de.agentview/agentview-mcp

MCPcommunitylive
v1.0.0de.agentviewUnknownUpdated 5mo ago

Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.

Endpoint healthlive
checked 1 day ago · 885ms
100% of the last 6 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
5mo agoLast update
Package
Authorde.agentview
LicenseUnknown
Version1.0.0
Sourcemcp-registry
Trust Status
D
30/100Risk
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
—Prompt-injection scan · findings+0/30
→ Publisher: remove instructions in the source aimed at AI clients rather than human readers
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface57 tools · 7 privileged
Security scan⚠ Warnings (1)vlive · 1mo agoHow well does this scan work?
PROMPTtool:authenticate#jwtExfiltration-shaped instruction
PROMPTtool:send_url#urlLinks to undeclared domain: example.com
PROMPTtool:pair_by_codeLinks to undeclared domain: display.agentview.de
PROMPTtool:get_agent_artifactReferences the system prompt
EvalsNone
IndexedJun 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

57 tools · 7 privileged · 1 flagged for injection
Observed live from the vendor's endpoint1mo ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://agentview.de/mcp57 tools · 1247ms
assign_display_categoriesAssigns displays to categories. mode 'replace' (default) sets the full category list of each display in display_ids to category_ids; mode 'add' or 'remove' adds/removes one category (category_ids[0]) across many displays without touching other assignments. Discover IDs with list_display_categories;…

Assigns displays to categories. mode 'replace' (default) sets the full category list of each display in display_ids to category_ids; mode 'add' or 'remove' adds/removes one category (category_ids[0]) across many displays without touching other assignments. Discover IDs with list_display_categories;…

ParameterTypeDescription
display_ids*arrayDisplay profile IDs to update.
category_ids*arrayCategory IDs; for mode 'add'/'remove' only the first entry is used.
modestringreplace (default) sets the exact list; add/remove mutates one category across displays.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_data_slotsLists data slots with optional filtering. Returns metadata only (no jsonContent). Each item includes readUrl. Use readUrl in display HTML fetch() calls. Requires authentication.

Lists data slots with optional filtering. Returns metadata only (no jsonContent). Each item includes readUrl. Use readUrl in display HTML fetch() calls. Requires authentication.

ParameterTypeDescription
group_idstringGroup/organization ID to list shared group slots. Omit for personal slots.
searchstringSearch in label (case-insensitive).
limitintegerMaximum results (default: 50, max: 200).
offsetintegerOffset for pagination.
access_tokenstringOptional bearer token; prefer session_request_id.
set_display_grantGrants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status) or 'control' (send content); action 'remove' revokes it. The target user must be an organization member. Requires admin scope.

Grants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status) or 'control' (send content); action 'remove' revokes it. The target user must be an organization member. Requires admin scope.

ParameterTypeDescription
org_id*stringOrganization ID.
display_id*stringDisplay profile ID.
target_user_id*stringUser to grant or revoke.
actionstring'set' (default) creates/updates the grant; 'remove' revokes it.
access_levelstringRequired for action 'set'.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
authenticateinjection riskValidates a JWT agent token and caches the identity on this MCP session so later calls work without resending it. Use only when your client cannot send an Authorization: Bearer header; prefer session_request_id-based auth via create_auth_session. Not needed after get_auth_session returned 'active'.

Validates a JWT agent token and caches the identity on this MCP session so later calls work without resending it. Use only when your client cannot send an Authorization: Bearer header; prefer session_request_id-based auth via create_auth_session. Not needed after get_auth_session returned 'active'.

INJECTIONIn parameter jwt: Exfiltration-shaped instructione this if your wrapper cannot send the 'token' field reliably.
ParameterTypeDescription
tokenstringThe raw JWT token string returned by get_auth_session or an OAuth access token. Pass the opaque token exactly as received — do not add a 'Bearer ' prefix and d…
jwtstringAlias for token. Use this if your wrapper cannot send the 'token' field reliably.
access_tokenstringAlias for token. Use this if your wrapper follows OAuth naming conventions.
create_api_keyCreates a long-lived API key for server-to-server integration without OAuth. The raw key is returned only once — store it securely. The user must explicitly consent to creating the key. Requires admin scope. Supports granular scoping: restrict the key to specific data-slot slugs, specific display I…

Creates a long-lived API key for server-to-server integration without OAuth. The raw key is returned only once — store it securely. The user must explicitly consent to creating the key. Requires admin scope. Supports granular scoping: restrict the key to specific data-slot slugs, specific display I…

ParameterTypeDescription
name*stringHuman-readable name for the key. Example: 'Home Assistant', 'CI Pipeline'.
scopestringScope for the key: 'content_only' (send content, list displays) or 'admin' (full management).
org_idstringOptional organization ID. If set, the key acts on behalf of this organization.
expires_in_daysintegerOptional expiration in days. If not set, the key never expires.
permissionsstringGranular permission flag: 'read', 'write', or 'read_write' (default). Applied on top of 'scope' — e.g. a content_only read-only key cannot PUT data slots. Matc…
allowed_slot_slugsarrayOptional JSON array of data-slot slugs this key may touch (max 64). When set, every data-slot request must target one of these slugs. Omit or pass [] for no sl…
allowed_display_idsarrayOptional JSON array of display profile IDs this key may touch (max 64). When set, every display request must target one of these IDs. Omit or pass [] for no di…
capabilitiesarrayOptional JSON array of fine-grained capability flags this key may exercise. Allowed values: 'slot.read' (list/get slots), 'slot.write' (put/delete slots), 'dis…
access_tokenstringOptional bearer token; prefer session_request_id.
get_data_slotReturns the current JSON content and metadata of a data slot by slug. Supply group_id to look up a group slot; omit it for personal slots. The response includes readUrl — the public anonymous URL for display HTML to fetch. Requires authentication.

Returns the current JSON content and metadata of a data slot by slug. Supply group_id to look up a group slot; omit it for personal slots. The response includes readUrl — the public anonymous URL for display HTML to fetch. Requires authentication.

ParameterTypeDescription
slug*stringThe slug of the data slot to retrieve.
group_idstringGroup/organization ID to retrieve a group slot. Omit for personal slots.
access_tokenstringOptional bearer token; prefer session_request_id.
get_storage_usageReturns the storage pool snapshot (used, limit and remaining bytes) for the personal scope or a group — data slots and uploaded assets share this quota; check before large set_data_slot or upload_asset writes. Pass slug to additionally scan which displays reference that data slot (do this before de…

Returns the storage pool snapshot (used, limit and remaining bytes) for the personal scope or a group — data slots and uploaded assets share this quota; check before large set_data_slot or upload_asset writes. Pass slug to additionally scan which displays reference that data slot (do this before de…

ParameterTypeDescription
group_idstringGroup/organization ID for the group pool. Omit for the personal pool.
slugstringOptional data-slot slug: also report which displays reference it (slotUsage).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
broadcast_contentSends HTML to many displays at once. Target explicit display_ids, all=true for every accessible display, or include_category_ids to reach every display in those categories (include_descendants for subcategories, dry_run to preview matches without sending). Locked displays are skipped with reasons.…

Sends HTML to many displays at once. Target explicit display_ids, all=true for every accessible display, or include_category_ids to reach every display in those categories (include_descendants for subcategories, dry_run to preview matches without sending). Locked displays are skipped with reasons.…

ParameterTypeDescription
descriptionstringShort summary of the content being sent (required when sending).
htmlstringComplete HTML document. Mutually exclusive with base64_html.
base64_htmlstringBase64-encoded HTML. Mutually exclusive with html.
display_idsarrayDisplay profile IDs to target.
allbooleantrue targets all accessible displays.
include_category_idsarrayCategory IDs: broadcast to displays assigned to these categories.
include_descendantsbooleanWith include_category_ids: also include subcategories.
dry_runbooleanPreview: return the matched displays without sending. Works with all targeting modes.
durationintegerSeconds the content stays; 0 = indefinite.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
manage_licensesManages premium display licenses: action 'allocate' sets how many license slots an organization gets (licenses, 0 deallocates all), 'assign' binds a free license to a display, 'unassign' releases a display's license back to the pool. Check availability first with get_license_info. Requires admin sc…

Manages premium display licenses: action 'allocate' sets how many license slots an organization gets (licenses, 0 deallocates all), 'assign' binds a free license to a display, 'unassign' releases a display's license back to the pool. Check availability first with get_license_info. Requires admin sc…

ParameterTypeDescription
action*stringLicense operation.
org_idstringOrganization ID (action 'allocate').
licensesintegerLicense slot count for 'allocate'; 0 deallocates all.
display_idstringDisplay profile ID (actions 'assign' and 'unassign').
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_public_statusReturns the server's public readiness status, version string and discovery URLs. Use this before authenticating to verify the server is reachable and to obtain entry-point URLs. No authentication required. Returns status ('ready'), server name, version, statusUrl and instructionsUrl.

Returns the server's public readiness status, version string and discovery URLs. Use this before authenticating to verify the server is reachable and to obtain entry-point URLs. No authentication required. Returns status ('ready'), server name, version, statusUrl and instructionsUrl.

No input schema was published for this tool.

get_displayReturns one display's state: status, lock, URLs, settings, language and current content summary. response_format 'detailed' adds browser/runtime facts (screen, viewport, engine), resolved connectivity mode with allowed domains, and full content state (idle content, content URL) — use detailed befor…

Returns one display's state: status, lock, URLs, settings, language and current content summary. response_format 'detailed' adds browser/runtime facts (screen, viewport, engine), resolved connectivity mode with allowed domains, and full content state (idle content, content URL) — use detailed befor…

ParameterTypeDescription
display_id*string8-character display profile ID from list_displays, e.g. 'ABCD1234'.
response_formatstringconcise (default) returns key fields; detailed adds runtime facts, connectivity/capabilities and full content state.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
create_auth_sessionStarts a browser login and returns a loginUrl plus sessionRequestId. Use as STEP 0 in a fresh conversation before any protected tool. Show the loginUrl to the user as a clickable link in their language, then poll get_auth_session until 'active' and pass session_request_id on every later call. Retur…

Starts a browser login and returns a loginUrl plus sessionRequestId. Use as STEP 0 in a fresh conversation before any protected tool. Show the loginUrl to the user as a clickable link in their language, then poll get_auth_session until 'active' and pass session_request_id on every later call. Retur…

ParameterTypeDescription
agent_identifierstringOptional display name of the MCP client or agent, shown to the user in the browser consent screen. Example: 'ChatGPT' or 'my-home-automation'.
scopestringRequested access scope. Must be either 'content_only' (read and send content to displays) or 'admin' (content_only plus create/delete/rename displays). Default…
list_store_categoriesLists all published agentView store categories (e.g. Gastronomie, Wartezimmer, Empfang, Smart Home) with localized titles, descriptions and template counts. Use this to narrow a subsequent search_store_templates call when the user asks for 'templates for a waiting room' or similar. No authenticatio…

Lists all published agentView store categories (e.g. Gastronomie, Wartezimmer, Empfang, Smart Home) with localized titles, descriptions and template counts. Use this to narrow a subsequent search_store_templates call when the user asks for 'templates for a waiting room' or similar. No authenticatio…

ParameterTypeDescription
languagestringPreferred content language. Defaults to 'en'.
send_store_template_to_displayInstalls a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within seconds. Call get_store_template_install_options first for valid targets and slots; customize per-slot JSON inline via data_slot_overrides (raw J…

Installs a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within seconds. Call get_store_template_install_options first for valid targets and slots; customize per-slot JSON inline via data_slot_overrides (raw J…

ParameterTypeDescription
slug*stringTemplate slug to install, e.g. 'bistro-warm-door'. Must be a currently published template.
display_id*stringDisplay profile ID (8-char alphanumeric) from list_displays or get_store_template_install_options.
data_slot_overridesobjectOptional { key: value } map keyed by data-slot key (see requiredDataSlots). Each value is JSON payload to install into that slot — either a string of raw JSON…
idempotency_keystringOptional opaque key (max 128 chars) to make this install retry-safe. If a previous successful install for the same (user, display, idempotency_key) tuple exist…
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
create_displayPre-provisions a display without hardware, personal or inside an organization (org_id). The new display starts offline. For a physical screen ALWAYS prefer pair_by_code, which creates and pairs in one step; use create_display only to prepare a display before the screen exists or for virtual/API-onl…

Pre-provisions a display without hardware, personal or inside an organization (org_id). The new display starts offline. For a physical screen ALWAYS prefer pair_by_code, which creates and pairs in one step; use create_display only to prepare a display before the screen exists or for virtual/API-onl…

ParameterTypeDescription
namestringFriendly display name, e.g. 'Lobby Screen'. Required when org_id is set.
org_idstringOptional: create the display inside this organization (needs manager role and a free license slot).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
delete_data_slotprivilegedPermanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; omit for personal slots. Requires authentication.

Permanently deletes a data slot. Display HTML fetching its readUrl will receive 404 after deletion. Cannot be undone. Supply group_id to delete a group slot; omit for personal slots. Requires authentication.

ParameterTypeDescription
slug*stringThe slug of the data slot to delete.
group_idstringGroup/organization ID to delete a group slot. Omit for personal slots.
access_tokenstringOptional bearer token; prefer session_request_id.
get_license_infoReturns the authenticated user's complete license allocation overview: total premium licenses, personal usage, allocatable licenses, per-organization allocations, and free licenses. Use this to understand available capacity before allocating licenses. Requires content_only scope.

Returns the authenticated user's complete license allocation overview: total premium licenses, personal usage, allocatable licenses, per-organization allocations, and free licenses. Use this to understand available capacity before allocating licenses. Requires content_only scope.

ParameterTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
get_organizationReturns one organization's details: plan, your role, display count, allocated and remaining license slots. response_format 'detailed' adds the full member list (with roles) and display list. Use after list_organizations. Requires content scope and membership.

Returns one organization's details: plan, your role, display count, allocated and remaining license slots. response_format 'detailed' adds the full member list (with roles) and display list. Use after list_organizations. Requires content scope and membership.

ParameterTypeDescription
org_id*stringOrganization ID from list_organizations or get_account.
response_formatstringconcise (default) returns counts and core fields; detailed adds members and displays arrays.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
remove_display_from_orgprivilegedRemoves a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.

Removes a display from an organization, clearing its group assignment and all display grants. The display becomes unassigned. Requires admin scope and admin or owner role.

ParameterTypeDescription
org_id*stringThe organization ID.
display_id*stringThe display profile ID to remove.
access_tokenstringOptional bearer token; prefer session_request_id.
set_data_slotCreates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stable; reusing it updates in place. type 'value' stores JSON verbatim; 'aggregate' composes up to 32 sources ({slot:'name'} or one {prefixMatch…

Creates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stable; reusing it updates in place. type 'value' stores JSON verbatim; 'aggregate' composes up to 32 sources ({slot:'name'} or one {prefixMatch…

ParameterTypeDescription
slug*stringStable slug for the data slot. Must match ^[A-Za-z0-9_-]{8,64}$. Same slug on a later call updates the existing slot. Slug stays exactly as supplied; the publi…
content*—JSON content to store. For value slots: any valid JSON value up to 2 MB. For aggregate slots: a definition object { sources: [{slot,as?} | {prefixMatch}], onMi…
labelstringHuman-readable label (max 200 chars). Required when creating a new slot; optional on update.
group_idstringGroup/organization ID for shared group slots. Omit for personal slots.
typestringSlot kind. 'value' (default) stores 'content' verbatim. 'aggregate' stores 'content' as a composite-slot definition. Immutable after creation.
access_tokenstringOptional bearer token; prefer session_request_id.
submit_feedbackSends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user before sending; optional sentiment. There is no automatic reply. Requires content scope.

Sends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user before sending; optional sentiment. There is no automatic reply. Requires content scope.

ParameterTypeDescription
message*stringThe user's verbatim feedback text (max 2000 characters). Pass what the user actually said; do not paraphrase or add your own commentary.
sentimentstringOptional overall sentiment of the feedback. Set only when the user's tone is clear; omit if unsure.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
upload_assetprivilegedUpload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets are cached on displays. Pass files as base64-encoded data. Requires authentication with at least content_only scope.

Upload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets are cached on displays. Pass files as base64-encoded data. Requires authentication with at least content_only scope.

ParameterTypeDescription
files*arrayArray of file objects, each with 'name' (filename with extension) and 'data' (base64-encoded content).
descriptions*objectJSON object mapping each filename to a human-readable description.
group_idstringOptional group ID to associate the assets with.
access_tokenstringOptional bearer token; prefer session_request_id.
configure_displayUpdates display settings: rename (name), lock or unlock content changes (locked), privacy mode for share links (privacy_mode), embed-origin allowlist (origins), hardware permissions (camera, microphone, geolocation), preferred language, mouse cursor, badge overlay and watermark position. Only the f…

Updates display settings: rename (name), lock or unlock content changes (locked), privacy mode for share links (privacy_mode), embed-origin allowlist (origins), hardware permissions (camera, microphone, geolocation), preferred language, mouse cursor, badge overlay and watermark position. Only the f…

ParameterTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
namestringNew display name (rename).
lockedbooleantrue blocks content changes until unlocked; false unlocks.
privacy_modestringPrivate caps share-link TTL at 1 hour; Public (signage mode) allows 24 hours.
originsarrayEmbed-origin allowlist for Public displays; [] allows all origins.
allow_cameraboolean—
allow_microphoneboolean—
allow_geolocationboolean—
preferred_languagestring—
show_mouse_cursorboolean—
show_badge_overlayboolean—
watermark_positionstring—
connectivity_modestringPer-display network mode override.
whitelistarrayDomain whitelist for whitelist-only mode.
strict_whitelistbooleantrue: the display whitelist replaces the org whitelist instead of extending it.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
search_public_apisSearches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images, food and 40+ more categories. Use when generating HTML that needs live internet data. Set list_categories=true to get the category menu wi…

Searches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images, food and 40+ more categories. Use when generating HTML that needs live internet data. Set list_categories=true to get the category menu wi…

ParameterTypeDescription
querystringFree-text search, e.g. 'weather forecast', 'bitcoin price', 'jokes'.
categorystringCategory ID filter, e.g. 'weather', 'finance', 'news'. Omit for all.
cors_onlybooleantrue returns only APIs with confirmed browser CORS support. Default false.
list_categoriesbooleantrue returns all categories with API counts instead of search results.
limitintegerMaximum results, 1-20. Default 10.
claim_displayAdopts an unclaimed guest or pending display as a managed personal display (permanent ownership transfer, counts against quota). Use only when the user explicitly wants to take over hardware that is already running; for first-time setup prefer pair_by_code. Requires admin scope.

Adopts an unclaimed guest or pending display as a managed personal display (permanent ownership transfer, counts against quota). Use only when the user explicitly wants to take over hardware that is already running; for first-time setup prefer pair_by_code. Requires admin scope.

ParameterTypeDescription
display_id*stringThe short ID of the pending, guest or demo display to claim. This is the hardware or temporary ID shown on the device.
profile_name*stringFriendly name to assign to the newly claimed display. Non-empty string. Example: 'Reception Kiosk'.
access_tokenstringOptional bearer token; prefer session_request_id.
send_urlShows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first whe…

Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first whe…

NOTEIn parameter url: Links to undeclared domain: example.com
ParameterTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
url*stringAbsolute HTTP or HTTPS URL to load, e.g. 'https://example.com/dashboard'.
slotstring'live' (default) or 'idle' for default/fallback content (admin scope).
durationintegerSeconds the content stays; 0 = indefinite (default). Live slot only.
content_descriptionstringShort summary of what the page shows (recommended).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
clear_displayRemoves the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants to blank or reset a display. This does not delete the display itself — use delete_display for that. Requires authentication with at least c…

Removes the current live content from a display and returns it to its idle/default state. Viewers will immediately see the change. Use this when the user wants to blank or reset a display. This does not delete the display itself — use delete_display for that. Requires authentication with at least c…

ParameterTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID to clear, e.g. 'ABCD1234'.
access_tokenstringOptional bearer token; prefer session_request_id.
get_accountReturns the user's account profile: plan and features, personal display limits and remaining quota, accessible display count, organization memberships and points balance. Use for subscription, quota and membership questions. Not for listing displays (use list_displays). Requires content scope.

Returns the user's account profile: plan and features, personal display limits and remaining quota, accessible display count, organization memberships and points balance. Use for subscription, quota and membership questions. Not for listing displays (use list_displays). Requires content scope.

ParameterTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
delete_assetprivilegedDeletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.

Deletes one or more assets. Displays referencing deleted assets will show broken images. Requires authentication with at least content_only scope.

ParameterTypeDescription
asset_ids*arrayOne or more asset IDs to delete.
access_tokenstringOptional bearer token; prefer session_request_id.
get_store_template_contentReturns the raw display HTML of a published store template plus its slot definitions and allowed external origins, for editing or embedding the template yourself. {{asset:NAME}} placeholders resolve to public URLs; {{slot:KEY.prop}} stay intact for your own binding. Large HTML is windowed via max_b…

Returns the raw display HTML of a published store template plus its slot definitions and allowed external origins, for editing or embedding the template yourself. {{asset:NAME}} placeholders resolve to public URLs; {{slot:KEY.prop}} stay intact for your own binding. Large HTML is windowed via max_b…

ParameterTypeDescription
slug*stringTemplate slug from search_store_templates, e.g. 'bistro-warm-door'.
versionstringOptional published version id (stpv_…) to pin. Omit for current.
offsetintegerByte offset into the HTML. Default 0.
max_bytesintegerMaximum HTML bytes to return. Default 51200.
get_auth_sessionPolls a login session created by create_auth_session until the user completes the browser login. Poll every 2-3 seconds while status is 'pending'. Status 'active' auto-authenticates this MCP session — protected tools work immediately; keep passing session_request_id on later calls (the raw token is…

Polls a login session created by create_auth_session until the user completes the browser login. Poll every 2-3 seconds while status is 'pending'. Status 'active' auto-authenticates this MCP session — protected tools work immediately; keep passing session_request_id on later calls (the raw token is…

ParameterTypeDescription
session_request_id*stringThe sessionRequestId string returned by create_auth_session. Must be passed exactly as received.
send_htmlShows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idle' stores the default/fallback content shown when nothing live is active (idle requires admin scope). Always pass a short description so la…

Shows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idle' stores the default/fallback content shown when nothing live is active (idle requires admin scope). Always pass a short description so la…

ParameterTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
description*stringShort human-readable summary of the content, e.g. 'Weekly KPI dashboard'.
htmlstringComplete HTML document to render. Mutually exclusive with base64_html.
base64_htmlstringBase64-encoded HTML (standard base64). Use only when raw HTML cannot survive JSON transport. Mutually exclusive with html.
slotstringTarget slot: 'live' (default) replaces current content; 'idle' sets the default shown when idle (admin scope).
durationintegerSeconds the content stays; 0 = indefinite (default). Live slot only.
tokenstringDisplay-specific demo/preview token for unauthenticated access. NOT the OAuth token.
access_tokenstringOptional bearer token; prefer session_request_id. Distinct from the display-specific 'token'.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
delete_displayprivilegedPermanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requires admin scope. Returns id, name and deleted (boolean true).

Permanently deletes a display and all its associated content. This action cannot be undone. Use this only when the user explicitly confirms they want to remove the display. Requires admin scope. Returns id, name and deleted (boolean true).

ParameterTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID to delete, e.g. 'ABCD1234'.
access_tokenstringOptional bearer token; prefer session_request_id.
logoutClears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.

Clears the cached login from this MCP session (does not revoke the underlying token). Use when the user wants to sign out or switch accounts.

No input schema was published for this tool.

search_store_templatesSearches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pre-built design instead of generated HTML; results render as a gallery widget. Filter by category, suite and language; paginate with limit/o…

Searches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pre-built design instead of generated HTML; results render as a gallery widget. Filter by category, suite and language; paginate with limit/o…

ParameterTypeDescription
querystringFree-text search over template title, description and tags. Examples: 'Zahnarzt', 'italienisches Bistro', 'conference room'.
categorystringOptional category slug to restrict the search (English kebab-case, e.g. 'gastronomie', 'waiting-room').
suitestringOptional design-family suite slug (e.g. 'bistro-warm', 'sushi-minimal').
languagestringPreferred content language. Defaults to 'en'.
limitintegerMaximum number of templates to return. Defaults to 10.
offsetintegerOffset into the filtered result set for pagination. Defaults to 0.
searchSearches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippets to read via fetch. Unauthenticated searches cover public docs only. Skip when you already know the URI — call fetch directly.

Searches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippets to read via fetch. Unauthenticated searches cover public docs only. Skip when you already know the URI — call fetch directly.

ParameterTypeDescription
querystringFree-text search terms. Examples: a display name, 'account', 'OAuth', 'status'. At least one of query or resource_type should be provided.
resource_typestringRestricts results to a specific resource category. Must be one of: 'all', 'documentation', 'status', 'account', 'display', 'api'. Defaults to 'all' when omitte…
limitintegerMaximum number of results to return. Integer between 1 and 20 inclusive. Defaults to 5.
pair_by_codePairs a physical screen with the 6-character code shown on https://display.agentview.de — the recommended first-time setup: ask the user to open that URL on the TV and read the code, then call this (creates and pairs in one step). Pass target_display_id to rebind an EXISTING display profile onto ne…

Pairs a physical screen with the 6-character code shown on https://display.agentview.de — the recommended first-time setup: ask the user to open that URL on the TV and read the code, then call this (creates and pairs in one step). Pass target_display_id to rebind an EXISTING display profile onto ne…

NOTELinks to undeclared domain: display.agentview.de
ParameterTypeDescription
code*stringThe 6-character pairing code shown on the display (e.g. 'AB3K7F').
profile_namestringFriendly name for the display (required for new pairing, ignored for rebind). Example: 'Lobby Screen'.
target_display_idstringTo rebind: the existing display profile ID to switch to the new hardware. Omit for new display pairing.
access_tokenstringOptional bearer token; prefer session_request_id.
get_store_template_detailsReturns full details of one store template: localized title and description, long-form markdown, category, suite, tags, features, preview image and agentArtifacts (bot-onboarding files such as system prompts, Agent Skills SKILL.md, MCP config). Use after search_store_templates before recommending o…

Returns full details of one store template: localized title and description, long-form markdown, category, suite, tags, features, preview image and agentArtifacts (bot-onboarding files such as system prompts, Agent Skills SKILL.md, MCP config). Use after search_store_templates before recommending o…

ParameterTypeDescription
slug*stringThe template slug (English kebab-case) returned by search_store_templates, e.g. 'bistro-warm-door' or 'agent-ops-cyan-wall'.
languagestringPreferred content language. Defaults to 'en'.
list_displaysLists all displays the user can access, with id, name, online status, lock state and device class — the starting point to discover display IDs before get_display, send_html or send_store_template_to_display. Pass org_id to list an organization's displays instead. response_format 'detailed' adds scr…

Lists all displays the user can access, with id, name, online status, lock state and device class — the starting point to discover display IDs before get_display, send_html or send_store_template_to_display. Pass org_id to list an organization's displays instead. response_format 'detailed' adds scr…

ParameterTypeDescription
org_idstringOptional organization ID: list that organization's displays (member access required).
response_formatstringconcise (default) returns key fields per display; detailed adds screen/viewport, URLs and language.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_assetsLists the user's uploaded assets (images, videos, fonts, documents) with public URLs for use in display HTML. Filter by type, search term or group. Check before upload_asset to avoid duplicates. response_format 'detailed' adds description, size and timestamps per asset. Requires content scope.

Lists the user's uploaded assets (images, videos, fonts, documents) with public URLs for use in display HTML. Filter by type, search term or group. Check before upload_asset to avoid duplicates. response_format 'detailed' adds description, size and timestamps per asset. Requires content scope.

ParameterTypeDescription
typestringFilter by MIME category.
searchstringSearch in filename and description.
group_idstringOnly this group's assets. Omit for personal.
limitintegerMaximum results (default 50).
response_formatstringconcise (default): id, name, url, mimeType; detailed adds description, sizeBytes, createdAt.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_agent_artifactReturns an agent-onboarding artifact shipped with a store template: system prompt, Agent Skills SKILL.md or MCP-config snippet. Pass slug for the RAW template artifact (before install, {{slot:...}} placeholders intact) or display_id for the display-bound artifact with placeholders resolved against…

Returns an agent-onboarding artifact shipped with a store template: system prompt, Agent Skills SKILL.md or MCP-config snippet. Pass slug for the RAW template artifact (before install, {{slot:...}} placeholders intact) or display_id for the display-bound artifact with placeholders resolved against…

NOTEReferences the system prompthipped with a store template: system prompt, Agent Skills SKILL.md or MCP…
ParameterTypeDescription
key*stringArtifact key, e.g. 'bot-system-prompt', 'agent-skill', 'mcp-config'.
slugstringTemplate slug for the raw artifact. Provide slug OR display_id.
display_idstringDisplay profile ID for the placeholder-resolved artifact. If both slug and display_id are given, display_id wins (substituted body).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
configure_organizationUpdates organization settings: rename (name) and/or network connectivity defaults for all its displays (default_connectivity_mode, global_whitelist). Only provided fields change. Use when an org admin renames the organization or declares network topology. Requires admin scope and org-admin role.

Updates organization settings: rename (name) and/or network connectivity defaults for all its displays (default_connectivity_mode, global_whitelist). Only provided fields change. Use when an org admin renames the organization or declares network topology. Requires admin scope and org-admin role.

ParameterTypeDescription
org_id*stringOrganization ID from list_organizations.
namestringNew organization name (rename).
default_connectivity_modestringDefault connectivity for all org displays.
global_whitelistarrayDomain whitelist applied org-wide in whitelist-only mode.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_api_keysLists all API keys for the current user. Returns key metadata (prefix, name, scope, dates) but never the raw key. Requires admin scope.

Lists all API keys for the current user. Returns key metadata (prefix, name, scope, dates) but never the raw key. Requires admin scope.

ParameterTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
read_display_htmlReads the raw HTML source currently shown on a display so you can inspect or edit it and push it back with send_html. content_type 'idle' reads the default/fallback content instead. Responses are windowed for large documents: max_bytes (default 51200) and offset page through the source; the result…

Reads the raw HTML source currently shown on a display so you can inspect or edit it and push it back with send_html. content_type 'idle' reads the default/fallback content instead. Responses are windowed for large documents: max_bytes (default 51200) and offset page through the source; the result…

ParameterTypeDescription
display_id*string8-character display profile ID, e.g. 'ABCD1234'.
content_typestring'live' (default) reads active content; 'idle' reads default content.
offsetintegerByte offset to start reading from. Default 0.
max_bytesintegerMaximum bytes of HTML to return. Default 51200.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
list_organizationsReturns all organizations the authenticated user belongs to with their role, display count, member count and allocated slots. Use this to answer questions about the user's organizations, how many displays an organization has, or team membership. Requires authentication with at least content_only sc…

Returns all organizations the authenticated user belongs to with their role, display count, member count and allocated slots. Use this to answer questions about the user's organizations, how many displays an organization has, or team membership. Requires authentication with at least content_only sc…

ParameterTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
revoke_api_keyPermanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.

Permanently revokes an API key. This is irreversible — the key will immediately stop working. Requires admin scope.

ParameterTypeDescription
key_id*stringThe ID of the key to revoke (from list_api_keys).
access_tokenstringOptional bearer token; prefer session_request_id.
get_display_preview_urlCreates a short-lived signed link showing what a display is presenting RIGHT NOW, rendered inline as a preview widget. ALWAYS call this when the user wants to SEE their display or screen content (preview, 'zeig mir das Display'). Link lifetime follows the display's privacy mode. Requires content sc…

Creates a short-lived signed link showing what a display is presenting RIGHT NOW, rendered inline as a preview widget. ALWAYS call this when the user wants to SEE their display or screen content (preview, 'zeig mir das Display'). Link lifetime follows the display's privacy mode. Requires content sc…

ParameterTypeDescription
display_id*stringThe 8-character alphanumeric display profile ID, e.g. 'ABCD1234'.
ttl_secondsintegerLifetime of the share link in seconds. Default 3600 (1 hour). Clamped to [60, 86400].
access_tokenstringOptional bearer token; prefer session_request_id.
delete_organizationprivilegedPermanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.

Permanently deletes an organization, releasing all its displays and removing all members. Only the owner can delete. This cannot be undone. Requires admin scope.

ParameterTypeDescription
org_id*stringThe organization ID to delete.
access_tokenstringOptional bearer token; prefer session_request_id.
list_display_categoriesLists the authenticated user's personal display categories with stable IDs, paths and assignment counts. Use this to discover existing categories before assigning or replacing categories on a display. Requires authentication with at least content_only scope and display.read capability.

Lists the authenticated user's personal display categories with stable IDs, paths and assignment counts. Use this to discover existing categories before assigning or replacing categories on a display. Requires authentication with at least content_only scope and display.read capability.

ParameterTypeDescription
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
update_assetUpdates the name and/or description of an existing asset. The URL does not change. At least one of name or description must be provided. Requires authentication with at least content_only scope.

Updates the name and/or description of an existing asset. The URL does not change. At least one of name or description must be provided. Requires authentication with at least content_only scope.

ParameterTypeDescription
asset_id*stringThe asset ID to update.
namestringNew filename for the asset.
descriptionstringNew description for the asset.
access_tokenstringOptional bearer token; prefer session_request_id.
create_organizationCreates a new organization and makes the authenticated user the owner. Use this when the user wants to set up a shared display fleet. Returns orgId, name, slug, type and yourRole. Requires admin scope.

Creates a new organization and makes the authenticated user the owner. Use this when the user wants to set up a shared display fleet. Returns orgId, name, slug, type and yourRole. Requires admin scope.

ParameterTypeDescription
name*stringFriendly name for the organization. Example: 'Marketing Team'.
typestringOrganization type. Defaults to 'organization' if omitted.
access_tokenstringOptional bearer token; prefer session_request_id.
get_assetReturns metadata for a single asset including its URL. Use this to verify an asset still exists before referencing it in HTML. Requires authentication with at least content_only scope.

Returns metadata for a single asset including its URL. Use this to verify an asset still exists before referencing it in HTML. Requires authentication with at least content_only scope.

ParameterTypeDescription
asset_id*stringThe asset ID (e.g. 'ast_01H7KXZ...').
access_tokenstringOptional bearer token; prefer session_request_id.
fetchFetches one agentView resource by agentview:// URI, e.g. agentview://public/status, agentview://account/me or agentview://display/ABCD1234. Use after search or with a known URI. Public URIs need no auth; account and display URIs need a session. Returns uri, type, title, text and structured data.

Fetches one agentView resource by agentview:// URI, e.g. agentview://public/status, agentview://account/me or agentview://display/ABCD1234. Use after search or with a known URI. Public URIs need no auth; account and display URIs need a session. Returns uri, type, title, text and structured data.

ParameterTypeDescription
uri*stringThe resource URI to fetch. Must use the agentview:// scheme. Examples: 'agentview://public/status', 'agentview://account/me', 'agentview://display/ABCD1234'.
manage_display_categoryCreates or renames a display category (categories group displays for broadcast_content include_category_ids). action 'create' needs name (optional parent_category_id for a subcategory); action 'rename' needs category_id and new_name — assignments and grants stay intact. Discover IDs with list_displ…

Creates or renames a display category (categories group displays for broadcast_content include_category_ids). action 'create' needs name (optional parent_category_id for a subcategory); action 'rename' needs category_id and new_name — assignments and grants stay intact. Discover IDs with list_displ…

ParameterTypeDescription
action*stringOperation to perform.
namestringCategory name for action 'create', e.g. 'Reception'.
parent_category_idstringOptional parent category ID (create only) for a subcategory.
category_idstringCategory ID to rename (rename only).
new_namestringNew category name (rename only).
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
test_display_contentDry-run validator for generated HTML: runs agentView's size and description checks WITHOUT touching a real display. Use after composing complex HTML and before send_html or broadcast_content. No display_id needed; the response carries simulated=true. Capped at 1 MB. Requires authentication.

Dry-run validator for generated HTML: runs agentView's size and description checks WITHOUT touching a real display. Use after composing complex HTML and before send_html or broadcast_content. No display_id needed; the response carries simulated=true. Capped at 1 MB. Requires authentication.

ParameterTypeDescription
description*stringShort human-readable description of what the HTML represents (1-1000 chars). Same validation rules as send_html.
htmlstringComplete HTML document to validate. Mutually exclusive with base64_html — provide exactly one.
base64_htmlstringBase64-encoded HTML payload. Mutually exclusive with html.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
get_store_template_install_optionsprivilegedReturns the displays the user can install a store template on plus the data slots it needs (key, label, type, required). Call before send_store_template_to_display. An empty displays list means the user must first set up a display (pair_by_code). Requires content scope.

Returns the displays the user can install a store template on plus the data slots it needs (key, label, type, required). Call before send_store_template_to_display. An empty displays list means the user must first set up a display (pair_by_code). Requires content scope.

ParameterTypeDescription
slug*stringTemplate slug returned by search_store_templates, e.g. 'bistro-warm-door'.
languagestringPreferred UI language for labels. Defaults to 'en'.
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.
manage_org_memberManages organization membership: action 'invite' adds a member by email with a role, 'set_role' changes a member's role, 'remove' removes the member. Roles for organizations: 'admin' (manage members and displays), 'manager' (manage displays and content), 'viewer' (read-only); families accept 'child…

Manages organization membership: action 'invite' adds a member by email with a role, 'set_role' changes a member's role, 'remove' removes the member. Roles for organizations: 'admin' (manage members and displays), 'manager' (manage displays and content), 'viewer' (read-only); families accept 'child…

ParameterTypeDescription
org_id*stringOrganization ID.
action*stringMembership operation.
emailstringEmail address to invite (action 'invite').
target_user_idstringMember user ID (actions 'set_role' and 'remove').
rolestringRole for 'invite' and 'set_role': 'admin', 'manager', 'viewer' (families: 'child').
access_tokenstringOptional bearer token; prefer session_request_id.
session_request_idstringSession handle from create_auth_session; pass it on every authenticated call.

57 of 57 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.