Recued
Menu
Community catalog

Marketplace

Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.

Tags
Sort

927 packs

Batch Payouts - Wise

Wise batch-group drafting, retrieval, status control, transfer creation, payment initiation retrieval, and region-limited funding. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinessbatches
by Recued Core v1 1 item Pack
Business Profiles and Reference Data - Wise

Wise business users, profiles, addresses, currencies, and exchange-rate reference capabilities. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinessprofiles
by Recued Core v1 1 item Pack
Transfer Quotes - Wise

Create, retrieve, and update authenticated Wise transfer quotes for SMB payout preparation. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinessquotes
by Recued Core v1 1 item Pack
Payout Recipients - Wise

Current Wise recipient listing, retrieval, dynamic account requirements, and approval-gated recipient creation for SMB payout workflows. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinessrecipients
by Recued Core v1 1 item Pack
Transfers and Evidence - Wise

Wise transfer requirements, draft creation, status tracking, cancellation, payments, payout information, regional funding, and PDF evidence capture. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinesstransfers
by Recued Core v1 1 item Pack
Profile Transfer Webhooks - Wise

Approval-gated Wise profile webhook lifecycle for transfer state-change tracking. Generated from Wise's pinned OpenAPI document and bounded to the current self-service Wise Business personal-token surface. Arguments are enumerated, scalar-only requests are fail-closed, financial and identity-bearing reads avoid durable caching, reads install on, and every mutation remains grant-off and approval-gated.

pack:wisewisebusinesswebhooks
by Recued Core v1 1 item Pack
Commerce - WooCommerce

API capability pack for bounded WooCommerce REST API v3 operations. The default egress base is https://example.com/wp-json/wc/v3; enroll a woocommerce connection with base_url set to the actual store endpoint, for example https://store.example.com/wp-json/wc/v3, and Basic auth using the WooCommerce consumer key as username and consumer secret as password. Reads store status, reference data, orders, notes, refunds, products, variations, categories, tags, reviews, customers, downloads, coupons, reports, payment gateways, shipping zones and methods, settings, and webhooks. Bundles a scheduled store performance digest, an AI-assisted order/customer brief, and an approval-gated coupon offer workflow. Writes are approval-gated and limited to one order/manual order, order note, product, variation, category, tag, review, customer, coupon, or webhook at a time. The pack intentionally excludes destructive deletes, batch endpoints, refund creation, payment-gateway mutation, tax/shipping mutation, system-status tools, product duplication, bulk imports, checkout/cart/session APIs, WordPress admin APIs, arbitrary API passthrough, and credential-bearing fields in operation arguments.

pack:woocommercewoocommercecommerceorders
by Recued Core v1 4 items Pack
WooCommerce Customer Reply Desk

Workflow pack for WooCommerce order customer replies. It composes the WooCommerce capability pack with Email / Outbox and the existing outbound response loop: read one order and customer context, draft a grounded plain-text response, send only when send_reply is explicitly enabled so the mail-send approval boundary handles the customer-facing write, then watch the customer reply and surface actionable responses for owner follow-up or conversion. WooCommerce remains read-only in this workflow; it does not edit orders, refunds, products, inventory, coupons, payment gateways, shipping settings, webhooks, WordPress admin surfaces, or arbitrary endpoints.

pack:woocommerce-customer-reply-deskwoocommercecommerceorders
by Recued Core v1 6 items Pack
Site CMS - WordPress

API capability pack for bounded WordPress REST API v2 operations. The default egress base is https://example.com/wp-json; enroll a wordpress connection with base_url set to the actual site REST root, for example https://site.example.com/wp-json, and Basic auth using a WordPress username plus an Application Password for authenticated reads and writes. Reads REST index metadata, site settings, posts, pages, revisions, media metadata, comments, categories, tags, users, search results, taxonomies, post types, and statuses for daily site publishing operations. Bundles a scheduled content digest, an AI-assisted post brief, and an approval-gated post-draft workflow. Writes are approval-gated and limited to creating or updating one post, page, media metadata record, comment, category, or tag at a time. The pack intentionally excludes destructive deletes, binary media uploads, plugin/theme/sidebar/widget/global-style mutation, user create/update/delete, application-password management, settings mutation, custom endpoint passthrough, unauthenticated credential arguments, arbitrary WordPress admin APIs, and plugin-specific REST namespaces.

pack:wordpresswordpresscmssite
by Recued Core v1 4 items Pack
Identity Access - WorkOS

API capability pack for bounded WorkOS REST API operations against https://api.workos.com only. Enroll a WorkOS API-key connection named workos that injects Authorization: Bearer <sk_...>; no credential is embedded in this manifest. The pack reads organizations, AuthKit users, organization memberships, invitations, SSO connections, directory sync directories/users/groups, environment roles, organization roles, and permissions for B2B SaaS access governance, customer onboarding, directory-sync review, and offboarding. It exposes WorkOS before/after list cursors as explicit query args. Writes are approval-gated and limited to creating or updating one organization, user, invitation, or organization membership, and deactivating/reactivating one membership. The pack intentionally excludes deletes, password/password-hash fields, authentication token exchange, session revocation, API key creation, audit-log ingestion/export, SSO authorize/token/profile flows, destructive role/permission deletes, feature flags, data integrations, webhooks, and arbitrary WorkOS API passthrough.

pack:workosworkosidentityaccess-governance
by Recued Core v1 7 items Pack
Full Accounting, Files, Projects, Assets, and Finance - Xero

One-install Xero organisation front door over eight bounded official-contract packs and eighteen non-chat read workflows. It covers tenant discovery plus the complete representable Accounting, Fixed Assets, Files, Projects, and Finance surfaces. Regional Payroll, Bank Feeds, and App Store billing stay separately installed so ordinary bookkeeping never asks for irrelevant workforce, partner, or non-tenanted billing authority. Every tenant-scoped call requires an explicit Xero tenant ID; reads are uncached, mutations are grant-off and always approved, binary downloads are isolated file_ref values, and unsafe JSON integers remain exact strings. The suite admits 453 outbound operations from immutable hash-pinned Xero contracts and records 24 transport exclusions rather than emitting invalid multipart or binary upload bodies.

pack:xeroxeroaccountingfinance
by Recued Core v1 18 items Pack
Ledger, Banking, Payments, and Tax - Xero

Xero accounts, banking transactions and transfers, payments, journals, tax rates, currencies, and tracking categories. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_accounting.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. Binary attachment downloads are isolated as file_ref values; binary attachment uploads are explicitly excluded because body_raw is text-only. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroaccountingledger
by Recued Core v1 1 item Pack
Contacts, Purchasing, Expenses, and Reports - Xero

Xero contacts, purchase orders, receipts, expense claims, items, budgets, organisation settings, users, and reports. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_accounting.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. Binary attachment downloads are isolated as file_ref values; binary attachment uploads are explicitly excluded because body_raw is text-only. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroaccountingcontacts
by Recued Core v1 1 item Pack
Sales, Invoices, Quotes, and Credit - Xero

Xero invoices, quotes, repeating invoices, credit notes, prepayments, overpayments, branding, and payment services. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_accounting.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. Binary attachment downloads are isolated as file_ref values; binary attachment uploads are explicitly excluded because body_raw is text-only. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroaccountinginvoices
by Recued Core v1 1 item Pack
App Store Subscriptions and Usage - Xero

Separately credentialed Xero App Store subscription and usage-billing operations. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-app-store.yaml bytes are SHA-256 pinned. Xero documents marketplace.billing as a non-tenanted client-credentials scope; this leaf therefore uses a separate manually managed bearer connection and is not installed by the ordinary Xero front door. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroapp-storesubscriptions
by Recued Core v1 2 items Pack
Fixed Assets - Xero

Xero fixed assets, asset types, and asset settings. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_assets.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroassetsfixed-assets
by Recued Core v1 1 item Pack
Bank Feed Connections and Statements - Xero

Separately installed Xero Bank Feeds connections and statement delivery operations. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_bankfeeds.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxerobank-feedsstatements
by Recued Core v1 2 items Pack
Files, Folders, and Associations - Xero

Xero file metadata, isolated file downloads, folders, and accounting-object associations. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero_files.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. The two multipart upload routes are explicitly excluded because the current REST adapter cannot emit binary multipart bodies; file content downloads are captured as isolated file_ref values. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxerofilesfolders
by Recued Core v1 1 item Pack
Finance Statements and Validation - Xero

Xero Finance financial statements, cash validation, contact revenue and expense, and Bank Statements Plus. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-finance.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxerofinancestatements
by Recued Core v1 1 item Pack
Tenants and Connection Lifecycle - Xero

Xero OAuth tenant discovery and explicit connection revocation. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-identity.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroidentitytenants
by Recued Core v1 1 item Pack
Payroll Australia - Xero

Region-specific Xero Payroll Australia employees, leave, pay items, calendars, pay runs, payslips, superannuation, and timesheets. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-payroll-au.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeropayrollaustralia
by Recued Core v1 4 items Pack
Payroll Australia Timesheets v2 - Xero

The separately versioned Xero Payroll Australia v2 timesheet lifecycle. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-payroll-au-v2.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeropayrollaustralia
by Recued Core v1 2 items Pack
Payroll New Zealand - Xero

Region-specific Xero Payroll New Zealand employees, leave, settings, pay runs, payslips, timesheets, and working patterns. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-payroll-nz.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeropayrollnew-zealand
by Recued Core v1 4 items Pack
Payroll United Kingdom - Xero

Region-specific Xero Payroll United Kingdom employees, statutory leave, settings, pay runs, payslips, and timesheets. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-payroll-uk.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeropayrollunited-kingdom
by Recued Core v1 4 items Pack
Projects, Tasks, and Time - Xero

Xero projects, project users, tasks, and time entries. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-projects.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.

pack:xeroxeroprojectstasks
by Recued Core v1 1 item Pack
XLSX2CSV Pack

V3 deterministic spreadsheet-to-CSV capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local xlsx2csv CLI converts the first worksheet of one XLSX workbook to UTF-8 CSV via the spreadsheet.to_csv catalog operation. Fixed-function and reproducible: the executor materializes the source workbook and owns the throwaway output directory, while xlsx2csv writes a fixed sheet.csv result that is captured as result.file_ref. Write-tier but approval=never: xlsx2csv writes only to an engine-managed output dir, exposes no arbitrary flags, and never streams workbook bytes through op-step values. Requires xlsx2csv on PATH (Debian/Ubuntu: apt install xlsx2csv; Python environments: pip install xlsx2csv). Local and no-egress.

pack:xlsx2csvxlsx2csvclispreadsheet
by Recued Core v1 1 item Pack
Platform Utilities - Stripe

Stripe files and links, events, webhook endpoints, exchange rates, Apple Pay domains, apps, Sigma, and payment-method configuration utilities. This bounded feature leaf carries 37 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripeeventswebhooks
by Recued Core v1 1 item Pack
Subscriptions and Catalog - Stripe

Stripe subscriptions, schedules, items, products, prices, plans, discounts, promotion codes, tax rates, shipping rates, and entitlements. This bounded feature leaf carries 54 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripesubscriptionscatalog
by Recued Core v1 1 item Pack
Tax and Climate - Stripe

Stripe Tax calculations, registrations, settings, transactions, tax codes, and Climate orders, products, and suppliers. This bounded feature leaf carries 25 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripetaxclimate
by Recued Core v1 1 item Pack
Terminal, Risk, and Identity - Stripe

Stripe Terminal readers and locations, Radar lists and value items, reviews, Identity verification, and request forwarding. This bounded feature leaf carries 52 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripeterminalradar
by Recued Core v1 1 item Pack
Test Helpers - Stripe

Stripe test-clock and test-helper state transitions for non-live integration environments. This bounded feature leaf carries 44 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripetest-helperssandbox
by Recued Core v1 1 item Pack
Treasury and Financial Connections - Stripe

Stripe Treasury financial accounts and transactions plus Financial Connections accounts and sessions. This bounded feature leaf carries 51 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripetreasuryfinancial-connections
by Recued Core v1 1 item Pack
V2 Core - Stripe

Stripe v2 Core accounts, event destinations, events, and meter-event streams. This bounded feature leaf carries 32 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.

pack:stripestripev2core
by Recued Core v1 1 item Pack
Backend Platform - Supabase

API capability pack for bounded Supabase Management API v1 operations against https://api.supabase.com. Enroll a supabase bearer-token connection backed by a personal access token or OAuth token; no credential is embedded in the manifest. The pack reads profile, organizations, organization members and entitlements, projects, available regions, service health, restore-version metadata, Postgres upgrade status, performance/security advisor lints, usage aggregates, SQL snippets, migration and backup metadata, Postgres configuration, SSL enforcement, readonly status, database metadata/OpenAPI, preview branches and action runs/logs, domain configuration, Edge Function metadata, storage buckets, third-party auth and SSO provider metadata, and realtime configuration. Approval-gated writes are limited to project pause/restart, custom-hostname reverify/activate, vanity subdomain check/activate/deactivate, and preview-branch create/update/merge/delete. The pack intentionally excludes project create/delete/transfer/upgrade, raw SQL read/write query, analytics SQL log query endpoints, API-key and signing-key reads/writes, OAuth token exchange/revoke, billing/addons, database credentials/connection-string reads, auth provider secret config reads/writes, PostgREST JWT-secret reads, Edge Function body reads and deploy uploads, arbitrary migration/rollback/PITR execution, database password and pooler mutation, network restriction mutation, JIT access, read replicas, log drains, secret reads/writes, storage external-provider mutation, and arbitrary API passthrough.

pack:supabasesupabasebackenddatabase
by Recued Core v1 1 item Pack
Survey Operations - SurveyMonkey

API capability pack for bounded SurveyMonkey API v3 operations against https://api.surveymonkey.com/v3. Enroll a SurveyMonkey OAuth bearer connection named surveymonkey with least-privilege read scopes plus collectors_write only when outreach writes are installed. The pack reads the current user, surveys, survey details, pages, questions, collectors, collector stats, messages, message stats, recipients, full survey responses, response details, rollups, and trends for customer research, employee feedback, NPS, and marketing research workflows. It bundles a scheduled survey response digest, AI-assisted response and collector/message briefs, and approval-gated workflows for creating a web collector, creating an invite message, adding one recipient, and sending or scheduling one message. The pack intentionally excludes survey/page/question mutation, response mutation, deletes, webhooks, contact-list bulk imports, recipient bulk uploads, file downloads from response attachments, benchmark analysis, organizations/groups/workgroups/roles administration, library administration, OAuth token endpoints, and arbitrary SurveyMonkey API passthrough.

pack:surveymonkeysurveymonkeysurveysresponses
by Recued Core v1 8 items Pack
Syft Pack

V3 deterministic local SBOM capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local syft CLI ingredient exposes bounded project operations for readiness and CycloneDX JSON SBOM generation. The scan runs from an explicit project directory cwd supplied at execution time, scans one trusted local target directory, and writes a CycloneDX JSON software bill of materials via the software.sbom_cyclonedx catalog operation. Fixed-function and reproducible: no container registry pulls, no login, no attestation upload, no caller-supplied config/template path, no arbitrary syft flags, no shell wrapper, and no network egress. The SBOM is captured as result.file_ref instead of stdout so large dependency metadata stays behind the Gateway-gated file-ref boundary. Requires syft on PATH (macOS: brew install syft; Linux: install the Anchore syft binary). Local and no-egress.

pack:syftsyftsbomcyclonedx
by Recued Core v1 1 item Pack
Full Tailnet Administration - Tailscale API

One-install Tailscale API front door over three bounded domain packs and 14 non-chat, uncached read workflows. It admits all 90 official operations across 58 paths and adds 5 explicit policy details/HuJSON media variants, for 95 callable capabilities. Tailscale calls its endpoints stable but its generated OpenAPI unstable, so generation byte- and hash-locks the live first-party document. Runtime calls use the origin-only https://api.tailscale.com base plus explicit /api/v2 paths, reconciled by path_alias.wire_prefix. Every operation inherits the global bearerAuth contract; users can enroll a personal API access token or a short-lived scoped OAuth access token. All body-bearing operations require bounded verbatim JSON or HuJSON payloads, repairing thirty-one omitted requestBody.required markers. Policy details, JSON, and HuJSON modes are separated so the forbidden details-plus-Accept combination cannot be emitted. JSON integers remain exact, empty responses claim no body, and the provider's explicit no-pagination contract is preserved. One-time keys, invite URLs, webhook secrets, OAuth app client secrets, and third-party credential bodies are labeled and excluded from bundled workflows. Every mutation requires approval; reads are uncached and provider failures are never silently retried. The local tailscale CLI and tailscaled daemon remain a separate future pack rather than an implicit runtime prerequisite. No work-entity Source is claimed.

pack:tailscale-apitailscaletailscale-apinetworking
by Recued Core v1 14 items Pack
Devices, Invites, and Keys - Tailscale API

Tailscale devices, routes, posture attributes, sharing and user invitations, auth keys, API access tokens, OAuth clients, and federated identities. Generated from Tailscale's byte- and hash-locked official OpenAPI 3.1.0 document (95fa0cb9d3be…) at https://api.tailscale.com/api/v2?outputOpenapiSchema=true. This leaf carries 31 of 95 callable capabilities derived from all 90 official operations. Runtime uses the origin-only https://api.tailscale.com base plus explicit /api/v2 wire paths, with path_alias.wire_prefix preserving documentary proof. Every operation inherits the global bearerAuth contract, and encrypted API access or OAuth access tokens never become arguments. All documented request bodies are required bounded body_raw payloads; JSON and HuJSON media remain distinct. JSON responses preserve unsafe integers, HuJSON responses remain text, and empty successes claim no body. The provider explicitly declares no pagination. Every mutation requires approval, reads are uncached, and provider failures receive no hidden retry. One-time keys, invitation URLs, webhook secrets, and OAuth app client secrets are labeled and excluded from bundled workflows. The local tailscale CLI is a separate binary/daemon capability family, and no network resource is misrepresented as a task, note, or user-work project Source.

pack:tailscale-apitailscaletailscale-apidevices
by Recued Core v1 1 item Pack
DNS, Policy, Posture, and Services - Tailscale API

Tailscale DNS, JSON and HuJSON policy operations, device-posture integrations, Services, host approvals, and policy validation. Generated from Tailscale's byte- and hash-locked official OpenAPI 3.1.0 document (95fa0cb9d3be…) at https://api.tailscale.com/api/v2?outputOpenapiSchema=true. This leaf carries 32 of 95 callable capabilities derived from all 90 official operations. Runtime uses the origin-only https://api.tailscale.com base plus explicit /api/v2 wire paths, with path_alias.wire_prefix preserving documentary proof. Every operation inherits the global bearerAuth contract, and encrypted API access or OAuth access tokens never become arguments. All documented request bodies are required bounded body_raw payloads; JSON and HuJSON media remain distinct. JSON responses preserve unsafe integers, HuJSON responses remain text, and empty successes claim no body. The provider explicitly declares no pagination. Every mutation requires approval, reads are uncached, and provider failures receive no hidden retry. One-time keys, invitation URLs, webhook secrets, and OAuth app client secrets are labeled and excluded from bundled workflows. The local tailscale CLI is a separate binary/daemon capability family, and no network resource is misrepresented as a task, note, or user-work project Source.

pack:tailscale-apitailscaletailscale-apidns
by Recued Core v1 1 item Pack
Organization and Automation - Tailscale API

Tailscale audit and flow logs, log streaming, users, contacts, webhooks, tailnet settings, and user-delegated OAuth apps. Generated from Tailscale's byte- and hash-locked official OpenAPI 3.1.0 document (95fa0cb9d3be…) at https://api.tailscale.com/api/v2?outputOpenapiSchema=true. This leaf carries 32 of 95 callable capabilities derived from all 90 official operations. Runtime uses the origin-only https://api.tailscale.com base plus explicit /api/v2 wire paths, with path_alias.wire_prefix preserving documentary proof. Every operation inherits the global bearerAuth contract, and encrypted API access or OAuth access tokens never become arguments. All documented request bodies are required bounded body_raw payloads; JSON and HuJSON media remain distinct. JSON responses preserve unsafe integers, HuJSON responses remain text, and empty successes claim no body. The provider explicitly declares no pagination. Every mutation requires approval, reads are uncached, and provider failures receive no hidden retry. One-time keys, invitation URLs, webhook secrets, and OAuth app client secrets are labeled and excluded from bundled workflows. The local tailscale CLI is a separate binary/daemon capability family, and no network resource is misrepresented as a task, note, or user-work project Source.

pack:tailscale-apitailscaletailscale-apiorganization
by Recued Core v1 1 item Pack
Tailscale Local Diagnostics CLI Pack

V3 bounded Tailscale local-device diagnostics capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local tailscale CLI ingredient exposes 18 fixed, read-only operations for version, node/peer state, local Tailscale IPs, physical-network checks, bounded peer ping and identity lookup, DNS, exit-node inventory, Serve/Funnel exposure status, Tailnet Lock state/logs, system policy, local accounts, metrics, and App Connector routes. This pack is intentionally separate from tailscale-api: it uses the installed client and its existing local identity state, never an API connection or token argument. All private daemon/tailnet/network reads require approval; only the local CLI version is approval-free. It exposes no custom --socket, login server, auth key, arbitrary argv, environment override, stdin, shell wrapper, or output-file write. It also excludes login/logout, up/down/set routing changes, SSH/nc sessions, Taildrop/Taildrive file access, certificates/private keys, Serve/Funnel mutations, Tailnet Lock mutations, system configuration, software update, web servers, GUI processes, and indefinite waits. Requires tailscale on PATH; all operations except version and netcheck require a compatible running tailscaled-equivalent local daemon, and tailnet-scoped reads require the local client to be enrolled.

pack:tailscale-clitailscaleclinetworking
by Recued Core v1 1 item Pack
TAR Pack

V3 deterministic TAR archive capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local tar CLI exposes readiness, member listing, single-file TAR creation, and extraction of one requested TAR member via fixed catalog operations. Listing is read-only and works for tar plus common compressed tar archives supported by the installed tar. File-output operations materialize the source file/archive and write exactly one result file under an engine-managed output directory; these create/extract operations require GNU-compatible --transform support because the pack strips source/extracted path components with a fixed transform. Write-tier but approval=never: tar writes only to an engine-managed output dir, disables owner/permission restoration during extraction, and exposes no arbitrary flags, recursive extraction, overwrite target, file-list, remote, or compression-program surface. Requires tar on PATH with GNU-compatible transform support for file-output operations (Debian/Ubuntu: tar is commonly installed; macOS system bsdtar supports the new list operations but not the existing --transform file-output ops). Local and no-egress.

pack:tartarcliarchive
by Recued Core v1 1 item Pack
Team Chat - Microsoft Teams

API capability pack for bounded Microsoft Teams operations through Microsoft Graph at https://graph.microsoft.com/v1.0 only. Enroll a Microsoft Graph OAuth access token connection named microsoft. The pack reads the current user, joined teams, teams, team members, channels, channel members, channel tabs, enabled apps, installed apps, channel messages and replies, chats, chat members, chat tabs, chat installed apps, pinned chat messages, chat messages, and chat replies. Bundles a scheduled channel activity digest, an AI-assisted channel thread brief, and an approval-gated channel update workflow. Writes are approval-gated and limited to sending a single channel/chat message or reply, or setting/removing one message reaction. It intentionally excludes Teams admin endpoints, app install/update/delete, member add/remove, team/channel/chat creation, tabs mutation, deletes/soft-deletes, message edits, pin/unpin, hosted-content binary reads, activity notifications, migration endpoints, permission grants, calendar/file surfaces already covered by calendar/OneDrive/SharePoint packs, and arbitrary Microsoft Graph passthrough.

pack:teamsmicrosoft-teamsmicrosoft-graphchat
by Recued Core v1 4 items Pack
Full Cloud Operations Control Plane - Temporal

One-install Temporal Cloud Ops API front door over four bounded capability packs and 11 non-chat, uncached, read-only workflows. It admits all 87 official v0.18.0 operations across 55 paths: namespaces, capacity, regions, high availability, connectivity, Nexus, exports, users, service accounts, API keys, groups, custom roles, projects, account settings, audit, billing, and asynchronous operations. The relative OpenAPI server resolves against its official source to the origin-pinned https://saas-api.tmprl.cloud host; a selected encrypted Bearer API key remains inside the trusted adapter and Temporal RBAC continues to govern every call. All 37 request bodies are required bounded body_raw JSON objects. All responses preserve unsafe integers, 20 documented page-token collections paginate automatically at 100 records per request; 19 carry the documented provider maximum of 1000 while Connectivity Rules retains provider-owned maximum semantics. The regions list is extracted from its single documented response. API-key creation remains callable but its one-time secret response is labeled sensitive and excluded from workflows. Billing-report reads return metadata without following expiring download URLs; those capability URLs are also labeled sensitive and excluded from workflows. Reads are uncached, every mutation requires approval, and no provider failure is silently retried. Temporal control-plane projects are not claimed as user-work project Sources.

pack:temporal-cloudtemporal-cloudcontrol-planecloud
by Recued Core v1 11 items Pack
Account, Audit, Billing, and Operations - Temporal Cloud

Temporal Cloud account settings, current identity, audit logs and sinks, billing reports, and asynchronous operation status. Generated from Temporal's byte- and hash-locked official v0.18.0 Cloud Ops OpenAPI (8eccf9183cd7…) at https://saas-api.tmprl.cloud/spec.json. This leaf carries 13 of all 87 official operations at the origin-pinned https://saas-api.tmprl.cloud boundary. Every call uses an encrypted Bearer API key inside the trusted connection adapter and remains subject to Temporal Cloud RBAC. All documented bodies are required bounded verbatim JSON objects; all responses are JSON with lossless unsafe integers. One-time API-key tokens and expiring billing-download URLs are labeled sensitive and excluded from reusable workflows. Documented page-token collections paginate at 100 records per request; a 1000 maximum is applied only where the provider declares it. Reads are uncached, every mutation requires approval, and provider failures receive no hidden retry. No control-plane namespace, identity, or project is misrepresented as a task, note, or user-work project Source.

pack:temporal-cloudtemporal-cloudcontrol-planeaccount
by Recued Core v1 1 item Pack
Identity and Access - Temporal Cloud

Temporal Cloud users, service accounts, API keys, groups, custom roles, membership, and namespace access assignments. Generated from Temporal's byte- and hash-locked official v0.18.0 Cloud Ops OpenAPI (8eccf9183cd7…) at https://saas-api.tmprl.cloud/spec.json. This leaf carries 34 of all 87 official operations at the origin-pinned https://saas-api.tmprl.cloud boundary. Every call uses an encrypted Bearer API key inside the trusted connection adapter and remains subject to Temporal Cloud RBAC. All documented bodies are required bounded verbatim JSON objects; all responses are JSON with lossless unsafe integers. One-time API-key tokens and expiring billing-download URLs are labeled sensitive and excluded from reusable workflows. Documented page-token collections paginate at 100 records per request; a 1000 maximum is applied only where the provider declares it. Reads are uncached, every mutation requires approval, and provider failures receive no hidden retry. No control-plane namespace, identity, or project is misrepresented as a task, note, or user-work project Source.

pack:temporal-cloudtemporal-cloudcontrol-planeidentity
by Recued Core v1 1 item Pack
Namespaces, Networking, and Export - Temporal Cloud

Temporal Cloud namespaces, capacity, regions, high availability, connectivity rules, Nexus endpoints, and workflow-history export sinks. Generated from Temporal's byte- and hash-locked official v0.18.0 Cloud Ops OpenAPI (8eccf9183cd7…) at https://saas-api.tmprl.cloud/spec.json. This leaf carries 28 of all 87 official operations at the origin-pinned https://saas-api.tmprl.cloud boundary. Every call uses an encrypted Bearer API key inside the trusted connection adapter and remains subject to Temporal Cloud RBAC. All documented bodies are required bounded verbatim JSON objects; all responses are JSON with lossless unsafe integers. One-time API-key tokens and expiring billing-download URLs are labeled sensitive and excluded from reusable workflows. Documented page-token collections paginate at 100 records per request; a 1000 maximum is applied only where the provider declares it. Reads are uncached, every mutation requires approval, and provider failures receive no hidden retry. No control-plane namespace, identity, or project is misrepresented as a task, note, or user-work project Source.

pack:temporal-cloudtemporal-cloudcontrol-planenamespaces
by Recued Core v1 1 item Pack
Projects and Assignments - Temporal Cloud

Temporal Cloud project lifecycle, scoped users, groups, service accounts, and project access assignments. Generated from Temporal's byte- and hash-locked official v0.18.0 Cloud Ops OpenAPI (8eccf9183cd7…) at https://saas-api.tmprl.cloud/spec.json. This leaf carries 12 of all 87 official operations at the origin-pinned https://saas-api.tmprl.cloud boundary. Every call uses an encrypted Bearer API key inside the trusted connection adapter and remains subject to Temporal Cloud RBAC. All documented bodies are required bounded verbatim JSON objects; all responses are JSON with lossless unsafe integers. One-time API-key tokens and expiring billing-download URLs are labeled sensitive and excluded from reusable workflows. Documented page-token collections paginate at 100 records per request; a 1000 maximum is applied only where the provider declares it. Reads are uncached, every mutation requires approval, and provider failures receive no hidden retry. No control-plane namespace, identity, or project is misrepresented as a task, note, or user-work project Source.

pack:temporal-cloudtemporal-cloudcontrol-planeprojects
by Recued Core v1 1 item Pack