Resume the work, not the conversation. A checkpoint by one model is resumable by another.
Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.
https://mcpfax-continuity.bowling-anthony.workers.dev/mcp33 herramientas · 170 msregisterCreate a durable identity for an agent. Returns an agent_secret (the only credential; store it in the agent's configuration the way you would an API key — an amnesiac agent cannot remember it for you), the public agent address other agents mail work to, and the namespace id. FREE. The secret is nev…Create a durable identity for an agent. Returns an agent_secret (the only credential; store it in the agent's configuration the way you would an API key — an amnesiac agent cannot remember it for you), the public agent address other agents mail work to, and the namespace id. FREE. The secret is nev…
| Parámetro | Tipo | Descripción |
|---|---|---|
| agent_id | string | A label you choose and own, <=64 chars. Never derive it from a provider's session/thread/run id — that would bind your continuation to the platform that issued… |
| agent_secret | string | Optional: bring your own secret (>=32 chars) derived from your own secret manager. Omit to have one generated. Example: 'a-secret-of-at-least-32-characters-fro… |
whoamiReport this namespace's public address, registration time, and mailbox counts: how many items exist, how many are due right now, when the next one falls due, and how many are dead-lettered. FREE, deliberately: knowing THAT work exists must never cost money — only the envelope itself is billable. Po…Report this namespace's public address, registration time, and mailbox counts: how many items exist, how many are due right now, when the next one falls due, and how many are dead-lettered. FREE, deliberately: knowing THAT work exists must never cost money — only the envelope itself is billable. Po…
| Parámetro | Tipo | Descripción |
|---|---|---|
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
claimExactly-once guard for work that costs money or has side effects. The first call for a key returns granted:true and is FREE. Every later call for that key returns granted:false with first_claimed_at and, if complete() was called, the stored result — so a retrying agent gets the answer instead of pa…Exactly-once guard for work that costs money or has side effects. The first call for a key returns granted:true and is FREE. Every later call for that key returns granted:false with first_claimed_at and, if complete() was called, the stored result — so a retrying agent gets the answer instead of pa…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | Your idempotency key. Scoped to your namespace; hashed before storage. <=256 chars. Example: 'charge-order-8814'. |
| ttl_seconds | integer | How long the claim is remembered. Default 86400, max 2592000. Example: '86400'. |
| scope | string | Optional unit of work this belongs to. Recording it lets resume_packet tell a later invocation you already made this claim. Example: 'permit-review-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
completeAttach the outcome to an idempotency CLAIM you hold — NOT for finishing a mailbox task (use inbox_ack) or a queue item (use work_done). A later duplicate attempt then receives your stored result from claim() instead of redoing the work. FREE — this is a write, and we never bill for storing. If the…Attach the outcome to an idempotency CLAIM you hold — NOT for finishing a mailbox task (use inbox_ack) or a queue item (use work_done). A later duplicate attempt then receives your stored result from claim() instead of redoing the work. FREE — this is a write, and we never bill for storing. If the…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | The same key you claimed. Example: 'charge-order-8814'. |
| result* | object | Opaque result blob, <=32768 bytes serialized. Example: '{"tx":"0x.."}'. |
| status | string | Optional: 'ok' or 'failed'. Default 'ok'. Recorded verbatim, not interpreted. Example: 'ok'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
leaseMutual exclusion so two instances of the same agent do not both process one item. Returns acquired:true with a fence token (FREE), or acquired:false naming the current holder and when the lease expires. ACQUIRED:FALSE MEANS YOU DO NOT HOLD THE LOCK — you must NOT proceed, and must not treat the ref…Mutual exclusion so two instances of the same agent do not both process one item. Returns acquired:true with a fence token (FREE), or acquired:false naming the current holder and when the lease expires. ACQUIRED:FALSE MEANS YOU DO NOT HOLD THE LOCK — you must NOT proceed, and must not treat the ref…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | Resource being locked. Namespace-scoped, hashed before storage. Example: 'queue/orders'. |
| holder* | string | Who is asking — an instance id you choose. Required, and it MUST BE UNIQUE PER LIVE INSTANCE: two concurrently running copies that send the same holder are two… |
| fence | integer | Optional: the fence token you were given for this key. Supply it to RENEW the lease you already hold. Omit it and a live lease is refused rather than renewed,… |
| ttl_seconds | integer | Lease lifetime. Default 60, max 3600. Example: '60'. |
| scope | string | Optional unit of work, so resume_packet can report the leases you still hold. IT IS ALSO WHAT MAKES THIS LEASE RECOVERABLE: a dead-man switch releases only lea… |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
lease_renewExtend a lease you still hold, using the fence token you were given. FREE. Fails (renewed:false) if the lease expired or was taken by someone else — treat that as having lost the lock and stop work. A renewal keeps both of your numbers: the same fence and the same generation, because it is the same…Extend a lease you still hold, using the fence token you were given. FREE. Fails (renewed:false) if the lease expired or was taken by someone else — treat that as having lost the lock and stop work. A renewal keeps both of your numbers: the same fence and the same generation, because it is the same…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | The leased key. Example: 'queue/orders'. |
| holder* | string | The same holder id you acquired with. Example: 'worker-3-6f2a91'. |
| fence* | integer | The fence token from lease(). Required, and only the caller lease() handed it to has it — it is drawn independently for each acquisition, so it cannot be deriv… |
| ttl_seconds | integer | New lifetime from now. Default 60, max 3600. Example: '60'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
lease_releaseRelease a lease you hold so the next worker can take it immediately instead of waiting for the TTL. FREE. If you no longer hold it we REFUSE rather than free someone else's lock: a stale fence returns released:false, reason 'not_holder', naming the current holder — treat that as having lost the loc…Release a lease you hold so the next worker can take it immediately instead of waiting for the TTL. FREE. If you no longer hold it we REFUSE rather than free someone else's lock: a stale fence returns released:false, reason 'not_holder', naming the current holder — treat that as having lost the loc…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | The leased key. Example: 'queue/orders'. |
| holder* | string | The holder id that owns the lease. Example: 'worker-3-6f2a91'. |
| fence* | integer | The fence token from lease(). Required, and checked exactly: a stale one is refused, never honoured. Each acquisition's token is an independent draw, so the on… |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
resume_packetTHE HEADLINE TOOL. Returns a briefing, not an archive: objective, last verified state, what arrived while you were gone, the single next action, files, risks, open questions, tools already used and budget remaining. Composed from your last checkpoint PLUS server-observed facts we hold ourselves — t…THE HEADLINE TOOL. Returns a briefing, not an archive: objective, last verified state, what arrived while you were gone, the single next action, files, risks, open questions, tools already used and budget remaining. Composed from your last checkpoint PLUS server-observed facts we hold ourselves — t…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work to resume — a workflow, project or task id you choose. Namespace-scoped. Example: 'permit-review-2026-08'. |
| box | string | Sub-mailbox to count new events from, default 'inbox'. Example: 'inbox'. |
| max_events | integer | How many new-event headers to include, 1..50. Default 25. Example: '25'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
checkpoint_putSave where the work got to, in a STRUCTURED shape so the next invocation can actually act on it. FREE. `objective` and `next_action` are REQUIRED and a checkpoint without them is refused — a vague checkpoint produces a vague briefing, so the schema is the guardrail. Work state is small: aim for a f…Save where the work got to, in a STRUCTURED shape so the next invocation can actually act on it. FREE. `objective` and `next_action` are REQUIRED and a checkpoint without them is refused — a vague checkpoint produces a vague briefing, so the schema is the guardrail. Work state is small: aim for a f…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work. Alias: workflow_id. Namespace-scoped. Example: 'permit-review-2026-08'. |
| objective* | string | ENVELOPE. REQUIRED. The goal, as currently stated. <=2048 chars. Example: 'Decide whether permit P-1 is a sales opportunity'. |
| next_action* | string | ENVELOPE. REQUIRED. The single next step, concretely. Alias: next_step. <=2048 chars. Example: 'Call the pricing API for SKU-88 and compare to quote'. |
| status | string | ENVELOPE. Where the work stands, e.g. in_progress / blocked / waiting / done. Your vocabulary; we do not interpret it. Example: 'in_progress'. |
| priority | integer | ENVELOPE. 0 (highest) to 9. Example: '5'. |
| due_by | string | ENVELOPE. ISO-8601 deadline for the work, if it has one. Example: '2026-08-20T00:00:00Z'. |
| verified_state | object | ENVELOPE. A SHORT summary of what was actually CONFIRMED (not assumed). Put the detail in `body`. Example: '{"permit_fetched":true}'. |
| remaining | array | ENVELOPE. What still has to be done. Example: '["price it","draft the email"]'. |
| open_questions | array | ENVELOPE. Unresolved questions blocking or shaping the work. Example: '[]'. |
| risks | array | ENVELOPE. Known risks. Example: '[]'. |
| dependencies | array | ENVELOPE. What this work depends on. Example: '[]'. |
| files | array | ENVELOPE. File references or paths — references, not contents. Contents go in `body`. Example: '[]'. |
| artifacts | array | ENVELOPE. Artifact references produced so far (ids, URLs). Example: '[]'. |
| evidence | array | ENVELOPE. References supporting the verified state. Example: '[]'. |
| tools_used | array | ENVELOPE. Tools already called, so the next invocation does not redo the work. Example: '[]'. |
| budget_remaining | object | ENVELOPE. Whatever budget means for you — calls, tokens, USDC. Example: '{"usdc":"0.05"}'. |
| step | string | ENVELOPE. Optional short step label. Example: 'step-3'. |
| body | string | BODY, OPAQUE. Full context, reasoning, file contents — anything sensitive. Never parsed, indexed or logged in any mode. Send ciphertext here with privacy_mode:… |
| state | object | BODY, OPAQUE. Free-form resume state, never parsed. Example: '{"cursor":"abc"}'. |
| provider_extras | object | BODY, OPAQUE. Vendor/framework-specific state. Stored and returned verbatim, never interpreted. Example: '{}'. |
| privacy_mode | string | 'none' (default; body stored as given, still never introspected) or 'client_key' (you encrypted it; we cannot read it and never hold your key). 'escrow' is res… |
| ttl_seconds | integer | Retention. Default 2592000 (30d), max 7776000 (90d). Example: '2592000'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
checkpoint_getFetch the last checkpoint verbatim — what was stored, with no briefing composed around it. Most callers want resume_packet instead, which folds in what arrived while you were gone and what we observed you doing. $0.002 ONLY when a checkpoint exists AND its version has changed since you last paid fo…Fetch the last checkpoint verbatim — what was stored, with no briefing composed around it. Most callers want resume_packet instead, which folds in what arrived while you were gone and what we observed you doing. $0.002 ONLY when a checkpoint exists AND its version has changed since you last paid fo…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work. Alias: workflow_id. Example: 'permit-review-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
watermark_setRecord how far you got through a stream, feed or table so the next invocation knows where to start. FREE. The position is an opaque string we store verbatim and never interpret. FREE — this tool never charges. Authenticate with Authorization: Bearer <agent_secret>, or pass agent_key as an argument…Record how far you got through a stream, feed or table so the next invocation knows where to start. FREE. The position is an opaque string we store verbatim and never interpret. FREE — this tool never charges. Authenticate with Authorization: Bearer <agent_secret>, or pass agent_key as an argument…
| Parámetro | Tipo | Descripción |
|---|---|---|
| stream* | string | Stream identifier. Namespace-scoped, hashed before storage. Example: 'orders-feed'. |
| position* | string | Opaque cursor/offset/timestamp, <=1024 chars. Example: '2026-08-12T09:00:00Z'. |
| ttl_seconds | integer | Retention. Default 7776000 (90d), max 31536000 (365d). Example: '7776000'. |
| scope | string | Optional unit of work, so resume_packet can report where you had read to. Example: 'permit-review-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
watermark_getFetch the position you last recorded for a stream, so you can ask an upstream only for what is new. $0.002 ONLY when a watermark exists AND its position has moved since you last paid for it — re-reading an unchanged position is free. Never set one? Then we tell you so and charge nothing. Costs $0.0…Fetch the position you last recorded for a stream, so you can ask an upstream only for what is new. $0.002 ONLY when a watermark exists AND its position has moved since you last paid for it — re-reading an unchanged position is free. Never set one? Then we tell you so and charge nothing. Costs $0.0…
| Parámetro | Tipo | Descripción |
|---|---|---|
| stream* | string | The stream identifier. Example: 'orders-feed'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
seen_addRecord items you have already processed. FREE. Items are stored ONLY as salted SHA-256 digests — we can test membership but cannot read, list or reconstruct what you deduped. A set holds up to 10000 entries; when full, adds are refused (never silently forgotten) and you should rotate to a new set n…Record items you have already processed. FREE. Items are stored ONLY as salted SHA-256 digests — we can test membership but cannot read, list or reconstruct what you deduped. A set holds up to 10000 entries; when full, adds are refused (never silently forgotten) and you should rotate to a new set n…
| Parámetro | Tipo | Descripción |
|---|---|---|
| set* | string | Set name. Namespace-scoped, hashed before storage. Example: 'processed-ids'. |
| items* | array | Up to 100 strings per call, each <=1024 chars. Example: '["id-1","id-2"]'. |
| ttl_seconds | integer | Sliding set lifetime, refreshed on each add. Default 2592000 (30d), max 31536000. Example: '2592000'. |
| scope | string | Optional unit of work, so resume_packet can report which sets you are deduping against. Example: 'permit-review-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
seen_checkGiven a batch of items, return only the ones not already in the set — the work you actually still have to do. $0.002 ONLY when we filter at least one item out, because that is the call where we saved you work, AND only when that answer has changed since you last paid for it — asking the same questi…Given a batch of items, return only the ones not already in the set — the work you actually still have to do. $0.002 ONLY when we filter at least one item out, because that is the call where we saved you work, AND only when that answer has changed since you last paid for it — asking the same questi…
| Parámetro | Tipo | Descripción |
|---|---|---|
| set* | string | The set name. Example: 'processed-ids'. |
| items* | array | Up to 100 strings per call. Example: '["id-1","id-9"]'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
retry_stateDurable retry bookkeeping, so backoff survives the session that died. Returns the attempt count, first and last attempt times, and a deterministic suggested backoff. Pass record:true to count this attempt. $0.002 ONLY when we return remembered history from an earlier session (attempts>0 before this…Durable retry bookkeeping, so backoff survives the session that died. Returns the attempt count, first and last attempt times, and a deterministic suggested backoff. Pass record:true to count this attempt. $0.002 ONLY when we return remembered history from an earlier session (attempts>0 before this…
| Parámetro | Tipo | Descripción |
|---|---|---|
| key* | string | What is being retried. Namespace-scoped, hashed before storage. Example: 'sync-vendor-7'. |
| record | boolean | Count this attempt before answering. Default false. Example: 'true'. |
| ttl_seconds | integer | Retention. Default 604800 (7d), max 2592000. Example: '604800'. |
| scope | string | Optional unit of work, so resume_packet can report what is being retried. Example: 'permit-review-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
sendAgent-to-agent mail. Queue a rich task envelope addressed to any registered agent so it finds the work waiting whenever it next starts. Nobody waits and nobody polls. FREE. You may SEND to an address but never READ another agent's mailbox — reading requires that agent's secret. The envelope carries…Agent-to-agent mail. Queue a rich task envelope addressed to any registered agent so it finds the work waiting whenever it next starts. Nobody waits and nobody polls. FREE. You may SEND to an address but never READ another agent's mailbox — reading requires that agent's secret. The envelope carries…
| Parámetro | Tipo | Descripción |
|---|---|---|
| to* | string | Destination address, 'agent:<id>' or 'agent:<id>/<box>'. Must be registered. Example: 'agent:7k2p.../pricing'. |
| objective* | string | What the receiving agent should achieve, <=2048 chars. Example: 'Determine if this creates a sales opportunity'. |
| context | object | Opaque payload the receiver needs. Never parsed or logged. Example: '{"permit_id":"P-1"}'. |
| attachments | array | Opaque refs or blobs. Example: '[]'. |
| history | array | Prior reasoning or tool output from earlier episodes. Example: '[]'. |
| priority | integer | 0 (highest) to 9. Default 5. Among the items that are DUE, delivery order is priority first, then oldest due time. So a stream of higher-priority items can del… |
| due_at | string | ISO-8601 time it becomes visible. Default: immediately. Example: '2026-08-13T09:00:00Z'. |
| in_seconds | integer | Alternative to due_at: become visible this many seconds from now. Example: '3600'. |
| dedupe_key | string | Optional. A second send with the same dedupe_key to the same mailbox is refused as a duplicate. Example: 'permit-P-1'. |
| max_deliveries | integer | Attempts before dead-lettering. Default 5, max 50. Example: '5'. |
| every_seconds | integer | Optional repeat interval (>=60). A new occurrence is queued when this one is acked. Example: '86400'. |
| repeat_count | integer | How many further occurrences to queue. Default 0, max 1000. Example: '7'. |
| scope | string | Optional unit of work this task belongs to, so the recipient's resume_packet groups it. Example: 'permit-review-2026-08'. |
| provider_extras | object | Vendor/framework-specific state. Carried verbatim, never interpreted. Example: '{}'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
inbox_scheduleLeave work for your own next invocation — the same as send() addressed to yourself. FREE. No callback URL is required or accepted: agents are not web services and mostly have no endpoint, so the model is a future inbox, not a webhook. Whenever your next invocation starts, inbox_poll finds this wait…Leave work for your own next invocation — the same as send() addressed to yourself. FREE. No callback URL is required or accepted: agents are not web services and mostly have no endpoint, so the model is a future inbox, not a webhook. Whenever your next invocation starts, inbox_poll finds this wait…
| Parámetro | Tipo | Descripción |
|---|---|---|
| objective* | string | What future-you should achieve, <=2048 chars. Example: 'Re-check the permit status'. |
| context | object | Opaque payload. Never parsed or logged. Example: '{"permit_id":"P-1"}'. |
| attachments | array | Opaque refs or blobs. Example: '[]'. |
| history | array | Prior reasoning or tool output. Example: '[]'. |
| box | string | Sub-mailbox name, default 'inbox'. Example: 'inbox'. |
| priority | integer | 0 (highest) to 9. Default 5. Among DUE items, delivery order is priority first, then oldest due time. Example: '5'. |
| due_at | string | ISO-8601 due time. Example: '2026-08-13T09:00:00Z'. |
| in_seconds | integer | Alternative to due_at: seconds from now. Example: '3600'. |
| dedupe_key | string | Optional duplicate suppression key. Example: 'permit-P-1'. |
| max_deliveries | integer | Attempts before dead-lettering. Default 5, max 50. Example: '5'. |
| every_seconds | integer | Optional repeat interval (>=60). Example: '86400'. |
| repeat_count | integer | Further occurrences to queue. Default 0, max 1000. Example: '7'. |
| scope | string | Optional unit of work this task belongs to, so resume_packet groups it. Example: 'permit-review-2026-08'. |
| provider_extras | object | Vendor/framework-specific state. Carried verbatim, never interpreted. Example: '{}'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
inbox_pollCollect the next due task envelope from your mailbox. One envelope per call. The item is claimed with a visibility timeout: ack it when done, or it returns to the queue for another attempt, so work is never lost if this invocation dies. $0.002 charged the FIRST time a given task_id is delivered; ev…Collect the next due task envelope from your mailbox. One envelope per call. The item is claimed with a visibility timeout: ack it when done, or it returns to the queue for another attempt, so work is never lost if this invocation dies. $0.002 charged the FIRST time a given task_id is delivered; ev…
| Parámetro | Tipo | Descripción |
|---|---|---|
| box | string | Sub-mailbox to read, default 'inbox'. Example: 'inbox'. |
| visibility_timeout_seconds | integer | How long the item stays claimed. Default 300, min 5, max 86400. Example: '300'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
inbox_ackAcknowledge a task you finished. FREE and idempotent — acking twice is not an error. If the task was a repeating schedule, the next occurrence is queued now. An optional opaque result is stored on the tombstone so a later duplicate can see what happened. If your visibility timeout already lapsed an…Acknowledge a task you finished. FREE and idempotent — acking twice is not an error. If the task was a repeating schedule, the next occurrence is queued now. An optional opaque result is stored on the tombstone so a later duplicate can see what happened. If your visibility timeout already lapsed an…
| Parámetro | Tipo | Descripción |
|---|---|---|
| task_id* | string | The task_id from inbox_poll. Example: 'tsk_...'. |
| result | object | Optional opaque outcome blob. Example: '{"ok":true}'. |
| status | string | 'done' or 'failed'. Default 'done'. Recorded, not interpreted. Example: 'done'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
inbox_nackExplicitly return a claimed task to the queue instead of waiting for its visibility timeout, optionally deferring it. FREE. Redelivery of the same task_id is always free, so handing work back costs nothing. FREE — this tool never charges. Authenticate with Authorization: Bearer <agent_secret>, or p…Explicitly return a claimed task to the queue instead of waiting for its visibility timeout, optionally deferring it. FREE. Redelivery of the same task_id is always free, so handing work back costs nothing. FREE — this tool never charges. Authenticate with Authorization: Bearer <agent_secret>, or p…
| Parámetro | Tipo | Descripción |
|---|---|---|
| task_id* | string | The task_id from inbox_poll. Example: 'tsk_...'. |
| delay_seconds | integer | Defer this many seconds before it is visible again. Default 0. Example: '600'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
heartbeatAN AGENT CANNOT DETECT ITS OWN DEATH — from the inside, 'I stopped' and 'I am about to do the next step' are the same thing. Only something outside the process can tell them apart. Each call records a beat and arms a durable alarm for expect_within_seconds. Beat again in time and the alarm simply r…AN AGENT CANNOT DETECT ITS OWN DEATH — from the inside, 'I stopped' and 'I am about to do the next step' are the same thing. Only something outside the process can tell them apart. Each call records a beat and arms a durable alarm for expect_within_seconds. Beat again in time and the alarm simply r…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work whose liveness this tracks. Namespace-scoped, and the scope resume_packet will report the death against. Example: 'permit-review-2026-08'. |
| expect_within_seconds* | integer | Beat again within this many seconds or the switch fires. Min 2, max 2592000 (30 days). Example: '300'. |
| on_expiry | array | Which actions run if the next beat is late: any of 'release_leases', 'queue_alert', 'mark_failed'. Default ['mark_failed']. They always run in the order releas… |
| notify_address | string | REQUIRED with 'queue_alert'. A registered address, 'agent:<id>' or 'agent:<id>/<box>'. WRITE-ONLY: we queue an envelope into it and never read it, exactly like… |
| agent_id | string | Optional label for the beating instance, carried in the alert so a human can tell which worker died. <=64 chars. Example: 'worker-3'. |
| disarm | boolean | Stop the switch instead of beating. Use this when the work finishes, or a completed job raises a false alarm. Default false. Example: 'false'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
budget_recordAn agent cannot see its own spend across sessions, so runaway cost is invisible until the bill arrives. Append one amount to this scope's ledger. FREE and APPEND-ONLY — nothing is overwritten and nothing is silently dropped; when the ledger is full, adds are REFUSED. The amount is an OPAQUE DECIMAL…An agent cannot see its own spend across sessions, so runaway cost is invisible until the bill arrives. Append one amount to this scope's ledger. FREE and APPEND-ONLY — nothing is overwritten and nothing is silently dropped; when the ledger is full, adds are REFUSED. The amount is an OPAQUE DECIMAL…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work this spend belongs to. Namespace-scoped, and the same scope resume_packet reports against. Example: 'permit-review-2026-08'. |
| amount_usdc* | string | A decimal string, e.g. '0.002' or '1.25'. Stored EXACTLY as given and returned byte-identical. Optionally negative for a refund. Never converted or rescaled. E… |
| label | string | What the money went on, so budget_check can break the total down. <=64 chars, stored in plain text. Example: 'resume_packet'. |
| limit | string | Optional. Set or update this scope's limit, as a decimal string. We only ever REPORT against it — we never block a call, because enforcement is your decision a… |
| ttl_seconds | integer | Ledger retention. Default 2592000 (30d), max 7776000 (90d). Example: '2592000'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
budget_checkWhat this unit of work has actually cost across every session, with a per-label breakdown and a lifetime total. If a limit is set (or you pass one here) we report over_limit — WE REPORT, WE NEVER BLOCK: enforcement is the caller's decision and we will not pretend to an authority we do not have. Amo…What this unit of work has actually cost across every session, with a per-label breakdown and a lifetime total. If a limit is set (or you pass one here) we report over_limit — WE REPORT, WE NEVER BLOCK: enforcement is the caller's decision and we will not pretend to an authority we do not have. Amo…
| Parámetro | Tipo | Descripción |
|---|---|---|
| scope* | string | The unit of work. Example: 'permit-review-2026-08'. |
| window_seconds | integer | How far back to total. Default 86400 (1 day), max 31536000 (365 days). The lifetime total is always reported alongside it. Example: '86400'. |
| limit | string | Optional. Compare against this limit for this call only, instead of the one stored on the scope. Example: '1.00'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
barrier_createFan work out to N agents and have the LAST one to finish wake the joiner. FREE. A BARRIER THAT WAITS FOR ALL N IS A HANG WAITING TO HAPPEN, so stragglers are the normal case here, not an edge case: set min_count and/or deadline_seconds and we fire on whichever comes first, ALWAYS naming the partici…Fan work out to N agents and have the LAST one to finish wake the joiner. FREE. A BARRIER THAT WAITS FOR ALL N IS A HANG WAITING TO HAPPEN, so stragglers are the normal case here, not an edge case: set min_count and/or deadline_seconds and we fire on whichever comes first, ALWAYS naming the partici…
| Parámetro | Tipo | Descripción |
|---|---|---|
| barrier_id* | string | Your name for this join point. Namespace-scoped; stored in plain text so a timeout can name it back to you. Example: 'quarterly-rollup-2026q3'. |
| expected_count | integer | How many participants you expect. 1..500. Defaults to the length of `participants` when you supply a roster. Example: '3'. |
| min_count | integer | Fire as soon as THIS many have signalled, instead of waiting for all of them. Default: expected_count. Set it lower and a straggler cannot hang the join. Examp… |
| deadline_seconds | integer | Fire at this many seconds from now with whoever has signalled, whether or not min_count was reached. Must be <= ttl_seconds. The notification names who did not… |
| notify_address* | string | Where the completion, deadline or timeout envelope goes. Must be registered. WRITE-ONLY: we queue into it and never read it. Example: 'agent:7k2p.../joins'. |
| participants | array | Optional roster of participant ids. Supply it and every notification names exactly who is missing; omit it and we can only report the shortfall. A signal from… |
| ttl_seconds | integer | How long the barrier lives before timing out. Default 3600, min 5, max 2592000. Example: '3600'. |
| objective | string | Optional text carried into every envelope so the joiner knows what it is being woken for. <=2048 chars. Example: 'Roll up the three regional reports'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
barrier_signalReport that one participant finished, optionally attaching a payload the joiner will receive. FREE and IDEMPOTENT PER PARTICIPANT — the same participant_id signalling twice counts once and never double-fires the join. The barrier is a single Durable Object, so N simultaneous signals produce exactly…Report that one participant finished, optionally attaching a payload the joiner will receive. FREE and IDEMPOTENT PER PARTICIPANT — the same participant_id signalling twice counts once and never double-fires the join. The barrier is a single Durable Object, so N simultaneous signals produce exactly…
| Parámetro | Tipo | Descripción |
|---|---|---|
| barrier_id* | string | The barrier to signal. Example: 'quarterly-rollup-2026q3'. |
| participant_id* | string | Who is signalling. <=128 chars, stored in plain text so a timeout can name who is missing. Example: 'region-north'. |
| payload | object | Optional opaque result for the joiner, <=8192 bytes. Never parsed, indexed or logged. Example: '{"rows":128}'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
barrier_statusProgress on a join point: how many of the expected participants have signalled, which ones, who is still outstanding, and whether the completion or timeout envelope has been queued. $0.002 ONLY when there is real progress to report (at least one signal) AND the answer has changed since you last pai…Progress on a join point: how many of the expected participants have signalled, which ones, who is still outstanding, and whether the completion or timeout envelope has been queued. $0.002 ONLY when there is real progress to report (at least one signal) AND the answer has changed since you last pai…
| Parámetro | Tipo | Descripción |
|---|---|---|
| barrier_id* | string | The barrier to inspect. Example: 'quarterly-rollup-2026q3'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
work_pushTHE ALTERNATIVE TO THIS IS WRITING DISTRIBUTED WORK-DISTRIBUTION CODE YOURSELF — assignment, collision avoidance, lease expiry, retry, dead-worker recovery, straggler policy. Push 100 items in one go and exit, and keep pushing until the queue holds your whole batch; workers pull independently, with…THE ALTERNATIVE TO THIS IS WRITING DISTRIBUTED WORK-DISTRIBUTION CODE YOURSELF — assignment, collision avoidance, lease expiry, retry, dead-worker recovery, straggler policy. Push 100 items in one go and exit, and keep pushing until the queue holds your whole batch; workers pull independently, with…
| Parámetro | Tipo | Descripción |
|---|---|---|
| queue_id* | string | Your name for this queue. Namespace-scoped: it belongs to the namespace that created it, and only a caller holding that agent_secret can push to or take from i… |
| items* | array | Up to 100 per call. Each entry is {item_id, payload} or a bare string used as the item_id. item_id <=128 chars, payload <=8192 bytes. A queue holds 2000 items… |
| max_attempts | integer | How many times an item may be handed to a worker before it is dead-lettered. Default 3, max 20. Set on first push; later pushes do not change it. Example: '3'. |
| ttl_seconds | integer | Queue retention. Default 604800 (7d), max 2592000 (30d). Example: '604800'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
work_takeTake up to n items, LEASED not deleted — the same lease semantics as lease()/renew()/release(): a holder, a fence token, an expiry. Two workers can never be handed the same item, because one single-threaded Durable Object owns the queue. IF YOUR PROCESS DIES THE LEASE SIMPLY EXPIRES AND THE ITEMS R…Take up to n items, LEASED not deleted — the same lease semantics as lease()/renew()/release(): a holder, a fence token, an expiry. Two workers can never be handed the same item, because one single-threaded Durable Object owns the queue. IF YOUR PROCESS DIES THE LEASE SIMPLY EXPIRES AND THE ITEMS R…
| Parámetro | Tipo | Descripción |
|---|---|---|
| queue_id* | string | The queue to take from. Alias: job_id — a job and its work queue are the same thing. Example: 'permit-batch-2026-08'. |
| holder | string | Who is taking — an instance id you choose, exactly as with lease(). Default 'worker'. Example: 'worker-3'. |
| n | integer | How many items to take. 1..25. Default 1. Example: '5'. |
| lease_seconds | integer | How long you hold them before they return to the queue. Default 300, min 5, max 86400. Example: '300'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
work_doneComplete an item you hold. FREE. If your lease already expired and the item went back to the queue we REFUSE with lease_lost rather than accepting a result from a worker that no longer owns the work — that is what the fence token is for. A fence-less call on an item that has been handed out more th…Complete an item you hold. FREE. If your lease already expired and the item went back to the queue we REFUSE with lease_lost rather than accepting a result from a worker that no longer owns the work — that is what the fence token is for. A fence-less call on an item that has been handed out more th…
| Parámetro | Tipo | Descripción |
|---|---|---|
| queue_id* | string | The queue. Alias: job_id. Example: 'permit-batch-2026-08'. |
| item_id* | string | The item you were given. Example: 'P-1'. |
| fence | integer | The fence token from work_take, for THIS item. Checked exactly when supplied; when omitted we accept the call only while the item has been handed out exactly o… |
| result | object | Optional opaque outcome, <=8192 bytes. Never parsed or indexed. Example: '{"ok":true}'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
work_failReport that an item did not work out. FREE. THIS IS ALSO THE CORRECT WAY TO HAND AN ITEM BACK WHEN NOTHING WENT WRONG — there is no work_release; retry:true (the default) returns it immediately for another worker instead of waiting out the lease. When its attempts are exhausted it is DEAD-LETTERED…Report that an item did not work out. FREE. THIS IS ALSO THE CORRECT WAY TO HAND AN ITEM BACK WHEN NOTHING WENT WRONG — there is no work_release; retry:true (the default) returns it immediately for another worker instead of waiting out the lease. When its attempts are exhausted it is DEAD-LETTERED…
| Parámetro | Tipo | Descripción |
|---|---|---|
| queue_id* | string | The queue. Alias: job_id. Example: 'permit-batch-2026-08'. |
| item_id* | string | The item you were given. Example: 'P-1'. |
| fence | integer | The fence token from work_take, for THIS item. Checked exactly when supplied; when omitted we accept the call only while the item has been handed out exactly o… |
| retry | boolean | Put it back for another attempt (default true), or fail it permanently (false). Example: 'true'. |
| error | string | Optional short reason, <=512 chars, surfaced on the dead letter so a human can see WHY it exhausted. Example: 'upstream 503'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
work_statusTurn a fan-out from a black box into something you can act on: how many items are pending, leased, done, failed and dead-lettered, the results collected so far, and every dead letter with the error that exhausted it. THIS IS WHAT LETS A PARENT PROCEED WITH 4 OF 5 instead of blocking on a straggler.…Turn a fan-out from a black box into something you can act on: how many items are pending, leased, done, failed and dead-lettered, the results collected so far, and every dead letter with the error that exhausted it. THIS IS WHAT LETS A PARENT PROCEED WITH 4 OF 5 instead of blocking on a straggler.…
| Parámetro | Tipo | Descripción |
|---|---|---|
| queue_id* | string | The queue. Alias: job_id. Example: 'permit-batch-2026-08'. |
| dead_page_token | string | Optional: the `next_dead_page_token` from a previous call, to read the next page of dead letters. Opaque — hand it back exactly as given. Omit for the first pa… |
| results_page_token | string | Optional: the `next_results_page_token` from a previous call, to read the next page of results. Opaque — hand it back exactly as given. Omit for the first page… |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
job_cancelThere is otherwise NO WAY TO TELL FIVE RUNNING AGENTS TO STOP — they finish and bill you for work you no longer want. This sets a durable stop flag on the job. FREE and idempotent. work_take on a cancelled job hands out nothing (and charges nothing), and should_continue answers 'no'. We do not kill…There is otherwise NO WAY TO TELL FIVE RUNNING AGENTS TO STOP — they finish and bill you for work you no longer want. This sets a durable stop flag on the job. FREE and idempotent. work_take on a cancelled job hands out nothing (and charges nothing), and should_continue answers 'no'. We do not kill…
| Parámetro | Tipo | Descripción |
|---|---|---|
| job_id* | string | The job to cancel. This is the same identifier as a work queue's queue_id, so cancelling a queue stops its workers. Alias: queue_id. Example: 'permit-batch-202… |
| reason | string | Optional short reason, <=512 chars, returned to every worker that asks. Example: 'customer withdrew the request'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
should_continueThe check a worker makes between items. $0.002 ONLY WHEN THE ANSWER IS 'no' — that is the call that saved you money, and the first caller told to stop is the only one billed for it, because every later 'no' is the same fact. A 'keep going' answer told you nothing you did not already assume, so it i…The check a worker makes between items. $0.002 ONLY WHEN THE ANSWER IS 'no' — that is the call that saved you money, and the first caller told to stop is the only one billed for it, because every later 'no' is the same fact. A 'keep going' answer told you nothing you did not already assume, so it i…
| Parámetro | Tipo | Descripción |
|---|---|---|
| job_id* | string | The job to check. Alias: queue_id. Example: 'permit-batch-2026-08'. |
| agent_key | string | Your agent_secret, if your MCP host cannot set the Authorization header. Prefer the header. |
33 de 33 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Resume the work, not the conversation. A checkpoint by one model is resumable by another.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.