de.agentview/agentview-mcp

MCPcommunautéen ligne
v1.0.0de.agentviewUnknownMis à jour il y a 6 mois

Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.

État de l’endpointen ligne
vérifié il y a 2 jours · 885 ms
100 % des dernières 6 vérifications ont atteint cet endpoint
Fonctionne dans
ClaudeCursorCopilotChatGPTGemini

Déduit des transports déclarés par cette annonce (streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
il y a 6 moisDernière mise à jour
Paquet
Auteurde.agentview
LicenceUnknown
Version1.0.0
Sourcemcp-registry
Statut de confiance
D
30/100Risque
✓Listé dans l’index Forge+10/10
—Identité de l’éditeur vérifiée+0/30
→ Éditeur : aucune référence de dépôt n’est enregistrée pour cette annonce, `forge publish` ne peut donc pas vérifier la propriété automatiquement. Utilisez « Revendiquer cette annonce » ci-dessus — Forge les examine à la main.
—Vérification de domaine+0/10
→ Actuellement indisponible pour ce type d’annonce — la vérification de domaine ne s’exécute aujourd’hui que pour les paquets adossés à npm, cette ligne ne peut donc pas encore être obtenue ici, quel que soit le contenu hébergé sur le domaine.
—Analyse d’injection de prompt · constats+0/30
→ Éditeur : retirez du code les instructions destinées aux clients d’IA plutôt qu’à des lecteurs humains
✓Analyse d’obfuscation / exfiltration · propre+20/20
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance—
DépendancesNon audité
Surface d’outils57 outils · 7 privilégiés
Analyse de sécurité⚠ Avertissements (1)vlive · il y a 1 moisQuelle est l’efficacité de cette analyse ?
PROMPTtool:authenticate#jwtExfiltration-shaped instruction
PROMPTtool:send_url#urlLinks to undeclared domain: example.com
PROMPTtool:pair_by_codeLinks to undeclared domain: display.agentview.de
PROMPTtool:get_agent_artifactReferences the system prompt
ÉvaluationsAucune
Indexé13 juin 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

57 outils · 7 privilégiés · 1 signalés pour injection
Observé en direct depuis l’endpoint du fournisseur1mo ago

Lu depuis un véritable échange MCP initialize → tools/list contre l’endpoint déclaré. Aucun outil n’a été invoqué — tools/list est l’appel d’introspection en lecture seule que le protocole prévoit pour cela. Cela reflète ce que le serveur annonçait à cet instant ; un endpoint hébergé n’est figé sur aucune version et peut changer sans préavis.

  • https://agentview.de/mcp57 outils · 1247 ms
assign_display_categoriesAssigns displays to categories. mode 'replace' (default) sets the full category list of each display in display_ids to category_ids; mode 'add' or 'remove' adds/removes one category (category_ids[0]) across many displays without touching other assignments. Discover IDs with list_display_categories;…

Assigns displays to categories. mode 'replace' (default) sets the full category list of each display in display_ids to category_ids; mode 'add' or 'remove' adds/removes one category (category_ids[0]) across many displays without touching other assignments. Discover IDs with list_display_categories;…

ParamètreTypeDescription
display_ids*arrayDisplay profile IDs to update.
category_ids*arrayCategory IDs; for mode 'add'/'remove' only the first entry is used.
modestringreplace (default) sets the exact list; add/remove mutates one category across displays.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_data_slotsLists data slots with optional filtering. Returns metadata only (no jsonContent). Each item includes readUrl. Use readUrl in display HTML fetch() calls. Requires authentication.

Lists data slots with optional filtering. Returns metadata only (no jsonContent). Each item includes readUrl. Use readUrl in display HTML fetch() calls. Requires authentication.

ParamètreTypeDescription
group_idstringGroup/organization ID to list shared group slots. Omit for personal slots.
searchstringSearch in label (case-insensitive).
limitintegerMaximum results (default: 50, max: 200).
offsetintegerOffset for pagination.
access_tokenstringOptional bearer token; prefer session_request_id.
set_display_grantGrants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status) or 'control' (send content); action 'remove' revokes it. The target user must be an organization member. Requires admin scope.

Grants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status) or 'control' (send content); action 'remove' revokes it. The target user must be an organization member. Requires admin scope.

ParamètreTypeDescription
org_id*stringOrganization ID.
display_id*stringDisplay profile ID.
target_user_id*stringUser to grant or revoke.
actionstring'set' (default) creates/updates the grant; 'remove' revokes it.
access_levelstringRequired for action 'set'.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
authenticaterisque d’injectionValidates a JWT agent token and caches the identity on this MCP session so later calls work without resending it. Use only when your client cannot send an Authorization: Bearer header; prefer session_request_id-based auth via create_auth_session. Not needed after get_auth_session returned 'active'.

Validates a JWT agent token and caches the identity on this MCP session so later calls work without resending it. Use only when your client cannot send an Authorization: Bearer header; prefer session_request_id-based auth via create_auth_session. Not needed after get_auth_session returned 'active'.

INJECTIONDans le paramètre jwt : Exfiltration-shaped instructione this if your wrapper cannot send the 'token' field reliably.
ParamètreTypeDescription
tokenstringThe raw JWT token string returned by get_auth_session or an OAuth access token. Pass the opaque token exactly as received — do not add a 'Bearer ' prefix and d…
jwtstringAlias for token. Use this if your wrapper cannot send the 'token' field reliably.
access_tokenstringAlias for token. Use this if your wrapper follows OAuth naming conventions.
create_api_keyCreates a long-lived API key for server-to-server integration without OAuth. The raw key is returned only once — store it securely. The user must explicitly consent to creating the key. Requires admin scope. Supports granular scoping: restrict the key to specific data-slot slugs, specific display I…

Creates a long-lived API key for server-to-server integration without OAuth. The raw key is returned only once — store it securely. The user must explicitly consent to creating the key. Requires admin scope. Supports granular scoping: restrict the key to specific data-slot slugs, specific display I…

ParamètreTypeDescription
name*stringHuman-readable name for the key. Example: 'Home Assistant', 'CI Pipeline'.
scopestringScope for the key: 'content_only' (send content, list displays) or 'admin' (full management).
org_idstringOptional organization ID. If set, the key acts on behalf of this organization.
expires_in_daysintegerOptional expiration in days. If not set, the key never expires.
permissionsstringGranular permission flag: 'read', 'write', or 'read_write' (default). Applied on top of 'scope' — e.g. a content_only read-only key cannot PUT data slots. Matc…
allowed_slot_slugsarrayOptional JSON array of data-slot slugs this key may touch (max 64). When set, every data-slot request must target one of these slugs. Omit or pass [] for no sl…
allowed_display_idsarrayOptional JSON array of display profile IDs this key may touch (max 64). When set, every display request must target one of these IDs. Omit or pass [] for no di…
capabilitiesarrayOptional JSON array of fine-grained capability flags this key may exercise. Allowed values: 'slot.read' (list/get slots), 'slot.write' (put/delete slots), 'dis…
access_tokenstringOptional bearer token; prefer session_request_id.
get_data_slotReturns the current JSON content and metadata of a data slot by slug. Supply group_id to look up a group slot; omit it for personal slots. The response includes readUrl — the public anonymous URL for display HTML to fetch. Requires authentication.

Returns the current JSON content and metadata of a data slot by slug. Supply group_id to look up a group slot; omit it for personal slots. The response includes readUrl — the public anonymous URL for display HTML to fetch. Requires authentication.

ParamètreTypeDescription
slug*stringThe slug of the data slot to retrieve.
group_idstringGroup/organization ID to retrieve a group slot. Omit for personal slots.
access_tokenstringOptional bearer token; prefer session_request_id.
get_storage_usageReturns the storage pool snapshot (used, limit and remaining bytes) for the personal scope or a group — data slots and uploaded assets share this quota; check before large set_data_slot or upload_asset writes. Pass slug to additionally scan which displays reference that data slot (do this before de…

Returns the storage pool snapshot (used, limit and remaining bytes) for the personal scope or a group — data slots and uploaded assets share this quota; check before large set_data_slot or upload_asset writes. Pass slug to additionally scan which displays reference that data slot (do this before de…

ParamètreTypeDescription
group_idstringGroup/organization ID for the group pool. Omit for the personal pool.
slugstringOptional data-slot slug: also report which displays reference it (slotUsage).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
broadcast_contentSends HTML to many displays at once. Target explicit display_ids, all=true for every accessible display, or include_category_ids to reach every display in those categories (include_descendants for subcategories, dry_run to preview matches without sending). Locked displays are skipped with reasons.…

Sends HTML to many displays at once. Target explicit display_ids, all=true for every accessible display, or include_category_ids to reach every display in those categories (include_descendants for subcategories, dry_run to preview matches without sending). Locked displays are skipped with reasons.…

ParamètreTypeDescription
descriptionstringShort summary of the content being sent (required when sending).
htmlstringComplete HTML document. Mutually exclusive with base64_html.
base64_htmlstringBase64-encoded HTML. Mutually exclusive with html.
display_idsarrayDisplay profile IDs to target.
allbooleantrue targets all accessible displays.
include_category_idsarrayCategory IDs: broadcast to displays assigned to these categories.
include_descendantsbooleanWith include_category_ids: also include subcategories.
dry_runbooleanPreview: return the matched displays without sending. Works with all targeting modes.
durationintegerSeconds the content stays; 0 = indefinite.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
manage_licensesManages premium display licenses: action 'allocate' sets how many license slots an organization gets (licenses, 0 deallocates all), 'assign' binds a free license to a display, 'unassign' releases a display's license back to the pool. Check availability first with get_license_info. Requires admin sc…

Manages premium display licenses: action 'allocate' sets how many license slots an organization gets (licenses, 0 deallocates all), 'assign' binds a free license to a display, 'unassign' releases a display's license back to the pool. Check availability first with get_license_info. Requires admin sc…

ParamètreTypeDescription
action*stringLicense operation.
org_idstringOrganization ID (action 'allocate').
licensesintegerLicense slot count for 'allocate'; 0 deallocates all.
display_idstringDisplay profile ID (actions 'assign' and 'unassign').
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_public_statusReturns the server's public readiness status, version string and discovery URLs. Use this before authenticating to verify the server is reachable and to obtain entry-point URLs. No authentication required. Returns status ('ready'), server name, version, statusUrl and instructionsUrl.

Returns the server's public readiness status, version string and discovery URLs. Use this before authenticating to verify the server is reachable and to obtain entry-point URLs. No authentication required. Returns status ('ready'), server name, version, statusUrl and instructionsUrl.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_displayReturns one display's state: status, lock, URLs, settings, language and current content summary. response_format 'detailed' adds browser/runtime facts (screen, viewport, engine), resolved connectivity mode with allowed domains, and full content state (idle content, content URL) — use detailed befor…

Returns one display's state: status, lock, URLs, settings, language and current content summary. response_format 'detailed' adds browser/runtime facts (screen, viewport, engine), resolved connectivity mode with allowed domains, and full content state (idle content, content URL) — use detailed befor…

ParamètreTypeDescription
display_id*string8-character display profile ID from list_displays, e.g. 'ABCD1234'.
response_formatstringconcise (default) returns key fields; detailed adds runtime facts, connectivity/capabilities and full content state.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
create_auth_sessionStarts a browser login and returns a loginUrl plus sessionRequestId. Use as STEP 0 in a fresh conversation before any protected tool. Show the loginUrl to the user as a clickable link in their language, then poll get_auth_session until 'active' and pass session_request_id on every later call. Retur…

Starts a browser login and returns a loginUrl plus sessionRequestId. Use as STEP 0 in a fresh conversation before any protected tool. Show the loginUrl to the user as a clickable link in their language, then poll get_auth_session until 'active' and pass session_request_id on every later call. Retur…

ParamètreTypeDescription
agent_identifierstringOptional display name of the MCP client or agent, shown to the user in the browser consent screen. Example: 'ChatGPT' or 'my-home-automation'.
scopestringRequested access scope. Must be either 'content_only' (read and send content to displays) or 'admin' (content_only plus create/delete/rename displays). Default…
list_store_categoriesLists all published agentView store categories (e.g. Gastronomie, Wartezimmer, Empfang, Smart Home) with localized titles, descriptions and template counts. Use this to narrow a subsequent search_store_templates call when the user asks for 'templates for a waiting room' or similar. No authenticatio…

Lists all published agentView store categories (e.g. Gastronomie, Wartezimmer, Empfang, Smart Home) with localized titles, descriptions and template counts. Use this to narrow a subsequent search_store_templates call when the user asks for 'templates for a waiting room' or similar. No authenticatio…

ParamètreTypeDescription
languagestringPreferred content language. Defaults to 'en'.
send_store_template_to_displayInstalls a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within seconds. Call get_store_template_install_options first for valid targets and slots; customize per-slot JSON inline via data_slot_overrides (raw J…

Installs a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within seconds. Call get_store_template_install_options first for valid targets and slots; customize per-slot JSON inline via data_slot_overrides (raw J…

ParamètreTypeDescription
slug*stringTemplate slug to install, e.g. 'bistro-warm-door'. Must be a currently published template.
display_id*stringDisplay profile ID (8-char alphanumeric) from list_displays or get_store_template_install_options.
data_slot_overridesobjectOptional { key: value } map keyed by data-slot key (see requiredDataSlots). Each value is JSON payload to install into that slot — either a string of raw JSON…
idempotency_keystringOptional opaque key (max 128 chars) to make this install retry-safe. If a previous successful install for the same (user, display, idempotency_key) tuple exist…
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
create_displayPre-provisions a display without hardware, personal or inside an organization (org_id). The new display starts offline. For a physical screen ALWAYS prefer pair_by_code, which creates and pairs in one step; use create_display only to prepare a display before the screen exists or for virtual/API-onl…

Pre-provisions a display without hardware, personal or inside an organization (org_id). The new display starts offline. For a physical screen ALWAYS prefer pair_by_code, which creates and pairs in one step; use create_display only to prepare a display before the screen exists or for virtual/API-onl…

ParamètreTypeDescription
namestringFriendly display name, e.g. 'Lobby Screen'. Required when org_id is set.
org_idstringOptional: create the display inside this organization (needs manager role and a free license slot).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
delete_data_slotprivilégiéPermanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; omit for personal slots. Requires authentication.

Permanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; omit for personal slots. Requires authentication.

ParamètreTypeDescription
slug*stringThe slug of the data slot to delete.
group_idstringGroup/organization ID to delete a group slot. Omit for personal slots.
access_tokenstringOptional bearer token; prefer session_request_id.
get_license_infoReturns the authenticated user's complete license allocation overview: total premium licenses, personal usage, allocatable licenses, per-organization allocations, and free licenses. Use this to understand available capacity before allocating licenses. Requires content_only scope.

Returns the authenticated user's complete license allocation overview: total premium licenses, personal usage, allocatable licenses, per-organization allocations, and free licenses. Use this to understand available capacity before allocating licenses. Requires content_only scope.

ParamètreTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
get_organizationReturns one organization's details: plan, your role, display count, allocated and remaining license slots. response_format 'detailed' adds the full member list (with roles) and display list. Use after list_organizations. Requires content scope and membership.

Returns one organization's details: plan, your role, display count, allocated and remaining license slots. response_format 'detailed' adds the full member list (with roles) and display list. Use after list_organizations. Requires content scope and membership.

ParamètreTypeDescription
org_id*stringOrganization ID from list_organizations or get_account.
response_formatstringconcise (default) returns counts and core fields; detailed adds members and displays arrays.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
remove_display_from_orgprivilégiéRemoves a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.

Removes a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.

ParamètreTypeDescription
org_id*stringThe organization ID.
display_id*stringThe display profile ID to remove.
access_tokenstringOptional bearer token; prefer session_request_id.
set_data_slotCreates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stable; reusing it updates in place. type 'value' stores JSON verbatim; 'aggregate' composes up to 32 sources ({slot:'name'} or one {prefixMatch…

Creates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stable; reusing it updates in place. type 'value' stores JSON verbatim; 'aggregate' composes up to 32 sources ({slot:'name'} or one {prefixMatch…

ParamètreTypeDescription
slug*stringStable slug for the data slot. Must match ^[A-Za-z0-9_-]{8,64}$. Same slug on a later call updates the existing slot. Slug stays exactly as supplied; the publi…
content*—JSON content to store. For value slots: any valid JSON value up to 2 MB. For aggregate slots: a definition object { sources: [{slot,as?} | {prefixMatch}], onMi…
labelstringHuman-readable label (max 200 chars). Required when creating a new slot; optional on update.
group_idstringGroup/organization ID for shared group slots. Omit for personal slots.
typestringSlot kind. 'value' (default) stores 'content' verbatim. 'aggregate' stores 'content' as a composite-slot definition. Immutable after creation.
access_tokenstringOptional bearer token; prefer session_request_id.
submit_feedbackSends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user before sending; optional sentiment. There is no automatic reply. Requires content scope.

Sends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user before sending; optional sentiment. There is no automatic reply. Requires content scope.

ParamètreTypeDescription
message*stringThe user's verbatim feedback text (max 2000 characters). Pass what the user actually said; do not paraphrase or add your own commentary.
sentimentstringOptional overall sentiment of the feedback. Set only when the user's tone is clear; omit if unsure.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
upload_assetprivilégiéUpload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets are cached on displays. Pass files as base64-encoded data. Requires authentication with at least content_only scope.

Upload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets are cached on displays. Pass files as base64-encoded data. Requires authentication with at least content_only scope.

ParamètreTypeDescription
files*arrayArray of file objects, each with 'name' (filename with extension) and 'data' (base64-encoded content).
descriptions*objectJSON object mapping each filename to a human-readable description.
group_idstringOptional group ID to associate the assets with.
access_tokenstringOptional bearer token; prefer session_request_id.
configure_displayUpdates display settings: rename (name), lock or unlock content changes (locked), privacy mode for share links (privacy_mode), embed-origin allowlist (origins), hardware permissions (camera, microphone, geolocation), preferred language, mouse cursor, badge overlay and watermark position. Only the f…

Updates display settings: rename (name), lock or unlock content changes (locked), privacy mode for share links (privacy_mode), embed-origin allowlist (origins), hardware permissions (camera, microphone, geolocation), preferred language, mouse cursor, badge overlay and watermark position. Only the f…

ParamètreTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
namestringNew display name (rename).
lockedbooleantrue blocks content changes until unlocked; false unlocks.
privacy_modestringPrivate caps share-link TTL at 1 hour; Public (signage mode) allows 24 hours.
originsarrayEmbed-origin allowlist for Public displays; [] allows all origins.
allow_cameraboolean—
allow_microphoneboolean—
allow_geolocationboolean—
preferred_languagestring—
show_mouse_cursorboolean—
show_badge_overlayboolean—
watermark_positionstring—
connectivity_modestringPer-display network mode override.
whitelistarrayDomain whitelist for whitelist-only mode.
strict_whitelistbooleantrue: the display whitelist replaces the org whitelist instead of extending it.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
search_public_apisSearches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images, food and 40+ more categories. Use when generating HTML that needs live internet data. Set list_categories=true to get the category menu wi…

Searches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images, food and 40+ more categories. Use when generating HTML that needs live internet data. Set list_categories=true to get the category menu wi…

ParamètreTypeDescription
querystringFree-text search, e.g. 'weather forecast', 'bitcoin price', 'jokes'.
categorystringCategory ID filter, e.g. 'weather', 'finance', 'news'. Omit for all.
cors_onlybooleantrue returns only APIs with confirmed browser CORS support. Default false.
list_categoriesbooleantrue returns all categories with API counts instead of search results.
limitintegerMaximum results, 1-20. Default 10.
claim_displayAdopts an unclaimed guest or pending display as a managed personal display (permanent ownership transfer, counts against quota). Use only when the user explicitly wants to take over hardware that is already running; for first-time setup prefer pair_by_code. Requires admin scope.

Adopts an unclaimed guest or pending display as a managed personal display (permanent ownership transfer, counts against quota). Use only when the user explicitly wants to take over hardware that is already running; for first-time setup prefer pair_by_code. Requires admin scope.

ParamètreTypeDescription
display_id*stringThe short ID of the pending, guest or demo display to claim. This is the hardware or temporary ID shown on the device.
profile_name*stringFriendly name to assign to the newly claimed display. Non-empty string. Example: 'Reception Kiosk'.
access_tokenstringOptional bearer token; prefer session_request_id.
send_urlShows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first whe…

Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first whe…

NOTEDans le paramètre url : Links to undeclared domain: example.com
ParamètreTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
url*stringAbsolute HTTP or HTTPS URL to load, e.g. 'https://example.com/dashboard'.
slotstring'live' (default) or 'idle' for default/fallback content (admin scope).
durationintegerSeconds the content stays; 0 = indefinite (default). Live slot only.
content_descriptionstringShort summary of what the page shows (recommended).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
clear_displayRemoves the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants to blank or reset a display. This does not delete the display itself — use delete_display for that. Requires authentication with at least c…

Removes the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants to blank or reset a display. This does not delete the display itself — use delete_display for that. Requires authentication with at least c…

ParamètreTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID to clear, e.g. 'ABCD1234'.
access_tokenstringOptional bearer token; prefer session_request_id.
get_accountReturns the user's account profile: plan and features, personal display limits and remaining quota, accessible display count, organization memberships and points balance. Use for subscription, quota and membership questions. Not for listing displays (use list_displays). Requires content scope.

Returns the user's account profile: plan and features, personal display limits and remaining quota, accessible display count, organization memberships and points balance. Use for subscription, quota and membership questions. Not for listing displays (use list_displays). Requires content scope.

ParamètreTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
delete_assetprivilégiéDeletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.

Deletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.

ParamètreTypeDescription
asset_ids*arrayOne or more asset IDs to delete.
access_tokenstringOptional bearer token; prefer session_request_id.
get_store_template_contentReturns the raw display HTML of a published store template plus its slot definitions and allowed external origins, for editing or embedding the template yourself. {{asset:NAME}} placeholders resolve to public URLs; {{slot:KEY.prop}} stay intact for your own binding. Large HTML is windowed via max_b…

Returns the raw display HTML of a published store template plus its slot definitions and allowed external origins, for editing or embedding the template yourself. {{asset:NAME}} placeholders resolve to public URLs; {{slot:KEY.prop}} stay intact for your own binding. Large HTML is windowed via max_b…

ParamètreTypeDescription
slug*stringTemplate slug from search_store_templates, e.g. 'bistro-warm-door'.
versionstringOptional published version id (stpv_…) to pin. Omit for current.
offsetintegerByte offset into the HTML. Default 0.
max_bytesintegerMaximum HTML bytes to return. Default 51200.
get_auth_sessionPolls a login session created by create_auth_session until the user completes the browser login. Poll every 2-3 seconds while status is 'pending'. Status 'active' auto-authenticates this MCP session — protected tools work immediately; keep passing session_request_id on later calls (the raw token is…

Polls a login session created by create_auth_session until the user completes the browser login. Poll every 2-3 seconds while status is 'pending'. Status 'active' auto-authenticates this MCP session — protected tools work immediately; keep passing session_request_id on later calls (the raw token is…

ParamètreTypeDescription
session_request_id*stringThe sessionRequestId string returned by create_auth_session. Must be passed exactly as received.
send_htmlShows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idle' stores the default/fallback content shown when nothing live is active (idle requires admin scope). Always pass a short description so la…

Shows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idle' stores the default/fallback content shown when nothing live is active (idle requires admin scope). Always pass a short description so la…

ParamètreTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
description*stringShort human-readable summary of the content, e.g. 'Weekly KPI dashboard'.
htmlstringComplete HTML document to render. Mutually exclusive with base64_html.
base64_htmlstringBase64-encoded HTML (standard base64). Use only when raw HTML cannot survive JSON transport. Mutually exclusive with html.
slotstringTarget slot: 'live' (default) replaces current content; 'idle' sets the default shown when idle (admin scope).
durationintegerSeconds the content stays; 0 = indefinite (default). Live slot only.
tokenstringDisplay-specific demo/preview token for unauthenticated access. NOT the OAuth token.
access_tokenstringOptional bearer token; prefer session_request_id. Distinct from the display-specific 'token'.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
delete_displayprivilégiéPermanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requires admin scope. Returns id, name and deleted (boolean true).

Permanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requires admin scope. Returns id, name and deleted (boolean true).

ParamètreTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID to delete, e.g. 'ABCD1234'.
access_tokenstringOptional bearer token; prefer session_request_id.
logoutClears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.

Clears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.

Aucun schéma d’entrée n’a été publié pour cet outil.

search_store_templatesSearches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pre-built design instead of generated HTML; results render as a gallery widget. Filter by category, suite and language; paginate with limit/o…

Searches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pre-built design instead of generated HTML; results render as a gallery widget. Filter by category, suite and language; paginate with limit/o…

ParamètreTypeDescription
querystringFree-text search over template title, description and tags. Examples: 'Zahnarzt', 'italienisches Bistro', 'conference room'.
categorystringOptional category slug to restrict the search (English kebab-case, e.g. 'gastronomie', 'waiting-room').
suitestringOptional design-family suite slug (e.g. 'bistro-warm', 'sushi-minimal').
languagestringPreferred content language. Defaults to 'en'.
limitintegerMaximum number of templates to return. Defaults to 10.
offsetintegerOffset into the filtered result set for pagination. Defaults to 0.
searchSearches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippets to read via fetch. Unauthenticated searches cover public docs only. Skip when you already know the URI — call fetch directly.

Searches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippets to read via fetch. Unauthenticated searches cover public docs only. Skip when you already know the URI — call fetch directly.

ParamètreTypeDescription
querystringFree-text search terms. Examples: a display name, 'account', 'OAuth', 'status'. At least one of query or resource_type should be provided.
resource_typestringRestricts results to a specific resource category. Must be one of: 'all', 'documentation', 'status', 'account', 'display', 'api'. Defaults to 'all' when omitte…
limitintegerMaximum number of results to return. Integer between 1 and 20 inclusive. Defaults to 5.
pair_by_codePairs a physical screen with the 6-character code shown on https://display.agentview.de — the recommended first-time setup: ask the user to open that URL on the TV and read the code, then call this (creates and pairs in one step). Pass target_display_id to rebind an EXISTING display profile onto ne…

Pairs a physical screen with the 6-character code shown on https://display.agentview.de — the recommended first-time setup: ask the user to open that URL on the TV and read the code, then call this (creates and pairs in one step). Pass target_display_id to rebind an EXISTING display profile onto ne…

NOTELinks to undeclared domain: display.agentview.de
ParamètreTypeDescription
code*stringThe 6-character pairing code shown on the display (e.g. 'AB3K7F').
profile_namestringFriendly name for the display (required for new pairing, ignored for rebind). Example: 'Lobby Screen'.
target_display_idstringTo rebind: the existing display profile ID to switch to the new hardware. Omit for new display pairing.
access_tokenstringOptional bearer token; prefer session_request_id.
get_store_template_detailsReturns full details of one store template: localized title and description, long-form markdown, category, suite, tags, features, preview image and agentArtifacts (bot-onboarding files such as system prompts, Agent Skills SKILL.md, MCP config). Use after search_store_templates before recommending o…

Returns full details of one store template: localized title and description, long-form markdown, category, suite, tags, features, preview image and agentArtifacts (bot-onboarding files such as system prompts, Agent Skills SKILL.md, MCP config). Use after search_store_templates before recommending o…

ParamètreTypeDescription
slug*stringThe template slug (English kebab-case) returned by search_store_templates, e.g. 'bistro-warm-door' or 'agent-ops-cyan-wall'.
languagestringPreferred content language. Defaults to 'en'.
list_displaysLists all displays the user can access, with id, name, online status, lock state and device class — the starting point to discover display IDs before get_display, send_html or send_store_template_to_display. Pass org_id to list an organization's displays instead. response_format 'detailed' adds scr…

Lists all displays the user can access, with id, name, online status, lock state and device class — the starting point to discover display IDs before get_display, send_html or send_store_template_to_display. Pass org_id to list an organization's displays instead. response_format 'detailed' adds scr…

ParamètreTypeDescription
org_idstringOptional organization ID: list that organization's displays (member access required).
response_formatstringconcise (default) returns key fields per display; detailed adds screen/viewport, URLs and language.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_assetsLists the user's uploaded assets (images, videos, fonts, documents) with public URLs for use in display HTML. Filter by type, search term or group. Check before upload_asset to avoid duplicates. response_format 'detailed' adds description, size and timestamps per asset. Requires content scope.

Lists the user's uploaded assets (images, videos, fonts, documents) with public URLs for use in display HTML. Filter by type, search term or group. Check before upload_asset to avoid duplicates. response_format 'detailed' adds description, size and timestamps per asset. Requires content scope.

ParamètreTypeDescription
typestringFilter by MIME category.
searchstringSearch in filename and description.
group_idstringOnly this group's assets. Omit for personal.
limitintegerMaximum results (default 50).
response_formatstringconcise (default): id, name, url, mimeType; detailed adds description, sizeBytes, createdAt.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_agent_artifactReturns an agent-onboarding artifact shipped with a store template: system prompt, Agent Skills SKILL.md or MCP-config snippet. Pass slug for the RAW template artifact (before install, {{slot:...}} placeholders intact) or display_id for the display-bound artifact with placeholders resolved against…

Returns an agent-onboarding artifact shipped with a store template: system prompt, Agent Skills SKILL.md or MCP-config snippet. Pass slug for the RAW template artifact (before install, {{slot:...}} placeholders intact) or display_id for the display-bound artifact with placeholders resolved against…

NOTEReferences the system prompthipped with a store template: system prompt, Agent Skills SKILL.md or MCP…
ParamètreTypeDescription
key*stringArtifact key, e.g. 'bot-system-prompt', 'agent-skill', 'mcp-config'.
slugstringTemplate slug for the raw artifact. Provide slug OR display_id.
display_idstringDisplay profile ID for the placeholder-resolved artifact. If both slug and display_id are given, display_id wins (substituted body).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
configure_organizationUpdates organization settings: rename (name) and/or network connectivity defaults for all its displays (default_connectivity_mode, global_whitelist). Only provided fields change. Use when an org admin renames the organization or declares network topology. Requires admin scope and org-admin role.

Updates organization settings: rename (name) and/or network connectivity defaults for all its displays (default_connectivity_mode, global_whitelist). Only provided fields change. Use when an org admin renames the organization or declares network topology. Requires admin scope and org-admin role.

ParamètreTypeDescription
org_id*stringOrganization ID from list_organizations.
namestringNew organization name (rename).
default_connectivity_modestringDefault connectivity for all org displays.
global_whitelistarrayDomain whitelist applied org-wide in whitelist-only mode.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_api_keysLists all API keys for the current user. Returns key metadata (prefix, name, scope, dates) but never the raw key. Requires admin scope.

Lists all API keys for the current user. Returns key metadata (prefix, name, scope, dates) but never the raw key. Requires admin scope.

ParamètreTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
read_display_htmlReads the raw HTML source currently shown on a display so you can inspect or edit it and push it back with send_html. content_type 'idle' reads the default/fallback content instead. Responses are windowed for large documents: max_bytes (default 51200) and offset page through the source; the result…

Reads the raw HTML source currently shown on a display so you can inspect or edit it and push it back with send_html. content_type 'idle' reads the default/fallback content instead. Responses are windowed for large documents: max_bytes (default 51200) and offset page through the source; the result…

ParamètreTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
content_typestring'live' (default) reads active content; 'idle' reads default content.
offsetintegerByte offset to start reading from. Default 0.
max_bytesintegerMaximum bytes of HTML to return. Default 51200.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_organizationsReturns all organizations the authenticated user belongs to with their role, display count, member count and allocated slots. Use this to answer questions about the user's organizations, how many displays an organization has, or team membership. Requires authentication with at least content_only sc…

Returns all organizations the authenticated user belongs to with their role, display count, member count and allocated slots. Use this to answer questions about the user's organizations, how many displays an organization has, or team membership. Requires authentication with at least content_only sc…

ParamètreTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
revoke_api_keyPermanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.

Permanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.

ParamètreTypeDescription
key_id*stringThe ID of the key to revoke (from list_api_keys).
access_tokenstringOptional bearer token; prefer session_request_id.
get_display_preview_urlCreates a short-lived signed link showing what a display is presenting RIGHT NOW, rendered inline as a preview widget. ALWAYS call this when the user wants to SEE their display or screen content (preview, 'zeig mir das Display'). Link lifetime follows the display's privacy mode. Requires content sc…

Creates a short-lived signed link showing what a display is presenting RIGHT NOW, rendered inline as a preview widget. ALWAYS call this when the user wants to SEE their display or screen content (preview, 'zeig mir das Display'). Link lifetime follows the display's privacy mode. Requires content sc…

ParamètreTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID, e.g. 'ABCD1234'.
ttl_secondsintegerLifetime of the share link in seconds. Default 3600 (1 hour). Clamped to [60, 86400].
access_tokenstringOptional bearer token; prefer session_request_id.
delete_organizationprivilégiéPermanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.

Permanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.

ParamètreTypeDescription
org_id*stringThe organization ID to delete.
access_tokenstringOptional bearer token; prefer session_request_id.
list_display_categoriesLists the authenticated user's personal display categories with stable IDs, paths and assignment counts. Use this to discover existing categories before assigning or replacing categories on a display. Requires authentication with at least content_only scope and display.read capability.

Lists the authenticated user's personal display categories with stable IDs, paths and assignment counts. Use this to discover existing categories before assigning or replacing categories on a display. Requires authentication with at least content_only scope and display.read capability.

ParamètreTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
update_assetUpdates the name and/or description of an existing asset. The URL does not change. At least one of name or description must be provided. Requires authentication with at least content_only scope.

Updates the name and/or description of an existing asset. The URL does not change. At least one of name or description must be provided. Requires authentication with at least content_only scope.

ParamètreTypeDescription
asset_id*stringThe asset ID to update.
namestringNew filename for the asset.
descriptionstringNew description for the asset.
access_tokenstringOptional bearer token; prefer session_request_id.
create_organizationCreates a new organization and makes the authenticated user the owner. Use this when the user wants to set up a shared display fleet. Returns orgId, name, slug, type and yourRole. Requires admin scope.

Creates a new organization and makes the authenticated user the owner. Use this when the user wants to set up a shared display fleet. Returns orgId, name, slug, type and yourRole. Requires admin scope.

ParamètreTypeDescription
name*stringFriendly name for the organization. Example: 'Marketing Team'.
typestringOrganization type. Defaults to 'organization' if omitted.
access_tokenstringOptional bearer token; prefer session_request_id.
get_assetReturns metadata for a single asset including its URL. Use this to verify an asset still exists before referencing it in HTML. Requires authentication with at least content_only scope.

Returns metadata for a single asset including its URL. Use this to verify an asset still exists before referencing it in HTML. Requires authentication with at least content_only scope.

ParamètreTypeDescription
asset_id*stringThe asset ID (e.g. 'ast_01H7KXZ...').
access_tokenstringOptional bearer token; prefer session_request_id.
fetchFetches one agentView resource by agentview:// URI, e.g. agentview://public/status, agentview://account/me or agentview://display/ABCD1234. Use after search or with a known URI. Public URIs need no auth; account and display URIs need a session. Returns uri, type, title, text and structured data.

Fetches one agentView resource by agentview:// URI, e.g. agentview://public/status, agentview://account/me or agentview://display/ABCD1234. Use after search or with a known URI. Public URIs need no auth; account and display URIs need a session. Returns uri, type, title, text and structured data.

ParamètreTypeDescription
uri*stringThe resource URI to fetch. Must use the agentview:// scheme. Examples: 'agentview://public/status', 'agentview://account/me', 'agentview://display/ABCD1234'.
manage_display_categoryCreates or renames a display category (categories group displays for broadcast_content include_category_ids). action 'create' needs name (optional parent_category_id for a subcategory); action 'rename' needs category_id and new_name — assignments and grants stay intact. Discover IDs with list_displ…

Creates or renames a display category (categories group displays for broadcast_content include_category_ids). action 'create' needs name (optional parent_category_id for a subcategory); action 'rename' needs category_id and new_name — assignments and grants stay intact. Discover IDs with list_displ…

ParamètreTypeDescription
action*stringOperation to perform.
namestringCategory name for action 'create', e.g. 'Reception'.
parent_category_idstringOptional parent category ID (create only) for a subcategory.
category_idstringCategory ID to rename (rename only).
new_namestringNew category name (rename only).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
test_display_contentDry-run validator for generated HTML: runs agentView's size and description checks WITHOUT touching a real display. Use after composing complex HTML and before send_html or broadcast_content. No display_id needed; the response carries simulated=true. Capped at 1 MB. Requires authentication.

Dry-run validator for generated HTML: runs agentView's size and description checks WITHOUT touching a real display. Use after composing complex HTML and before send_html or broadcast_content. No display_id needed; the response carries simulated=true. Capped at 1 MB. Requires authentication.

ParamètreTypeDescription
description*stringShort human-readable description of what the HTML represents (1-1000 chars). Same validation rules as send_html.
htmlstringComplete HTML document to validate. Mutually exclusive with base64_html — provide exactly one.
base64_htmlstringBase64-encoded HTML payload. Mutually exclusive with html.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_store_template_install_optionsprivilégiéReturns the displays the user can install a store template on plus the data slots it needs (key, label, type, required). Call before send_store_template_to_display. An empty displays list means the user must first set up a display (pair_by_code). Requires content scope.

Returns the displays the user can install a store template on plus the data slots it needs (key, label, type, required). Call before send_store_template_to_display. An empty displays list means the user must first set up a display (pair_by_code). Requires content scope.

ParamètreTypeDescription
slug*stringTemplate slug returned by search_store_templates, e.g. 'bistro-warm-door'.
languagestringPreferred UI language for labels. Defaults to 'en'.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
manage_org_memberManages organization membership: action 'invite' adds a member by email with a role, 'set_role' changes a member's role, 'remove' removes the member. Roles for organizations: 'admin' (manage members and displays), 'manager' (manage displays and content), 'viewer' (read-only); families accept 'child…

Manages organization membership: action 'invite' adds a member by email with a role, 'set_role' changes a member's role, 'remove' removes the member. Roles for organizations: 'admin' (manage members and displays), 'manager' (manage displays and content), 'viewer' (read-only); families accept 'child…

ParamètreTypeDescription
org_id*stringOrganization ID.
action*stringMembership operation.
emailstringEmail address to invite (action 'invite').
target_user_idstringMember user ID (actions 'set_role' and 'remove').
rolestringRole for 'invite' and 'set_role': 'admin', 'manager', 'viewer' (families: 'child').
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.

57 outils sur 57 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Aucune couverture des dépendances

Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.