|
8130 | 8130 | "AgentMcpTool": { |
8131 | 8131 | "type": "object", |
8132 | 8132 | "properties": { |
| 8133 | + "operationPolicy": { |
| 8134 | + "oneOf": [ |
| 8135 | + { |
| 8136 | + "type": "object", |
| 8137 | + "properties": { |
| 8138 | + "mode": { |
| 8139 | + "type": "string", |
| 8140 | + "const": "all", |
| 8141 | + "description": "Allow all operations available to the authorized credential." |
| 8142 | + } |
| 8143 | + }, |
| 8144 | + "required": ["mode"], |
| 8145 | + "additionalProperties": false |
| 8146 | + }, |
| 8147 | + { |
| 8148 | + "type": "object", |
| 8149 | + "properties": { |
| 8150 | + "mode": { |
| 8151 | + "type": "string", |
| 8152 | + "const": "allow", |
| 8153 | + "description": "Allow only the selected exact operations." |
| 8154 | + }, |
| 8155 | + "operations": { |
| 8156 | + "maxItems": 1000, |
| 8157 | + "type": "array", |
| 8158 | + "items": { |
| 8159 | + "type": "object", |
| 8160 | + "properties": { |
| 8161 | + "serverId": { |
| 8162 | + "type": "string", |
| 8163 | + "minLength": 1, |
| 8164 | + "maxLength": 256, |
| 8165 | + "description": "Canonical MCP server identity, independent of the selected credential." |
| 8166 | + }, |
| 8167 | + "name": { |
| 8168 | + "type": "string", |
| 8169 | + "minLength": 1, |
| 8170 | + "maxLength": 256, |
| 8171 | + "description": "Exact operation name returned by MCP discovery." |
| 8172 | + } |
| 8173 | + }, |
| 8174 | + "required": ["serverId", "name"], |
| 8175 | + "additionalProperties": false |
| 8176 | + }, |
| 8177 | + "description": "Allowed server-scoped operation identities; an empty list grants no access." |
| 8178 | + } |
| 8179 | + }, |
| 8180 | + "required": ["mode", "operations"], |
| 8181 | + "additionalProperties": false |
| 8182 | + }, |
| 8183 | + { |
| 8184 | + "type": "object", |
| 8185 | + "properties": { |
| 8186 | + "mode": { |
| 8187 | + "type": "string", |
| 8188 | + "const": "deny", |
| 8189 | + "description": "Exclude the selected exact operations." |
| 8190 | + }, |
| 8191 | + "operations": { |
| 8192 | + "maxItems": 1000, |
| 8193 | + "type": "array", |
| 8194 | + "items": { |
| 8195 | + "type": "object", |
| 8196 | + "properties": { |
| 8197 | + "serverId": { |
| 8198 | + "type": "string", |
| 8199 | + "minLength": 1, |
| 8200 | + "maxLength": 256, |
| 8201 | + "description": "Canonical MCP server identity, independent of the selected credential." |
| 8202 | + }, |
| 8203 | + "name": { |
| 8204 | + "type": "string", |
| 8205 | + "minLength": 1, |
| 8206 | + "maxLength": 256, |
| 8207 | + "description": "Exact operation name returned by MCP discovery." |
| 8208 | + } |
| 8209 | + }, |
| 8210 | + "required": ["serverId", "name"], |
| 8211 | + "additionalProperties": false |
| 8212 | + }, |
| 8213 | + "description": "Denied server-scoped operation identities; an empty list allows otherwise permitted tools." |
| 8214 | + } |
| 8215 | + }, |
| 8216 | + "required": ["mode", "operations"], |
| 8217 | + "additionalProperties": false |
| 8218 | + } |
| 8219 | + ], |
| 8220 | + "description": "Saved workflow operation restrictions that can only narrow authorized credential access." |
| 8221 | + }, |
8133 | 8222 | "type": { |
8134 | 8223 | "type": "string", |
8135 | 8224 | "const": "mcp", |
|
8201 | 8290 | "const": "mcp-server-advanced", |
8202 | 8291 | "description": "Server-wide MCP binding discriminator." |
8203 | 8292 | }, |
| 8293 | + "operationPolicy": { |
| 8294 | + "oneOf": [ |
| 8295 | + { |
| 8296 | + "type": "object", |
| 8297 | + "properties": { |
| 8298 | + "mode": { |
| 8299 | + "type": "string", |
| 8300 | + "const": "all", |
| 8301 | + "description": "Allow all operations available to the authorized credential." |
| 8302 | + } |
| 8303 | + }, |
| 8304 | + "required": ["mode"], |
| 8305 | + "additionalProperties": false |
| 8306 | + }, |
| 8307 | + { |
| 8308 | + "type": "object", |
| 8309 | + "properties": { |
| 8310 | + "mode": { |
| 8311 | + "type": "string", |
| 8312 | + "const": "allow", |
| 8313 | + "description": "Allow only the selected exact operations." |
| 8314 | + }, |
| 8315 | + "operations": { |
| 8316 | + "maxItems": 1000, |
| 8317 | + "type": "array", |
| 8318 | + "items": { |
| 8319 | + "type": "object", |
| 8320 | + "properties": { |
| 8321 | + "serverId": { |
| 8322 | + "type": "string", |
| 8323 | + "minLength": 1, |
| 8324 | + "maxLength": 256, |
| 8325 | + "description": "Canonical MCP server identity, independent of the selected credential." |
| 8326 | + }, |
| 8327 | + "name": { |
| 8328 | + "type": "string", |
| 8329 | + "minLength": 1, |
| 8330 | + "maxLength": 256, |
| 8331 | + "description": "Exact operation name returned by MCP discovery." |
| 8332 | + } |
| 8333 | + }, |
| 8334 | + "required": ["serverId", "name"], |
| 8335 | + "additionalProperties": false |
| 8336 | + }, |
| 8337 | + "description": "Allowed server-scoped operation identities; an empty list grants no access." |
| 8338 | + } |
| 8339 | + }, |
| 8340 | + "required": ["mode", "operations"], |
| 8341 | + "additionalProperties": false |
| 8342 | + }, |
| 8343 | + { |
| 8344 | + "type": "object", |
| 8345 | + "properties": { |
| 8346 | + "mode": { |
| 8347 | + "type": "string", |
| 8348 | + "const": "deny", |
| 8349 | + "description": "Exclude the selected exact operations." |
| 8350 | + }, |
| 8351 | + "operations": { |
| 8352 | + "maxItems": 1000, |
| 8353 | + "type": "array", |
| 8354 | + "items": { |
| 8355 | + "type": "object", |
| 8356 | + "properties": { |
| 8357 | + "serverId": { |
| 8358 | + "type": "string", |
| 8359 | + "minLength": 1, |
| 8360 | + "maxLength": 256, |
| 8361 | + "description": "Canonical MCP server identity, independent of the selected credential." |
| 8362 | + }, |
| 8363 | + "name": { |
| 8364 | + "type": "string", |
| 8365 | + "minLength": 1, |
| 8366 | + "maxLength": 256, |
| 8367 | + "description": "Exact operation name returned by MCP discovery." |
| 8368 | + } |
| 8369 | + }, |
| 8370 | + "required": ["serverId", "name"], |
| 8371 | + "additionalProperties": false |
| 8372 | + }, |
| 8373 | + "description": "Denied server-scoped operation identities; an empty list allows otherwise permitted tools." |
| 8374 | + } |
| 8375 | + }, |
| 8376 | + "required": ["mode", "operations"], |
| 8377 | + "additionalProperties": false |
| 8378 | + } |
| 8379 | + ], |
| 8380 | + "description": "Saved workflow operation restrictions that can only narrow authorized credential access." |
| 8381 | + }, |
8204 | 8382 | "params": { |
8205 | 8383 | "type": "object", |
8206 | 8384 | "properties": { |
| 8385 | + "connectionId": { |
| 8386 | + "description": "Optional managed connection ID or upstream reference bound to the canonical server.", |
| 8387 | + "type": "string", |
| 8388 | + "minLength": 1, |
| 8389 | + "maxLength": 128 |
| 8390 | + }, |
8207 | 8391 | "serverId": { |
8208 | 8392 | "type": "string", |
8209 | 8393 | "minLength": 1, |
|
8213 | 8397 | }, |
8214 | 8398 | "required": ["serverId"], |
8215 | 8399 | "additionalProperties": false, |
8216 | | - "description": "Server identity for discovering and invoking every available MCP tool." |
| 8400 | + "description": "Server and optional connection identity for authorized operation discovery and execution." |
8217 | 8401 | }, |
8218 | 8402 | "usageControl": { |
8219 | 8403 | "type": "string", |
|
8226 | 8410 | "description": "Forward-compatible MCP server metadata preserved by the workflow editor." |
8227 | 8411 | }, |
8228 | 8412 | "title": "Agent MCP server (advanced)", |
8229 | | - "description": "All tools available to the executing subject from one MCP server.", |
| 8413 | + "description": "Dynamically discovered operations permitted by the authorized credential and saved block policy.", |
8230 | 8414 | "examples": [ |
8231 | 8415 | { |
8232 | 8416 | "type": "mcp-server-advanced", |
|
0 commit comments