API capability pack for bounded Squarespace Commerce REST operations against https://api.squarespace.com only. Reads the authorized member, website profile, store pages, orders, products, product image processing status, inventory, contacts, address books, contact transaction summaries, profiles, webhook subscriptions, and transaction documents for daily solo-business storefront operations. Writes are approval-gated and limited to order fulfillment, inventory adjustment with caller-supplied Idempotency-Key, product create/update, product variant create/update, product image alt/order updates, contact create/update, and contact address create/replace using documented Squarespace request bodies. Enroll a Squarespace API key or OAuth bearer-token connection named squarespace; no credential is embedded in the manifest. The connection needs the relevant Squarespace Commerce API key permissions or OAuth scopes such as website.orders.read, website.orders, website.products.read, website.products, website.inventory.read, website.inventory, website.contacts.read, website.contacts, website.profiles.read, and website.transactions.read. The pack intentionally excludes deletes, order creation/import, refunds/payment mutation, profile mutation, webhook subscription mutation/secret rotation/test delivery, OAuth token exchange, arbitrary endpoint passthrough, and any endpoint outside api.squarespace.com.
Marketplace
Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.
927 packs
V3 deterministic filesystem metadata capability pack for BSD/macOS stat syntax. By-value connector composition (service_kind=cli, no separate ingredient): one local stat CLI ingredient exposes bounded read-only file metadata for one trusted local path using built-in stat output modes: default, raw numeric, shell-variable, verbose, and ls-style long format. The operations return stat metadata only; they do not return file content, follow symlinks via -L, canonicalize paths, recurse directories, read stdin, accept file lists, expose arbitrary stat formats, write files, or use a shell wrapper. Editable paths reject flag-like values, URL-like references, and scp-style remotes. Requires a BSD-compatible stat on PATH (macOS / FreeBSD option set). Local and no-egress.
One-install Statsig Console API front door over eight bounded capability packs and 22 non-chat, uncached, read-only workflows. It admits every one of the official 313 method/path operations across 201 paths: gates, dynamic configs, experiments, warehouse-native analytics, metrics, Autotunes, holdouts, layers, segments, prompts, ingestion, releases, observability, project administration, and access control. Every call is origin-pinned to https://statsigapi.net, uses a selected encrypted Console API Key only inside the trusted header-auth adapter, and sends STATSIG-API-VERSION: 20240601. All 127 request bodies are required bounded body_raw JSON: 120 object schemas, six object-union schemas, and one array schema, so nested structures and exact integer literals survive unchanged. Forty-six documented limit/page collections, one provider-sized page collection, and the Logs cursor feed paginate automatically within engine ceilings; one additional limit/page list remains manual because its official success contract declares no body. The billing CSV is isolated as a private file_ref. API-key responses remain callable but never enter bundled rendering workflows; warehouse credential bodies are explicitly marked secret. Reads are uncached, response integers remain exact strings, every mutation requires approval, and no provider failure is silently retried. Feature-control and experimentation resources are not claimed as task, note, or user-work project Sources.
Statsig segments, ID lists, parameter stores, prompts and versions, tags, target apps, and unit ID types. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 41 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig dynamic configuration and layer definitions, rules, reviews, versions, lineage, overrides, and lifecycle controls. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 37 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig experiment diagnostics, exposures, Pulse results, warehouse-native loads, assignment sources, entity properties, and qualifying events. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 29 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig experiment creation, configuration, reviews, versions, overrides, start, decision, archive, and cleanup controls. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 34 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig feature-gate definitions, rules, references, reviews, versions, overrides, launch, and lifecycle controls. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 38 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig metric and metric-source administration, Autotune experiments, holdouts, reviews, results, reloads, and lifecycle controls. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 48 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig alerts, audit and event data, dashboards, Logs Explorer, ingestion, release pipelines, override audits, reports, and billing export. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 49 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
Statsig project and company information, environments, API keys, roles, review and team settings, users, teams, usage, and change validation. Generated from Statsig's hash-locked official versioned Console OpenAPI 20240601.0.0 document (21dd0e248e0a…) plus separately hash-locked Console introduction and API-key guide sections. This leaf carries 37 of all 313 official method/path operations at the origin-pinned https://statsigapi.net boundary. Every call uses a Console API Key inside the trusted header-auth connection adapter and sends STATSIG-API-VERSION: 20240601. All documented request bodies are required and remain bounded verbatim JSON; response integers are lossless strings, reads are uncached, and every mutation requires approval. Documented page and cursor collections paginate within engine ceilings. Provider failures receive no hidden retries. No feature-control or experimentation resource is misrepresented as a task, note, or user-work project Source.
API capability pack for bounded Atlassian Statuspage Manage API calls against https://api.statuspage.io/v1 only. Reads pages, components, component groups, component uptime, incidents, unresolved incidents, scheduled incidents, upcoming incidents, and active maintenance, and supports approval-gated incident creation, incident updates, and component status updates. Bundles a scheduled component health digest, an AI-assisted incident brief, and approval-gated workflows for creating an incident, updating a component status, and updating an incident status. Enroll a Statuspage header-auth connection named statuspage that injects Authorization: OAuth <api-key>. The pack intentionally excludes page configuration mutation, component create/delete, component-group mutation, subscriber mutation, page-access users/groups, incident deletion, postmortem publish/revert/delete, metric mutation, organization/user/permission APIs, SCIM, and arbitrary API passthrough.
Stripe Billing meters and alerts, invoices, invoice items and payments, credit notes, quotes, portal sessions, rendering templates, and reports. This bounded feature leaf carries 58 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.
Stripe Connect accounts, links, sessions, external accounts, application fees, transfers, top-ups, payouts, country specs, and balance settings. This bounded feature leaf carries 60 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.
Stripe customers, customer tax identifiers, legacy payment sources, and provider tokens. This bounded feature leaf carries 30 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.
Stripe Issuing cards, cardholders, authorizations, disputes, transactions, tokens, and personalization designs. This bounded feature leaf carries 30 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.
Stripe balances, charges, PaymentIntents, payment methods, refunds, disputes, Checkout, SetupIntents, mandates, and payment records. This bounded feature leaf carries 41 operations from Stripe's hash-pinned public GA OpenAPI. The full family admits 610 official operations and records 9 exact runtime/media exclusions. Every call pins Stripe-Version 2026-06-24.dahlia and every mutation requires approval; reads are uncached, POST retries require a caller-owned Idempotency-Key, expand and Stripe-Account are omitted, JSON integers remain exact strings, and credentials come only from the enrolled Basic connection. This control-plane family declares no user-work Source.
API capability pack for bounded Replicate HTTP API operations against https://api.replicate.com/v1 only. Enroll a Replicate API token bearer connection named replicate; no credential is embedded in this manifest. The pack reads account context, public model search, collections, models, model versions, examples, README text, available hardware, deployments, prediction history, training history, and file metadata for AI model discovery, run monitoring, and cost-control workflows. It bundles a model discovery brief, a scheduled prediction operations digest, and approval-gated workflows for running one prediction or canceling one prediction. Writes are limited to creating one prediction through a version, official model, or deployment, canceling one prediction, or canceling one training. The pack intentionally excludes model/deployment create-update-delete, model version delete, file upload/download/delete, webhook signing secrets, webhook callback configuration, training creation, billing, token management, arbitrary GraphQL or arbitrary HTTP passthrough, and dynamic outbound webhook routing.
API capability pack for bounded Resend API-key calls against https://api.resend.com only. The pack can send and schedule one transactional email, update/cancel one scheduled email, read and search sent and received email, read domains and trigger domain verification, read segments, search/read/create/update/delete contacts, manage contact segment and topic subscriptions, read topics, create/update/send/delete broadcasts, and search/read API request logs. Enroll a Resend API-key connection as a bearer token; no credential is embedded in the manifest. Email sending, scheduled email changes, domain verification, contact mutation, topic/segment subscription changes, and broadcast changes are write-tier and approval-gated. The pack intentionally excludes batch sending, API-key management, webhook management, domain create/update/delete/claim, segment create/delete, topic create/update/delete, contact imports/properties, attachment download, automation/event mutation, and arbitrary API passthrough.
API capability pack for bounded REST Countries v5 lookups against https://api.restcountries.com only. The pack reads country records by name, alpha-2 code, or currency code and projects a small response-field set. Enroll a REST Countries API key connection as bearer auth; no credential is embedded in the manifest.
V3 deterministic local file-search capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local rg CLI ingredient exposes bounded operations for readiness, ignore-aware file listing, glob-filtered path listing, regex search, fixed-string search, case-insensitive search, matching-file discovery, and count-by-file summaries. Content search operations scan one trusted local root and return bounded JSONL match events or compact text summaries. Bundles a manual local content search recipe and a scheduled TODO/FIXME project watch so users can install the pack and immediately turn trusted folders into recurring search workflows. Fixed-function and reproducible: no arbitrary rg flags, no shell, no produced files, no hidden-file override, no ripgrep config-file/env influence, no preprocessors, bounded match count, bounded per-file size, and exit code 1 (no matches/no files) is treated as success where empty results are expected. Requires ripgrep on PATH (Debian/Ubuntu: apt install ripgrep; macOS: brew install ripgrep). Local and no-egress.
API capability pack for bounded Rootly REST API v1 operations against https://api.rootly.com only. Reads current user identity, incidents, incident timeline events, action items, alerts, services, teams, severities, statuses, schedules, escalation policies, and users, and supports approval-gated incident creation/update/mitigation/resolution, timeline note creation, action-item creation/update, alert creation/update, and alert acknowledge/resolve. Bundles incident operations digesting, incident and alert triage briefs, and approval-gated workflows for incident intake, incident status updates, and action-item creation. Enroll a Rootly API-key or OAuth connection named rootly that injects Authorization: Bearer <token> with the narrowest Rootly permissions needed. The pack intentionally excludes deletes, cancellation/restart/duplicate mutation, subscriber mutation, API-key rotation, alert route/source/config mutation, schedule/escalation/service/team/severity/status mutation, workflow/webhook/catalog/admin/security APIs, and arbitrary API passthrough.
V3 Ruby/RSpec test-run capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local bundle CLI ingredient exposes bounded project operations for RSpec readiness and test execution. Invocations run the project's bundled rspec command from one explicit project directory cwd supplied at execution time and return plain RSpec output via the ruby.test_run catalog operation. Fixed invocation, but approval-gated: RSpec loads project Ruby code, Rails initializers, support files, factories, mocks, and test fixtures, and may write project/database/cache state or contact services depending on the project. The pack uses the project bundle, progress formatter, no ANSI color, no caller-supplied spec path, formatter, tag, pattern, require, profile, seed, dry-run, bisect, env override, stdin, or shell wrapper. Test failures and RSpec diagnostics are represented as text results so the caller can inspect output. Requires bundle on PATH and rspec in the project bundle.
V3 bounded local rsync preview capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local rsync CLI ingredient exposes fixed operations for readiness, source tree listing, recursive dry-run sync preview, archive-mode dry-run sync preview, and checksum dry-run sync preview. All filesystem operations require approval because they can reveal local path names, directory shape, file sizes, modification times, planned deletions, and sync topology. Every non-version operation is fixed to --dry-run, rejects remote rsync/SSH syntax by disallowing colons and URL-like inputs, and exposes no actual transfer, delete mutation, remote endpoint, rsync daemon, SSH transport, filter/include/exclude files, password file, batch write/read, backup paths, chmod, partial files, progress streaming, arbitrary flags, environment override, stdin, output-file write, or shell wrapper. Requires rsync or OpenRsync on PATH.
V3 Ruby lint capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local bundle CLI ingredient exposes bounded project operations for RuboCop readiness and lint diagnostics. Invocations run the project's bundled rubocop command from one explicit project directory cwd supplied at execution time; linting checks one trusted file or directory target and returns RuboCop JSON diagnostics via the ruby.lint catalog operation. Fixed invocation, but approval-gated: RuboCop loads project configuration, custom cops, plugins, and Ruby gems, and may write cache state depending on project configuration. The pack uses the project bundle, JSON formatter, force-exclusion behavior, no autocorrect, no caller-supplied config path, require hook, formatter, cache path, parallelism, stdin, env override, or shell wrapper. Offenses are represented as successful JSON output; RuboCop invocation/configuration errors still fail. Requires bundle on PATH and rubocop in the project bundle.
V3 deterministic Python lint and format-check capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local ruff CLI ingredient exposes bounded project operations for readiness, lint diagnostics, and format-check diagnostics. Checks run from an explicit project directory cwd supplied at execution time, inspect one trusted local Python file or project path, and return JSON diagnostics via python.lint and python.format_check catalog operations. Fixed-function and reproducible: no arbitrary ruff flags, no fixing/writing mode, no caller-supplied config path, no shell wrapper, and no network egress. Lint or formatting findings are represented as JSON output instead of failing the op; real invocation errors still fail. Requires ruff on PATH (Python environments: pip install ruff; macOS: brew install ruff). Local and no-egress.
One-install RunPod front door over 4 bounded official domain packs and 7 non-chat, uncached, read-only workflows. It admits 42 of 45 exact operations: every contract-complete resource operation from RunPod's immutable official management OpenAPI plus all eight queue-job routes in the immutable official operation reference, with v2 origin, bearer authorization, and common job transport corroborated by the current Python SDK. Three operations are excluded exactly: the OpenAPI document endpoint, the HTML documentation endpoint, and Pod restart because its official contract declares no 2xx success response. Pods, network volumes, Serverless endpoints, templates, registry credential references, billing, and queue-job lifecycle are otherwise covered; the optional status ttl selector is deliberately omitted because that nominal GET changes job retention. Management and Serverless execution origins remain separate even though both use RunPod API-key authorization. JSON bodies remain verbatim, bounded query integers retain their safe numeric constraints, and unsafe response integers remain exact strings. Reads are uncached and not approval-gated; every private mutation requires approval. No task, note, or project Source is claimed for infrastructure or runtime records.
RunPod Pod discovery, provisioning, configuration, lifecycle interruption, deletion, and persistent network-volume management. Generated from the immutable official RunPod OpenAPI at docs commit 97887252ea4f07dd897c1c17f6ef12858e9a743b. This leaf carries 15 of the suite total 42 admitted operations. Pick the RunPod management connection whose Authorization header contains the complete bearer API-key value for rest.runpod.io. JSON request documents are sent verbatim, bounded query integers retain their safe numeric constraints, and unsafe JSON response integers remain exact strings. Reads are uncached and not approval-gated, and every private mutation requires approval. No infrastructure object is misrepresented as a task, note, or project Source.
RunPod container-registry credential references plus Pod, Serverless endpoint, and network-volume billing history. Generated from the immutable official RunPod OpenAPI at docs commit 97887252ea4f07dd897c1c17f6ef12858e9a743b. This leaf carries 7 of the suite total 42 admitted operations. Pick the RunPod management connection whose Authorization header contains the complete bearer API-key value for rest.runpod.io. JSON request documents are sent verbatim, bounded query integers retain their safe numeric constraints, and unsafe JSON response integers remain exact strings. Reads are uncached and not approval-gated, and every private mutation requires approval. No infrastructure object is misrepresented as a task, note, or project Source.
RunPod queue-based Serverless synchronous and asynchronous submission, status, finite stream snapshots, cancellation, retry, queue purge, and health operations. Generated from the immutable official queue-operation reference at docs commit 97887252ea4f07dd897c1c17f6ef12858e9a743b and official Python SDK commit f8fa7b11262fb8516c703abe9e498cce4d69f8e8; this leaf deliberately does not mislabel those documents as OpenAPI. This leaf carries 8 of the suite total 42 admitted operations. Pick the distinct RunPod Serverless job connection whose Authorization header contains the complete Bearer API-key value for api.runpod.ai. JSON request documents are sent verbatim, bounded query integers retain their safe numeric constraints, and unsafe JSON response integers remain exact strings. Reads are uncached and not approval-gated, and every private mutation requires approval. No infrastructure object is misrepresented as a task, note, or project Source.
RunPod Serverless endpoint and reusable template discovery, provisioning, configuration, and deletion. Generated from the immutable official RunPod OpenAPI at docs commit 97887252ea4f07dd897c1c17f6ef12858e9a743b. This leaf carries 12 of the suite total 42 admitted operations. Pick the RunPod management connection whose Authorization header contains the complete bearer API-key value for rest.runpod.io. JSON request documents are sent verbatim, bounded query integers retain their safe numeric constraints, and unsafe JSON response integers remain exact strings. Reads are uncached and not approval-gated, and every private mutation requires approval. No infrastructure object is misrepresented as a task, note, or project Source.
One-install Salesloft v2 front door over four bounded domain packs and seven revenue-engagement workflows. The suite admits all 198 current v2 method/path operations published through Salesloft's content-hashed OpenAPI reference fragments: the 16-operation compatibility root preserves every prior ID and effective route while dependencies add 182 operations. Salesloft does not publish the monolithic build-time OpenAPI file, so no false openapi_source pin is declared; the generated audit fixture records each official page and hashed fragment instead. The upgrade repairs cadence-enrollment query transport, note association fields, array-valued filters, origin/path composition, and recipe bindings. Operations that publish the page/per_page contract walk bounded pagination until metadata.next_page is null. Every mutation requires approval, sensitive new reads are marked sensitive-read, reads are uncached, JSON request fields follow Salesloft's recommended format, and unsafe response integers remain exact strings.
Salesloft actions, activities, cadences, memberships, collections, imports and exports, steps, successes, and task workflows. Generated from Salesloft's 2026-07-15 published, content-hashed OpenAPI operation fragments. The vendor does not expose the monolithic build-time specification, so this composition deliberately carries no misleading openapi_source pin. Reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, operations that publish page/per_page walk through metadata.next_page, request bodies use Salesloft's recommended JSON form, and unsafe response integers remain exact strings.
Salesloft calls, emails, templates, calendars, meetings, conversations, transcriptions, phone settings, live-feed items, and signal registrations. Generated from Salesloft's 2026-07-15 published, content-hashed OpenAPI operation fragments. The vendor does not expose the monolithic build-time specification, so this composition deliberately carries no misleading openapi_source pin. Reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, operations that publish page/per_page walk through metadata.next_page, request bodies use Salesloft's recommended JSON form, and unsafe response integers remain exact strings.
Salesloft accounts, people, stages, opportunities, CRM projections, custom fields, notes, tags, and external-ID mappings. Generated from Salesloft's 2026-07-15 published, content-hashed OpenAPI operation fragments. The vendor does not expose the monolithic build-time specification, so this composition deliberately carries no misleading openapi_source pin. Reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, operations that publish page/per_page walk through metadata.next_page, request bodies use Salesloft's recommended JSON form, and unsafe response integers remain exact strings.
Salesloft audit reports, data-control requests, redaction, bulk jobs, imports, groups, roles, team settings, users, saved views, and webhooks. Generated from Salesloft's 2026-07-15 published, content-hashed OpenAPI operation fragments. The vendor does not expose the monolithic build-time specification, so this composition deliberately carries no misleading openapi_source pin. Reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, operations that publish page/per_page walk through metadata.next_page, request bodies use Salesloft's recommended JSON form, and unsafe response integers remain exact strings.
One-install Samsara front door over ten bounded domain packs and 35 non-chat, uncached, read-only operating workflows. It admits 316 of 331 operations from the current official consolidated OpenAPI. The two driver-token issuance routes and thirteen Samsara Functions code, storage, deploy, log, and runtime routes are explicit exclusions. Coverage includes assets, vehicles, equipment, trailers, telematics, safety, drivers, compliance, routes, maintenance, forms, industrial systems, administration, hubs, and ridership. Enroll one organization connection at its US, EU, or CA regional origin with a least-privilege API token. Every operation declares the exact documented Samsara permission label, every read is uncached, sensitive reads are marked sensitive-read, every mutation requires approval, and unsafe JSON integers are stringified. Five request contracts use explicit raw JSON to avoid int64 identifier corruption; another eighteen required all-optional bodies use required raw JSON so they cannot degrade into bodyless calls. Beta, preview, and legacy operations remain callable but visibly labeled. No operational write is bundled into a workflow, and no issue or work-order Source is claimed before the repository-mandated human field-path verification gate.
Samsara alert, contact, user, webhook, report-run, and Agent Studio voice-session operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara assets, attributes, tags, organization metadata, devices, and device-recovery operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara driver, assignment, HOS, tachograph, qualification, training, and driver-setting operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara form-template, form-submission, document, and PDF-export operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara hub, capacity, location, plan, order, route-template, skill, and ridership operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara industrial asset, data-input, reading, sensor, machine, job, camera, and vision-run operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara maintenance, issue, defect, DVIR, vendor, preventive-schedule, and work-order operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara route, route-event, address, place, message, and live-sharing operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara location, vehicle-stat, trip, safety, coaching, media, fuel, energy, IFTA, idling, and emissions operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
Samsara vehicle, equipment, trailer, gateway, installer, AEMP, lock, and immobilizer operations. Generated from a point-in-time SHA-256 pin of Samsara current official consolidated OpenAPI 2025-10-23. Enroll the organization connection at the correct US, EU, or CA regional origin; the per-organization connection base overrides the representative US origin without exposing runtime routing as an operation argument. Use a manually enrolled Samsara API token with only the permission labels declared on each operation. All reads are uncached, sensitive reads are marked sensitive-read, every mutation is grant-off and approval-gated, all JSON responses stringify unsafe integers, and comma-separated versus exploded query arrays follow the official OpenAPI serialization contract. Beta, preview, and legacy operations are labeled explicitly. Driver-token issuance and the Samsara Functions code/runtime surface are excluded. Issues and work orders are not declared as Sources because the repository Source brief requires a separate human field-path verification gate.
V3 approval-gated remote file transfer capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local OpenSSH scp CLI uploads or downloads a single file over SSH via remote.file_upload and remote.file_download catalog operations. This pack deliberately does not expose generic SSH command execution, recursive copies, globbing, arbitrary flags, ProxyCommand, or host-key bypasses. Each transfer requires an explicit host, user, port, remote path, identity-file path, and known-hosts-file path. scp runs in batch mode with IdentitiesOnly and StrictHostKeyChecking enabled, so a recipe cannot silently accept a new host key or fall back to password prompts. Upload consumes a data.file ref or trusted local path; download captures the fetched file as result.file_ref. Requires OpenSSH scp on PATH (Debian/Ubuntu: apt install openssh-client; macOS: scp ships with OpenSSH). Networked and credential-bearing; approval=ask for every operation.