PayPal webhook administration, event types, event history, signature verification, resend, and simulation. Generated from PayPal's immutable commit-pinned Webhooks Management OpenAPI 1.11. This source-pinned leaf carries 10 of the installed family's 109 catalog operations; the family covers 105 of 115 unique official routes with 10 exact fail-closed exclusions. Bearer authorization and merchant/partner identity remain connection-owned, new reads are uncached and not approval-gated, every mutation requires approval, documented PayPal-Request-Id values are mandatory for supported mutation retries, JSON inputs are bounded, and unsafe response integers remain exact strings. No financial or control-plane object is misrepresented as a task, note, or project Source.
Marketplace
Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.
927 packs
V3 deterministic PDF text-search capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local pdfgrep CLI exposes readiness, bounded page-numbered PDF text search, fixed-string search, case-insensitive search, context search, match-only extraction, total match counts, and page-level match counts for one trusted local PDF path. This pack deliberately exposes bounded path-based value output rather than file_ref materialization, because matched PDF text is returned on stdout. No arbitrary pdfgrep flags, recursive directory search, password arguments, pattern-file inputs, cache writes, debug output, shell wrapper, stdin, or multi-file glob search are exposed, and exit code 1 (no matches) is treated as success for search/count operations. Requires pdfgrep on PATH (Debian/Ubuntu: apt install pdfgrep). Local and no-egress.
V3 deterministic PDF image-inventory capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfimages CLI exposes readiness, full-document embedded-image inventory, fixed first-page image inventory, and bounded first-N-pages image inventory for one trusted local PDF path. This pack deliberately ships inventory modes only, not bulk image extraction, because pdfimages extraction writes one file per image and v1 output_capture expects exactly one produced file. The operations are path-based stdout text for the same reason as pdfinfo: the current CLI safety contract forbids materialized file_ref input with stdout value capture. It exposes no password arguments, image-root output prefix, extraction format flags, stdin mode, shell wrapper, arbitrary flags, or network egress. Requires pdfimages on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).
V3 deterministic PDF information capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfinfo CLI exposes readiness, basic document/page information, page-box bounding boxes, document-level metadata stream output, and URL annotation listing for one trusted local PDF path. This pack deliberately exposes path-based stdout helpers, not file_ref materialization, because the current CLI safety contract forbids materialized file_ref input with stdout value capture. It exposes no password arguments, JavaScript dump, tagged-structure dump, arbitrary pdfinfo flags, stdin mode, shell wrapper, output-file path, or network egress. Requires pdfinfo on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler). Local and no-egress.
V3 deterministic PDF page-extraction capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfseparate CLI exposes readiness, fixed first-page extraction, and single selected-page extraction for one source PDF. Fixed-function and reproducible: the executor materializes the source PDF and owns the throwaway output directory, while pdfseparate writes exactly one page PDF per operation that is captured as result.file_ref. The pack deliberately avoids arbitrary page ranges and full-document splitting because pdfseparate writes one PDF per page and the current output_capture contract expects a single produced file. It exposes no password arguments, caller-controlled output pattern, stdin mode, shell wrapper, arbitrary flags, or network egress. Requires pdfseparate on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).
V3 deterministic PDF text-extraction capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdftotext CLI exposes readiness, layout-preserving extraction, default reading-order extraction, fixed first-page preview extraction, bounding-box XHTML layout extraction, and TSV word-position extraction for a source PDF. Bundles a direct text-extraction recipe plus a preview-first PDF notes workflow that summarizes the extracted text by file ref. Fixed-function and reproducible: extraction happens locally before any model sees the PDF. Write-tier but approval=never: pdftotext writes only to an engine-managed throwaway output dir and each extracted artifact is captured as result.file_ref; downstream ai-* steps consume text through Gateway-gated file refs. The source can be a data.file ref or a trusted local path. This pack exposes no password args, arbitrary flags, stdin mode, caller-controlled output path, shell wrapper, or network egress. Requires the pdftotext binary on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).
V3 deterministic PDF merge capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfunite CLI exposes readiness, exact two-PDF merge, and bounded multi-PDF merge operations. The executor materializes ordered file_ref arrays into engine-managed temp paths, expands them into discrete argv elements in caller order, and owns the output path captured as result.file_ref. The pack exposes no arbitrary pdfunite flags, encrypted-PDF password handling, caller-controlled output path, stdin mode, shell wrapper, or network egress. Requires pdfunite on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).
API capability pack for bounded Perplexity REST API operations against https://api.perplexity.ai only. Enroll a Perplexity API key bearer connection named perplexity; no credential is embedded in this manifest. The pack reads the model catalog, creates bounded Web Search API responses, creates non-streaming Sonar responses with citations and search results, and creates text embeddings for research, competitive intelligence, source-backed answer review, semantic search preparation, and RAG readiness. It bundles a cited answer brief, a web search brief, an embedding readiness brief, and a model catalog brief. The pack intentionally excludes streaming, async chat jobs, Agent API responses, browser sessions, file and response content download, custom tools and tool-choice routing, MCP or code execution, contextualized embeddings, People Search, analytics, auth-token issue or revoke endpoints, arbitrary Perplexity API passthrough, dynamic outbound callbacks, and any operation outside api.perplexity.ai.
Keep up with the people you actually know, from the mail and calendar you already sync. Four recipes over your own warehouse — no CRM, no contact upload, nothing leaves your machine. keep-in-touch-cadence is a weekly nudge list of people you have real history with who have gone quiet; personal-circle-health-brief ranks your closest contacts and shows who is carrying each relationship; keep-gift-idea-ledger captures 'remember Sam likes X' as a note on Sam; draft-introduction-mail turns two contacts plus your reason into an intro you copy and send yourself. The two digests are read-only. Only two things ever write, and only what they name: the gift ledger creates one note linked to the person, and nothing else is touched. No recipe here sends mail, creates or edits a contact, or notifies anyone. Both digests read enrichment rollups that the housekeeping producers maintain, so a contact you have never exchanged mail with will not appear in them.
Find the money leaking out of your inbox, without any of it leaving your machine. Eight warehouse-first recipes over mail you already sync and files you already have — no bank connection, no aggregator, no statement upload to anyone: audit-subscriptions-from-mail ranks recurring charges by cost; renewal-radar surfaces annual renewals before they auto-charge; categorize-expenses-from-statement parses a dropped statement locally with docling and categorizes it into a table plus a CSV; detect-spend-anomalies-statement compares two months per category with pure arithmetic and no model call; price-increase-detector watches new mail behind deterministic subject-then-body gates; track-warranty-from-receipt turns a receipt into a warranty reminder with the receipt linked to it; assemble-tax-document-packet checks off the documents for a tax year and collects the files; collect-receipts-monthly-packet gathers a month of receipt mail and receipt files into one markdown evidence file. The read-side recipes never write. Two recipes write, and only what they name: track-warranty-from-receipt creates a Recued task, and collect-receipts-monthly-packet writes its packet into a file collection you nominate (it needs one with the write capability, and writes nothing until you set it). Nothing here pays, cancels, unsubscribes, or replies to anyone, and nothing moves, renames, or deletes a file. The two mail watchers install disarmed — you arm them.
One-install Personio front door over 5 bounded v2 capability packs and 29 non-chat read workflows. It admits 69 callable operations from 72 official endpoint fragments and explicitly excludes 3 credential-lifecycle routes. Coverage includes people and employments, organization reference data, compensation and salary bands, reports, document management and binary download, attendance, absence, time-tracking projects and memberships, recruiting, and webhook administration. Personnel access and recruiting access remain separate bearer enrollments because Personio documents distinct credential contexts. Personnel tokens are stable for 24 hours but require manual renewal until the connection substrate supports client-credentials renewal. All reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, cursor pagination follows same-operation token replay, and no operation receives an implicit default grant. The genuine Personio Project entity is not declared as a Source in this commit because the repository requires a separate human field-path verification gate.
Personio compensation records and types, custom reports, and document metadata, download, update, and deletion. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.
Personio people, employments, org units, legal entities, cost centers, workplaces, jobs, and salary bands. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.
Personio recruiting applications, candidates, jobs, categories, and application stage transitions. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf is isolated to the separately enrolled Recruiting API bearer documented by Personio; it does not claim that a personnel token can authorize recruiting endpoints. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.
Personio attendance periods, absence periods and types, time-tracking projects, and project membership. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.
Personio webhook configuration, delivery activity, event inspection, redelivery, ping, and test-event controls. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.
V3 Python dependency-vulnerability audit capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local pip-audit CLI ingredient exposes bounded project operations for readiness and dependency vulnerability audits. Audits run from an explicit project directory cwd supplied at execution time, audit one trusted, fully pinned requirements file, and return JSON findings via the python.dependency_audit catalog operation. Fixed-function and bounded: requirements-file mode only, JSON output, fixed PyPI vulnerability service, no dependency resolution, no pip resolver, no package fixing/upgrading, no local environment/project scan, no lockfile/project-path scan, no caller-supplied package indexes, no ignored vulnerability list, no output-file write, no arbitrary pip-audit flags, and no shell wrapper. Approval is ask because package names and versions are sent to PyPI vulnerability data services. Vulnerability findings are represented as successful JSON output; real collection or invocation errors still fail. Requires pip-audit on PATH with Python 3.10+. Network egress to PyPI vulnerability data services.
Still-live Pipedrive API v1 administration and platform features, including billing, goals, teams, permissions, roles, projects, users, settings, recents, and webhooks. Generated from the current hash-pinned official Pipedrive v1 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.
Preferred Pipedrive API v2 coverage for activities, deals, deal products and installments, people, organizations, products, leads, search, stages, and pipelines. Generated from the current hash-pinned official Pipedrive v2 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.
Preferred Pipedrive API v2 coverage for field administration, projects, templates, tasks, boards, phases, and user followers. Generated from the current hash-pinned official Pipedrive v2 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.
Still-live Pipedrive API v1 features without a complete v2 replacement, including sales history, calls, channels, files, mail, notes, contact relationships, filters, and lead metadata. Generated from the current hash-pinned official Pipedrive v1 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.
One-install MongoDB Atlas Admin API v2 front door over 8 bounded capability packs and 31 non-chat, uncached, read-only workflows. It admits all 429 nondeprecated operations across 306 official paths and excludes exactly 58 provider-deprecated operations. Organizations, projects, users, billing, credentials, identity, clusters, networking, backups, observability, Search, Data Federation, and Streams are covered. The mutable official OpenAPI URL must retain 4,590,007 bytes and SHA-256 5040b0d3973e891f9e9048f6c305ed54977d0d69153ad073b232a39d90a50c77 before regeneration. Calls stay on cloud.mongodb.com and carry the exact per-resource versioned media types. The supported credential path is MongoDB's recommended OAuth2 service-account bearer token; Atlas documents a one-hour token lifetime, this pack does not claim automatic token exchange, and legacy HTTP Digest API keys are unsupported. Seventy-one exact page-number collections are automatic; one correlated multi-array response remains explicitly manual. Six non-JSON downloads become private file_refs. Six validation, verification, report, or download POSTs are read-tier; disruptive restores, resets, cutovers, migrations, access removals, and infrastructure reconfiguration are destructive. JSON bodies remain verbatim and unsafe response integers remain exact strings. Reads are uncached and not approval-gated; every mutation requires approval. No task, note, or user-work project Source is claimed for infrastructure tenancy containers.
MongoDB Atlas cloud-provider access, network peering, private endpoints, project IP access lists, and third-party integrations. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 36 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.
MongoDB Atlas activity feeds, events, alerts, process and database metrics, logs, Performance Advisor, query insights, and log export. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 65 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.
MongoDB Atlas organizations, projects, teams, Cloud users, memberships, settings, delegation, and invoices. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 61 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.
MongoDB Atlas Search deployments and indexes, Data Federation, private network settings, and Atlas Stream Processing workspaces, connections, and processors. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 64 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.
V3 deterministic MuPDF document-manipulation capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local mutool CLI cleans a PDF, extracts a caller-selected page range into one PDF, or renders the first page to PNG via fixed catalog operations. Write-tier but approval=never: mutool writes only to an engine-managed throwaway output dir and each result is captured as result.file_ref; source PDF bytes never flow through stdout values. Requires mutool on PATH (Debian/Ubuntu: apt install mupdf-tools; macOS: brew install mupdf). Local and no-egress.
V3 Python type-check capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local mypy CLI ingredient exposes bounded project operations for readiness and Python type-check diagnostics. Type checks run from an explicit project directory cwd supplied at execution time, inspect one trusted Python file or directory, and return plain diagnostics via the python.type_check catalog operation. Fixed-function and reproducible: ignores discovered project config, ignores missing third-party imports, disables incremental cache reads, disables cache writes on Unix-like hosts, disables color and summary noise, no daemon, no command/eval string, no module/package selector, no caller-supplied config/plugin/cache path, no install/stubgen/stubtest, no arbitrary mypy flags, no shell wrapper, and no network egress. Type errors are represented as successful text findings; real invocation failures still fail. Requires mypy on PATH. Local and no-egress.
Manage n8n through the bounded Public API: workflows, executions, credentials metadata, tags, users, variables, data tables, projects, folders, insights, community packages, source-control pulls, audit reports, and package export. Enroll an n8n API connection with X-N8N-API-KEY and set base_url to the tenant API root, such as https://example.app.n8n.cloud/api/v1 or https://n8n.example.com/api/v1. Enterprise API keys should grant only the listed required_scopes; non-enterprise n8n API keys may have full account access. Pagination is exposed through query.limit and query.cursor because n8n returns a top-level nextCursor token. Package export/import and arbitrary webhook/raw API passthrough are intentionally excluded: export is a POST binary response while current REST pack file capture is GET-only, and import requires multipart binary upload.
API capability pack for bounded Neon API v2 operations against https://console.neon.tech/api/v2 only. Enroll a Neon API key bearer connection named neon with the narrowest project, branch, endpoint, database, role, operation, region, and organization read scopes plus explicit write scopes for project rename, preview branch creation, branch rename, and compute start/suspend/restart. No credential is embedded in this manifest. The pack reads current-user context, organizations, regions, projects, branches, compute endpoints, databases, roles, and project operations for developer database operations, preview branch workflows, cost-control checks, and production-readiness reviews. It bundles a project operations digest, an AI-assisted branch readiness brief, and approval-gated workflows for creating one preview branch and suspending one compute endpoint. Writes are limited to one project rename, one branch create/rename, one database create, or one compute start/suspend/restart at a time. The pack intentionally excludes API-key create/revoke, role create/reset/reveal-password, connection URI retrieval, SQL/data API execution, storage object download, project/branch/endpoint/database deletes, branch restore/recover/reset/default changes, snapshots/backup mutation, VPC/project transfer, auth administration, consumption billing changes, OAuth token exchange, and arbitrary Neon API passthrough.
API capability pack for bounded Netlify REST API operations against https://api.netlify.com/api/v1 by default. Enroll a netlify OAuth or personal-access-token bearer connection; no credential is embedded in the manifest. The pack reads the current user, accounts, account audit events, sites, TLS certificate status, deploys, builds, deployed branches, function bundles, forms, submissions, files, assets, snippets, site metadata, DNS zones and records, split tests, public add-on service metadata, database migration metadata, and database snapshots. Approval-gated writes are limited to one site/deploy/build/cache/env/split-test action at a time: enable or disable a site, cancel/restore/rollback/lock/unlock a deploy, trigger a non-upload build, purge cache for one site or tag set, update or remove one environment variable/value, and create/update/publish/unpublish one branch split test. The pack intentionally excludes deploy creation and file/function upload, build-hook reads or writes, deploy keys, OAuth tickets, account/member/billing mutation, site creation/deletion/update, DNS mutation, form/submission deletes, snippet injection writes, asset uploads/deletes, service instance mutation, AI gateway token reads, database connection-string reads, database create/delete/reset/restore/migration-run operations, agent-runner endpoints, plugin mutation, webhooks, and arbitrary API passthrough.
No-auth API capability pack for occasional address geocoding and reverse geocoding through the public OpenStreetMap Nominatim service. The pack exposes only bounded single-lookup operations against https://nominatim.openstreetmap.org, fixes JSON output, caps search results at five, and sends an identifying User-Agent. This pack is not for bulk or periodic geocoding; cache results and stay within the public service policy.
One-install Northflank front door over 9 bounded domain packs and 13 non-chat, uncached, read-only workflows. It admits all 609 nondeprecated operations across 422 official paths and excludes exactly 76 provider-deprecated operations. Projects, services, jobs, pipelines, workflows, addons, storage, secrets, integrations, networking, cloud and GPU clusters, AI models, templates, previews, teams, roles, tags, and billing are covered. The vendor-hosted OpenAPI is mutable but generation fails closed unless its 5,911,172 bytes retain SHA-256 59fdc2ce6fe8a7652715b2e0a24f762b2e248666393843d019af019159fa1d3b; official Markdown pins repair the schema's placeholder server and empty security declarations with the documented api.northflank.com origin and Bearer authorization. Two team billing paths omit teamId from their reused operation objects, so the exact path placeholder is repaired as a required string; eight collection operations incorrectly carry an ID path parameter absent from their own path, so those phantom inputs are omitted. Twelve optional repeated-value query selectors expose their official scalar alternative because closed operation args cannot serialize duplicate query keys. All repairs and reductions are recorded in the audit fixture. 112 exact cursor loops are automatic; 14 contradictory cursor shapes stay explicitly manual. JSON bodies remain verbatim and unsafe response integers remain exact strings, with compact response schemas accepting both safe numeric and unsafe decimal-string forms. Reads are uncached and not approval-gated; every mutation requires approval. No task, note, or project Source is claimed for infrastructure or runtime records.
Northflank teams, organization and team roles, members, tags, billing, plans, regions, DNS identity, and account administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 53 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank managed addon types, instances, credentials, backups, restores, logs, metrics, versions, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 73 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank cloud-provider and cluster management, node operations, regions and node types, AI model deployments, and OpenTofu logs. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 47 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank VCS, registry, notification, log-sink, SSH, cloud-identity, and workload-identity integration discovery and administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 70 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank job, pipeline, preview-flow, release-flow, and workflow discovery, execution, build, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 92 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank domains, subdomains, egress IPs, load balancers, network policies, gradual rollouts, and delivery configuration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 86 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank project and long-running service discovery, provisioning, build, deployment, runtime, metrics, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 66 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank global and project secrets, volumes, backups, backup destinations, and external addon discovery and administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 76 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
Northflank reusable templates, template runs, preview blueprints, preview environments, and blueprint-run lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 46 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.
API capability pack for bounded Notion page, block, comment, user, and data-source operations against https://api.notion.com only. The pack uses Notion API version 2026-03-11, reads token identity, workspace users, shared pages/data sources, page properties, page markdown, block children, comments, and one page of data-source entries, searches shared pages/data sources by title, and creates or updates daily workspace content. It also bundles a scheduled workspace digest, an AI-assisted page/data-source brief, and approval-gated page intake workflow. Enroll a Notion personal access token or OAuth access token connection as bearer auth; no credential is embedded in the manifest. Writes are limited to page create/update, appending child blocks, creating/updating comments, and updating one to-do block, all approval-gated. The bundled recipes only use page.create and optional comment.create as writes. The pack intentionally excludes arbitrary fetches, deletes, trash/restore, moving pages, broad block updates beyond to-do content/state, comment delete, file upload flows, admin configuration, and workspace-wide export.
Workflow pack for Recued-created Notion page comments. It composes the Notion capability pack with a closure ledger: add one owner-approved comment to an existing Notion page, persist only the connection/page/status-property/comment linkage in data.shared, and let a scheduled watcher re-read that exact page and configured status property until Notion reports a terminal status such as done, complete, completed, closed, or archived, or until the page is in trash. This pack does not replace Notion comments, status properties, native notifications, database views, dashboards, reminders, automations, templates, or project management workflows; it adds Recued-visible closure state for page comments Recued created.
V3 npm toolchain capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local npm CLI ingredient exposes bounded project operations for readiness, package manifest inspection, lockfile dependency tree inspection, test execution, dependency audit, and CycloneDX SBOM generation. Project operations run from an explicit project directory cwd supplied at execution time, avoid caller-supplied npm flags, avoid shell wrappers, and keep diagnostics visible as text or JSON output. Manifest and lockfile inspection are local and read-only. Test execution is approval-gated because package scripts execute project-defined code. Dependency audit is approval-gated because npm sends dependency inventory to the fixed npm registry. SBOM generation is local and read-only. Requires npm on PATH.
V3 deterministic searchable-PDF and OCR-text capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local OCRmyPDF CLI ingredient exposes bounded operations for readiness, searchable-PDF generation, and OCR sidecar text extraction. Bundles a direct searchable-PDF recipe plus a scanned-document notes workflow that chains OCRmyPDF with PDF text extraction and preview-first AI summarization. Fixed-function and reproducible: the executor materializes the source file and owns the throwaway output directory, while OCRmyPDF writes fixed captured outputs. Write-tier but approval=never: OCRmyPDF writes only to engine-managed output dirs, exposes no arbitrary plugin/config flags, no caller-supplied output paths, no deskew/clean/rotate mutators, no force-ocr, no Tesseract config overrides, and source bytes never flow through op-step values. Requires ocrmypdf plus Tesseract language data on PATH (Debian/Ubuntu: apt install ocrmypdf tesseract-ocr-eng). Local and no-egress.
API capability pack for bounded Okta Management API v1 operations. Enroll an okta API connection with base_url set to the tenant API root, for example https://example.okta.com/api/v1, and authenticate with a scoped OAuth/OIDC bearer token where available; a tightly scoped SSWS-token header connection can also be used when the tenant still relies on API tokens. The pack reads users, user groups, user app links, groups, group members, applications, application users, and System Log events for access governance, offboarding review, and identity incident triage. It bundles a scheduled access hygiene digest, an AI-assisted user access brief, and approval-gated workflows for suspending/unsuspending one user and adding/removing one user from one group. The pack intentionally excludes user creation, deactivation, deletion, password and factor reset flows, authenticator enrollment mutation, role/admin assignment, app assignment mutation, policy/profile/schema mutation, token/session/recovery-factor administration, domain/network/brand/rate-limit/admin APIs, and arbitrary API passthrough.
API capability pack for bounded OneDrive metadata operations through Microsoft Graph at https://graph.microsoft.com/v1.0 only. Reads the current user, current drive, root drive item, drive-item metadata, folder children, root-folder children, root delta changes, file versions, sharing permissions, and followed items. It supports approval-gated daily organization actions: create folders, rename drive items, move drive items within a drive, asynchronously copy drive items, and follow or unfollow drive items. File upload/download, sharing-link creation, permission mutation, delete/trash, conflict-behavior tuning, and arbitrary Microsoft Graph passthrough are intentionally not exposed in this metadata pack. Enroll a Microsoft Graph OAuth access token connection as bearer auth; no credential is embedded in the manifest.