Skip to main content
POST
Build a tool
Authentication: Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key, integration API key. Permission: tools:build. Effect: Write: creates or changes something in your account. Errors: effect_required (400), invalid_request (400), unauthorized (401), reauthentication_required (401), save_forbidden (403), site_not_supported (403), forbidden (403), not_found (404), idempotency_conflict (409), quota_expired (409), account_selection_required (409), saved_login_conflict (409), login_identity_conflict (409), legacy_duplicate_saved_logins (409), saved_login_unsettled (409), request_too_large (413), quota_exceeded (429), internal_error (500), not_configured (501), acceptance_unknown (503), temporarily_unavailable (503). Every error has the same envelope.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

Idempotency-Key
string

Repeat a request safely: the same key and body answer the first request's job again with Idempotent-Replayed: true; the same key with a different body answers idempotency_conflict. 1 to 200 letters, digits, _ or -, such as a UUID

Pattern: ^[A-Za-z0-9_-]{1,200}$

Body

application/json
task
string
required

What the tool should do, in words

Required string length: 1 - 20000
site_url
string

The website's https address; omit it for offline parsing, which is a read

Maximum string length: 2048
start_url
string

The exact https page on site_url the build starts on, path, query and fragment kept

Maximum string length: 4096
effect
enum<string>

read when the tool only looks things up; write when it changes the website (submitting, booking, saving a form, uploads, account updates); ask to have the build ask first. A website build needs one.

Available options:
read,
write,
ask
example_input

The input of the one real example the build runs

login_id
string

The saved login to sign in with, when the site has several

Example:

"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

login
object

A login for this call, used only when the site has no saved login: a username (or email, phone or account number) with its password, or mode "code" and no password when the site sends a code. It reaches this caller's client and model provider; without one, the run asks the person on its answer page.

save_login
boolean

Keep login as a saved login (requires login)

redact_at_rest
boolean

Staging and preview only: true seals what this job stores and redacts it once it settles, false keeps it readable, overriding the environment's setting. Production refuses a request that names it with invalid_request.

Response

The job this Idempotency-Key already started, with Idempotent-Replayed: true

id
string
required

a job ID: job_ and 32 lowercase hex digits

Example:

"job_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

type
enum<string>
required
Available options:
run,
build
status
enum<string>
required
Available options:
queued,
running,
needs_input,
succeeded,
failed,
cancelled
tool_id
string | null
required
input_request
object | null
required
result
any
required
result_expires_at
string | null
required

a string to be decoded into a Date

write_status
enum<string> | null
required
Available options:
not_attempted,
may_have_applied,
applied,
not_applied
login_save
object | null
required
error
object | null
required
message
string | null
required
maintenance
object | null
required
build
object | null
required
watch_url
string
required
created_at
string
required

a string to be decoded into a Date

updated_at
string
required

a string to be decoded into a Date

completed_at
string | null
required

a string to be decoded into a Date

tip
string