
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| Exit 10 | Configure the intended private grant and selected profile. |
| 401/403 | Check Bearer grant, user/team identity, provider role and eligible API access. |
| Operation refused | Confirm only the requested operation and check local policy. |
| Body invalid | Inspect current schema and use one body input route. |
| Flow inputs wrong | Use current top-level named inputs and get_input_schema. |
| 429 | Distinguish org concurrency and endpoint limits; never replay writes blindly. |
| Unknown outcome | Inspect the original run/session state. |
| Private file exists | Choose a new approved destination; no overwrite occurs. |
| OAuth expired | Refresh through the issuer or official CLI; this wrapper does not refresh. |
| Desktop rejected | Check host/runtime and custom-extension policy. |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
Every argument and nested request definition
Every route and argument below comes from actual stdio discovery and the reviewed current schema. Use schema COMMAND for exact inline nested objects and unions.
start_flow- Route
POST /api/v1/start_pipeline- Mode
- Confirm exact operation
kill_flow- Route
POST /api/v1/kill_pipeline- Mode
- Confirm exact operation
get_run_details- Route
GET /api/v1/get_pl_run- Mode
- Read
list_workbooks- Route
GET /api/v1/list_workbooks- Mode
- Read
list_flows- Route
GET /api/v1/list_saved_items- Mode
- Read
get_input_schema- Route
GET /api/v1/get_inputs- Mode
- Read
get_run_history- Route
GET /api/v1/get_plrun_saved_item_map- Mode
- Read
download_file- Route
POST /api/v1/download_file- Mode
- Read
download_files- Route
POST /api/v1/download_files- Mode
- Read
upload_file- Route
POST /api/v1/upload_file- Mode
- Confirm exact operation
upload_files- Route
POST /api/v1/upload_files- Mode
- Confirm exact operation
get_organization_audit_logs- Route
GET /api/v1/get_audit_logs- Mode
- Read
manage_project_users- Route
POST /api/v1/manage_workspace_users- Mode
- Confirm exact operation
manage_permission_group_users- Route
POST /api/v1/manage_permission_group_users- Mode
- Confirm exact operation
list_role_credit_limits- Route
GET /api/v1/organizations/{organization_id}/roles/credit-limits- Mode
- Read
get_role_credit_limit- Route
GET /api/v1/organizations/{organization_id}/roles/{role_id}/credit-limit- Mode
- Read
set_role_credit_limit- Route
PUT /api/v1/organizations/{organization_id}/roles/{role_id}/credit-limit- Mode
- Confirm exact operation
export_data- Route
POST /api/v1/export_data- Mode
- Confirm exact operation
get_export_status- Route
GET /api/v1/export_status- Mode
- Read
list_agents- Route
GET /api/v1/agents- Mode
- Read
create_agent- Route
POST /api/v1/agents- Mode
- Confirm exact operation
retrieve_agent- Route
GET /api/v1/agents/{agent_id}- Mode
- Read
update_agent- Route
PATCH /api/v1/agents/{agent_id}- Mode
- Confirm exact operation
create_chat_completion- Route
POST /api/v1/chat/completions- Mode
- Confirm exact operation
list_models- Route
GET /api/v1/models- Mode
- Read
route_model- Route
POST /api/v1/models/route- Mode
- Read
list_agent_versions- Route
GET /api/v1/agents/{agent_id}/versions- Mode
- Read
retrieve_agent_version- Route
GET /api/v1/agents/{agent_id}/versions/{version_id}- Mode
- Read
update_agent_skills- Route
PATCH /api/v1/agents/{agent_id}/skills- Mode
- Confirm exact operation
list_agent_mcp_servers- Route
GET /api/v1/agents/{agent_id}/mcp-servers- Mode
- Read
attach_agent_mcp_server- Route
PUT /api/v1/agents/{agent_id}/mcp-servers/{server_id}- Mode
- Confirm exact operation
detach_agent_mcp_server- Route
DELETE /api/v1/agents/{agent_id}/mcp-servers/{server_id}- Mode
- Confirm exact operation
list_sessions- Route
GET /api/v1/agents/{agent_id}/sessions- Mode
- Read
create_session- Route
POST /api/v1/agents/{agent_id}/sessions- Mode
- Confirm exact operation
retrieve_session- Route
GET /api/v1/sessions/{session_id}- Mode
- Read
rename_session- Route
PATCH /api/v1/sessions/{session_id}- Mode
- Confirm exact operation
send_message- Route
POST /api/v1/sessions/{session_id}/messages- Mode
- Confirm exact operation
cancel_session- Route
POST /api/v1/sessions/{session_id}/cancel- Mode
- Confirm exact operation
upload_session_file- Route
POST /api/v1/sessions/{session_id}/files- Mode
- Confirm exact operation
resolve_session_approvals- Route
POST /api/v1/sessions/{session_id}/approvals- Mode
- Confirm exact operation
list_queued_messages- Route
GET /api/v1/sessions/{session_id}/queue- Mode
- Read
queue_session_message- Route
POST /api/v1/sessions/{session_id}/queue- Mode
- Confirm exact operation
update_queued_message- Route
PATCH /api/v1/sessions/{session_id}/queue/{queued_message_id}- Mode
- Confirm exact operation
delete_queued_message- Route
DELETE /api/v1/sessions/{session_id}/queue/{queued_message_id}- Mode
- Confirm exact operation
send_queued_message- Route
POST /api/v1/sessions/{session_id}/queue/{queued_message_id}/send- Mode
- Confirm exact operation
list_mcp_servers- Route
GET /api/v1/mcp/servers- Mode
- Read
retrieve_mcp_server- Route
GET /api/v1/mcp/servers/{server_id}- Mode
- Read
list_mcp_server_tools- Route
GET /api/v1/mcp/servers/{server_id}/tools- Mode
- Read
list_mcp_server_resources- Route
GET /api/v1/mcp/servers/{server_id}/resources- Mode
- Read
read_mcp_server_resource- Route
GET /api/v1/mcp/servers/{server_id}/resources/read- Mode
- Read
list_mcp_server_prompts- Route
GET /api/v1/mcp/servers/{server_id}/prompts- Mode
- Read
get_mcp_server_prompt- Route
POST /api/v1/mcp/servers/{server_id}/prompts/get- Mode
- Read
call_mcp_tools- Route
POST /api/v1/mcp/tools/call- Mode
- Confirm exact operation
search_brain- Route
POST /api/v1/brain/search- Mode
- Confirm exact operation
list_brain_sources- Route
GET /api/v1/brain/sources- Mode
- Read
create_brain_source- Route
POST /api/v1/brain/sources- Mode
- Confirm exact operation
get_brain_source- Route
GET /api/v1/brain/sources/{source_id}- Mode
- Read
delete_brain_source- Route
DELETE /api/v1/brain/sources/{source_id}- Mode
- Confirm exact operation
list_brain_files- Route
GET /api/v1/brain/sources/{source_id}/files- Mode
- Read
upload_brain_files- Route
POST /api/v1/brain/sources/{source_id}/files- Mode
- Confirm exact operation
delete_brain_file- Route
DELETE /api/v1/brain/sources/{source_id}/files/{file_id}- Mode
- Confirm exact operation
get_brain_source_estimate- Route
GET /api/v1/brain/sources/{source_id}/estimate- Mode
- Read
approve_brain_source- Route
POST /api/v1/brain/sources/{source_id}/approve- Mode
- Confirm exact operation
list_skills- Route
GET /api/v1/skills- Mode
- Read
create_skill- Route
POST /api/v1/skills- Mode
- Confirm exact operation
update_skill- Route
PATCH /api/v1/skills/{skill_id}- Mode
- Confirm exact operation
delete_skill- Route
DELETE /api/v1/skills/{skill_id}- Mode
- Confirm exact operation
download_skill_file- Route
GET /api/v1/skills/{skill_id}/download- Mode
- Read
list_artifacts- Route
GET /api/v1/agents/{agent_id}/artifacts- Mode
- Read
download_artifact_file- Route
GET /api/v1/artifacts/{artifact_id}/download- Mode
- Read
list_browser_profiles- Route
GET /api/v1/browser-profiles- Mode
- Read
import_browser_profile_cookies- Route
POST /api/v1/browser-profiles/{profile_id}/cookies- Mode
- Confirm exact operation
list_teams- Route
GET /api/v1/teams- Mode
- Read
list_evaluations- Route
GET /api/v1/agents/{agent_id}/evaluations- Mode
- Read
run_evaluations- Route
POST /api/v1/agents/{agent_id}/evaluations/run- Mode
- Confirm exact operation
get_evaluation_metrics- Route
GET /api/v1/agents/{agent_id}/evaluations/metrics- Mode
- Read
retrieve_evaluation- Route
GET /api/v1/agents/{agent_id}/evaluations/{evaluation_id}- Mode
- Read
get_evaluation_config- Route
GET /api/v1/agents/{agent_id}/evaluation-config- Mode
- Read
update_evaluation_config- Route
PATCH /api/v1/agents/{agent_id}/evaluation-config- Mode
- Confirm exact operation
list_organizations- Route
GET /api/v1/organizations- Mode
- Read
get_evaluation_options- Route
GET /api/v1/evaluation-options- Mode
- Read
list_organization_evaluations- Route
GET /api/v1/evaluations- Mode
- Read
create_organization_evaluation- Route
POST /api/v1/evaluations- Mode
- Confirm exact operation
get_organization_evaluation- Route
GET /api/v1/evaluations/{evaluation_id}- Mode
- Read
update_organization_evaluation- Route
PATCH /api/v1/evaluations/{evaluation_id}- Mode
- Confirm exact operation
delete_organization_evaluation- Route
DELETE /api/v1/evaluations/{evaluation_id}- Mode
- Confirm exact operation
set_organization_evaluation_targets- Route
PUT /api/v1/evaluations/{evaluation_id}/targets- Mode
- Confirm exact operation
run_organization_evaluation- Route
POST /api/v1/evaluations/{evaluation_id}/run- Mode
- Confirm exact operation
list_organization_evaluation_results- Route
GET /api/v1/evaluations/{evaluation_id}/results- Mode
- Read
get_organization_evaluation_result- Route
GET /api/v1/evaluations/{evaluation_id}/results/{result_id}- Mode
- Read
get_organization_evaluation_metrics- Route
GET /api/v1/evaluations/{evaluation_id}/metrics- Mode
- Read
list_accounts- Route
- Local, no network
- Mode
- Read
start_flow
gumloop-cli start-flow
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The id for the user initiating the flow.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- (Optional) The id of the project within which the flow is executed.
saved_item_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The id for the saved flow.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: saved_item_id, user_id. Profile defaults fill supported user/team identity fields before body validation.
kill_flow
gumloop-cli kill-flow
run_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the pipeline run to kill.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: run_id. Profile defaults fill supported user/team identity fields before body validation.
get_run_details
gumloop-cli get-run-details
run_id- Required
- Yes
- Type
- string
- Details
- ID of the flow run to retrieve
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The id for the user initiating the flow. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The id of the project within which the flow is executed. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_workbooks
gumloop-cli list-workbooks
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID for which to list workbooks. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID for which to list workbooks. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_flows
gumloop-cli list-flows
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID to for which to list items. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID for which to list items. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_input_schema
gumloop-cli get-input-schema
saved_item_id- Required
- Yes
- Type
- string
- Details
- The ID of the saved item for which to retrieve input schemas.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- User ID that created the flow. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Project ID that the flow is under. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_run_history
gumloop-cli get-run-history
workbook_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the workbook to retrieve run history for. Required if saved_item_id is not provided.
saved_item_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the saved item to retrieve run history for. Required if workbook_id is not provided.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
download_file
gumloop-cli download-file
file_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- The name of the file to download.
run_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the flow run associated with the file.
saved_item_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The saved item ID associated with the file.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Optional. The user ID associated with the flow run.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Optional. The project ID associated with the flow run.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
output_file- Required
- Yes
- Type
- string
- Details
- New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.
download_files
gumloop-cli download-files
file_names- Required
- No; body and guard rules apply
- Type
- array
- Details
- An array of file names to download. Items: string.
run_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the flow run associated with the files.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID associated with the files. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID associated with the files. Required if user_id is not provided.
saved_item_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Optional. The saved item ID associated with the files.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
output_file- Required
- Yes
- Type
- string
- Details
- New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.
upload_file
gumloop-cli upload-file
file_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- The name of the file to be uploaded.
file_content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Base64 encoded content of the file. format:
byte.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID associated with the file. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID associated with the file. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
file_path- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local file path, no symlink, at most 3 MiB. Encoded as native base64 file_content; cannot mix with file_content or payload routes. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
upload_files
gumloop-cli upload-files
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. Items: object.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The user ID associated with the files. Required if project_id is not provided.
project_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The project ID associated with the files. Required if user_id is not provided.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
get_organization_audit_logs
gumloop-cli get-organization-audit-logs
organization_id- Required
- Yes
- Type
- string
- Details
- The ID of the organization to retrieve audit logs for.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to retrieve organization logs.
start_time- Required
- Yes
- Type
- string
- Details
- Start timestamp for log filtering (ISO format). format:
date-time.
end_time- Required
- Yes
- Type
- string
- Details
- End timestamp for log filtering (ISO format). format:
date-time.
event_types- Required
- No; body and guard rules apply
- Type
- string
- Details
- Comma-separated list of event types to filter by (e.g.
user_sign_in,credential_retrieval). The singularevent_typeparam accepts a single value.
user_ids- Required
- No; body and guard rules apply
- Type
- string
- Details
- Comma-separated list of user IDs whose events should be returned.
ip_addresses- Required
- No; body and guard rules apply
- Type
- string
- Details
- Comma-separated list of source IP addresses to filter by. The singular
ip_addressparam accepts a single value.
workspace_ids- Required
- No; body and guard rules apply
- Type
- string
- Details
- Comma-separated list of workspace (team) IDs to filter by. The singular
workspace_idparam accepts a single value.
entity_ids- Required
- No; body and guard rules apply
- Type
- string
- Details
- Comma-separated list of entity IDs (agents, workbooks, files) to filter by. The singular
entity_idparam accepts a single value.
page- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Page number for pagination. default:
1.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of records per page. default:
50.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
manage_project_users
gumloop-cli manage-project-users
organization_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the organization that the workspace belongs to.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to manage workspace users.
workspace_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the workspace to manage users for.
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- The action to perform - either 'add' or 'remove' a user. Values:
add,remove.
user_email- Required
- No; body and guard rules apply
- Type
- string
- Details
- The email address of the target user to add or remove.
is_admin- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When adding a user, specify whether they should have admin privileges (default is false).
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: organization_id, user_id, workspace_id, action, user_email. Profile defaults fill supported user/team identity fields before body validation.
manage_permission_group_users
gumloop-cli manage-permission-group-users
organization_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the organization that the custom role belongs to.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to manage custom role users.
group_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the custom role to manage users for.
action- Required
- No; body and guard rules apply
- Type
- string
- Details
- The action to perform - either 'add' or 'remove' a user. Values:
add,remove.
user_email- Required
- No; body and guard rules apply
- Type
- string
- Details
- The email address of the target user to add or remove.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: organization_id, user_id, group_id, action, user_email. Profile defaults fill supported user/team identity fields before body validation.
list_role_credit_limits
gumloop-cli list-role-credit-limits
organization_id- Required
- Yes
- Type
- string
- Details
- The ID of the organization. minLength:
1.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to manage custom role credit limits.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of roles per page. maximum:
100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque cursor from a previous response's
next_cursor; omit for the first page.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_role_credit_limit
gumloop-cli get-role-credit-limit
organization_id- Required
- Yes
- Type
- string
- Details
- The ID of the organization the custom role belongs to. minLength:
1.
role_id- Required
- Yes
- Type
- string
- Details
- The ID of the custom role (the same ID used as
group_idby the Manage custom role users endpoint). minLength:1.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to manage custom role credit limits.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
set_role_credit_limit
gumloop-cli set-role-credit-limit
organization_id- Required
- Yes
- Type
- string
- Details
- The ID of the organization the custom role belongs to. minLength:
1.
role_id- Required
- Yes
- Type
- string
- Details
- The ID of the custom role (the same ID used as
group_idby the Manage custom role users endpoint). minLength:1.
monthly_credit_limit- Required
- No; body and guard rules apply
- Type
- integer/null
- Details
- The monthly credit limit applied to each member of this role, or null to clear the role-level limit. minimum:
0. maximum:1000000000.
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Your user id -- you must be an organization admin to manage custom role credit limits.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: monthly_credit_limit, user_id. Profile defaults fill supported user/team identity fields before body validation.
export_data
gumloop-cli export-data
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the user requesting the export.
data_type- Required
- No; body and guard rules apply
- Type
- string
- Details
- The type of data to export. Use
"workflows"to export workflow run data,"agents"to export agent configuration data,"agent_interactions"to export agent interaction data,"credit_logs"to export credit transaction history,"interaction_evaluations"to export completed chat evaluations, or"gumstack"to export Gumstack tool call activity. Defaults to"workflows". Audit-log exports are available in the Gumloop app only, not through this endpoint. Values:workflows,agents,agent_interactions,credit_logs,interaction_evaluations,gumstack. default:workflows.
category_filter- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only applicable when
data_typeis"credit_logs". Optional filter to export only credit logs matching a specific category (e.g.,"PIPELINE_RUN","AGENT_RUN","CUSTOM_NODE_RD","EXTERNAL_GUMCP_CALL"). When omitted, all categories are included.
export_level- Required
- No; body and guard rules apply
- Type
- string
- Details
- The scope of the export. Use
"organization"to export across the entire organization, or"workspace"to export from a single workspace (requires exactly one ID inworkspace_ids). Defaults to"organization". Not applicable whendata_typeis"credit_logs". Values:workspace,organization. default:organization.
export_fields- Required
- No; body and guard rules apply
- Type
- array
- Details
- Array of fields to include in the export. The available fields depend on the
data_type. Workflow fields (whendata_typeis"workflows"): -workbook_id- The workbook identifier -workbook_name- The workbook name -workbook_created_ts- Workbook creation timestamp -user_id- The user identifier -user_email- The user's email address -workspace_id- The workspace identifier -workspace_name- The workspace name -run_id- The flow run identifier -credit_cost- Credits consumed by the run -pl_run_created_ts- Flow run creation timestamp -pl_run_finished_ts- Flow run completion timestamp -pipeline- The full pipeline configuration (JSON) Agent fields (whendata_typeis"agents"): -agent_id- The agent identifier -agent_name- The agent name -agent_description- The agent description -agent_model- The model used by the agent -agent_system_prompt- The agent's system prompt -agent_created_ts- Agent creation timestamp -agent_tools- Tools configured for the agent (JSON) -agent_metadata- Additional agent metadata (JSON) -agent_evaluations_enabled- Whether the agent's own Evaluations are turned on (true/false) -creator_email- Email of the user who created the agent -workspace_id- The workspace identifier -workspace_name- The workspace name -folder_id- The identifier of the folder containing the agent (empty when the agent is not in a folder) -folder_name- The name of the folder containing the agent (empty when the agent is not in a folder) Agent interaction fields (whendata_typeis"agent_interactions"): -interaction_id- Unique identifier for the chat session -agent_id- The agent identifier -agent_name- The agent name -interaction_type- Type of interaction (e.g., chat, slack, api, triggered) -interaction_name- Display name of the chat session -trigger_type- For triggered interactions, the specific trigger type (e.g., time_based, polling_new_record_salesforce). Null for non-triggered interactions. -interaction_created_ts- Chat session creation timestamp -user_email- Email of the user who initiated the chat -credit_cost- Total credits consumed (LLM + tool + flow) -llm_credit_cost- Credits consumed by LLM calls only -tool_credit_cost- Credits consumed by tool calls -flow_credit_cost- Credits consumed by pipeline runs -message_count- Number of messages in the conversation -workspace_id- The workspace identifier -workspace_name- The workspace name Interaction evaluation fields (whendata_typeis"interaction_evaluations"): -evaluation_id- Unique identifier for the evaluation row -interaction_id- The chat session that was evaluated (one chat can have several evaluation rows) -agent_id- The identifier of the agent that was evaluated -organization_evaluation_id- The organization-level evaluation this row belongs to (empty for agent-level rubrics) -evaluation_created_ts- When the evaluation reached its final state -status- The evaluation's state -grade- The grade the evaluation produced -call_outcome- The outcome the evaluation recorded for the conversation -sentiment- The sentiment the evaluation recorded -error_code- Error code when the evaluation could not complete -summary- The evaluation's written summary -evaluation_model- The model that ran the evaluation -credit_cost- Credits consumed by the evaluation -user_email- Email of the user whose chat was evaluated Credit log fields (whendata_typeis"credit_logs"): -user_email- Email of the user associated with the credit log entry -permission_group_id- Custom role ID(s) the user belongs to (semicolon-separated if multiple) (disabled by default) -permission_group_name- Custom role name(s) the user belongs to (semicolon-separated if multiple) (disabled by default) -timestamp- When the credit transaction occurred -category- The category of the credit log (e.g., PIPELINE_RUN, AGENT_RUN) -type- The specific type of credit charge -name- Display name of the credit log entry -amount- Number of credits charged or adjusted -balance- Credit balance after the transaction -log_id- Unique identifier for the credit log entry -correlation_id- Join key to the related run or interaction (disabled by default) -balance_scope- Whether the balance is organization- or user-scoped (disabled by default) -project_id- The project identifier (disabled by default) Not all combinations of selected fields are guaranteed to produce data for every row. Items: string.
start_date- Required
- No; body and guard rules apply
- Type
- string
- Details
- Start date for the export in ISO 8601 format (e.g.,
2025-01-01T00:00:00Z). format:date-time.
end_date- Required
- No; body and guard rules apply
- Type
- string
- Details
- End date for the export in ISO 8601 format (e.g.,
2025-12-31T23:59:59Z). format:date-time.
include_all_workspaces- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include all workspaces in the organization. When
true, also setsinclude_personal_workspacestotrue. Not applicable whendata_typeis"credit_logs". default:False.
include_personal_workspaces- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether to include personal workspaces in the export. Ignored if
include_all_workspacesistrue. Not applicable whendata_typeis"credit_logs". default:False.
workspace_ids- Required
- No; body and guard rules apply
- Type
- array
- Details
- An optional array of workspace IDs to include in the export. When
export_levelis"workspace", exactly one workspace ID is required. Ignored ifinclude_all_workspacesistrue. Not applicable whendata_typeis"credit_logs". Items: string.
entity_ids- Required
- No; body and guard rules apply
- Type
- array
- Details
- An optional array of specific entity IDs to filter the export. For workflow exports (
data_type: "workflows"), these are workbook IDs. For agent exports (data_type: "agents") and agent interaction exports (data_type: "agent_interactions"), these are agent IDs. When provided, only data for the specified entities will be included. Not applicable whendata_typeis"credit_logs". Items: string.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: user_id, export_fields, start_date, end_date. Profile defaults fill supported user/team identity fields before body validation.
get_export_status
gumloop-cli get-export-status
user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The ID of the user requesting the export status.
data_export_id- Required
- Yes
- Type
- string
- Details
- The unique identifier of the data export job to check (returned by the Export data endpoint).
download- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Set to
trueto download the export file directly when the export is completed. Whentrueand the export state isCOMPLETED, the response will be a CSV file download instead of JSON. default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
output_file- Required
- Yes
- Type
- string
- Details
- New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength:
1.
output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.
list_agents
gumloop-cli list-agents
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the listing to a single team. When omitted, returns agents owned by the authenticated user.
search- Required
- No; body and guard rules apply
- Type
- string
- Details
- Case-insensitive substring match against the agent name.
creator- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to agents created by this user ID.
has_triggers- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When
true, only returns agents that have at least one active trigger configured.
tool- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to agents that use the specified MCP server as a tool.
flow- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to agents that use the specified saved flow as a tool.
sort_order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Sort order for the listing. Defaults to newest first. Values:
newest,oldest,name_asc,name_desc. default:newest.
include_last_used- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When
true, populateslast_used_aton each agent with the timestamp of its most recent session.
include_last_updated- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- When
true, populateslast_updated_aton each agent with the timestamp of its most recent configuration change.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of agents per page. Sending
page_sizeorcursoropts into cursor pagination; requests that send neither return the full list. minimum:1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque cursor from a previous response's
next_cursor. Pass it to fetch the next page.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
create_agent
gumloop-cli create-agent
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Display name for the agent.
model_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- ID of the LLM the agent runs on. Use
GET /modelsto discover valid values.
description- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema.
system_prompt- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema.
tools- Required
- No; body and guard rules apply
- Type
- array
- Details
- Tools the agent can call. Each tool is an object whose shape depends on the tool type. default:
[]. Items: object.
resources- Required
- No; body and guard rules apply
- Type
- array
- Details
- Resources attached to the agent. default:
[]. Items: object.
skill_ids- Required
- No; body and guard rules apply
- Type
- array/null
- Details
- IDs of skills to attach to the agent. Attachment happens inside the create transaction, so an invalid ID fails the whole request (no orphaned agent). Omit to attach none. The caller must hold
INVOKEon each skill. After creation, manage skills withPATCH /agents/{agent_id}/skills. Items: string.
metadata- Required
- No; body and guard rules apply
- Type
- object/null
- Details
- Arbitrary key/value metadata stored on the agent.
folder_id- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- ID of the folder to place the agent in.
is_active- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether the agent is active. Defaults to
true. Setting this tofalseretires the agent: it disappears fromGET /agents, andGET/PATCH /agents/{agent_id}return404, so it cannot be reactivated through the API. This is not a pause switch — to stop an agent from running while keeping it reachable, disable its triggers instead. default:True.
agent_id- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- Optional caller-supplied agent ID. When omitted, the server generates one.
team_id- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- ID of the team to create the agent under. When omitted, the agent is owned by the authenticated user.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name, model_name. Profile defaults fill supported user/team identity fields before body validation.
retrieve_agent
gumloop-cli retrieve-agent
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent to retrieve. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
update_agent
gumloop-cli update-agent
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent to update. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
name- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema.
model_name- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- ID of the LLM the agent runs on. Use
GET /modelsto discover valid values.
description- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema.
system_prompt- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema.
tools- Required
- No; body and guard rules apply
- Type
- array/null
- Details
- When provided, replaces the agent's tool list. Items: object.
resources- Required
- No; body and guard rules apply
- Type
- array/null
- Details
- When provided, replaces the agent's resource list. Items: object.
metadata- Required
- No; body and guard rules apply
- Type
- object/null
- Details
- See the full input schema.
is_active- Required
- No; body and guard rules apply
- Type
- boolean/null
- Details
- Setting this to
falseretires the agent: it disappears fromGET /agents, andGET/PATCH /agents/{agent_id}return404, so it cannot be reactivated through the API. This is not a pause switch — to stop an agent from running while keeping it reachable, disable its triggers instead.
team_id- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- When provided, transfers ownership of the agent to this team.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
create_chat_completion
gumloop-cli create-chat-completion
model- Required
- No; body and guard rules apply
- Type
- string
- Details
- Model slug. Use the
idfromGET /modelsor one of Gumloop's preset routes.
messages- Required
- No; body and guard rules apply
- Type
- array
- Details
- Conversation history. Roles
system,developer,user,assistant, andtool. User messages accept multipartcontentwithtextandimage_urlparts. Assistant messages can carrytool_calls; answer each one with atoolmessage whosetool_call_idmatches the call'sid. Items: object.
stream- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Only non-streaming JSON is supported. Streaming requests are refused before fetch.
temperature- Required
- No; body and guard rules apply
- Type
- number
- Details
- Sampling temperature.
max_completion_tokens- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Cap on completion tokens. Replaces the deprecated
max_tokensfield.
modalities- Required
- No; body and guard rules apply
- Type
- array
- Details
- Output modalities. Include
"image"to route to an image-generation model. Items: string.
image_config- Required
- No; body and guard rules apply
- Type
- object
- Details
- Image-generation parameters (size, quality, aspect_ratio, background, output_format, partial_images). Optional. Image-generation models accept either
modalities: ["image"]orimage_config(or both); chat models ignore this field.
response_format- Required
- No; body and guard rules apply
- Type
- object
- Details
- Constrain the response.
{type: "json_object"}returns a JSON object;{type: "json_schema", json_schema: {name, strict, schema}}returns JSON matching the supplied schema.
tools- Required
- No; body and guard rules apply
- Type
- array
- Details
- OpenAI-shape tool definitions (
{type: "function", function: {name, description, parameters}}). Passtool_choiceto constrain selection.
tool_choice- Required
- No; body and guard rules apply
- Type
- Union
- Details
"auto"lets the model choose and is the default whentoolsare sent."none"disables tool calls,"required"forces a tool call, and{"type": "function", "function": {"name": "..."}}forces a specific tool.
provider- Required
- No; body and guard rules apply
- Type
- object
- Details
- OpenRouter provider routing config. Caller fields like
sortandorderare honored; ZDR/data_collection policy is server-enforced.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: model, messages. Profile defaults fill supported user/team identity fields before body validation.
list_models
gumloop-cli list-models
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope model availability to a specific team. When omitted, uses the authenticated user's default organization.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
route_model
gumloop-cli route-model
input- Required
- No; body and guard rules apply
- Type
- Union
- Details
- The message to route.
messageis accepted as an alias. A string or an array of{type: text, text: ...}parts.
models- Required
- No; body and guard rules apply
- Type
- array
- Details
- Candidate model IDs to choose between. IDs must be nonempty, unique after remapping, and registered. Omit to use Chew's lane-chain union. minItems:
1. maxItems:50. Items: string.
history- Required
- No; body and guard rules apply
- Type
- array
- Details
- Prior turns, oldest first, for context. maxItems:
20. Items: object.
agent- Required
- No; body and guard rules apply
- Type
- object
- Details
- Optional context about the agent the message is for. Sharper context produces a sharper route.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope model availability and credit attribution to a team the caller belongs to.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.
list_agent_versions
gumloop-cli list-agent-versions
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent whose versions to list. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of versions to return per page. Clamped to 1–100. minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque pagination cursor returned by a prior call as
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
retrieve_agent_version
gumloop-cli retrieve-agent-version
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent the version belongs to. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
version_id- Required
- Yes
- Type
- string
- Details
- ID of the version to retrieve, from
GET /agents/{agent_id}/versions. minLength:1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
update_agent_skills
gumloop-cli update-agent-skills
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent whose skills to update. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
attach- Required
- No; body and guard rules apply
- Type
- array
- Details
- Skill IDs to attach. Ignored if already attached. default:
[]. Items: string.
detach- Required
- No; body and guard rules apply
- Type
- array
- Details
- Skill IDs to detach. Ignored if not attached. default:
[]. Items: string.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
list_agent_mcp_servers
gumloop-cli list-agent-mcp-servers
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
attach_agent_mcp_server
gumloop-cli attach-agent-mcp-server
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
server_id- Required
- Yes
- Type
- string
- Details
- ID of the MCP server from the caller's catalog. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
detach_agent_mcp_server
gumloop-cli detach-agent-mcp-server
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
server_id- Required
- Yes
- Type
- string
- Details
- ID of the MCP server to detach. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
list_sessions
gumloop-cli list-sessions
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent whose sessions to list. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of sessions to return per page. Defaults to
20, maximum100. minimum:1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Cursor for the next page of results. Use the
next_cursorvalue from a previous response.
search- Required
- No; body and guard rules apply
- Type
- string
- Details
- Free-text search query to filter sessions by name or content. Also accepted as
search_query.
sort_order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Sort order for the results (e.g.
newestoroldest).
type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter sessions by type (e.g.
api,web,slack).
state- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter sessions by state. Values:
processing,completed,failed,queued,idle.
creator_user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter sessions by the user who created them.
trigger_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter sessions by the trigger that initiated them.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
create_session
gumloop-cli create-session
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent to start a session on. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
input- Required
- No; body and guard rules apply
- Type
- string
- Details
- The first user message for the session. Also accepted as
messagefor backwards compatibility. When omitted, an idle session is created with no messages.
session_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Caller-supplied session ID. When omitted, the server generates one. If provided and the ID already exists, the request returns
409 session_already_exists.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Optional display name for the session. Leading and trailing whitespace is removed before the 1-256 character limit is applied, so an empty or whitespace-only value is rejected. A name you supply is kept; the automatic title only fills in sessions created without one. Rename the session later with
PATCH /sessions/{session_id}. maxLength:256.
metadata- Required
- No; body and guard rules apply
- Type
- object
- Details
- Arbitrary key/value metadata attached to the session. Stored under
metadata.client.
stream- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be
false(or omitted) when callingapi.gumloop.com. Set totrueonly when callingws.gumloop.com(see the streaming section above). default:False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
retrieve_session
gumloop-cli retrieve-session
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to retrieve. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
rename_session
gumloop-cli rename-session
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to rename. minLength:
1.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- New name for the session. Leading and trailing whitespace is removed before the 1-256 character limit is applied, so a whitespace-only value is rejected. minLength:
1. maxLength:256.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.
send_message
gumloop-cli send-message
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to continue. minLength:
1.
input- Required
- No; body and guard rules apply
- Type
- string
- Details
- The next user message. Required. Also accepted as
messagefor backwards compatibility.
stream- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be
false(or omitted) when callingapi.gumloop.com. Set totrueonly when callingws.gumloop.com(see the streaming section above). default:False.
attachments- Required
- No; body and guard rules apply
- Type
- array
- Details
- Files to attach to the message. Each
file_namemust be a stored path returned by Upload session file for this session. maxItems:10. Items: object.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.
cancel_session
gumloop-cli cancel-session
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to cancel. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
upload_session_file
gumloop-cli upload-session-file
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to upload the file to. minLength:
1.
file_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Name of the file. Directory components are stripped; the base name is sanitized before storage.
file_content- Required
- No; body and guard rules apply
- Type
- string
- Details
- Base64-encoded file contents. Maximum decoded size is 200MB. format:
byte.
media_type- Required
- No; body and guard rules apply
- Type
- string
- Details
- MIME type of the file. Echoed back in the response.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: file_name, file_content. Profile defaults fill supported user/team identity fields before body validation.
resolve_session_approvals
gumloop-cli resolve-session-approvals
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session with pending approvals. minLength:
1.
approval_responses- Required
- No; body and guard rules apply
- Type
- array
- Details
- Answers to pending asks. Each
action_request_idmay appear at most once. minItems:1. maxItems:20. Items: object.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: approval_responses. Profile defaults fill supported user/team identity fields before body validation.
list_queued_messages
gumloop-cli list-queued-messages
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session whose queue to list. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
queue_session_message
gumloop-cli queue-session-message
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session to queue the message on. minLength:
1.
input- Required
- No; body and guard rules apply
- Type
- string
- Details
- The message to queue. Cannot be empty. Also accepted as
messagefor backwards compatibility.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.
update_queued_message
gumloop-cli update-queued-message
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session the queued message belongs to. minLength:
1.
queued_message_id- Required
- Yes
- Type
- string
- Details
- ID of the queued message to update. minLength:
1.
input- Required
- No; body and guard rules apply
- Type
- string
- Details
- The new message content. Cannot be empty. Also accepted as
messagefor backwards compatibility.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: input. Profile defaults fill supported user/team identity fields before body validation.
delete_queued_message
gumloop-cli delete-queued-message
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session the queued message belongs to. minLength:
1.
queued_message_id- Required
- Yes
- Type
- string
- Details
- ID of the queued message to delete. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
send_queued_message
gumloop-cli send-queued-message
session_id- Required
- Yes
- Type
- string
- Details
- ID of the session the queued message belongs to. minLength:
1.
queued_message_id- Required
- Yes
- Type
- string
- Details
- ID of the queued message to send. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
list_mcp_servers
gumloop-cli list-mcp-servers
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the catalog to a single team. When omitted, returns servers visible to the authenticated user.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
retrieve_mcp_server
gumloop-cli retrieve-mcp-server
server_id- Required
- Yes
- Type
- string
- Details
- Identifier of the MCP server to retrieve. minLength:
1.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the lookup to a single team.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_mcp_server_tools
gumloop-cli list-mcp-server-tools
server_id- Required
- Yes
- Type
- string
- Details
- Identifier of the MCP server. minLength:
1.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the lookup to a single team.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_mcp_server_resources
gumloop-cli list-mcp-server-resources
server_id- Required
- Yes
- Type
- string
- Details
- Identifier of the MCP server. minLength:
1.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the lookup to a single team.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque cursor from a previous response's
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
read_mcp_server_resource
gumloop-cli read-mcp-server-resource
server_id- Required
- Yes
- Type
- string
- Details
- See current schema minLength:
1.
uri- Required
- Yes
- Type
- string
- Details
- The resource
urifrom List MCP server resources.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See current schema
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_mcp_server_prompts
gumloop-cli list-mcp-server-prompts
server_id- Required
- Yes
- Type
- string
- Details
- See current schema minLength:
1.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- See current schema
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_mcp_server_prompt
gumloop-cli get-mcp-server-prompt
server_id- Required
- Yes
- Type
- string
- Details
- See current schema minLength:
1.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Prompt name from List MCP server prompts.
arguments- Required
- No; body and guard rules apply
- Type
- object
- Details
- Argument values for the template.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the lookup to a single team.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.
call_mcp_tools
gumloop-cli call-mcp-tools
calls- Required
- No; body and guard rules apply
- Type
- array
- Details
- Tool calls to execute. Dispatched concurrently; the batch is capped at 5. minItems:
1. maxItems:5. Items: object.
team_id- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- Team the calls are scoped to.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: calls. Profile defaults fill supported user/team identity fields before body validation.
search_brain
gumloop-cli search-brain
query- Required
- No; body and guard rules apply
- Type
- string
- Details
- The natural-language search query.
limit- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Maximum number of results to return. minimum:
1. maximum:50. default:8.
source_type- Required
- No; body and guard rules apply
- Type
- array/null
- Details
- Restrict results to specific source types. Omit to search every source you can access. Valid values:
notion,google_drive,slack,github,confluence,direct_file_uploads,gumloop_artifacts. minItems:1. Items: string.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: query. Profile defaults fill supported user/team identity fields before body validation.
list_brain_sources
gumloop-cli list-brain-sources
scope- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only sources in this scope. Values:
personal,team,organization.
source_type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only sources of this type, for example
direct_file_uploadsornotion.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only team sources belonging to this team.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Maximum number of sources to return. minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque cursor from a previous response's
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
create_brain_source
gumloop-cli create-brain-source
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Display name of the source. minLength:
1. maxLength:200.
source_type- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only
direct_file_uploadsis accepted. default:direct_file_uploads.
scope- Required
- No; body and guard rules apply
- Type
- string
- Details
- Which Brain the source belongs to.
teamrequiresteam_id. Values:personal,team,organization. default:personal.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- The team for
scope: team. Not accepted with other scopes.
require_approval- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Create as a draft that estimates credits before anything is indexed. default:
False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: name. Profile defaults fill supported user/team identity fields before body validation.
get_brain_source
gumloop-cli get-brain-source
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
delete_brain_source
gumloop-cli delete-brain-source
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
list_brain_files
gumloop-cli list-brain-files
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- See current schema minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- See current schema
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
upload_brain_files
gumloop-cli upload-brain-files
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems:
1. maxItems:25. Items: string.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.
files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.
delete_brain_file
gumloop-cli delete-brain-file
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
file_id- Required
- Yes
- Type
- string
- Details
- See current schema minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
get_brain_source_estimate
gumloop-cli get-brain-source-estimate
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
approve_brain_source
gumloop-cli approve-brain-source
source_id- Required
- Yes
- Type
- string
- Details
- The source id. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
list_skills
gumloop-cli list-skills
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Scope the listing to a single team. When omitted, returns skills owned by the authenticated user.
search_query- Required
- No; body and guard rules apply
- Type
- string
- Details
- Case-insensitive substring match against the skill name.
sort_order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Sort order for the returned skills. Values:
newest,popular,most_used. default:newest.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of skills per page. Clamped between 1 and 100. minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque pagination cursor returned in
next_cursorfrom a prior page.
creator_user_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to skills created by this user ID.
related_server_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to skills that reference this MCP server ID in their metadata.
agent_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to skills attached to this agent.
unused- Required
- No; body and guard rules apply
- Type
- string
- Details
- When set, filters to skills that have not been used.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
create_skill
gumloop-cli create-skill
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems:
1. maxItems:25. Items: string.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Team that should own the skill. When omitted, the skill is owned by the authenticated user.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.
files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.
update_skill
gumloop-cli update-skill
skill_id- Required
- Yes
- Type
- string
- Details
- ID of the skill to update. minLength:
1.
files- Required
- No; body and guard rules apply
- Type
- array
- Details
- Regular local file paths, not base64; each file and total upload at most 5 MiB. Paths cannot be symlinks. minItems:
1. maxItems:25. Items: string.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: files. Profile defaults fill supported user/team identity fields before body validation.
files contains regular local paths. The handler reads actual bytes and sends native multipart file parts after confirmation; 5 MiB per file/total local cap, no symlinks.
delete_skill
gumloop-cli delete-skill
skill_id- Required
- Yes
- Type
- string
- Details
- ID of the skill to delete. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
download_skill_file
gumloop-cli download-skill-file
skill_id- Required
- Yes
- Type
- string
- Details
- ID of the skill to download. minLength:
1.
version_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Specific version to download. When omitted, the current draft is returned.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
output_file- Required
- Yes
- Type
- string
- Details
- New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength:
1.
output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.
list_artifacts
gumloop-cli list-artifacts
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent whose artifacts to list. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
session_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter to artifacts produced within a specific session.
search_query- Required
- No; body and guard rules apply
- Type
- string
- Details
- Case-insensitive substring match against the artifact filename.
sort_order- Required
- No; body and guard rules apply
- Type
- string
- Details
- Sort order for results. Defaults to
newest. default:newest.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of artifacts to return per page. Clamped to 1–100. minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Opaque pagination cursor returned by a prior call as
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
download_artifact_file
gumloop-cli download-artifact-file
artifact_id- Required
- Yes
- Type
- string
- Details
- ID of the artifact to download. minLength:
1.
version_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Specific version of the artifact to download. Defaults to the latest version when omitted.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
output_file- Required
- Yes
- Type
- string
- Details
- New absolute result file in a private owner-only directory. Private download or signed credential result stays out of model output; no overwrite. minLength:
1.
output_file must be new and absolute in a private directory, reserved exclusively before the API call. Binary bytes or signed JSON are kept out of model output. This wrapper never follows a signed external download URL.
list_browser_profiles
gumloop-cli list-browser-profiles
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- List a team's profiles instead of your personal ones.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
import_browser_profile_cookies
gumloop-cli import-browser-profile-cookies
profile_id- Required
- Yes
- Type
- string
- Details
- A profile id, or
default. minLength:1.
url- Required
- No; body and guard rules apply
- Type
- string
- Details
- Import only the cookies for this site and replace what the profile had for it. Omit to import every site in
cookies. maxLength:2048.
cookies- Required
- No; body and guard rules apply
- Type
- array
- Details
- Cookies in
chrome.cookies.Cookieor CDPCookieshape. minItems:1. Items: object.
team_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Import into a team-owned profile instead of a personal one.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: cookies. Profile defaults fill supported user/team identity fields before body validation.
list_teams
gumloop-cli list-teams
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_evaluations
gumloop-cli list-evaluations
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent whose evaluations to list. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of evaluations to return per page (1-100). minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Pagination cursor from a previous response's
next_cursorfield.
grade- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter evaluations by grade. Values:
pass,needs_review,needs_attention.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- Return evaluations in one lifecycle state instead of the default completed and failed set. Values:
queued,in_progress,completed,failed.
session_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only evaluations of this session.
organization_evaluation_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Return the results one organization evaluation produced for this agent instead of the agent's own evaluation results.
created_after- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only evaluations created at or after this ISO 8601 timestamp. Timestamps without an offset are read as UTC. format:
date-time.
created_before- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only evaluations created before this ISO 8601 timestamp. Timestamps without an offset are read as UTC. format:
date-time.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
run_evaluations
gumloop-cli run-evaluations
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent that owns the sessions. minLength:
1.
session_ids- Required
- No; body and guard rules apply
- Type
- array
- Details
- Sessions to grade. Duplicates are rejected. minItems:
1. maxItems:200. Items: string.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Report cost and skipped sessions without queuing. default:
False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: session_ids. Profile defaults fill supported user/team identity fields before body validation.
get_evaluation_metrics
gumloop-cli get-evaluation-metrics
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
days- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Number of days to look back (1-365). Defaults to 30. minimum:
1. maximum:365. default:30.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
retrieve_evaluation
gumloop-cli retrieve-evaluation
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent the evaluation belongs to. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the evaluation to retrieve. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_evaluation_config
gumloop-cli get-evaluation-config
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
update_evaluation_config
gumloop-cli update-evaluation-config
agent_id- Required
- Yes
- Type
- string
- Details
- ID of the agent. Also accepts the reserved aliases
gumballandanalytics. minLength:1.
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Whether evaluations are enabled for this agent.
model_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- LLM model to use for evaluation.
include_auto_tags- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Allow the evaluator to suggest tags beyond your predefined vocabulary.
criteria- Required
- No; body and guard rules apply
- Type
- array
- Details
- Quality criteria to check (replaces existing list). Max 30. Items: object.
tags- Required
- No; body and guard rules apply
- Type
- array
- Details
- Tag vocabulary (replaces existing list). Max 50. Items: object.
data_points- Required
- No; body and guard rules apply
- Type
- array
- Details
- Data points to extract (replaces existing list). Max 40. Items: object.
sentiment- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
list_organizations
gumloop-cli list-organizations
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_evaluation_options
gumloop-cli get-evaluation-options
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_organization_evaluations
gumloop-cli list-organization-evaluations
organization_id- Required
- Yes
- Type
- string
- Details
- The organization whose evaluations to list.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Items per page (1-100). minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Pagination cursor from a previous response's
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
create_organization_evaluation
gumloop-cli create-organization-evaluation
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
get_organization_evaluation
gumloop-cli get-organization-evaluation
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
update_organization_evaluation
gumloop-cli update-organization-evaluation
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: Inspect endpoint requirements. Profile defaults fill supported user/team identity fields before body validation.
delete_organization_evaluation
gumloop-cli delete-organization-evaluation
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
set_organization_evaluation_targets
gumloop-cli set-organization-evaluation-targets
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
targets- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. maxItems:
1000. Items: EvaluationTarget.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: targets. Profile defaults fill supported user/team identity fields before body validation.
run_organization_evaluation
gumloop-cli run-organization-evaluation
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
session_ids- Required
- No; body and guard rules apply
- Type
- array
- Details
- Sessions to grade. Duplicates are rejected. minItems:
1. maxItems:200. Items: string.
dry_run- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Report cost and skipped sessions without queuing. default:
False.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
confirm- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be true for this exact requested account change, agent/flow execution, upload or deletion.
payload- Required
- No; body and guard rules apply
- Type
- object
- Details
- Complete JSON request body instead of body flags. Preserves current endpoint fields and values.
payload_file- Required
- No; body and guard rules apply
- Type
- string
- Details
- Regular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload. minLength:
1.
A body is required. Native body flags, payload and payload_file are mutually exclusive. Required native body fields: session_ids. Profile defaults fill supported user/team identity fields before body validation.
list_organization_evaluation_results
gumloop-cli list-organization-evaluation-results
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
agent_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only results for this agent.
session_id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only results for this session.
grade- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter by grade. Values:
pass,needs_review,needs_attention.
status- Required
- No; body and guard rules apply
- Type
- string
- Details
- Filter by status. Values:
queued,in_progress,completed,failed.
created_after- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only results created at or after this time. RFC 3339 with an explicit offset (for example
2026-09-01T00:00:00Z). format:date-time.
created_before- Required
- No; body and guard rules apply
- Type
- string
- Details
- Only results created before this time. RFC 3339 with an explicit offset. format:
date-time.
page_size- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Items per page (1-100). minimum:
1. maximum:100. default:20.
cursor- Required
- No; body and guard rules apply
- Type
- string
- Details
- Pagination cursor from a previous response's
next_cursor.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_organization_evaluation_result
gumloop-cli get-organization-evaluation-result
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
result_id- Required
- Yes
- Type
- string
- Details
- Result ID from a run response or a results list. minLength:
1.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
get_organization_evaluation_metrics
gumloop-cli get-organization-evaluation-metrics
evaluation_id- Required
- Yes
- Type
- string
- Details
- ID of the organization evaluation. minLength:
1.
days- Required
- No; body and guard rules apply
- Type
- integer
- Details
- Window length in days. minimum:
1. maximum:365. default:30.
account- Required
- No; body and guard rules apply
- Type
- string
- Details
- Named private Gumloop account; selects private credentials and user/team identity.
list_accounts
gumloop-cli list-accounts
- Required
- No
- Type
- None
- Details
- No arguments
Nested request definitions
These definitions are shared by the current native bodies. Required fields depend on the selected union branch. Full inline shapes remain in schema COMMAND.
##### EvaluationRubric
What and how the evaluation grades. Entries in criteria, tags, and data_points accept additional fields as the product evolves.
model_name- Required
- No; body and guard rules apply
- Type
- string
- Details
- Grading model.
autopicks the recommended model.
frequency- Required
- No; body and guard rules apply
- Type
- string
- Details
- When to grade new sessions automatically.
manualonly grades viaPOST /evaluations/{evaluation_id}/run. Values:debounced,per_turn,manual.
language- Required
- No; body and guard rules apply
- Type
- string
- Details
- Language for summaries and rationales, or
auto.
include_auto_tags- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- See the full input schema.
session_types- Required
- No; body and guard rules apply
- Type
- array
- Details
- Session types to grade. See
session_typesinGET /evaluation-options. Items: string.
criteria- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. maxItems:
30. Items: object.
tags- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. maxItems:
50. Items: object.
data_points- Required
- No; body and guard rules apply
- Type
- array
- Details
- See the full input schema. maxItems:
40. Items: object.
sentiment- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
notifications- Required
- No; body and guard rules apply
- Type
- object
- Details
- See the full input schema.
##### EvaluationCreateRequest
Current request definition.
scope- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. Values:
organization. default:organization.
organization_id- Required
- Yes
- Type
- string
- Details
- See the full input schema.
name- Required
- Yes
- Type
- string
- Details
- Unique among the organization's active evaluations. minLength:
1. maxLength:256.
description- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- See the full input schema. maxLength:
4000.
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- Must be omitted or false on create; a new evaluation has no targets yet.
config- Required
- No; body and guard rules apply
- Type
- EvaluationRubric
- Details
- See the full input schema.
##### EvaluationUpdateRequest
Current request definition.
name- Required
- No; body and guard rules apply
- Type
- string
- Details
- See the full input schema. minLength:
1. maxLength:256.
description- Required
- No; body and guard rules apply
- Type
- string/null
- Details
- Null clears the description. maxLength:
4000.
enabled- Required
- No; body and guard rules apply
- Type
- boolean
- Details
- See the full input schema.
config- Required
- No; body and guard rules apply
- Type
- EvaluationRubric
- Details
- See the full input schema.
##### EvaluationTarget
Current request definition.
type- Required
- Yes
- Type
- string
- Details
- What the target expands to.
usercovers a member's personal agents. Values:organization,team,user,agent.
id- Required
- No; body and guard rules apply
- Type
- string
- Details
- Team, user, or agent ID. Omitted for
organization; responses return the organization ID.
Complete client, OS and desktop setup
Codex
Codex is the current validation priority. Private token paths must exist in the process or remote environment where the server runs.
codex mcp add gumloop -- npx -y @thenavidm/gumloop-mcp-cli@latest
codex mcp listAccount credentials must reach the server through private environment settings. codex mcp add --env NAME=value stores values in your local config, so never commit that config or put secrets in a shared command. In TOML, the equivalent server is:
[mcp_servers.gumloop]
command = "npx"
args = ["-y", "@thenavidm/gumloop-mcp-cli@latest"]
env_vars = ["GUMLOOP_API_KEY", "GUMLOOP_TOKEN_FILE", "GUMLOOP_ACCOUNTS", "GUMLOOP_DEFAULT_ACCOUNT", "GUMLOOP_READ_ONLY", "GUMLOOP_ALLOW_DESTRUCTIVE", "GUMLOOP_USER_ID", "GUMLOOP_TEAM_ID"]env_vars forwards those names from the environment available to Codex. If that environment does not contain them, configure private env settings locally. Codex can also call the CLI directly with SKILL.md and --agent output.
Claude Code
For a user-scoped connection, after privately configuring credentials:
claude mcp add --scope user gumloop -- npx -y @thenavidm/gumloop-mcp-cli@latest
claude mcp listUse the client's private local environment settings for the account variable if they are not inherited. Claude's -e NAME=value registration option writes values into its config; only use it locally through your secret manager, with no shared command transcript. Never place credentials in a project .mcp.json. Reconnect and ask Claude to verify credentials.
Alternatively install the CLI, make SKILL.md available to Claude, and use shell commands. Registering both surfaces is optional.
Claude Desktop
Install the .mcpb extension
- Download
gumloop-2.0.1.mcpbfrom GitHub Releases. - In a supported Claude Desktop build, open Settings > Extensions > Advanced settings > Install Extension… and select it.
- Enter a private API key in the sensitive setting, or an absolute private token-file path. Leave the unused credential method empty. Requests use Authorization: Bearer, with the configured user ID in x-auth-key when supplied. Enter the intended user ID and optional team ID in the private extension settings.
- Enable read-only if you want only the 50 read operations. Reconnect and ask for account verification.
The bundle includes production dependencies and no credentials. Use a regular private token-only file if you prefer file-based credentials. The manifest requires Node 22 or newer from a compatible host. Organization policy may restrict custom extensions. Manual bundle updates require installing the new version; no automatic directory updates are promised. GUI installation remains unverified separately from archive/protocol checks.
Manual config
Open Settings > Developer > Edit Config, or use your platform's config file:
| OS | Typical config path |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json |
| Linux | ~/.config/Claude/claude_desktop_config.json; confirm the location through Edit Config in your installed build |
{
"mcpServers": {
"gumloop": {
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "YOUR_PRIVATE_API_KEY",
"GUMLOOP_TOKEN_FILE": "",
"GUMLOOP_USER_ID": "YOUR_USER_ID",
"GUMLOOP_TEAM_ID": ""
}
}
}
}Replace the placeholders only in your private file. Merge the server entry into an existing mcpServers object instead of replacing other integrations. Fully quit and reopen Claude Desktop. Do not enable an extension and a manual entry with the same name; choose one route.
If a Windows launcher cannot execute npx directly, use "command": "cmd" with "args": ["/c", "npx", "-y", "@thenavidm/gumloop-mcp-cli@latest"]. An absolute node executable and installed dist/index.js path also avoids launcher/PATH problems.
Cursor
Use private user settings at ~/.cursor/mcp.json, or Settings > Tools & MCP. Cursor documents environment interpolation and envFile support.
{
"mcpServers": {
"gumloop": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "${env:GUMLOOP_API_KEY}",
"GUMLOOP_TOKEN_FILE": "${env:GUMLOOP_TOKEN_FILE}",
"GUMLOOP_USER_ID": "${env:GUMLOOP_USER_ID}",
"GUMLOOP_TEAM_ID": "${env:GUMLOOP_TEAM_ID}"
}
}
}
}The environment values must exist for the Cursor process. If you use envFile, keep that file private and outside version control. A project's .cursor/mcp.json must not contain actual credentials. Reconnect the server after saving.
VS Code and Copilot
Use MCP: Open User Configuration. VS Code uses servers and secure inputs, rather than a mcpServers root:
{
"inputs": [
{"type": "promptString", "id": "gumloop-api-key", "description": "Gumloop API key (leave empty for a private token file)", "password": true},
{"type": "promptString", "id": "gumloop-token-file", "description": "Optional private token-file path (leave empty for API key)"},
{"type": "promptString", "id": "gumloop-user-id", "description": "Gumloop user ID from your private profile"},
{"type": "promptString", "id": "gumloop-team-id", "description": "Optional Gumloop team ID (leave empty for personal access)"}
],
"servers": {
"gumloop": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "${input:gumloop-api-key}",
"GUMLOOP_TOKEN_FILE": "${input:gumloop-token-file}",
"GUMLOOP_USER_ID": "${input:gumloop-user-id}",
"GUMLOOP_TEAM_ID": "${input:gumloop-team-id}"
}
}
}
}Start Gumloop through the MCP controls, approve trust if prompted, and enter credentials in the private input prompts. Workspace .vscode/mcp.json may contain this placeholder-only structure, but never resolved secret values. Remote development runs the server in the selected remote environment, so local file paths refer to that environment.
Windsurf
Open Cascade's MCP settings or edit the private user file ~/.codeium/windsurf/mcp_config.json. Use the Claude Desktop manual mcpServers block above with your locally configured env values. See Windsurf's current MCP documentation. Restart or reconnect Gumloop in Cascade; project files must not contain secrets.
Zed
Open Settings > AI > MCP Servers > Add Server > Add Local Server, or your user settings file. Zed uses context_servers:
{
"context_servers": {
"gumloop": {
"command": "npx",
"args": ["-y", "@thenavidm/gumloop-mcp-cli@latest"],
"env": {
"GUMLOOP_API_KEY": "YOUR_PRIVATE_API_KEY",
"GUMLOOP_TOKEN_FILE": "",
"GUMLOOP_USER_ID": "YOUR_USER_ID",
"GUMLOOP_TEAM_ID": ""
}
}
}
}Enter actual values only in private user settings. Check the active-server indicator before prompting. Do not wrap command and args inside a nested command object from older Zed examples.
Gemini CLI
Merge the Claude Desktop manual mcpServers block into your private ~/.gemini/settings.json. Configure the private credential values locally, then restart Gemini CLI and inspect /mcp. See Gemini CLI's MCP configuration. Its project settings must not contain real credentials. You can instead use the CLI from an agent shell.
Other local stdio clients use the same command and arguments, adapted to their config format. A client that only accepts a remote MCP URL cannot connect directly: this package does not ship a public HTTP listener. ChatGPT's remote connector setup is not a substitute for local stdio installation.
Docker
Build locally from the reviewed source; no prebuilt registry image is claimed:
git clone https://github.com/thenavidm/gumloop-mcp-cli.git
cd gumloop-mcp-cli
docker build -t gumloop-mcp-cli .
docker run --rm -i -e GUMLOOP_API_KEY gumloop-mcp-cliCline and other local MCP clients
Use the client's Add MCP server flow with command npx, arguments -y and @thenavidm/gumloop-mcp-cli@latest, stdio transport, and private local GUMLOOP_API_KEY or GUMLOOP_TOKEN_FILE settings. UI names depend on the installed client. Reconnect and discover tools before an account call. Browser-only clients need a remote HTTPS connector; use Gumloop's official server rather than this local stdio command.
Output, flags and exit codes
Tool results go to stdout. Errors are JSON on stderr. JSON operations return structured results, so --select can retain nested fields. Private download operations return file metadata; binary bytes and signed results stay in the requested private file.
gumloop-cli start-flow --help
gumloop-cli schema start-flow
gumloop-cli list-agents --agent --select agents| Flag | What it does |
|---|---|
--json | JSON output |
--compact | Single-line JSON |
--agent | JSON, compact, no input and no color |
--select a,b.c | Keep selected fields; dotted paths descend and arrays are traversed |
--confirm | Confirm the requested flow, session, paid search or account operation |
--no-input, --no-color, --yes | Automation switches; none overrides the spending guard |
Global output flags apply to tool commands. doctor has its own --network option and returns a JSON diagnostic.
- Meaning
- Success
- What a script should do
- Read stdout
- Meaning
- Usage, invalid input or a refused write
- What a script should do
- Fix the input or confirm only the requested action
- Meaning
- Job or local upload file not found
- What a script should do
- Check the ID/path
- Meaning
- Authentication or entitlement rejected
- What a script should do
- Check private credential settings and permissions
- Meaning
- API or network failure
- What a script should do
- Inspect an accepted job before another paid submission
- Meaning
- Rate limited
- What a script should do
- Wait; do not loop over paid submissions
- Meaning
- Credentials not configured
- What a script should do
- Complete local setup
The underscore spelling also works. start_flow and start-flow call the same tool. Nested objects use quoted JSON. Arrays of objects use repeated flags, one JSON object at a time.
Official and community comparisons
- Surface
- PyPI gumloop 0.5.2, Python >=3.10
- Capability and tradeoff
- Agents/sessions, evaluations, chat, MCP, Brain, skills/artifacts, OAuth/keychain, browser/sync/plugin workflows; native Windows explicitly refused, WSL/SDK alternatives documented
- Surface
- https://mcp.gumloop.com/gumloop/mcp
- Capability and tradeoff
- Docs list 46 tools, including flows/workbooks/runs, agents/sessions, files/skills, audit and exports. This is documented coverage, not authenticated discovery
- Surface
- Shared Node CLI/local MCP/.mcpb
- Capability and tradeoff
- Current reviewed 91 REST operations plus private account labels; enforced operation approval/read-only, isolated profiles, native Windows target and exclusive private downloads
- Surface
- Python gumloop and JavaScript gumloop
- Capability and tradeoff
- Application integration; the Python SDK works on Windows and already has credential/transport controls
- Surface
- Earlier private source
- Capability and tradeoff
- Flow/workbook/agent/file declarations without current shared CLI, release setup or enforced approval
Checked October 3, 2026. Current official CLI docs and the checksum-reviewed published 0.5.2 source refuse native Windows. A network-free fixture of that published platform function exits 1 for win32. Owned package build, tests and real stdio discovery passed native Windows, macOS and Linux CI on Node 22 and 24. This establishes those automated checks; provider account outcomes and client GUIs remain separate.
Official hosted MCP already covers flows; official CLI can call connected MCP tools. No blanket flow absence or absent client approval is claimed. Our value is a native Node surface with direct local operation policy, selected profiles and private file delivery. Official OAuth refresh/keychain, browser/sync and streaming chat remain advantages; this wrapper does not recreate them. More names and SEO alone are not a superiority claim.
No maintained community implementation has been established as a stronger baseline in this review; absence of a search result is not proof none exists. Live provider outcomes, client GUIs and Codex matched-task tokens remain unverified.
Versions and migration
| Component | Baseline |
|---|---|
| Package/desktop | 2.0.1 |
| Current REST schema | OpenAPI 3.0.0/document 1.0.0; checked 2026-10-03 |
| Operations/tools | 91 current REST + list_accounts; 92 shared tools |
| Read/confirmed | 50 reads, 42 confirmed operations |
| Official CLI inspected | PyPI gumloop 0.5.2 |
| Official hosted MCP | 46 documented tools; live discovery unverified |
| Node | 22+; CI targets 22/24 on macOS/Linux/Windows |
| MCP SDK / Ajv / ajv-formats | 1.32.0 / 8.20.0 / 3.0.1 |
| TypeScript / Vitest / Vite / MCPB / YAML | 7.0.2 / 5.0.3 / 8.3.2 / 2.1.2 / 2.9.1 |
The dated CHANGELOG records user-facing changes. Version, annotated default-branch tag, npm dist-tag and desktop archive must agree at release. Preserve AGPL and private legacy history.
Legacy GUMLOOP_API_KEY/USER_ID remain supported. start_flow now uses current named top-level inputs. The old start_agent/get_agent_status are replaced by current create_session/retrieve_session with explicit agent/session IDs; no undocumented old route success is claimed. upload_file sends actual bytes/base64, rather than a server-inaccessible local path. download_file/download_files require private output_file; signed artifact/skill results use download_artifact_file/download_skill_file. Writes and paid Brain search now need confirmation. Re-check scripts/client config during this breaking upgrade.
Updates and removal
npm and client updates
Configs using npx -y @thenavidm/gumloop-mcp-cli@latest resolve the current published version when they launch. Reconnect or restart the MCP client after an update.
npm install -g @thenavidm/gumloop-mcp-cli@latest
gumloop-cli --versionGlobal installs need that command to update. Desktop bundles are separate downloads: install the new .mcpb from the latest release through Extensions settings. Do not assume a manually installed custom bundle updates itself.
Every release is recorded in CHANGELOG.md. Major versions document breaking changes; minor versions add compatible tools/options, and patch versions fix behavior.
Migrating from the old MCP-only server
Keep the old tool names where supported, but change the package to @thenavidm/gumloop-mcp-cli@latest. Node 22 is required. Paid media calls now need confirmation. Downloads now require an explicit flag.
n maps to numVariations where supported. width and height must be supplied together. Fill uses the current async endpoint. Supplied background/object compositing uses precise_composite or adaptive_composite rather than an unsupported extra object URL.
Remove it
npm uninstall -g @thenavidm/gumloop-mcp-cli
claude mcp remove --scope user gumloopIn other clients, remove the Gumloop entry you added. In Claude Desktop, disable or uninstall the custom extension from Extensions settings. Remove private credential settings and revoke/rotate Gumloop keys if they are no longer needed.
Output images and audit logs are your files and are kept. Remove them yourself if desired.
Validation and remaining evidence
Thirty-five behavior/shared-CLI tests pass. Actual stdio discovery returns 92 tools; read-only returns 50 and direct confirmed-operation calls refuse. Seven CI jobs passed Linux, macOS and native Windows builds, tests and protocol discovery on Node 22 and 24, plus desktop packaging. Public npm installation and downloaded desktop discovery are checked separately from authenticated provider-account outcomes and desktop GUI installation.
Runtime dependency audit has zero findings. Development packaging advisories do not ship in runtime artifacts. Public source schemas remove examples and credential-bearing URLs; source history, npm and desktop artifacts are scanned for secrets.
Fresh Codex standing-context and equivalent successful task usage measurements remain pending. Claude Code is optional and its measurements are deferred. The private site scene deployment batch remains separately tracked.
More tools for your workflows
Connect the tools needed for the precise workflow you want.
Gumloop MCP Server & CLI FAQs
Official alternatives, API keys, user/team profiles, flows, sessions, private uploads/downloads, Windows, desktop setup and safeguards.
No.
Navid Media builds this owned wrapper.
Gumloop supplies separate official CLI, hosted MCP and SDKs.
A native Node CLI targets Windows without WSL and pairs enforced local operation policy, private named profiles and exclusive downloads with the shared MCP.
Official OAuth/keychain and other workflows remain useful.
Yes.
Current docs include flows, workbooks and runs.
The official CLI can call connected MCP tools.
No blanket flow-coverage gap is claimed.
Yes. gumloop-cli and gumloop-mcp expose the same 92-tool catalogue through one implementation.
The AGPL wrapper is free.
Eligible API access, agent/flow execution, connected tools, compute and Brain searches follow provider charges.
Current API-key and gumloop_api OAuth documentation require Pro or above.
Team/organization endpoints also need the appropriate provider role.
Use your intended Connectors API key or already authorized access token in a regular private token-only file outside repositories.
Configure the matching user/team identity privately.
Yes.
Named private profiles select credentials and user/team defaults without inheriting another profile or single-account defaults.
Explicit request identities still follow provider permissions.
Use the documented stdio registration or shared shell commands.
Codex is the priority; fresh matched-task usage measurements remain pending.
This package targets native Node 22+ on Windows.
Official gumloop 0.5.2 CLI refuses native Windows; WSL and its Python SDK are alternatives.
Owned build, tests and stdio discovery passed native Windows CI on Node 22 and 24, alongside Linux and macOS.
Provider account and desktop GUI outcomes remain separate.
A versioned .mcpb bundles runtime dependencies for a compatible host.
Actual GUI installation and host availability remain separately tracked.
No.
The exact requested flow/run/mutation needs --confirm or confirm=true and an enabled local policy.
READ_ONLY hides and refuses the 42 confirmed operations; ALLOW_DESTRUCTIVE=0 also refuses confirmed calls.
Read-only is not a provider spend cap.
No.
The provider can process a request before transport failure.
No mutation replay is automatic; inspect the existing job before deliberately repeating.
Inspect get_input_schema and current start_flow schema.
Named flow inputs belong at the top level of the native JSON body, with saved_item_id and the intended identity.
Yes, after confirmation. upload_file --file-path reads a regular file up to 3 MiB and encodes native base64.
Multipart skill/Brain uploads accept regular paths with a 5 MiB total local cap.
Only into a new requested absolute private output_file.
Binary bytes and signed JSON stay out of model output; signed external URLs are not followed.
No automatic OAuth refresh/keychain or streaming chat is provided.
Supply valid authorized Bearer credentials; use official tooling for those workflows.
No measured blanket claim is made.
Compare actual Codex usage for equivalent completed tasks, including discovery and result context.
Tool counts and character estimates are insufficient.
Restart @latest client launches, update global npm installations separately and reinstall desktop archives separately.
Uninstall does not revoke keys, delete provider resources or undo runs.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
Related free tools
Free AI newsletterThe most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.












