> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Integration MCP tools

> The tools an integration MCP lists: one site's tools and its job tools.

An integration MCP serves one site's tools plus `get_job`, `answer_job` and `cancel_job`. Each site tool takes its own input schema, the one `find_website_tool` returns as `input_schema`, under `input`. The example below is an Amazon integration with two tools; yours lists its own.

## Site tools (example)

### `build_tool`

Build a new Example Shop tool and add it to this MCP, when none of its tools covers the task, then run the requested example once. The returned job preserves that example result; do not repeat a completed website action. A build takes about 10 minutes: follow it with get\_job. Builds for ticket, bank and government sites are refused with site\_not\_supported. A website build requires effect. Use read when the operation only looks things up. Use write when it changes the website: filling in or advancing a form that saves data (an application, profile or checkout) is a write, as are submitting, booking, drafts, holds, uploads and account updates; a search, filter or query form is a read. Use ask when unsure: before anything runs, the build asks read or write as a pending input request (get\_job shows it; answer with answer\_job). A read build that finds its task needs a website change asks the same way before switching to a write. Set entry\_url only to the exact requested https page on [https://shop.example.com](https://shop.example.com). Website login: without connected\_account\_id or website\_auth the build stays anonymous; if it signs in, it uses the site's saved login, asks the owner which one when several could sign in, and asks through the protected form only when none is saved. With website\_auth, a saved login for the site with the same username is used instead, and a different username is refused. A job that reports status needs\_credentials (the website rejected its saved login; a run waits only when nothing was changed, and a build that may have changed the website checks that on resuming, as possible\_commit says) waits up to 60 minutes for the user who started it to correct that login, then resumes as the same job; its next names the page to correct it. Do not resubmit it. Values passed here are visible to your client and its model provider; the protected form keeps them out of this conversation. Pomerado keeps them from the minting model, traces and logs either way.

**Effect:** May change a website or your account, and a change may not be undoable.

| Argument | Required | Type | Description |
| - | - | - | - |
| `intent` | Yes | string, up to 20,000 characters | |
| `entry_url` | No | string, up to 4,096 characters | Exact https page on site\_origin, including path, query and fragment, that the host opens before the first live execution. |
| `effect` | No | one of: `read`, `write`, `ask` | |
| `retry_key` | No | string | |
| `connected_account_id` | No | string | |
| `website_auth` | No | object | |
| `input` | Yes | string | A JSON-encoded value matching the operation's input schema. |

### `get_order_status`

Read the status and delivery estimate of one order from the signed-in Amazon account.

Returns the validated operation result. A client that accepts SSE gets a stream that waits up to 5 minutes for the result, with progress while the job runs. Any other client waits up to 50 seconds. A run that asks a question returns input\_required at once. A job still running then returns status "running" with its job\_id; follow its next block (get\_job with wait\_seconds) instead of calling again.

Signs in with this site's saved login; pass connected\_account\_id to choose among several. website\_auth is used only when no login is saved, and one that differs from a saved login is refused. Without either, the run asks the user for the login on its protected page and may save it. A job that reports status needs\_credentials (the website rejected its saved login; a run waits only when nothing was changed, and a build that may have changed the website checks that on resuming, as possible\_commit says) waits up to 60 minutes for the user who started it to correct that login, then resumes as the same job; its next names the page to correct it. Do not resubmit it.

Its sign-in takes: email, password; two-factor sign\_in\_method: sms, authenticator. website\_auth may carry the listed ones; one the login lacks is asked for when the sign-in needs it.

**Effect:** Reads only; changes nothing.

| Argument | Required | Type | Description |
| - | - | - | - |
| `input` | Yes | object | The operation's input: order\_number (string, required): The order number from the confirmation email. |
| `retry_key` | No | string | Optional. Your key for this call; reuse it only to retry the same call. |
| `connected_account_id` | No | string | Optional. The ID of the saved login to sign in with, when the site has several. |
| `correct_rejected_credentials` | No | one of: `true` | Optional. Ask to correct this saved login during the run; requires connected\_account\_id. |
| `website_auth` | No | object | Optional. A website login for this call, used only when the site has no saved login this caller may use; save stores it. Values passed here are visible to your client and its model provider; the protected form keeps them out of this conversation. Pomerado keeps them from the minting model, traces and logs either way. |
| `sign_in_method` | No | one of: `sms`, `authenticator` | The two-factor method (sms, call, email, totp or push) the tool's sign-in picks when the site offers several. Without it, a saved authenticator seed picks totp, otherwise the run asks. |

### `search_products`

Search Amazon's catalog by keywords and return up to 20 products with title, price, rating and URL.

Returns the validated operation result. A client that accepts SSE gets a stream that waits up to 5 minutes for the result, with progress while the job runs. Any other client waits up to 50 seconds. A run that asks a question returns input\_required at once. A job still running then returns status "running" with its job\_id; follow its next block (get\_job with wait\_seconds) instead of calling again.

**Effect:** Reads only; changes nothing.

| Argument | Required | Type | Description |
| - | - | - | - |
| `input` | Yes | object | The operation's input: query (string, required): Words to search for; max\_price (integer): Highest price in cents, optional. |
| `retry_key` | No | string | Optional. Your key for this call; reuse it only to retry the same call. |
| `connected_account_id` | No | string | Optional. The ID of the saved login to sign in with, when the site has several. |
| `correct_rejected_credentials` | No | one of: `true` | Optional. Ask to correct this saved login during the run; requires connected\_account\_id. |
| `website_auth` | No | object | Optional. A website login for this call, used only when the site has no saved login this caller may use; save stores it. Values passed here are visible to your client and its model provider; the protected form keeps them out of this conversation. Pomerado keeps them from the minting model, traces and logs either way. |
| `sign_in_method` | No | one of: `sms`, `call`, `email`, `totp`, `push` | The two-factor method (sms, call, email, totp or push) the tool's sign-in picks when the site offers several. Without it, a saved authenticator seed picks totp, otherwise the run asks. |

## Job tools

### `answer_job`

Answer the pending input request that get\_job lists as pending\_input, every question at once. Pass request\_id and request\_version from it and answers keyed by question id: choice, an option id (or \{"other": text} when allowOther); multi\_choice, an array of option ids; text and secret, a string; confirm, \{"confirmed": true|false}; credential, \{"username", "password", "saveLogin"}. With job\_id alone this returns the protected page, which keeps secrets and logins out of this conversation; answer a secret or credential here only if the user agrees. Values passed here are visible to your client and its model provider; the protected form keeps them out of this conversation. Pomerado keeps them from the minting model, traces and logs either way. Never send TOTP seeds or durable tokens.

**Effect:** May change a website or your account, and a change may not be undoable.

| Argument | Required | Type | Description |
| - | - | - | - |
| `job_id` | Yes | string (UUID) | |
| `request_id` | No | string (UUID) | |
| `request_version` | No | integer, 1 to 1000000 | |
| `retry_key` | No | string | |
| `answers` | No | string | A JSON-encoded object of answers keyed by question id, shaped as pending\_input.questions describe. |

### `get_job`

Get the status and authorized result of a job. Pass wait\_seconds to wait: the call returns the moment the job asks a question or finishes, and when the wait ends with the job still running (call again then). A client that accepts SSE waits up to 1800 seconds with progress; any other waits at most 50 seconds. A result for a live job carries next, the exact call to make next. With wait\_past naming a question already handed to the user, the wait holds while that question is pending. During a wait, a client that supports elicitation asks the user the job's question itself: a form for plain questions, the protected page for secrets and logins. A build that published a tool, or found an existing tool that covers its request, returns that tool as `tool`. It is then a tool on this MCP: list the tools again to call it. Never ask for passwords in chat: when a job needs a login, a code or an approval, give the user protected\_input\_url and keep waiting here. Follow a job until it finishes and never start the same job twice. A job that reports status needs\_credentials (the website rejected its saved login; a run waits only when nothing was changed, and a build that may have changed the website checks that on resuming, as possible\_commit says) waits up to 60 minutes for the user who started it to correct that login, then resumes as the same job; its next names the page to correct it. Do not resubmit it.

**Effect:** Reads only; changes nothing.

| Argument | Required | Type | Description |
| - | - | - | - |
| `job_id` | Yes | string (UUID) | |
| `wait_seconds` | No | integer, 0 to 1800 | Wait up to this many seconds (at most 1800, or 50 when your client accepts only JSON) for the job to ask a question or finish. 0 or absent reads the job at once. |
| `wait_past` | No | object | A question already handed to the user (its pending\_input request\_id and request\_version): the wait continues while it is pending and returns once it is answered, changes or expires, or the job finishes. |

### `cancel_job`

Request cancellation of a job. A dispatched website effect may already have occurred.

**Effect:** May change a website or your account, and a change may not be undoable.

| Argument | Required | Type | Description |
| - | - | - | - |
| `job_id` | Yes | string (UUID) | |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.