Change what a Napkin interface can reach
napkin_interfaces_grantSet what an interface may run — flows and shims, each pinned to a published version. This is the interface's ONLY reach into the workspace, and it replaces the whole list, so include everything it should keep. Ids and published versions come from workbench_flows_list / workbench_shim_list and their revisions. Ask the user before widening this.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| grants | Yes | The complete list. Passing an empty list removes all access. | |
| workspace | No | Workspace slug. Personal tokens with no default workspace MUST pass this; tokens with a default can override per call. Ignored for workspace API keys. | |
| approvalId | No | Approval id from a prior needs_confirmation response. Omit on the first call. | |
| interfaceId | Yes |