Gumloop MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GUMLOOP_API_KEY | No | Private Bearer credential; alternative to token file. | |
| GUMLOOP_TEAM_ID | No | Single-account default team; legacy project_id. | |
| GUMLOOP_USER_ID | No | Single-account default user identity. | |
| GUMLOOP_ACCOUNTS | No | Private named JSON profiles; takes precedence over single-account settings. | |
| GUMLOOP_AUDIT_LOG | No | Optional private local guard log. | |
| GUMLOOP_READ_ONLY | No | 1/true hides/refuses confirmed operations. | |
| GUMLOOP_TOKEN_FILE | No | Regular token-only file <=64 KB; overrides key. | |
| GUMLOOP_MAX_RETRIES | No | 0-5; default 2; short explicit GET 429 only. | 2 |
| GUMLOOP_DEFAULT_ACCOUNT | No | Exact label, otherwise first entry. | |
| GUMLOOP_ALLOW_DESTRUCTIVE | No | 0/false blocks confirmed operations. | |
| GUMLOOP_REQUEST_TIMEOUT_MS | No | 100-300000; default 30000. | 30000 |
| GUMLOOP_MIN_REQUEST_INTERVAL_MS | No | 0-10000; default 150; per account/process. | 150 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| start_flowA | This endpoint is used to trigger a flow run via API Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| kill_flowA | This endpoint is used to kill a flow run and all its subflow runs. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| get_run_detailsA | This endpoint can be used to poll for completion and retrieve final flow outputs. Output steps must be used to retrieve outputs. Read operation. |
| list_workbooksC | List workbooks and their saved flows Read operation. |
| list_flowsC | List saved flows Read operation. |
| get_input_schemaC | Retrieve input schema Read operation. |
| get_run_historyB | This endpoint retrieves the run history for automations, either by workbook or saved item. Returns the 10 most recent runs. Read operation. |
| download_fileC | Download file Read operation. |
| download_filesC | Download multiple files Read operation. |
| upload_fileB | Upload file Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| upload_filesA | Upload multiple files Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| get_organization_audit_logsB | This endpoint retrieves audit logs for all users in an organization for a specified time period. Read operation. |
| manage_project_usersB | This endpoint allows organization administrators to add or remove users from a workspace. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| manage_permission_group_usersA | This endpoint allows organization administrators to add or remove users from a custom role (formerly "permission group"). Adding a user to a role does not remove them from any other role they belong to. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| list_role_credit_limitsA | This endpoint lists every active custom role in an organization together with its monthly credit limit, so external systems can manage credit limits programmatically. A |
| get_role_credit_limitA | This endpoint returns the monthly credit limit of one custom role. A |
| set_role_credit_limitA | This endpoint sets or clears the monthly credit limit of a custom role. The limit applies to each member of the role individually and takes effect immediately: member allowances are recalculated while preserving credits already used in the current billing cycle. Send |
| export_dataA | This endpoint allows enterprise organization administrators to create and initiate a comprehensive data export for their organization or specific workspaces. The export supports six data types:
The available Scoping requirement: For non-credit-log exports, at least one scoping parameter must be provided: Note: Credit log exports work differently from workflow and agent exports. When |
| get_export_statusA | This endpoint retrieves the status of a data export job and optionally downloads the export file (as CSV) if the export has completed successfully. Use the |
| list_agentsA | List agents the caller has access to. Filter by team, search by name, or narrow to agents that use a specific tool or trigger. Results can be sorted with |
| create_agentA | Create a new agent. The authenticated caller must have permission to create agents on the target team. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| retrieve_agentA | Retrieve a single agent by ID. In addition to regular agent IDs, |
| update_agentA | Update an existing agent. Only fields included in the request body are changed; omitted fields are left untouched. This endpoint edits document fields only. To attach or detach skills, use
|
| create_chat_completionB | OpenAI-compatible chat completions endpoint, multiplexed across every model Gumloop supports
(Anthropic, OpenAI, Google Gemini, OpenRouter routes). Set Streaming hostChat completions live on the streaming host. Send all requests — unary or streaming — to:
Tool calls, images, and |
| list_modelsB | List the LLMs and preset model chains available to the caller, grouped for display in a model picker. Read operation. |
| route_modelA | Ask Gumloop Chew — the model router behind Auto — which model it would use for a given
message, and why. Chew is a router, not a model: This endpoint returns a decision only. It does not run the selected model or its fallbacks. The routing judgement consumes credits and is bounded by the caller's model access. Omit Team scope requires actual team membership, even within the same organization. Personal API keys and OAuth are supported; this is not team-key-only. Read operation. |
| list_agent_versionsA | List the immutable versions of an agent, newest first. Each entry is a point-in-time snapshot of the agent's configuration. Requires configuration access on the agent — callers limited to using the agent (no configuration access) get a |
| retrieve_agent_versionA | Retrieve one immutable agent version: its full configuration (
Requires configuration access on the agent — callers limited to using the agent (no configuration access) get a |
| update_agent_skillsA | Attach and/or detach skills on an agent using deltas. This is not a replace-list: skills you don't mention are left untouched.
|
| list_agent_mcp_serversA | List the MCP servers (connectors) attached to an agent. Sensitive fields such as |
| attach_agent_mcp_serverA | Attach an MCP server (connector) to an agent, or update its configuration if it's already attached (upsert). The Attach may succeed before OAuth is completed; |
| detach_agent_mcp_serverA | Detach an MCP server (connector) from an agent. This is idempotent — detaching a server that isn't attached returns |
| list_sessionsA | List sessions for an agent with cursor-based pagination, optional filtering, and search. Read operation. |
| create_sessionA | Create a new session for an agent. When
Streaming the response
The response is If you send |
| retrieve_sessionA | Retrieve a session by ID, including its messages, current state, agent metadata, and participants. Read operation. |
| rename_sessionA | Rename a session. Returns the full session, in the same shape as Retrieve session. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| send_messageA | Append a user message to an existing session and resume the agent. The session must be Files uploaded via Upload session file can be attached to the message with Sessions waiting on an approvalA session that stopped to ask you something is
See Human in the Loop for how agents pause for approvals and questions. Streaming the response
The response is If you send |
| cancel_sessionA | Cancel an in-progress session. If the session is currently The response carries a |
| upload_session_fileA | Upload a file into a session's input namespace so it can be attached to a message. The response returns the stored path — pass it as Files are base64 encoded in the request body and limited to 200MB (decoded). Uploaded files are scoped to the session they were uploaded to and cannot be attached to messages on other sessions. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| resolve_session_approvalsA | Answer pending asks on a session that is paused in the List the pending asks with Retrieve session: each entry in |
| list_queued_messagesA | List the messages waiting in a session's queue, in the order they will be sent. Queued messages are drained automatically when the agent finishes its current turn. Read operation. |
| queue_session_messageA | Add a message to a session's queue instead of interrupting the agent. Queued messages are sent automatically, in order, when the agent finishes its current turn. A session's queue holds at most 20 messages. To interrupt the current turn and send a queued message immediately, use Send queued message now. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| update_queued_messageA | Replace the content of a message that is still waiting in the session's queue. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| delete_queued_messageA | Remove a message from the session's queue before it is sent. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| send_queued_messageA | Send a queued message immediately instead of waiting for the agent to finish its current turn. Any in-progress run is aborted, the queued message is appended to the transcript, and the agent starts processing it. The response is the same envelope as Send message. Queued messages cannot be sent this way on incognito sessions, and a message that is currently being edited must have its edit finished or cancelled first. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| list_mcp_serversB | Return the catalog of MCP servers visible to the caller — Gumloop-hosted ( |
| retrieve_mcp_serverB | Return a single MCP server. The response populates |
| list_mcp_server_toolsA | Return the tools exposed by an MCP server. When the server is not in |
| list_mcp_server_resourcesA | Return the resources an MCP server exposes, fetched live from the server. When the server is not |
| read_mcp_server_resourceA | Read one resource by |
| list_mcp_server_promptsB | Return the prompt templates an MCP server exposes, fetched live from the server. When the server is not |
| get_mcp_server_promptB | Render one prompt template with arguments and return its messages. Read operation. |
| call_mcp_toolsA | Execute a batch of 1–5 MCP tool calls. Calls run concurrently and each result reports its own |
| search_brainA | Run a hybrid (semantic + keyword) search across the knowledge sources indexed in your Company Brain and return the most relevant, ranked snippets with citations. Results are scoped to what the authenticated user can see: personal sources, plus any team and organization sources shared with them. Requires the Brain feature, which is available on the Pro and Enterprise plans. Each search consumes Gumloop credits. Explicit confirmation is required for this credit-consuming Brain search. |
| list_brain_sourcesA | List the Company Brain sources the authenticated user can see: personal sources, plus team and organization sources shared with them. Every source type is listed, including ones connected in the app such as Notion or Google Drive. Read operation. |
| create_brain_sourceA | Create a file-upload source. Only By default the source is |
| get_brain_sourceB | Fetch one source the authenticated user can see. Read operation. |
| delete_brain_sourceA | Delete a source, every file in it, and everything it contributed to search. This cannot be undone. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| list_brain_filesA | List the files in a file-upload source with their indexing status. Each file carries the |
| upload_brain_filesA | Upload up to 25 files as Indexing starts on its own after the upload: an Files the upload policy refuses (unsupported type, too large, empty) are returned in |
| delete_brain_fileB | Remove a file from the source and from search. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| get_brain_source_estimateA | The latest credit estimate for a source created with |
| approve_brain_sourceA | Approve a |
| list_skillsA | List skills the caller has access to. Filter by team, search by name, or narrow to a specific creator, related MCP server, or agent. Read operation. |
| create_skillA | Upload a skill package and create a new skill. The package must include a |
| update_skillA | Replace a skill's files with a new upload. Reparses |
| delete_skillA | Permanently delete a skill. This is a soft-delete — the skill will no longer appear in listings or be usable by agents. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| download_skill_fileA | Generate a signed URL to download a skill's contents as a |
| list_artifactsA | List artifacts (files) produced by an agent. Optionally scope to a specific session, search by filename, sort, and paginate. Deleted files are excluded from the results. Read operation. |
| download_artifact_fileA | Returns a signed download URL for an artifact, plus its filename, media type, and size. Follow |
| list_browser_profilesA | List the browser profiles you own, or a team's profiles with |
| import_browser_profile_cookiesA | Add sign-in cookies to a browser profile. This is what Use |
| list_teamsC | List teams the authenticated caller belongs to. Read operation. |
| list_evaluationsA | Returns a cursor-paginated list of evaluation results for a specific agent, newest first.
Only completed and failed evaluations are returned unless Each evaluation includes the grade, criteria pass/fail results, extracted data points, applied tags, and sentiment analysis. Read operation. |
| run_evaluationsA | Grades up to 200 of the agent's finished sessions with its own evaluation configuration. Grading is asynchronous: each accepted session gets a result with Sessions are skipped, not rejected, when they are unfinished, incognito, or not owned by this agent ( Requires edit access on the agent and a plan with evaluations enabled. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| get_evaluation_metricsA | Returns aggregated grade and tag counts for an agent's evaluations over a time window. Useful for dashboards and reporting on agent quality trends. Read operation. |
| retrieve_evaluationA | Retrieve a single evaluation result by ID. The evaluation must belong to the specified agent. Read operation. |
| get_evaluation_configB | Retrieve the current evaluation configuration for an agent, including criteria, tags, data points, and sentiment settings. Read operation. |
| update_evaluation_configA | Partially update the evaluation configuration for an agent. Omitted fields keep their current value. Provided list fields (criteria, tags, data_points) replace that list entirely. Requires Pro tier or above. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| list_organizationsA | Returns the organization the authenticated user belongs to. Use its |
| get_evaluation_optionsA | Allowed values for evaluation fields and filters — session types, criterion types and priorities, data point types, frequencies, grades, statuses, target types, skip reasons — plus size limits. Use these instead of hardcoding enums. Read operation. |
| list_organization_evaluationsA | Cursor-paginated list of an organization's evaluations with their targets, coverage, and result rollups. Requires the |
| create_organization_evaluationA | Creates an organization evaluation. A new evaluation has no targets, so it cannot start enabled: set targets with Rubric values are validated strictly: an unknown |
| get_organization_evaluationB | Returns one evaluation with its rubric, targets, current coverage, and result rollup. Read operation. |
| update_organization_evaluationA | Partial update. Only the fields you send change. Setting |
| delete_organization_evaluationA | Deletes the evaluation. It stops running and disappears from lists; results it already produced stay attached to their sessions. Explicit confirmation is required for this exact account operation. Runs can spend credits or trigger downstream actions; never resubmit unknown outcomes automatically. |
| set_organization_evaluation_targetsA | Replaces the full set of targets — who the evaluation grades. Targets expand to agents live: |
| run_organization_evaluationA | Grades up to 200 existing sessions with this evaluation. Grading is asynchronous: each accepted session gets a result with Sessions are skipped, not rejected, when they are not completed sessions of an agent the evaluation covers ( |
| list_organization_evaluation_resultsA | Cursor-paginated results for one evaluation across every agent it grades, newest first. Each session appears once with its latest result; queued and in-progress results are included so a run can be followed to completion. Read operation. |
| get_organization_evaluation_resultA | One result, including per-criterion outcomes, extracted data points, and applied tags. Poll this after |
| get_organization_evaluation_metricsB | Grade counts for one evaluation over a trailing window (default 30 days, 1–365). Read operation. |
| list_accountsA | List private account labels, default selection and configured token method. No credentials, token paths or account content; no network request. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 92 tools
Many tools have overlapping or indistinguishable purposes across the 92-tool surface, such as list_flows vs list_workbooks vs get_run_history, or upload_file vs upload_files vs upload_session_file vs upload_brain_files. with such a large flat set, boundaries between agent, session, flow, evaluation, brain, and skill tools are unclear without deep cross-referencing.
Most tools follow a consistent verb_noun snake_case pattern (list_agents, create_skill, delete_brain_source), with only minor deviations like route_model and call_mcp_tools. The convention is largely predictable.
92 tools is excessive for a single MCP server and likely buries the core operations. Many are thin variants (get_evaluation_metrics vs get_organization_evaluation_metrics) that could be consolidated.
Coverage is broad and deep across flows, agents, sessions, evaluations, brain, skills, and MCP, with both read and write operations. minor CRUD gaps exist but the surface is mostly complete.