> ## Documentation Index
> Fetch the complete documentation index at: https://docs.checkfu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a Tool

> Read one discovered Tool by its logical name within a ToolSource, including the complete input and output schemas, schema hash, safety hints, and the immutable HTTP or MCP transport binding compiled at discovery. Safety hints are catalog metadata that feed the approval decision but never decide it alone: governance is consulted first and can deny or escalate regardless.

Checkfu support posture: alpha; hosted. Required evidence journey: capability-catalog. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json get /v1/tool-sources/{id}/tools/{name}
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-31'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-31); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: fileTrees
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: sessionHandoffs
  - name: sessionCapsules
  - name: sessionTrajectories
  - name: webhookEndpoints
  - name: integrationGateway
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/tool-sources/{id}/tools/{name}:
    get:
      tags:
        - toolSources
      summary: Get a Tool
      description: >-
        Read one discovered Tool by its logical name within a ToolSource,
        including the complete input and output schemas, schema hash, safety
        hints, and the immutable HTTP or MCP transport binding compiled at
        discovery. Safety hints are catalog metadata that feed the approval
        decision but never decide it alone: governance is consulted first and
        can deny or escalate regardless.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        capability-catalog. Deployment-specific readiness and the latest proven
        release are available from GET /v1/support/capabilities.
      operationId: toolSources.getTool
      parameters:
        - name: id
          in: path
          schema:
            $ref: '#/components/schemas/ToolSourceId'
          required: true
        - name: name
          in: path
          schema:
            type: string
            allOf:
              - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
          required: true
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-31'
          required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Objects_80'
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - validation.malformed
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#validation-malformed
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    required:
                      - type
                      - message
                      - more
                    additionalProperties: false
                additionalProperties: false
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    ToolSourceId:
      type: string
      allOf:
        - pattern: ^ts_[0-9a-f]{32}$
    Objects_80:
      type: object
      properties:
        tool_source_id:
          $ref: '#/components/schemas/ToolSourceId'
        workspace_id:
          $ref: '#/components/schemas/WorkspaceId'
        provider:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        name:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        description:
          type: string
          allOf:
            - maxLength: 16384
        input_schema:
          $ref: '#/components/schemas/JsonValue'
        output_schema:
          anyOf:
            - $ref: '#/components/schemas/JsonValue'
            - type: 'null'
        schema_hash:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        safety_hints:
          $ref: '#/components/schemas/Objects_74'
        http_binding:
          anyOf:
            - $ref: '#/components/schemas/ToolHttpBindingArguments'
            - type: 'null'
        mcp_binding:
          anyOf:
            - $ref: '#/components/schemas/Objects_79'
            - type: 'null'
        a2a_binding:
          anyOf:
            - $ref: '#/components/schemas/Objects_76'
            - type: 'null'
        integration_binding_digest:
          anyOf:
            - type: string
              allOf:
                - pattern: ^sha256:[0-9a-f]{64}$
            - type: 'null'
        enabled:
          type: boolean
        version:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        discovered_at:
          type: string
        updated_at:
          type: string
      required:
        - tool_source_id
        - workspace_id
        - provider
        - name
        - description
        - input_schema
        - output_schema
        - schema_hash
        - safety_hints
        - http_binding
        - mcp_binding
        - enabled
        - version
        - discovered_at
        - updated_at
      additionalProperties: false
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    JsonValue:
      description: >-
        A value in the JSON data model: null, boolean, finite number, string,
        array, or object.
    Objects_74:
      type: object
      properties:
        read_only:
          type: boolean
        destructive:
          type: boolean
        requires_approval:
          type: boolean
      required:
        - read_only
        - destructive
        - requires_approval
      additionalProperties: false
    ToolHttpBindingArguments:
      type: object
      properties:
        kind:
          type: string
          enum:
            - http
        scheme:
          type: string
          enum:
            - https
        host:
          $ref: '#/components/schemas/PublicHostname'
        port:
          type: integer
          allOf:
            - minimum: 1
              maximum: 65535
        method:
          $ref: '#/components/schemas/HttpMethod'
        path_template:
          $ref: '#/components/schemas/ToolHttpPathTemplate'
        arguments:
          $ref: '#/components/schemas/Objects_75'
      required:
        - kind
        - scheme
        - host
        - port
        - method
        - path_template
        - arguments
      additionalProperties: false
    Objects_79:
      type: object
      properties:
        kind:
          type: string
          enum:
            - mcp
        url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        tool_name:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        authenticated:
          type: boolean
      required:
        - kind
        - url
        - tool_name
      additionalProperties: false
    Objects_76:
      type: object
      properties:
        kind:
          type: string
          enum:
            - a2a
        card_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        endpoint_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        tenant:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 1024
            - type: 'null'
        skill_id:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 1024
        card_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        endpoint_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        verification_keyset_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        streaming:
          type: boolean
        push_notifications:
          type: boolean
        authentication:
          anyOf:
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - bearer
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - oauth2
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
                flow:
                  type: string
                  enum:
                    - authorization_code
                scopes:
                  $ref: '#/components/schemas/ConnectionScopes'
              required:
                - kind
                - scheme_name
                - flow
                - scopes
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - mtls
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
      required:
        - kind
        - card_url
        - endpoint_url
        - tenant
        - skill_id
        - card_fingerprint
        - endpoint_fingerprint
        - verification_keyset_fingerprint
      additionalProperties: false
    PublicHostname:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 253
        - pattern: ^[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?$
    HttpMethod:
      type: string
      enum:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
        - HEAD
        - OPTIONS
    ToolHttpPathTemplate:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 8192
    Objects_75:
      type: object
      properties:
        path:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                type: string
                allOf:
                  - minLength: 1
                  - maxLength: 128
                  - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
        query:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                $ref: '#/components/schemas/ToolHttpQueryName'
        body:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 128
                - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
            - type: 'null'
      required:
        - path
        - query
        - body
      additionalProperties: false
    PublicHttpsUrl:
      type: string
      allOf:
        - pattern: ^https:\/\/[^\s]+$
        - maxLength: 2048
    ConnectionScopes:
      type: array
      items:
        $ref: '#/components/schemas/ConnectionScope'
      allOf:
        - maxItems: 256
    ConnectionScope:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 512
        - pattern: ^[^\s,]+$
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````