curl --request GET \
--url https://api.checkfu.com/v1/tool-sources/{id}/tools/{name} \
--header 'Authorization: Bearer <token>' \
--header 'checkfu-version: <checkfu-version>'import requests
url = "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}"
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'checkfu-version': '<checkfu-version>', Authorization: 'Bearer <token>'}
};
fetch('https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"tool_source_id": "<string>",
"workspace_id": "<string>",
"provider": "<string>",
"name": "<string>",
"description": "<string>",
"input_schema": "<unknown>",
"output_schema": "<unknown>",
"schema_hash": "<string>",
"safety_hints": {
"read_only": true,
"destructive": true,
"requires_approval": true
},
"http_binding": {
"kind": "http",
"scheme": "https",
"host": "<string>",
"port": 32768,
"method": "GET",
"path_template": "<string>",
"arguments": {
"path": {},
"query": {},
"body": "<string>"
}
},
"mcp_binding": {
"kind": "mcp",
"url": "<string>",
"tool_name": "<string>",
"authenticated": true
},
"enabled": true,
"version": 1,
"discovered_at": "<string>",
"updated_at": "<string>",
"a2a_binding": {
"kind": "a2a",
"card_url": "<string>",
"endpoint_url": "<string>",
"tenant": "<string>",
"skill_id": "<string>",
"card_fingerprint": "<string>",
"endpoint_fingerprint": "<string>",
"verification_keyset_fingerprint": "<string>",
"streaming": true,
"push_notifications": true,
"authentication": {
"kind": "bearer",
"scheme_name": "<string>"
}
},
"integration_binding_digest": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Get a Tool
Read one discovered Tool by its logical name within a ToolSource, including the complete input and output schemas, schema hash, safety hints, and the immutable HTTP or MCP transport binding compiled at discovery. Safety hints are catalog metadata that feed the approval decision but never decide it alone: governance is consulted first and can deny or escalate regardless.
Checkfu support posture: alpha; hosted. Required evidence journey: capability-catalog. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
curl --request GET \
--url https://api.checkfu.com/v1/tool-sources/{id}/tools/{name} \
--header 'Authorization: Bearer <token>' \
--header 'checkfu-version: <checkfu-version>'import requests
url = "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}"
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'checkfu-version': '<checkfu-version>', Authorization: 'Bearer <token>'}
};
fetch('https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/tool-sources/{id}/tools/{name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"tool_source_id": "<string>",
"workspace_id": "<string>",
"provider": "<string>",
"name": "<string>",
"description": "<string>",
"input_schema": "<unknown>",
"output_schema": "<unknown>",
"schema_hash": "<string>",
"safety_hints": {
"read_only": true,
"destructive": true,
"requires_approval": true
},
"http_binding": {
"kind": "http",
"scheme": "https",
"host": "<string>",
"port": 32768,
"method": "GET",
"path_template": "<string>",
"arguments": {
"path": {},
"query": {},
"body": "<string>"
}
},
"mcp_binding": {
"kind": "mcp",
"url": "<string>",
"tool_name": "<string>",
"authenticated": true
},
"enabled": true,
"version": 1,
"discovered_at": "<string>",
"updated_at": "<string>",
"a2a_binding": {
"kind": "a2a",
"card_url": "<string>",
"endpoint_url": "<string>",
"tenant": "<string>",
"skill_id": "<string>",
"card_fingerprint": "<string>",
"endpoint_fingerprint": "<string>",
"verification_keyset_fingerprint": "<string>",
"streaming": true,
"push_notifications": true,
"authentication": {
"kind": "bearer",
"scheme_name": "<string>"
}
},
"integration_binding_digest": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-31 Path Parameters
^ts_[0-9a-f]{32}$^[a-z0-9](?:[a-z0-9._-]{0,93})$Response
Success
^ts_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$^[a-z0-9](?:[a-z0-9._-]{0,93})$^[a-z0-9](?:[a-z0-9._-]{0,93})$16384A value in the JSON data model: null, boolean, finite number, string, array, or object.
A value in the JSON data model: null, boolean, finite number, string, array, or object.
^sha256:[0-9a-f]{64}$Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
x > 0Show child attributes
Show child attributes
^sha256:[0-9a-f]{64}$