> ## Documentation Index
> Fetch the complete documentation index at: https://docs.checkfu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare connected account tools

> Prepare the reviewed native MCP provider catalog for one active, healthy Connection.



## OpenAPI

````yaml /openapi.json post /v1/connections/{id}/tools/prepare
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-31'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; bootstrap poll token; or anonymous bootstrap
    creation and credential-free pairing redemption. Every general Checkfu REST
    request requires the dated `Checkfu-Version` header (one of: 2026-08-31);
    the three MCP JSON-RPC transports use `MCP-Protocol-Version`, A2A uses
    `A2A-Version`, and the provider OAuth callback carries neither Checkfu
    header. API keys resolve one Workspace without a request selector;
    authenticated responses identify it with `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentBlueprints
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: managedTools
  - name: concepts
  - name: support
  - name: bootstrapRequests
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: fileTrees
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: workloadReviewPolicies
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: sessionHandoffs
  - name: sessionCapsules
  - name: sessionTrajectories
  - name: webhookEndpoints
  - name: integrationGateway
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: computerHeadlessOperations
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/connections/{id}/tools/prepare:
    post:
      tags:
        - connections
      summary: Prepare connected account tools
      description: >-
        Prepare the reviewed native MCP provider catalog for one active, healthy
        Connection. Requires expected_version and an Idempotency-Key. Reuses a
        complete healthy catalog with the exact reviewed descriptor; otherwise
        creates the Workspace ToolSource and discovers bounded tool metadata
        using the stored account grant inside credential custody, then publishes
        a generation guarded by the exact current Connection. Returns the
        ToolSource, never credentials or MCP session handles. Refuses mismatched
        packages, inactive accounts, incomplete discovery, and stale versions.
        Grants no Agent access and invokes no provider tools. Integration
        Runtime Connections use their capability-refresh operations instead.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        connection-lifecycle. Deployment-specific readiness and the latest
        proven release are available from GET /v1/support/capabilities.
      operationId: connections.prepareConnectionTools
      parameters:
        - name: id
          in: path
          schema:
            $ref: '#/components/schemas/ConnectionId'
          required: true
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-31'
          required: true
        - name: idempotency-key
          in: header
          schema:
            type: string
            allOf:
              - maxLength: 255
              - minLength: 1
          required: true
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrepareConnectionTools'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    $ref: '#/components/schemas/ToolSourceId'
                  workspace_id:
                    $ref: '#/components/schemas/WorkspaceId'
                  name:
                    type: string
                    pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
                  provider:
                    type: string
                    pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
                  description:
                    $ref: '#/components/schemas/Union_154'
                  source:
                    $ref: '#/components/schemas/Union_153'
                  status:
                    $ref: '#/components/schemas/Union_155'
                  default_enabled:
                    type: boolean
                  default_permission:
                    $ref: '#/components/schemas/Union_156'
                  tool_count:
                    type: integer
                    minimum: 0
                  last_sync_at:
                    $ref: '#/components/schemas/Union_157'
                  last_sync_error_code:
                    $ref: '#/components/schemas/Union_158'
                  version:
                    type: integer
                    exclusiveMinimum: 0
                  created_at:
                    type: string
                  updated_at:
                    type: string
                required:
                  - id
                  - workspace_id
                  - name
                  - provider
                  - description
                  - source
                  - status
                  - default_enabled
                  - default_permission
                  - tool_count
                  - last_sync_at
                  - last_sync_error_code
                  - version
                  - created_at
                  - updated_at
                additionalProperties: false
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - validation.malformed
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#validation-malformed
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    required:
                      - type
                      - message
                      - more
                    additionalProperties: false
                additionalProperties: false
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '409':
          description: >-
            The request conflicts with the resource's current state. | An
            idempotent mutation conflicts with a completed or in-progress
            request for the same key.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ValidationConflictError'
                  - $ref: '#/components/schemas/IdempotencyConflictError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    ConnectionId:
      type: string
      pattern: ^conn_[0-9a-f]{32}$
    PrepareConnectionTools:
      type: object
      properties:
        expected_version:
          type: integer
          allOf:
            - exclusiveMinimum: 0
            - maximum: 9007199254740991
      required:
        - expected_version
      additionalProperties: false
      description: Prepare the native catalog under the exact current Connection version.
    ToolSourceId:
      type: string
      pattern: ^ts_[0-9a-f]{32}$
    WorkspaceId:
      type: string
      pattern: ^wrkspc_[0-9a-f]{32}$
    Union_154:
      anyOf:
        - type: string
          allOf:
            - maxLength: 16384
        - type: 'null'
    Union_153:
      anyOf:
        - type: object
          properties:
            kind:
              type: string
              enum:
                - mcp
            url:
              $ref: '#/components/schemas/PublicHttpsUrl'
            authenticated:
              type: boolean
          required:
            - kind
            - url
          additionalProperties: false
        - type: object
          properties:
            kind:
              type: string
              enum:
                - openapi
            document_url:
              $ref: '#/components/schemas/PublicHttpsUrl'
            base_url:
              $ref: '#/components/schemas/CredentialFreeHttpsUrl'
          required:
            - kind
            - document_url
            - base_url
          additionalProperties: false
        - type: object
          properties:
            kind:
              type: string
              enum:
                - api
            base_url:
              $ref: '#/components/schemas/CredentialFreeHttpsUrl'
            tools:
              type: array
              items:
                $ref: '#/components/schemas/Objects_63'
              allOf:
                - maxItems: 1000
          required:
            - kind
            - base_url
            - tools
          additionalProperties: false
        - $ref: '#/components/schemas/Objects_67'
        - type: object
          properties:
            kind:
              type: string
              enum:
                - connector
            source_digest:
              type: string
              pattern: ^sha256:[0-9a-f]{64}$
            tools:
              type: array
              items:
                $ref: '#/components/schemas/Objects_63'
              allOf:
                - maxItems: 1000
          required:
            - kind
            - source_digest
            - tools
          additionalProperties: false
    Union_155:
      type: string
      enum:
        - pending
        - healthy
        - sync_failed
    Union_156:
      type: string
      enum:
        - always_ask
        - always_allow
    Union_157:
      anyOf:
        - type: string
        - type: 'null'
    Union_158:
      anyOf:
        - type: string
          allOf:
            - minLength: 1
            - maxLength: 8192
        - type: 'null'
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    ValidationConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.conflict
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The request conflicts with the resource's current state.
    IdempotencyConflictError:
      anyOf:
        - $ref: '#/components/schemas/ValidationIdempotencyConflictError'
        - $ref: '#/components/schemas/ValidationIdempotencyInProgressError'
      description: >-
        An idempotent mutation conflicts with a completed or in-progress request
        for the same key.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    PublicHttpsUrl:
      type: string
      allOf:
        - pattern: ^https:\/\/[^\s]+$
        - maxLength: 2048
    CredentialFreeHttpsUrl:
      type: string
      allOf:
        - pattern: ^https:\/\/[^\s]+$
        - maxLength: 2048
    Objects_63:
      type: object
      properties:
        name:
          type: string
          pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        description:
          type: string
          allOf:
            - maxLength: 16384
        input_schema:
          $ref: '#/components/schemas/JsonValue'
        output_schema:
          $ref: '#/components/schemas/JsonValue'
        safety_hints:
          $ref: '#/components/schemas/Objects_64'
        http:
          type: object
          properties:
            method:
              $ref: '#/components/schemas/HttpMethod'
            path_template:
              type: string
              allOf:
                - minLength: 1
                - maxLength: 8192
                - pattern: ^\/[^\r\n?#]*$
            arguments:
              $ref: '#/components/schemas/Objects_65'
          required:
            - method
            - path_template
            - arguments
          additionalProperties: false
        a2a:
          $ref: '#/components/schemas/Objects_66'
        integration:
          type: object
          properties:
            digest:
              type: string
              pattern: ^sha256:[0-9a-f]{64}$
          required:
            - digest
          additionalProperties: false
      required:
        - name
      additionalProperties: false
    Objects_67:
      type: object
      properties:
        kind:
          type: string
          enum:
            - a2a
        card_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        verification_keys:
          $ref: '#/components/schemas/A2aEs256PublicJwkSet'
      required:
        - kind
        - card_url
        - verification_keys
      additionalProperties: false
    ValidationIdempotencyConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_conflict
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The Idempotency-Key is already bound to a different request.
    ValidationIdempotencyInProgressError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_in_progress
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-in-progress
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An identical idempotent request is still in progress and may be retried
        later.
    JsonValue:
      description: >-
        A value in the JSON data model: null, boolean, finite number, string,
        array, or object.
    Objects_64:
      type: object
      properties:
        read_only:
          type: boolean
        destructive:
          type: boolean
        requires_approval:
          type: boolean
      required:
        - read_only
        - destructive
        - requires_approval
      additionalProperties: false
    HttpMethod:
      type: string
      enum:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
        - HEAD
        - OPTIONS
    Objects_65:
      type: object
      properties:
        path:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                type: string
                allOf:
                  - minLength: 1
                  - maxLength: 128
                  - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
        query:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                $ref: '#/components/schemas/ToolHttpQueryName'
        body:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 128
                - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
            - type: 'null'
      required:
        - path
        - query
        - body
      additionalProperties: false
    Objects_66:
      type: object
      properties:
        kind:
          type: string
          enum:
            - a2a
        card_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        endpoint_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        tenant:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 1024
            - type: 'null'
        skill_id:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 1024
        card_fingerprint:
          type: string
          pattern: ^sha256:[0-9a-f]{64}$
        endpoint_fingerprint:
          type: string
          pattern: ^sha256:[0-9a-f]{64}$
        verification_keyset_fingerprint:
          type: string
          pattern: ^sha256:[0-9a-f]{64}$
        streaming:
          type: boolean
        push_notifications:
          type: boolean
        authentication:
          anyOf:
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - bearer
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - oauth2
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
                flow:
                  type: string
                  enum:
                    - authorization_code
                scopes:
                  $ref: '#/components/schemas/ConnectionScopes'
              required:
                - kind
                - scheme_name
                - flow
                - scopes
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - mtls
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
      required:
        - kind
        - card_url
        - endpoint_url
        - tenant
        - skill_id
        - card_fingerprint
        - endpoint_fingerprint
        - verification_keyset_fingerprint
      additionalProperties: false
    A2aEs256PublicJwkSet:
      type: array
      items:
        type: object
        properties:
          kty:
            type: string
            enum:
              - EC
          crv:
            type: string
            enum:
              - P-256
          x:
            type: string
            allOf:
              - minLength: 43
              - maxLength: 43
              - pattern: ^[A-Za-z0-9_-]+$
          'y':
            type: string
            allOf:
              - minLength: 43
              - maxLength: 43
              - pattern: ^[A-Za-z0-9_-]+$
          kid:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 1024
          alg:
            type: string
            enum:
              - ES256
        required:
          - kty
          - crv
          - x
          - 'y'
          - kid
          - alg
        additionalProperties: false
      allOf:
        - minItems: 1
        - maxItems: 16
    ConnectionScopes:
      type: array
      items:
        $ref: '#/components/schemas/ConnectionScope'
      allOf:
        - maxItems: 256
    ConnectionScope:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 512
        - pattern: ^[^\s,]+$
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.