V3 Markdown lint capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local markdownlint CLI ingredient exposes bounded project operations for readiness and Markdown lint diagnostics. Lints run from an explicit project directory cwd supplied at execution time, check one trusted Markdown file, directory, or glob, and return JSON findings via the markdown.lint catalog operation. Fixed-function and reproducible at the invocation boundary: JSON output, no fix mode, no output-file write, no stdin, no caller-supplied config path, no custom rules, no caller-supplied ignore path, no arbitrary markdownlint flags, no shell wrapper, and no network egress. The command disables MD013 line-length noise to make the pack useful for prose-heavy docs by default; remaining findings are represented as successful JSON output. Requires markdownlint on PATH. Local and no-egress.
Marketplace
Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.
927 packs
One-install Make API v2 suite admitting 377 executable operations from the current 378-route official contract across this operation-ID-and-route-compatible 92-operation core and five bounded dependency packs. The sole route exclusion is the SDK app PNG upload, whose binary request body cannot yet be represented safely by connection.api; the PNG download is included as a file_ref. AI context creation uses the official JSON alternative rather than multipart file upload, and the finite AI-agent SSE route returns buffered text after the provider closes it. Coverage spans scenarios, hooks, executions, data stores, templates, connections, functions, AI Agents and contexts, organizations, teams, users, roles, devices, credential requests, audit, billing-adjacent reads and controls, and the SDK developer platform. Enroll a make API connection with Authorization: Token <api-token> and set base_url to the account Make or Celonis Make zone. Reads are approval-free except the state-changing password-reset session GET, which is admin/always-approved. Writes are grant-off and approval-gated; execution, credential, administrative, and destructive operations require approval every run. All original 92 operation IDs and method/path routes remain stable; their argument contracts follow the pinned current provider reference, with offset controls owned by the pagination engine rather than callers.
V3 generic project test-run capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local make CLI ingredient exposes bounded project operations for readiness and fixed-target test execution. Test runs execute the fixed test target from one explicit project directory cwd and return plain make output via the project.test_run catalog operation. Fixed invocation, but approval-gated: Makefiles can execute arbitrary project commands, compilers, scripts, containers, network clients, and test code, and may write project or cache state. The pack exposes no caller-supplied target, variables, makefile path, directory flag, job control, environment override, stdin, or shell wrapper; it runs exactly make test in the declared cwd. Test failures and make diagnostics are represented as text results so the caller can inspect the output. Requires make on PATH.
Make organization, team, role, audit, affiliate, cashier, and custom-property administration. Generated from the hash-anchored official Make API reference page set published 2026-07-13. The eu1 base is an enrollment default; use the connection base_url for the account's Make or Celonis Make zone. Ordinary reads are approval-free. Mutations are grant-off and approval-gated; state-changing GET, destructive, and administrative operations require approval every run.
Make AI Agents, JSON context creation, LLM providers, buffered finite agent-run event streams, and on-prem agent administration. The context route selects its official JSON alternative; multipart file context upload awaits file_ref request-body support. Generated from the hash-anchored official Make API reference page set published 2026-07-13. The eu1 base is an enrollment default; use the connection base_url for the account's Make or Celonis Make zone. Ordinary reads are approval-free. Mutations are grant-off and approval-gated; state-changing GET, destructive, and administrative operations require approval every run.
Make users, API tokens, credential requests, devices, SSO certificates, enumerations, and identity administration. Generated from the hash-anchored official Make API reference page set published 2026-07-13. The eu1 base is an enrollment default; use the connection base_url for the account's Make or Celonis Make zone. Ordinary reads are approval-free. Mutations are grant-off and approval-gated; state-changing GET, destructive, and administrative operations require approval every run.
Make SDK app, module, connection, function, RPC, webhook, invite, source-code, README, and release operations. PNG icon download is included as a file_ref; the raw PNG upload route is the suite's one explicit transport exclusion. Generated from the hash-anchored official Make API reference page set published 2026-07-13. The eu1 base is an enrollment default; use the connection base_url for the account's Make or Celonis Make zone. Ordinary reads are approval-free. Mutations are grant-off and approval-gated; state-changing GET, destructive, and administrative operations require approval every run.
Make scenarios, hooks, executions, data, connections, functions, keys, templates, notifications, and general automation operations not retained in the compatibility core. Generated from the hash-anchored official Make API reference page set published 2026-07-13. The eu1 base is an enrollment default; use the connection base_url for the account's Make or Celonis Make zone. Ordinary reads are approval-free. Mutations are grant-off and approval-gated; state-changing GET, destructive, and administrative operations require approval every run.
API capability pack for bounded Mailgun US API calls against https://api.mailgun.net only. Reads domains, DNS verification records, tracking and queue state, delivery events, domain and tag stats, tags, templates, suppression lists, mailing lists, list members, and inbound routes; can trigger one domain verification, remove one suppression record, and remove one mailing-list member. Enroll a Mailgun Basic Auth connection with username api and the API key as password; no credential is embedded in the manifest. Writes are approval-gated. The pack intentionally excludes EU-host calls, email sending, MIME/message attachment retrieval, domain/list/template/route create-update-delete, bulk suppression imports/clears, webhook/IP/admin management, and arbitrary API passthrough.
One-install Mailchimp Marketing API 3.0 suite admitting all 294 operations in the current official 3.0.91 contract across this backward-compatible 71-operation core and four bounded dependency packs. The default egress base is https://us1.api.mailchimp.com/3.0; enroll a Mailchimp connection named mailchimp with HTTP Basic auth using any non-empty username and the API key as the password, and set base_url to the account data-center host when it is not us1. Coverage includes audiences and contacts, classic lists and members, campaigns and reports, email and SMS send controls, automations and customer journeys, templates and files, landing pages, connected sites, conversations, exports, JSON batch jobs and batch webhooks, verified domains, and complete ecommerce administration. Reads are grant-controlled and approval-free. Writes are grant-off and approval-gated; destructive and administrative operations require approval every run. The original 71 operation IDs and three v2 workflows remain stable for compatibility.
Mailchimp automations, customer journeys, templates and folders, file manager, landing pages, surveys, connected sites, conversations, exports, batches, batch webhooks, verified domains, authorized apps, and account metadata not retained in the compatibility core. Generated from the hash-anchored official Mailchimp Marketing API 3.0.91 Swagger. The us1 base is only an enrollment default; the connection base_url must use the account data-center prefix. Reads are grant-controlled and approval-free. Mutations are grant-off and approval-gated; destructive and administrative operations require approval every run.
Mailchimp ecommerce carts, cart lines, customers, orders, order lines, products, variants, images, promo rules, promo codes, and store operations not retained in the compatibility core. Generated from the hash-anchored official Mailchimp Marketing API 3.0.91 Swagger. The us1 base is only an enrollment default; the connection base_url must use the account data-center prefix. Reads are grant-controlled and approval-free. Mutations are grant-off and approval-gated; destructive and administrative operations require approval every run.
Mailchimp email and SMS campaign lifecycle, send controls, reports, reporting analytics, search, Facebook ads, landing-page reports, and survey reports not retained in the compatibility core. Generated from the hash-anchored official Mailchimp Marketing API 3.0.91 Swagger. The us1 base is only an enrollment default; the connection base_url must use the account data-center prefix. Reads are grant-controlled and approval-free. Mutations are grant-off and approval-gated; destructive and administrative operations require approval every run.
Mailchimp audience contacts, classic list administration, members, segments, interests, merge fields, webhooks, signup forms, surveys, and audience-search operations not retained in the compatibility core. Generated from the hash-anchored official Mailchimp Marketing API 3.0.91 Swagger. The us1 base is only an enrollment default; the connection base_url must use the account data-center prefix. Reads are grant-controlled and approval-free. Mutations are grant-off and approval-gated; destructive and administrative operations require approval every run.
Core-only workflow pack for turning filtered inbound mail into Recued tasks. The producer is fail-closed by default until the owner configures subject or sender allow terms; matching mail is then read, extracted into one likely owner task, and persisted only as a small proposal ledger row in data.shared. The manual recipe creates the Recued task after the owner chooses to run it. This pack does not send email, depend on an external work tracker, create vendor tasks, or replace the inbox: it adds a deterministic filter and approval step between email and Recued-native work.
Core-only workflow pack for turning filtered inbound mail into Recued commitments. The producer is fail-closed by default until the owner configures subject or sender allow terms; matching mail is then read, extracted into one likely commitment, and persisted only as a small proposal ledger row in data.shared. The manual recipe creates the Recued commitment after the owner chooses to run it. This pack does not send email, depend on an external CRM or task vendor, create vendor work, or scan the full mailbox by default: it adds a deterministic filter and approval step between email and Recued-native commitments.
V3 local print capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local CUPS lp CLI submits a source document to a configured printer queue via the document.print catalog operation. This is a physical side-effecting operation: it can disclose document contents and consume paper/ink, so it is write-tier and approval=ask. The source can be a data.file ref or a trusted local path; the printer arg is editable so a recipe can prefill the user's default queue while the approval gate can override it before release. Requires CUPS client tools and a configured printer queue on PATH (Debian/Ubuntu: apt install cups-client; macOS: lp is built in with CUPS). Local and no-egress beyond the configured local/network printer transport.
API capability pack for bounded Linear GraphQL operations against https://api.linear.app only. Reads the current user, workspace users, teams, workflow states, projects, project updates, cycles, labels, issues, and issue comments for solo software work queues, bug triage, roadmap follow-up, and customer-feedback-to-issue workflows. It also exposes fixed daily views for assigned issues, created issues, blocked issues, active cycles, and next cycles without arbitrary GraphQL passthrough. Bundles a scheduled my-work digest, an AI-assisted issue/project brief, and an approval-gated issue intake workflow. Enroll a Linear personal API key or OAuth access token connection; no credential is embedded in the manifest. Writes are limited to creating or updating one issue, moving one issue to an explicit workflow state, and adding one issue comment, all approval-gated. The pack intentionally excludes arbitrary GraphQL, deletes, archive/unarchive, issue sharing/subscriptions, label writes, reminders, imports, admin configuration, webhooks, documents, releases, initiatives, customers, and project mutations.
Workflow pack for Recued-created Linear issue comments. It composes the Linear capability pack with a closure ledger: add one owner-approved Markdown comment to an existing Linear issue, persist only the connection/issue/comment linkage in data.shared, and let a scheduled watcher re-read that exact issue until Linear reports it completed or canceled. This pack does not replace Linear comments, native notifications, issue workflow states, project views, reminders, roadmaps, or general issue reporting; it adds Recued-visible closure state for issue comments Recued created.
Workflow pack for Recued-created Linear issues. It composes the Linear capability pack with a closure ledger: create one owner-approved issue in one Linear team, optionally attach it to a configured project, persist only the connection/team/project/issue linkage in data.shared, and let a scheduled watcher re-read that exact issue until Linear reports it completed or canceled. This pack does not replace Linear workflow states, issue views, project views, cycles, roadmaps, native notifications, automations, comments, or general issue reporting; it adds Recued-visible closure state for issues Recued created.
V3 deterministic office-conversion capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local LibreOffice soffice CLI ingredient exposes readiness plus fixed conversions from office documents to PDF, UTF-8 text, and HTML. Fixed-function and reproducible: the executor materializes the source file and owns the throwaway output directory, while soffice writes converted artifacts there and each result is captured as result.file_ref. Write-tier but approval=never: soffice writes only under an engine-managed output dir, exposes no arbitrary flags, macros, printer routing, template paths, remote URLs, or caller-supplied output paths, and never streams document bytes through op-step values. Requires the soffice binary on PATH (Debian/Ubuntu: apt install libreoffice-writer-nogui or libreoffice-writer; macOS: install LibreOffice and expose soffice). Local process, no shell, no intentional network egress.
API capability pack for bounded Lever Data API v1 operations against https://api.lever.co/v1. Enroll a Lever API key Basic Auth connection or OAuth bearer connection named lever with opportunity, posting, interview, feedback, note, offer, requisition, source, stage, tag, and user access. The pack reads recruiting pipeline records for hiring operations digests, opportunity evidence briefs, posting readiness review, interview and feedback follow-up, offer tracking, and recruiting operations reporting. It bundles a scheduled recruiting digest, AI-assisted opportunity and posting briefs, and approval-gated workflows for creating one opportunity and adding one opportunity note. Writes are limited to one opportunity or note at a time. The pack intentionally excludes file uploads, file/resume/offer downloads, candidate-path deprecated endpoints, opportunity stage/archive/link/tag/source mutation, panel/interview creation or mutation, feedback mutation, offer creation or mutation, posting/requisition/user administration, webhooks, OAuth token generation, and arbitrary Lever API passthrough.
One-install HiBob front door over 12 bounded capability packs and 25 non-chat read workflows. It admits 176 representable callable outbound operations from all 179 official endpoint fragments and records 3 binary multipart exclusions rather than emitting invalid request bodies. 28 inbound webhook payload pages are provenance-recorded but are not misrepresented as outbound calls. Coverage includes employee data and history, time off, attendance and projects, tasks, reports, documents, goals, job catalog, workforce planning, hiring, and learning-provider operations. Basic credentials remain connection-owned; reads are uncached and permission-scoped, sensitive reads are marked sensitive-read and require approval unless session-granted, ordinary reads remain unheld, and all mutations are grant-off and approval-gated.
HiBob employee search and lifecycle, onboarding wizards, employee-field metadata, and named lists. Generated from HiBob's complete callable outbound surface in the official machine-readable endpoint index: each route is checked against its own official embedded OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. Inbound webhook payload pages are recorded separately rather than misrepresented as callable operations. A single openapi_source is intentionally omitted because HiBob publishes separate Markdown-wrapped fragments rather than one fetchable OpenAPI document; pinning one fragment would falsely claim coverage for the rest. Reads are uncached and permission-scoped; sensitive HR, compensation, banking, document, report, performance, and hiring reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation is grant-off and approval-gated. JSON unsafe integers remain exact strings. No work-entity Source is declared because the official task and project contracts do not yet prove both a mandatory stable identity and a mandatory version signal.
HiBob report inventory, synchronous exports, and asynchronous report-download polling. Generated from HiBob's complete callable outbound surface in the official machine-readable endpoint index: each route is checked against its own official embedded OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. Inbound webhook payload pages are recorded separately rather than misrepresented as callable operations. A single openapi_source is intentionally omitted because HiBob publishes separate Markdown-wrapped fragments rather than one fetchable OpenAPI document; pinning one fragment would falsely claim coverage for the rest. Reads are uncached and permission-scoped; sensitive HR, compensation, banking, document, report, performance, and hiring reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation is grant-off and approval-gated. JSON unsafe integers remain exact strings. No work-entity Source is declared because the official task and project contracts do not yet prove both a mandatory stable identity and a mandatory version signal.
HiBob open employee tasks, per-employee task reads, and approval-gated task completion. Generated from HiBob's complete callable outbound surface in the official machine-readable endpoint index: each route is checked against its own official embedded OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. Inbound webhook payload pages are recorded separately rather than misrepresented as callable operations. A single openapi_source is intentionally omitted because HiBob publishes separate Markdown-wrapped fragments rather than one fetchable OpenAPI document; pinning one fragment would falsely claim coverage for the rest. Reads are uncached and permission-scoped; sensitive HR, compensation, banking, document, report, performance, and hiring reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation is grant-off and approval-gated. JSON unsafe integers remain exact strings. No work-entity Source is declared because the official task and project contracts do not yet prove both a mandatory stable identity and a mandatory version signal.
HiBob time-off requests and changes, balances, policy metadata, out-of-office views, and calendar-event search. Generated from HiBob's complete callable outbound surface in the official machine-readable endpoint index: each route is checked against its own official embedded OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. Inbound webhook payload pages are recorded separately rather than misrepresented as callable operations. A single openapi_source is intentionally omitted because HiBob publishes separate Markdown-wrapped fragments rather than one fetchable OpenAPI document; pinning one fragment would falsely claim coverage for the rest. Reads are uncached and permission-scoped; sensitive HR, compensation, banking, document, report, performance, and hiring reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation is grant-off and approval-gated. JSON unsafe integers remain exact strings. No work-entity Source is declared because the official task and project contracts do not yet prove both a mandatory stable identity and a mandatory version signal.
HiBob positions, openings, budgets, planning metadata, and controlled cancellation. Generated from HiBob's complete callable outbound surface in the official machine-readable endpoint index: each route is checked against its own official embedded OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. Inbound webhook payload pages are recorded separately rather than misrepresented as callable operations. A single openapi_source is intentionally omitted because HiBob publishes separate Markdown-wrapped fragments rather than one fetchable OpenAPI document; pinning one fragment would falsely claim coverage for the rest. Reads are uncached and permission-scoped; sensitive HR, compensation, banking, document, report, performance, and hiring reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation is grant-off and approval-gated. JSON unsafe integers remain exact strings. No work-entity Source is declared because the official task and project contracts do not yet prove both a mandatory stable identity and a mandatory version signal.
One-install Hightouch front door over five bounded capability packs and 13 non-chat, uncached, read-only workflows. It inventories all 39 official operations across 27 paths and admits 38: destinations, sources, models, syncs and sync sequences, identity resolution, campaigns, Decision Engine flows and messages, and event contracts. The one explicitly deprecated identity-graph trigger alias is excluded in favor of its documented current /idr replacement, so no capability is lost. Every call uses the selected encrypted Admin-created API-key connection at the fixed https://api.hightouch.com/api/v1 origin. All 17 admitted JSON bodies use bounded body_raw payloads, preserving the official 14 required versus 3 optional split. Nine documented limit/offset collections paginate automatically using their official default page sizes. Destination and source connection configuration plus model SQL remain callable but all six sensitive GETs are excluded from bundled rendering workflows. Documented 200 success/error unions are preserved, exact identifiers and unsafe response integers cannot be silently rounded, reads are uncached and not approval-gated, and every mutation requires approval. Trigger actions are destructive and receive no hidden retries. Hightouch's reverse-ETL control-plane objects are not claimed as task, note, or user-work project Sources.
Hightouch destination, source, and model configuration capabilities. Generated from Hightouch's hash-locked official OpenAPI 3.0.0 document (ee840baa9cab…) and its separately hash-locked API-guide section. This leaf carries 12 of the suite's 38 current admitted operations at https://api.hightouch.com/api/v1; the one explicitly deprecated identity-graph trigger alias is inventoried but excluded in favor of its documented replacement. Calls use an Admin-created Hightouch API key only through the trusted bearer connection adapter. Required and optional JSON bodies retain the official distinction and use bounded body_raw payloads. Documented limit/offset collections paginate automatically at their official default page sizes; response integers remain exact strings, reads are uncached and not approval-gated, and every mutation requires approval. Provider failures receive no hidden retries. No reverse-ETL control-plane object is misrepresented as a task, note, or user-work project Source.
Hightouch Decision Engine flows and messages plus campaign sending and status capabilities. Generated from Hightouch's hash-locked official OpenAPI 3.0.0 document (ee840baa9cab…) and its separately hash-locked API-guide section. This leaf carries 9 of the suite's 38 current admitted operations at https://api.hightouch.com/api/v1; the one explicitly deprecated identity-graph trigger alias is inventoried but excluded in favor of its documented replacement. Calls use an Admin-created Hightouch API key only through the trusted bearer connection adapter. Required and optional JSON bodies retain the official distinction and use bounded body_raw payloads. Documented limit/offset collections paginate automatically at their official default page sizes; response integers remain exact strings, reads are uncached and not approval-gated, and every mutation requires approval. Provider failures receive no hidden retries. No reverse-ETL control-plane object is misrepresented as a task, note, or user-work project Source.
Hightouch event-contract listing, inspection, creation, and update capabilities. Generated from Hightouch's hash-locked official OpenAPI 3.0.0 document (ee840baa9cab…) and its separately hash-locked API-guide section. This leaf carries 4 of the suite's 38 current admitted operations at https://api.hightouch.com/api/v1; the one explicitly deprecated identity-graph trigger alias is inventoried but excluded in favor of its documented replacement. Calls use an Admin-created Hightouch API key only through the trusted bearer connection adapter. Required and optional JSON bodies retain the official distinction and use bounded body_raw payloads. Documented limit/offset collections paginate automatically at their official default page sizes; response integers remain exact strings, reads are uncached and not approval-gated, and every mutation requires approval. Provider failures receive no hidden retries. No reverse-ETL control-plane object is misrepresented as a task, note, or user-work project Source.
Hightouch identity-resolution and identity-graph run, status, and reprocessing capabilities. Generated from Hightouch's hash-locked official OpenAPI 3.0.0 document (ee840baa9cab…) and its separately hash-locked API-guide section. This leaf carries 4 of the suite's 38 current admitted operations at https://api.hightouch.com/api/v1; the one explicitly deprecated identity-graph trigger alias is inventoried but excluded in favor of its documented replacement. Calls use an Admin-created Hightouch API key only through the trusted bearer connection adapter. Required and optional JSON bodies retain the official distinction and use bounded body_raw payloads. Documented limit/offset collections paginate automatically at their official default page sizes; response integers remain exact strings, reads are uncached and not approval-gated, and every mutation requires approval. Provider failures receive no hidden retries. No reverse-ETL control-plane object is misrepresented as a task, note, or user-work project Source.
Hightouch sync configuration, run inspection, triggering, and sync-sequence execution. Generated from Hightouch's hash-locked official OpenAPI 3.0.0 document (ee840baa9cab…) and its separately hash-locked API-guide section. This leaf carries 9 of the suite's 38 current admitted operations at https://api.hightouch.com/api/v1; the one explicitly deprecated identity-graph trigger alias is inventoried but excluded in favor of its documented replacement. Calls use an Admin-created Hightouch API key only through the trusted bearer connection adapter. Required and optional JSON bodies retain the official distinction and use bounded body_raw payloads. Documented limit/offset collections paginate automatically at their official default page sizes; response integers remain exact strings, reads are uncached and not approval-gated, and every mutation requires approval. Provider failures receive no hidden retries. No reverse-ETL control-plane object is misrepresented as a task, note, or user-work project Source.
V3 deterministic plain-text accounting report pack. By-value connector composition (service_kind=cli, no separate ingredient): the local hledger CLI reads one journal file and emits fixed text reports via ledger.balance_report and ledger.income_statement catalog operations. Fixed-function and reproducible: the executor materializes the source journal and owns the throwaway output directory, while hledger writes fixed report files captured as result.file_ref. Write-tier but approval=never: hledger writes only to an engine-managed output dir, exposes no arbitrary query/filter/report expression, and journal bytes never flow through op-step values. Requires hledger on PATH (Debian/Ubuntu: apt install hledger). Local and no-egress.
One-install Honeycomb configuration front door over two bounded domain packs and seventeen non-chat operating workflows. The complete five-pack suite admits all 85 operations across the exact hash-pinned official contract: 71 configuration operations, 11 separately credentialed Management API operations, two separately credentialed JSON ingest operations, and one separately credentialed Kinesis Firehose operation. This front door depends only on the configuration-key leaves, so installing it never asks for bearer management, ingest-only, or Firehose authority. The connection owns X-Honeycomb-Team and defaults to https://api.honeycomb.io; per-organization enrollment may select the documented https://api.eu1.honeycomb.io origin. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. Batch ingestion intentionally selects documented JSON rather than binary or compressed transport. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so the suite declares no work-entity Source.
Honeycomb configuration-key identity, datasets and definitions, columns and calculated fields, markers and marker settings, and notification recipients. Generated from the exact bytes of Honeycomb's mutable official OpenAPI URL, pinned by SHA-256. The default origin is https://api.honeycomb.io; per-organization enrollment may select the documented EU origin https://api.eu1.honeycomb.io. The connection owns X-Honeycomb-Team and may use a configuration key only. Credential headers and routing authority are never caller arguments. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so this pack declares no work-entity Source.
Separately installable Honeycomb single-event and batch JSON ingestion operations for configuration or ingest keys. Generated from the exact bytes of Honeycomb's mutable official OpenAPI URL, pinned by SHA-256. The default origin is https://api.honeycomb.io; per-organization enrollment may select the documented EU origin https://api.eu1.honeycomb.io. The connection owns X-Honeycomb-Team and is intentionally separate from the configuration suite so an ingest-only key is not granted control-plane operations. Credential headers and routing authority are never caller arguments. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so this pack declares no work-entity Source. No bundled workflow invokes telemetry ingestion; the operations are available only to explicitly authored, approval-gated compositions.
Separately installable Honeycomb Kinesis Firehose ingestion using its dedicated access-key header and request-id contract. Generated from the exact bytes of Honeycomb's mutable official OpenAPI URL, pinned by SHA-256. The default origin is https://api.honeycomb.io; per-organization enrollment may select the documented EU origin https://api.eu1.honeycomb.io. The connection owns X-Amz-Firehose-Access-Key and is intentionally separate from every other Honeycomb credential. Credential headers and routing authority are never caller arguments. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so this pack declares no work-entity Source. No bundled workflow invokes telemetry ingestion; the operations are available only to explicitly authored, approval-gated compositions.
Separately installable Honeycomb Management API identity, team environment administration, and API key lifecycle operations. Generated from the exact bytes of Honeycomb's mutable official OpenAPI URL, pinned by SHA-256. The default origin is https://api.honeycomb.io; per-organization enrollment may select the documented EU origin https://api.eu1.honeycomb.io. The connection owns a bearer Management API key and is intentionally separate from configuration and ingest credentials. Credential headers and routing authority are never caller arguments. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so this pack declares no work-entity Source.
Honeycomb boards and views, service-map dependency requests, burn alerts, queries and query results, query annotations, SLOs and reporting, and triggers. Generated from the exact bytes of Honeycomb's mutable official OpenAPI URL, pinned by SHA-256. The default origin is https://api.honeycomb.io; per-organization enrollment may select the documented EU origin https://api.eu1.honeycomb.io. The connection owns X-Honeycomb-Team and may use a configuration key only. Credential headers and routing authority are never caller arguments. Reads are uncached and never approval-gated; mutations are grant-off and approval-gated. JSON responses preserve unsafe integers as strings. The official contract does not prove a stable mandatory identity and version for an honest task, note, or project projection, so this pack declares no work-entity Source.
API capability pack for bounded Hugging Face Hub REST API operations against https://huggingface.co only. Enroll a Hugging Face user access token bearer connection named huggingface; no credential is embedded in this manifest. The pack reads Hub quicksearch, trending items, documentation search, model and dataset tag catalogs, Spaces hardware, collections, Daily Papers, Paper Pages, repository trees, commits, refs, security scans, and discussions for AI model, dataset, Space, and research discovery workflows. It bundles a Hub discovery brief, a model repository readiness brief, a Daily Papers digest, and approval-gated workflows for creating one repository discussion or one collection. Writes are limited to creating one collection or one repository discussion. The pack intentionally excludes repo create, move, delete, commit, upload, preupload, branch, tag, settings, and super-squash operations; Xet, JWT, registry, and service-account token endpoints; secrets, variables, volumes, billing, webhooks, organization admin, and access-grant/request/report endpoints; paper comments, claims, indexing, and link mutation; collection patch/delete/item mutation; arbitrary file resolve/download endpoints; and arbitrary Hugging Face API passthrough.
API capability pack for bounded incident.io REST API operations against https://api.incident.io only. Reads API-key identity, incidents, incident updates, actions, follow-ups, severities, incident statuses, users, teams, schedules, and escalations, and supports approval-gated incident creation/editing plus action and follow-up creation/update. Bundles an operations digest, incident and follow-up triage briefs, and approval-gated workflows for incident intake, incident field edits, action creation, and follow-up creation. Enroll an incident.io API-key connection named incidentio that injects Authorization: Bearer <api-key> with the narrowest incident.io roles needed for the installed operations. The pack intentionally excludes deletes, API-key rotation, incident membership revocation, status page mutation, schedule/config mutation, escalation creation/cancelation, catalog mutation, admin/security APIs, workflows, webhooks, audit logs, and arbitrary API passthrough.
One-install Intercom front door over three bounded domain packs and the existing conversation workflows and task Source. It admits 159 of 161 operations in Intercom's immutable 2.15 first-party schema. The two explicit exclusions are the cross-origin recording redirect rejected by the origin-pinned transport and one Fin Voice route with no documented success contract. The two same-origin export downloads use the engine's 64 MiB content-isolated file capture and return file_ref values. The compatibility root preserves all 46 prior operation IDs and routes, representing 45 unique official operations, while dependencies add the other 114 admitted routes. Every call pins Intercom-Version: 2.15; JSON responses preserve unsafe integers, supported collection contracts auto-page within engine caps, the new domain packs mark sensitive reads sensitive-read, the compatibility root retains its prior read posture, and every mutation remains approval-gated.
Intercom administrators, activity logs, custom objects, data attributes and events, export jobs, IP allowlists, jobs, and phone Switch operations. Generated from the hash-pinned first-party Intercom 2.15 OpenAPI document. Every call is fixed to the enrolled Intercom origin and pins Intercom-Version: 2.15; reads are uncached, sensitive reads are marked sensitive-read, every mutation is approval-gated, and unsafe JSON integers are preserved as exact strings.
Intercom Fin content and conversations, Help Center and internal articles, news, calls and transcripts, brands, email settings, messages, and workflows. Generated from the hash-pinned first-party Intercom 2.15 OpenAPI document. Every call is fixed to the enrolled Intercom origin and pins Intercom-Version: 2.15; reads are uncached, sensitive reads are marked sensitive-read, every mutation is approval-gated, and unsafe JSON integers are preserved as exact strings.
Workflow pack for Recued-sent Intercom customer replies. It composes the Intercom capability pack with a closure ledger: send one public admin comment through the existing Intercom approval gate, persist only the connection/conversation reply-watch linkage in data.shared, and let a scheduled watcher re-read that exact conversation until Intercom reports a configured closure state or a customer-waiting owner-review signal after the Recued reply. This pack does not replace Intercom Workflows, Rules, snooze/reopen/close automation, assignment/routing, SLAs, native notifications, webhooks, or teammate workflows; it adds Recued-visible closure state for conversations Recued replied to.
Intercom contacts, companies, conversations, tickets, tags, subscriptions, teams, visitors, notes, segments, and support configuration. Generated from the hash-pinned first-party Intercom 2.15 OpenAPI document. Every call is fixed to the enrolled Intercom origin and pins Intercom-Version: 2.15; reads are uncached, sensitive reads are marked sensitive-read, every mutation is approval-gated, and unsafe JSON integers are preserved as exact strings.