Skip to main content
tools/list is the authoritative tool reference for the current actor. Forge builds each definition from the same capability registry used by the REST API and CLI. Each advertised tool contains:
Clients should render and validate the returned inputSchema; do not maintain a separate permissive schema. Tool schemas reject unknown properties.

Search a large tool catalog

If your MCP client supports a search-first tool flow, send X-Forge-Tool-Search: 1 with tools/list. Forge then advertises forge_search_tools instead of loading every tool schema into the client. Call it with a query to find tools available to the current actor, then use the returned tool definitions for subsequent calls. Forge checks access again when each tool is called, so a search result does not grant access by itself. Install an API-backed integration in Registry → From API and configure its client access before searching its tools. The search only includes tools the actor can use. Clients that do not send the header continue to receive the normal tools/list response.

Discovery tools

Investigation tools

Policy tools

Governance tools

MCP approval tools

Assurance tools

Administration tools

Calling a tool

Use the exact schema returned by tools/list:
Forge validates the call again at execution time. A tool that appeared earlier can still be denied if the session was revoked, organization settings changed, the actor lost access, or required mutation safeguards are absent.

Mutation inputs

Guarded mutation tools expose applicable fields directly in their inputSchema: The fields are forwarded to the underlying Forge capability as safety headers and request-body values. They are not generic prompt instructions.

Output limits

Tool text content is bounded to protect the MCP session. Successful results also include the underlying object in structuredContent.result. Search tools expose their own cursor or offset semantics. forge_inventory_search additionally returns resultCount, totalMatching, hasMore, nextOffset, and a pagination object. Do not treat a bounded search page as an organization-wide total. forge_activity_aggregates_get computes exact totals across all activity that matches its canonical filters, while returning bounded dimension breakdowns. forge_llm_gateway_usage_get does the same for usage observed through Forge LLM Gateway. Search tools should be continued using the pagination fields returned by that specific tool. MCP call audit records store the tool, capability, decision, reason, request ID, and redacted bounded input/output summaries. Inputs containing credential-shaped fields are redacted from the summary.