Referencia de herramientas MCP
Todo lo que un agente puede llamar, con sus parámetros y lo que devuelve. Miralo antes de dar acceso.
Endpoint MCP: https://mcp.ardumaker.com/mcp. Versión legible por máquinas: tools.json. Metadatos OAuth: /.well-known/oauth-authorization-server.
Las herramientas de este dominio (266)
Salen del propio servidor MCP en cada compilación. Las descripciones están en inglés porque son las que lee el agente.
Attachments
crear_adjunto: Creates an attachment: external link (tipo='link', requires url), text note (tipo='nota', requires contenido), or metadata for an external resource ('pdf'/'video'/'foto'/'otro', requires url — this tool doesn't upload…editar_adjunto: Edits an attachment's nombre and/or contenido (only on tipo='nota'), or moves it to another folder of the same project with carpeta_id (null = no folder) keeping its id, comments and files. An MCP agent can never edit…eliminar_adjunto: Deletes an attachment and its comments. An MCP agent can never delete a secret attachment. This is a SOFT delete and can be undone: the attachment goes to the project's trash for 30 days (the uploaded file is kept on…listar_adjuntos: Lists a project's attachments as METADATA ONLY (id, nombre, tipo, carpeta, size, dates), newest first, with `total` for paging (limit default 50, max 200). It never returns a note's text: read it with… (solo lectura)mover_adjuntos: Moves attachments and notes to another folder of the same project (carpeta_id null = no folder) WITHOUT recreating them: id, content, files and comments stay. Same permission as editar_adjunto, max 100 per call, one…ver_adjunto: Full detail of a single attachment, including a note's text. Same secreto visibility rule as the web. A note longer than contenido_limit (max 30000 chars) comes in parts: then `contenido_recortado` says which part you… (solo lectura)
Blogs
agregar_seccion_blog: Adds a NEW content section to a blog (section_key: letters/numbers/underscores only, e.g. 'intro', 'section1'). It never overwrites: if the blog already has a section with that key the call fails with 409 and error_type…crear_blog: Creates a blog post in DRAFT status — publishing is a separate, deliberate step (see publicar_blog). Requires the agent's owner to have blog permission (is_blog_permitted) or be a system admin.crear_media_blog: Uploads a file to a blog from base64-encoded content (MCP tools can't send raw multipart files) — max 10MB decoded, allowed extensions: images (jpg/jpeg/png/gif/webp), video (mp4/ webm/ogg), audio (mp3/wav), documents…despublicar_blog: Archives a blog (removes it from public listings). Reversible — publicar_blog brings it back. There is deliberately no tool to permanently delete a blog; archive is the removal mechanism (see the destructive-operations…editar_blog: Edits a blog's titulo/descripcion/tags/cover_image (cover_image is a filename already uploaded via crear_media_blog). Does NOT change status — see publicar_blog/despublicar_blog. Any edit here invalidates cached…eliminar_media_blog: Deletes an uploaded file from a blog. This does NOT check whether a section or the cover_image still references it — remove those references first if it's in use.eliminar_seccion_blog: Removes a content section from a blog.listar_blogs: Lists PUBLISHED blogs only (public view) — most recently published first. search: matches title or description. limit: default 50, max 200. Use listar_mis_blogs for drafts/archived. (solo lectura)listar_media_blog: Lists every file already uploaded to a blog (not just the ones referenced in a section) — use this to discover existing assets before referencing one in agregar_seccion_blog or cover_image. (solo lectura)listar_mis_blogs: Lists ALL of this agent owner's blogs, including drafts and archived ones. (solo lectura)publicar_blog: Publishes a blog — from this point it's publicly visible and appears in listar_blogs/the sitemap. This is a DELIBERATE, separate action from crear_blog/editar_blog (new posts always start as drafts) — call this only…traducir_blog: Translates a blog's title and text sections (default languages: es/en/pt — pass a subset to only translate those). Can take a while: it calls an external translation service once per text section per language. Only…ver_blog: Full detail of a blog post by id, slug, or title (in that order — passing `lang` also tries the translated title). If it's not published, only its author can see it. Increments views_count, except when the reader is the… (solo lectura)ver_mi_blog: Full detail of one of the agent owner's own blogs, any status. (solo lectura)
Bug triage
actualizar_bug_triage: SYSTEM ADMINS ONLY. Triages a bug report: status, severity, muting, or marking it a duplicate. THIS IS THE TOOL THAT CLOSES A BUG — set `estado='resolved'`. One call can change several things at once; everything you…comentar_bug_triage: SYSTEM ADMINS ONLY. Adds an INTERNAL note to a bug report. Nothing you write here ever reaches the person who filed it. YOU CANNOT REPLY TO A REPORTER. Not a permission you are missing — a rule: a reply is emailed from…listar_bugs_triage: SYSTEM ADMINS ONLY. The internal bug inbox: every report from every user, not just yours. THE QUEUE IS SPLIT IN THREE and each one sorts differently — reading the wrong one wastes a triage session: · `personas` —… (solo lectura)ver_bug_triage: SYSTEM ADMINS ONLY. Everything about one bug report, with nothing hidden. The full record — description, captured context, traceback, error type, fingerprint, occurrences, affected agents, attachments — plus the status… (solo lectura)ver_resumen_bugs_triage: SYSTEM ADMINS ONLY. The numbers of the bug inbox: how many are open, how many are new, how many are critical or high, and how many of them nobody wrote. `de_personas` counts only what a person wrote by hand… (solo lectura)
Bugs
listar_mis_bugs: The bug reports you filed, and where each one stands. Also returns the ones filed by the person who authorized you: an agent acts on their behalf, so you share the same view. `estado` (optional) takes either a GROUP… (solo lectura)reportar_bug: Files a bug report. It lands in the same inbox a person's report goes to. `descripcion` is the only required field: what went wrong, in plain words. Include the exact error, the failing endpoint or tool, and the stack…ver_bug: Full detail of one of your bug reports: what was filed, the status timeline with dates, and the team's replies. Only replies meant for the reporter are returned — the team's internal notes are never exposed here.… (solo lectura)
Calendar
ver_calendario_proyecto: The project's calendar: dated tasks grouped day by day + project meetings for each day. user_id (optional) narrows the TASK workload down to a single member (the day's meetings still show all of them). desde/hasta:… (solo lectura)ver_disponibilidad: Checks whether several project members are free for a specific time slot (must fall on the same local day) — returns, per person, whether they're available and their real free blocks that day, plus the intersection… (solo lectura)
Checklist
agregar_checklist_item: Adds an item to a task's checklist. Once a task has at least one checklist item, its avance is automatically recalculated based on how many items are 'hecho' (done).editar_checklist_en_lote: Creates, edits and deletes many checklist items in ONE call, with the same per-element rules as editar_etapas_en_lote. Every element names its etapa_id and tarea_id. crear: {texto, orden?, adjunto_ids?}; editar:…editar_checklist_item: Edits a checklist item (texto/hecho/orden/referenced adjuntos).eliminar_checklist_item: Deletes a checklist item from a task. This is a SOFT delete and can be undone: the item goes to the project's trash for 30 days — see it with listar_papelera and bring it back with restaurar_papelera. `motivo` is…listar_checklist_items: Lists a task's checklist items in order. Until now the only way to read them was calling editar_tarea and inspecting its `checklist` field as a side effect of an edit call. (solo lectura)
Cloud – Apps
cambiar_lista_ip_app: Sets the IP allowlist of a database's external TCP access (shared by every database of the same engine). Requires the human who authorized you to be a company admin. `open_to_any` in the answer says whether the port is…controlar_app: Queues an action on an app, the same ones its allowed_actions offers: start, stop, restart, redeploy, update, close (ends a terminal), reconcile or retry. To uninstall: desinstalar_app.desinstalar_app: Uninstalls an app (unpublishes its web, closes its own TCP access, removes what Apps installed). Company admins only, and only when the app offers `uninstall` in allowed_actions. IRREVERSIBLE when delete_data=true.…instalar_app: Queues the install of an app on an existing, active VPS of the company (it never buys a server). Run ver_preflight_app first. Returns operation_id and operacion_id to follow it.listar_apps_empresa: Lists the Apps (databases, repos, n8n, Docker, terminals...) of a company, only on the VPS this agent can see, with each server's app count. Paginated with limit/offset; `total` is the real count. Wrapped as untrusted… (solo lectura)refrescar_apps: Queues a scan that reconciles the Apps inventory with what really runs on a VPS (or on every active VPS you can see). Coalesces with a scan already in progress (`coalesced: true`).reintentar_operacion_app: Re-queues a failed Apps operation whose `retryable` is true; the runner resumes from the step that failed. Answers 409 when it is not retryable or another one is running.revelar_credencial_app: SECRET. Returns the username, password and connection URI of a database app (PostgreSQL, MySQL, Redis): the app's own user, never the engine's root. Company admins only, same as the dashboard. The answer is marked…revocar_acceso_app: Closes the external TCP access of a database: removes the listener and firewall rules of the whole engine (every database of that engine loses it). Company admins only. Revoking something already closed answers…ver_acceso_app: External access of an app without secrets: host, port, TLS, allowed IP ranges and state. `my_ip` is always null here: the IP an agent connects from is not your user's computer. (solo lectura)ver_app: One app with its identity, components, last operation and allowed actions. Never includes passwords or connection secrets. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)ver_asistente_git_app: Git deploy helper, like the dashboard: no repo_id → repos your linked GitHub can read; repo_id → its branches; repo_id + branch → detected framework, build/start and, with vps_id, a free port (then instalar_app type… (solo lectura)ver_catalogo_apps: Which app types can be installed on a VPS right now and, for each one that cannot, why. (solo lectura)ver_operacion_app: State of an Apps operation by its operation_id (install, action, retry, refresh, IP allowlist), including ones started from the dashboard: steps, progress, error and whether it is retryable. For one you started here,… (solo lectura)ver_preflight_app: Binding pre-check before instalar_app: whether this type can be installed on this VPS now (plan, memory, disk, OS, existing apps) and every blocking reason with its next step. (solo lectura)
Cloud – Backups
configurar_backups_vps: Turns the weekly automatic backups of a VPS on or off. Excluding a VPS means it stops being copied: its existing copies stay, but they stop being refreshed.crear_backup_vps: Queues an out-of-schedule backup of a VPS. It does NOT run here: a daemon picks it up, and a full copy takes minutes. Rate-limited because a backup is heavy on the host's disk and network, and the host is serving other…crear_descarga_backup_vps: Requests a downloadable copy of a backup. The backend brings it from the backup host to its own disk and emails a link to whoever asked; the link expires in 72 hours. The returned `url`, when present, is the credential…listar_backups_vps: Lists the backup copies of a VPS, newest first. Each one shows its state, size, date and whether a download is already prepared. (solo lectura)ver_backup_vps: Full detail of one backup copy: what it contains, per its manifest. The step-by-step log is deliberately NOT returned: it is the literal output of commands run on the host and may carry internal paths or credentials.… (solo lectura)ver_estado_descarga_backup_vps: How the download of a backup is going: 'pending', 'staging', 'ready', 'expired' or 'failed'. Returns null if nobody requested it. (solo lectura)
Cloud – Catalog
listar_empresas: Lists the companies the user (who authorized this agent) administers or is a member of — use this to discover the company_id values other cloud tools require. Summary fields only (id/name/slug/status/rol_del_usuario) —… (solo lectura)listar_planes_vps: Lists the VPS plans this user is entitled to: public ones plus those of schools they belong to (all for system admins). With company_id and vps_id: the plans THAT server can change to (cambiar_plan_vps), judged against… (solo lectura)ver_funciones_por_sistema: The compatibility table: every VPS feature, where it runs, what it requires and its state on each known OS. For one VPS use `ver_funciones_vps`. (solo lectura)ver_opciones_vps: Where a VPS of this plan can be created: locations, storage types and their performance. Call this before `crear_vps` whenever the user cares where their server lives, then pass the chosen `ubicacion_id` and… (solo lectura)
Cloud – Databases
actualizar_fila_db_vps: Updates ONE row, identified by its COMPLETE primary key. There is no bulk update on purpose: an UPDATE with a wrong WHERE is one of the few things here that cannot be undone.borrar_fila_db_vps: Deletes ONE row by complete primary key. Same rule as the update: one row at a time.consultar_sql_db_vps: Runs a READ-ONLY SQL query, one single statement. Writes are rejected here on purpose: use the row tools or ejecutar_ddl_db_vps. Pass values through `params`, never glued into the SQL text. (solo lectura)contar_filas_db_vps: Exact COUNT(*), with the same filter as leer_filas_db_vps. It is a separate tool because on a big table it costs far more than reading a page. (solo lectura)describir_tabla_db_vps: Columns (with a normalized type that is the same for both engines), nullability, primary key, foreign keys and indexes. Read this before writing rows: it is where the real column names come from. (solo lectura)ejecutar_ddl_db_vps: Runs ONE DDL statement (CREATE / ALTER / DROP / TRUNCATE ...). If it DESTROYS data it fails with HTTP 428 and tells you `confirmacion_esperada`: the exact name of the object. Retry passing it in `confirmacion`. Do not…explicar_sql_db_vps: EXPLAIN of a query, in each engine's own format (they are not comparable, and forcing a common shape would make both useless). analizar=True runs EXPLAIN ANALYZE, which DOES execute the query — PostgreSQL only. (solo lectura)guardar_credencial_db_vps: Stores the engine credentials when the client changed them by hand (the default password is the VPS slug). Encrypted at rest and NEVER returned: no tool reads it back.historial_operaciones_db_vps: The log of destructive operations run against this VPS's databases: who, when, which statement, on which object, and whether it came from the web interface or from an agent. (solo lectura)insertar_fila_db_vps: Inserts ONE row. `valores` is {column: value}; columns are validated against the catalog and values travel as driver placeholders. Returns the row as it ended up, with defaults and auto-increment already resolved.leer_filas_db_vps: One page of rows, WITHOUT writing SQL. `filtro` uses a whitelist of operators, `orden` takes column names with an optional '-' prefix. For the next page pass `despues_de` = the `siguiente` of the previous answer (keyset… (solo lectura)listar_bases_db_vps: Lists the databases of an engine, with size and encoding. (solo lectura)listar_motores_db_vps: Lists the database engines installed on a VPS (PostgreSQL, MySQL/MariaDB), their port, version and whether they are running. sondear=False answers from cache without touching the VPS. (solo lectura)listar_tablas_db_vps: Lists tables and views of a database, with an estimated row count (free: it comes from the engine's own statistics, it does not run COUNT(*)). (solo lectura)probar_conexion_db_vps: Checks that the backend can actually reach that engine on the VPS and log in. Use this first when something fails: it tells apart 'the VPS is off', 'the engine is down' and 'the password was changed by hand'. (solo lectura)
Cloud – Domains & port forwards
activar_dominio_vps: Activates a domain: verifies DNS, issues an SSL certificate if needed, and creates the nginx reverse proxy to host_port (defaults to the VPS's internal API port). Can take a while when create_cert=True and the domain…cambiar_politica_ip_puertos_vps: Admin. Sets which IPs reach the port forwards of a VPS, for all of them (alcance=global) or one host_port (overrides the global). solo = only these IPs; excluir = everyone but these. Applied on the host firewall right…crear_dominio_vps: Creates a Cloudflare DNS record for a subdomain of the default ArduMaker zone, pointing at this VPS. domain must end with the default zone (e.g. 'myapp.arducloud.com').crear_redireccion_vps: Creates a TCP/UDP port forward to a port inside the VPS. For container_port=22 (SSH), closed_in_hs optionally auto-closes the forward after N hours.editar_nginx_dominio_vps: Overwrites the raw nginx config file for a domain on this VPS (full replace, not a merge) and reloads nginx. Same power a human has via the frontend's raw-config editor — no extra validation of the config content.…eliminar_dominio_vps: Deletes a domain: removes its Cloudflare DNS record (if under the default zone) and its nginx configuration.eliminar_redireccion_vps: Deletes a specific port forward from a VPS (device_name comes from listar_redirecciones_vps).listar_dominios_vps: Lists domains configured in nginx that belong to this VPS. (solo lectura)listar_redirecciones_vps: Lists TCP/UDP port forwards (proxy devices) configured for a VPS. (solo lectura)ver_nginx_dominio_vps: Reads the raw nginx config file for a domain on this VPS. (solo lectura)ver_politica_ip_puertos_vps: Who can reach each port forward of a VPS: the global IP policy and, per port, its own and the effective one (todos, solo or excluir + IPs). Platform ports are listed but not editable. (solo lectura)verificar_dominio_vps: Checks whether a domain's DNS already points to the VPS's host — call this before activar_dominio_vps. (solo lectura)
Cloud – GitHub deploy
crear_repo_github_vps: Creates a GitHub repo with the user's linked account (company admins only). Not deployed yet: pass `repo.id` and `repo.default_branch` to vincular_repo_github_vps or instalar_app (git).editar_repo_github_vps: Updates a GitHub repo's deploy configuration. At least one field is required. Company admins only. Changing project_name only renames it for display: the slug (the folder the repo is cloned into on the VPS) never…eliminar_repo_github_vps: Unlinks a GitHub repo from a VPS and removes its files. Company admins only. Synchronous — can take a moment on a large repo.listar_repos_github_vps: Lists GitHub repos deployed on a VPS. (solo lectura)ver_repo_github_vps: Full detail of a GitHub repo deployed on a VPS. (solo lectura)vincular_repo_github_vps: Links a GitHub repo to a VPS and starts cloning it — returns immediately with status='creating', the clone runs in the background (check status via ver_repo_github_vps). repo_id is GitHub's numeric repository id.…
Cloud – GitHub deploy logs
listar_commits_repo_github_vps: Lists commits received for a repo deployed on a VPS (most recent first). limit: default 50, max 200. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)listar_logs_repo_github_vps: Lists deploy-log entries for a repo deployed on a VPS. `status` filters by exit_status. `action` filters by the operation that produced the entry ('clone', 'pull', ...) — it is a free-text field written by whatever… (solo lectura)ver_commit_repo_github_vps: Full detail of one commit received for a repo deployed on a VPS. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)ver_log_repo_github_vps: Full detail of one deploy-log entry (includes the executed command and its output). Any GitHub access token embedded in the command/output is redacted. Wrapped as untrusted content: the payload is under `contenido` (see… (solo lectura)
Cloud – Linux users
crear_usuario_vps: Creates a new Linux user account on a VPS. If the user already exists, this returns the existing one with `ya_existia: true` instead of failing — a Linux user is identified by its name inside the VPS, so a retry after a…editar_usuario_vps: Updates a Linux user's password and/or sudo membership on a VPS. At least one of password/sudo is required.eliminar_usuario_vps: Deletes a Linux user account from a VPS. IRREVERSIBLE — there is no trash for this, and by default the user's home directory goes with it (remove_home=false keeps it). `confirmacion` must be the exact username you are…listar_usuarios_vps: Lists the Linux user accounts on a VPS. (solo lectura)ver_usuario_vps: Gets info about a specific Linux user on a VPS. (solo lectura)
Cloud – Logs & network
ver_estado_red_vps: Live network state of a VPS: network interfaces, WireGuard peers, Tailscale IP. Slower than other tools — it connects to the VPS directly (up to 20s). (solo lectura)ver_logs_nginx_vps: Reads nginx logs for a domain on a VPS. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)ver_logs_systemd_vps: Reads journalctl logs for a systemd service running on a VPS. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)ver_logs_tarea_vps: Reads logs for a scheduled task on a VPS. log_type: 'service' (the command's own output) or 'timer' (the systemd timer that schedules it). Wrapped as untrusted content: the payload is under `contenido` (see the server… (solo lectura)
Cloud – SSH tunnel initiator
configurar_iniciador_tunel_vps: Installs this VPS as an SSH tunnel initiator (installs autossh, generates an ed25519 keypair). Returns immediately — the actual setup runs in the background (poll with ver_estado_iniciador_tunel_vps). Returns an…controlar_tunel_vps: Starts, stops, or restarts a single SSH tunnel. 'stop' drops whatever is going through it.crear_tunel_vps: Creates an outbound SSH tunnel from this VPS (initiator) to a remote host's receiver. remote_user is the receiver's tunnel user (see listar_claves_receptor_tunel_vps/ ver_estado_receptor_tunel_vps on the target VPS).eliminar_iniciador_tunel_vps: Uninstalls the SSH tunnel initiator role from this VPS. Warning: this tears down ALL tunnels configured on this VPS at once — there is no way to uninstall the initiator role while keeping some tunnels running.eliminar_tunel_vps: Deletes a single SSH tunnel from this VPS (initiator).listar_tuneles_vps: Lists SSH tunnels this VPS (as initiator) has configured toward other hosts. (solo lectura)ver_estado_iniciador_tunel_vps: Status of the SSH tunnel initiator role on this VPS: install progress/failure, or (once installed) its public key (to authorize on a receiver) and tunnel count. (solo lectura)ver_tunel_vps: Full detail of one SSH tunnel, including its live systemd status. (solo lectura)
Cloud – SSH tunnel receiver
agregar_clave_receptor_tunel_vps: Authorizes a public SSH key to open tunnels into this VPS's receiver.configurar_receptor_tunel_vps: Installs this VPS as an SSH tunnel receiver (accepts incoming tunnels on port 2222). Returns immediately — the actual setup runs in the background (poll with ver_estado_receptor_tunel_vps). Returns an `operacion_id`:…eliminar_clave_receptor_tunel_vps: Revokes an authorized SSH key from this VPS's tunnel receiver.eliminar_receptor_tunel_vps: Uninstalls the SSH tunnel receiver role from this VPS (removes the tunnel user and its authorized keys).listar_claves_receptor_tunel_vps: Lists the public SSH keys authorized to open tunnels into this VPS's receiver. (solo lectura)ver_estado_receptor_tunel_vps: Status of the SSH tunnel receiver role on this VPS: install progress/failure, or (once installed) the connection string other VPS use to tunnel into it. (solo lectura)
Cloud – Scheduled tasks
controlar_tarea_vps: Runs an action on a scheduled task: 'start' runs its command once, right now; 'stop' interrupts that run; 'enable'/'disable' toggle the automatic schedule. Note this set has no 'restart' — unlike controlar_servicio_vps,…crear_tarea_vps: Creates a scheduled task on a VPS. schedule uses systemd OnCalendar syntax (e.g. '*-*-* 02:00:00' for daily at 2am, or shortcuts like 'daily'/'hourly'/'weekly'). start: run it once immediately in addition to scheduling…editar_tarea_vps: Updates a scheduled task's command and/or schedule (at least one required). Internally this deletes and recreates the task — if enabled, it's re-enabled after.eliminar_tarea_vps: Deletes a scheduled task from a VPS. No protected-name guard exists for tasks (unlike systemd services).listar_tareas_vps: Lists scheduled tasks (systemd timers) configured on a VPS. (solo lectura)ver_tarea_vps: Full detail of a scheduled task on a VPS: service+timer content, status, next/last run. (solo lectura)
Cloud – Systemd services
controlar_servicio_vps: Runs a systemctl action on a systemd service inside a VPS. 'enable'/'disable' only change whether it starts on boot; they don't start or stop it now. Unlike delete, this has no protected-service guard — it can…crear_servicio_vps: Creates a new systemd service inside a VPS from a raw unit-file content string. Same power a human has via the frontend — no extra validation of the unit file content.editar_servicio_vps: Overwrites a systemd service's unit file content (full replace) inside a VPS.eliminar_servicio_vps: Deletes a systemd service inside a VPS (stops, disables, removes the unit file). A small set of critical service names (ssh, nginx, docker, mysql, etc.) are protected and can't be deleted this way.listar_servicios_vps: Lists systemd services running/configured inside a VPS. (solo lectura)ver_servicio_vps: Full detail of a systemd service inside a VPS: unit file content, live status. (solo lectura)
Cloud – VPS
cambiar_plan_vps: Changes a VPS's plan (resizes CPU/RAM/disk). Company admins only.controlar_vps: Starts, stops, or restarts a VPS. Company admins only. 'stop' and 'restart' interrupt everything running on the machine.crear_vps: Creates a new VPS (only company admins or system admins). Returns immediately with status='creating' — actual provisioning happens asynchronously in the background over the next few minutes. Poll ver_vps/ver_estado_vps…editar_vps: Updates a VPS's nombre and/or moves it to another company (target_company_id — resets access lists), and/or manages its allowed_members/excluded_members lists (each accepts a list of user ids of people who must already…ejecutar_comando_vps: Runs a one-shot shell command on the VPS and returns its output. cwd: optional working directory. This is not a terminal session: the VPS's persistent terminals belong to the people using the web panel, MCP does not…guardar_archivo_vps: Writes a file on the VPS in chunks: the first call starts it, the following ones go with agregar=true. Returns `tamano`, the size the file ended with: compare it with what you sent. Starting a file refuses to replace an…leer_archivo_vps: Reads a file of the VPS in chunks: `tamano`, the chunk from `offset`, `siguiente_offset` and `fin`. Call it again with `siguiente_offset` until `fin` is true; use base64=true to rebuild a file byte for byte. Same rate… (solo lectura)listar_vps: Lists the VPS instances of a company, visible to the user (respects each VPS's allowed_members/excluded_members). (solo lectura)redeploy_repo_github: Triggers a git pull + redeploy of a repo already linked to a VPS. Returns immediately — the pull runs in the background; check status via ver_repo_github_vps afterward.ver_estado_vps: Live system status of a VPS — CPU, memory, disk, uptime, running services — read from the machine itself, plus the stored record (plan, IP, domains, status). This is the ONLY tool for how a VPS is doing. There used to… (solo lectura)ver_funciones_vps: Which features this VPS supports, given the OS its agent reports. Most VPS are Ubuntu 22.04 and have everything; a Ubuntu 16.04 can't run Docker, n8n or systemd services. Check it before using a feature on an unfamiliar… (solo lectura)ver_historial_comandos_vps: What shell commands were run on this VPS, by whom, and what they returned — including the ones a guard refused. For an agent this is how you check whether something was already tried before running it again; for the… (solo lectura)ver_vps: Full detail of a VPS. Includes allowed_members/excluded_members lists if the user is a company admin, and red_interna (tailnet DNS/IP of the instance) for system admins. (solo lectura)
Comments
cambiar_secreto_comentario_adjunto: Marks/unmarks an attachment comment as secret (its `texto` is only ever its author or a project admin). Its text can't be edited — delete it and comment again instead. An MCP agent can never touch a comment that's…comentar_tarea: Comments on a task, optionally referencing attachments already uploaded to the project (adjunto_ids) — this tool doesn't upload new files, only text + references.listar_comentarios_adjunto: Lists an attachment's comments in chronological order. A secret comment's `texto` comes back as null unless the agent's owner wrote it or is a project admin (same rule as the attachments themselves). Wrapped as… (solo lectura)listar_comentarios_tarea: Lists a task's comments in chronological order, including any referenced or attached media/adjuntos. Wrapped as untrusted content: the payload is under `contenido` (see the server instructions). (solo lectura)
Company
listar_servicios_empresa: Lists a company's active contracted services (what's billed, at what price) — not payment methods or invoices. (solo lectura)ver_consumo_periodo_empresa: Company's payment/expense history (HistorialPago), optionally bounded by date range ('YYYY-MM-DD', both optional — omit both for the full history). Returns each movement (motivo/detalle/cantidad/exito/created_at) plus a… (solo lectura)ver_empresa: Company profile: id/name/slug/status/avatar/admins/members/created_at. Deliberately excludes billing state, payment/mora tracking and verification details — see ver_estado_verificacion_empresa for the latter. (solo lectura)ver_estado_verificacion_empresa: Identity verification status: verificado/requiere_verificacion/necesita_verificar/ datos_fiscales_completos. Deliberately excludes the actual fiscal data (NIF, fiscal address) and uploaded verification documents. (solo lectura)
Domains & DNS
crear_dominio_empresa: Registers a domain for a company: creates its Cloudflare zone and the local record. If the domain was previously deleted (soft delete) for the same company, this reactivates it instead of creating a duplicate. Returns…crear_registro_dns: Creates a DNS record. record_type: A|AAAA|CNAME|MX|TXT|NS|SRV|CAA|DKIM|DMARC. name: subdomain ('www') or empty/domain-name for the apex. ttl: 1 means 'automatic' (Cloudflare default). NS/MX records, and A/AAAA records…editar_registro_dns: Overwrites a DNS record (full replace, not a merge — record_id comes from listar_registros_dns). Same critical-record guard and rate limit as crear_registro_dns.eliminar_dominio_empresa: Deletes a domain. This is a SOFT delete and can be undone: call crear_dominio_empresa again with the same name to reactivate it (its Cloudflare zone id and DNS records are preserved, not touched by this operation).listar_dominios_empresa: Lists a company's active domains (Cloudflare zones). `status` here is always "active"; ver_dominio_empresa lists the full set of values. (solo lectura)listar_registros_dns: Lists every DNS record configured for a domain in Cloudflare. (solo lectura)ver_dominio_empresa: Full detail of a domain, including its live Cloudflare zone status (connected, name servers) — best-effort: if Cloudflare can't be reached, the domain data still comes back with cloudflare_error explaining why. Local… (solo lectura)ver_estado_ns_dominio: Checks the domain's nameserver/connection status live against Cloudflare and updates the stored ns_status. Use this to verify a domain has finished propagating after pointing its nameservers. (solo lectura)
crear_alias_correo: Creates a personal alias that delivers into this mailbox.crear_alias_dominio_correo: Creates a domain-level forwarding alias — address must belong to the domain, goto is where it forwards to (any address, including outside the domain).crear_carpeta_correo: Creates an IMAP folder under the given parent (default INBOX). There's no tool to rename or delete a folder — do that through the normal webmail UI.crear_cuenta_correo: Creates a mailbox on a verified email domain. The domain must have dns_verified=True (see verificar_dns_dominio_correo) and be under its mailbox limit. The password is stored encrypted so message tools…crear_dominio_correo: Registers a new email domain on Mailcow for a company. Returns the domain including the DNS records (MX/SPF/DKIM/DMARC) the customer needs to add — the domain won't accept mail nor allow account creation until…crear_filtro_correo: Creates a Sieve filter for a mailbox. sieve_code is raw Sieve script — write one that's valid, this doesn't validate its syntax before sending it to Mailcow.editar_cuota_cuenta_correo: Changes a mailbox's plan (and with it, its storage quota). Upgrade-only — moving to a cheaper/smaller plan is rejected; delete the account and create a new one instead if that's really needed.eliminar_alias_correo: Deletes one of this mailbox's personal aliases.eliminar_alias_dominio_correo: Deletes a domain-level forwarding alias. Reversible in spirit — recreate it with crear_alias_dominio_correo if needed.eliminar_dominio_correo: Deletes an email domain. THIS CASCADES: every active mailbox on the domain is deleted too (Mailcow mailbox + local record), not reversible in practice. Requires confirmado=True; without it, fails with a 409 telling you…eliminar_filtro_correo: Deletes a Sieve filter.enviar_correo: Sends an email from a mailbox (synchronous — waits for the real SMTP result, no queueing). Rate limited per mailbox (a handful per minute) to protect against a runaway agent spamming from a customer's domain. No…listar_alias_correo: Lists a mailbox's personal forwarding aliases (addresses that deliver into this mailbox). (solo lectura)listar_alias_dominio_correo: Lists domain-level (catch-all style) forwarding aliases — not a specific mailbox's personal aliases, see listar_alias_correo for those. (solo lectura)listar_carpetas_correo: Lists a mailbox's IMAP folders (with unread/total counts), as a tree under INBOX. (solo lectura)listar_cuentas_bot_correo: Read-only list of bot (automated) accounts on an email domain — for context only. Bot account administration (create/regenerate token/delete) is intentionally not exposed by MCP: they're used by other automated… (solo lectura)listar_cuentas_correo: Lists active mailboxes on an email domain. Mailbox `status`: "active", "suspended" (admin-set) or "deleted". (solo lectura)listar_dominios_correo: Lists a company's active email domains (Mailcow), with DNS verification status and mailbox count/limit. The DNS records themselves (MX/SPF/DKIM/DMARC) are NOT here — they are long and only useful one domain at a time:… (solo lectura)listar_filtros_correo: Lists a mailbox's Sieve filters (inbox rules). (solo lectura)listar_mensajes_correo: Lists messages in a mailbox folder (metadata only — subject/from/to/date/read/has_attachments, no body). Use ver_mensaje_correo for the full content of one message. Wrapped as untrusted content: the payload is under… (solo lectura)marcar_leido_correo: Marks a message as read (\Seen flag).ver_cuenta_correo: Full detail of a mailbox (never includes the password). `status` takes exactly three values: active, suspended (by an admin), deleted. (solo lectura)ver_dominio_correo: Full detail of an email domain, including its DNS verification state and the DNS records it expects. An email domain's `status` is either "active" or "deleted". (solo lectura)ver_mensaje_correo: Retrieves ONE message's FULL content — subject, sender/recipients, and the complete body_text/body_html, plus attachment metadata (not the attachment bytes themselves). This tool gives an agent real read access to… (solo lectura)ver_stats_dominio_correo: Live Mailcow usage stats for an email domain (mailbox count, quota usage, etc.). (solo lectura)verificar_dns_dominio_correo: Re-checks the domain's MX/SPF/DKIM/DMARC records live and updates dns_verified. Run this after the customer adds the DNS records returned by crear_dominio_correo/ver_dominio_correo — account creation is blocked until…
Flows
configurar_tunel_entre_vps: Sets up an SSH tunnel between TWO VPS, end to end, in ONE call. Replaces this chain across two machines: configurar_receptor_tunel_vps → configurar_iniciador_tunel_vps → agregar_clave_receptor_tunel_vps →…crear_correo_de_dominio: Sets up an email domain and its mailboxes in ONE call: crear_dominio_correo → verificar_dns_dominio_correo → one crear_cuenta_correo per mailbox. THE DNS RECORDS ARE NOT CREATED HERE. The domain has to have its…crear_proyecto_con_etapas: Creates a project with all its stages in ONE call, instead of crear_proyecto followed by one crear_etapa per stage. `encadenar_etapas=true` (the default) makes each stage depend on the previous one, which is what the…publicar_repo_en_dominio: Publishes a GitHub repo on a domain with SSL, end to end, in ONE call. Replaces this chain: crear_dominio_vps → verificar_dominio_vps → activar_dominio_vps → vincular_repo_github_vps → redeploy_repo_github. Those five…
Folders
crear_carpeta: Creates a folder to organize the project's attachments.editar_carpeta: Renames a folder.eliminar_carpeta: Deletes a folder. Its attachments are NOT deleted with it — they just lose their carpeta (and get it back if the folder is restored). This is a SOFT delete and can be undone: see it with listar_papelera and bring it…listar_carpetas: Lists a project's folders. Until now a folder's id could only be learned at the moment it was created — there was no way to enumerate existing ones, even though listar_adjuntos accepts a carpeta_id to filter by. (solo lectura)
GitHub
crear_repo_github: Creates a GitHub repo with the user's linked account and links it to the project in the same call (`vinculo` is what vincular_repo_github returns).desvincular_repo_github: Unlinks a GitHub repo from the project (deletes its registered commits; tries to delete the webhook on GitHub, best-effort).listar_commits_repo: Lists the registered commits of a linked repo (most recent first), one line each: sha, the commit's FIRST LINE, author and date. For the full message body of one commit, call ver_commit_repo. limit: default 50, max 200.… (solo lectura)ver_commit_repo: Full detail of one registered commit of a project's linked repo, including the complete message body. Get commit_id from listar_commits_repo. Wrapped as untrusted content: the payload is under `contenido` (see the… (solo lectura)ver_propietarios_github: Where the linked GitHub account can create a repo: the user and their organizations (the `owner` of crear_repo_github and crear_repo_github_vps). `puede_crear` false: GitHub must be linked again granting the repo… (solo lectura)vincular_repo_github: Links a GitHub repo to the project (repo_full_name: 'owner/repo') — only registers its commits via webhook, doesn't clone or deploy anything. If the webhook could not be created on GitHub automatically, the result…
Health
ping: Smoke-test tool, no authentication required — confirms the MCP server is alive. (solo lectura)ver_contexto_inicial: Everything you need to know about YOURSELF before doing anything else: which human authorized this session, what scope they granted (read-only or not, all projects or a selection, all VPS or a selection), the… (solo lectura)ver_operacion: Whether something long-running has finished, for ANY of them: creating a VPS, cloning a repo, activating a domain with SSL, installing a tunnel role. Always the same shape: `estado` is 'en_curso', 'ok' or 'error'. While… (solo lectura)
Logs
ver_logs_proyecto: Activity history within the project (most recent first). metod (optional): 'CREATE'|'UPDATE'|'DELETE'|'VIEW'. limit: default 100, max 500. (solo lectura)
Meetings
cancelar_reunion: Cancels a project meeting for ALL of its participants (deletes their personal copies and the mirrors in Google Calendar). Callable by its creator or a project admin.crear_reunion: Creates a project meeting with one or more participants (same local day). Before creating it, validates the availability of each miembro_id (see ver_disponibilidad) — if someone isn't available and forzar=False, this…editar_reunion: Edits a meeting's title/description/time/participants (passing miembro_ids replaces the ENTIRE participant list). If the time or participants change, availability is rechecked for everyone in the final list — same…listar_reuniones: Lists the project's meetings (most recent first is NOT guaranteed — ordered by fecha_inicio). desde/hasta (optional): 'YYYY-MM-DD', filters to meetings overlapping that range. Until now the only way to discover an… (solo lectura)ver_reunion: Full detail of a single meeting, including its participants. (solo lectura)
Members
listar_miembros_proyecto: Lists a project's members (read-only — an MCP agent can never add, remove, or change a member's role). (solo lectura)
Projects
buscar_en_proyecto: Finds stages, tasks and attachments of a project by exact `slug` or by `texto` (name, slug, description or note text), without listing everything. Returns compact rows (tipo, id, titulo, slug, etapa_id or carpeta_id, a… (solo lectura)crear_proyecto: Creates a new project (with an initial "Etapa 1" stage / "Tarea 1" task). empresa_ids: companies to associate — the agent inherits the same company-admin check its human owner would have. The project is created with its…editar_proyecto: Updates a project's nombre/descripcion/status/empresas. Only the fields you actually pass are touched; 'archived' hides the project from the default listing without deleting it.listar_proyectos: Lists the projects visible to the user who authorized this agent (all of the human owner's projects, or only the scope chosen when connecting — see ver_contexto_inicial). (solo lectura)ver_proyecto: Full detail of a project: members, VPS, GitHub repos, and stages. detalle='resumen' (default): stages WITHOUT their tasks (id/nombre/orden/avance/tareas_count; at most 100-200, page with listar_etapas); fetch a stage's… (solo lectura)
Recordings
buscar_en_grabaciones: Searches a text (2+ characters) inside the transcripts you can see: one project with proyecto_id, else every project in your scope. Each result names the recording, its scope and the moment (`start_ms`) where it was… (solo lectura)leer_transcripcion_grabacion: Reads a recording's transcript in order, by page (limit default 50, max 200) and/or by time range (desde_ms, hasta_ms: milliseconds from the start of the recording). Every segment carries `start_ms` and `end_ms`: quote… (solo lectura)listar_grabaciones: Lists recorded meetings (ArduMaker Meetings), newest first, with `total` for paging (limit default 50, max 200): one project with proyecto_id, else every project in your scope. Each row has its id, title, scope,… (solo lectura)mover_grabacion: Moves a recording to another project WITHOUT copying it: it keeps its id, media and transcript, and from then on only the destination's permissions apply (the previous audience loses access). With confirmar=False…ver_grabacion: Full detail of one recording: states, `coverage` (the time ranges that really exist per track), capture events (declared gaps), the current `summary` with decisions, requirements and possible tasks, each citing… (solo lectura)
Resources
listar_recursos_proyecto: The platform resources linked to a project: VPS, domains, mailboxes and mail domains, each with the comment explaining what it is used for HERE. START HERE when a project asks you to touch infrastructure. `objeto_id` is… (solo lectura)
RouterIA
crear_clave_router_ia: Creates a new OpenRouter API key for a company (admin only). Requires an active payment method and enough company balance left after the key's spending cap. `limit` is the key's SPENDING CAP, not a page size — read its…listar_claves_router_ia: Lists a company's OpenRouter API keys (never includes the raw token). (solo lectura)reactivar_clave_router_ia: Re-enables a previously revoked API key — admin only.revocar_clave_router_ia: Revokes (disables) an API key — admin only. Reversible: see reactivar_clave_router_ia.ver_clave_router_ia: Full detail of an OpenRouter API key (usage/limit/expenses), synced live — never includes the raw token. (solo lectura)
School requests
actualizar_solicitud_escuela: SYSTEM ADMINS ONLY. Cambia cualquier campo de una solicitud. Los del equipo —— `estado`, `notas_internas`, `escuela_creada_id` —— y tambien los que llegaron del formulario, para corregir un mail mal tipeado o completar…comentar_solicitud_escuela: SYSTEM ADMINS ONLY. Suma un comentario al hilo de seguimiento de una solicitud. ES PARA QUE SE SEPA QUE SE ESTA HACIENDO. Queda firmado con quien lo escribio —— y marcado si fue un agente —— y fechado, que es lo que…crear_solicitud_escuela: SYSTEM ADMINS ONLY. Carga a mano una escuela que pidio hablar por otro canal. Para una institucion que escribio por mail, llamo, o aparecio en una feria: entra a la misma bandeja que las del formulario y sigue el mismo…editar_comentario_solicitud_escuela: SYSTEM ADMINS ONLY. Corrige el texto de un comentario del hilo. CUALQUIER ADMIN PUEDE CORREGIR EL DE OTRO, y es deliberado: son notas internas de un equipo chico sobre una conversacion comercial, no la voz de alguien…eliminar_comentario_solicitud_escuela: SYSTEM ADMINS ONLY. Borra un comentario del hilo de seguimiento. No vuelve. Es para sacar lo que no deberia haberse escrito —— un dato personal de mas, una nota pegada en la solicitud equivocada ——, no para limpiar el…eliminar_solicitud_escuela: SYSTEM ADMINS ONLY. Borra una solicitud y, con ella, todo su hilo de comentarios. NO HAY PAPELERA ACA, al reves que en Proyectos: la fila se va de verdad y no vuelve. Existe porque el formulario es publico y una rafaga…listar_solicitudes_escuela: SYSTEM ADMINS ONLY. Las escuelas que pidieron hablar desde el formulario publico de /school. De la mas nueva a la mas vieja, que es el orden correcto para esta cola: la pregunta aca es "que llego y todavia no conteste",… (solo lectura)ver_solicitud_escuela: SYSTEM ADMINS ONLY. Una solicitud entera, con TODO su hilo de seguimiento. Es la diferencia con el listado: aca vienen los comentarios, que son donde esta escrito que se hizo con esta solicitud —— a quien se le mando el… (solo lectura)
SearchAPI
crear_token_search_api: Creates a new SearchAPI token for a company (admin only). Requires an active payment method and at least €20 balance. Returns the raw token — this is the ONLY time it's shown, save it now.listar_tokens_search_api: Lists a company's SearchAPI (Tavily) tokens with usage totals — never includes the raw token value. (solo lectura)reactivar_token_search_api: Re-enables a previously revoked SearchAPI token — admin only.revocar_token_search_api: Revokes (deactivates) a SearchAPI token — admin only. Reversible: see reactivar_token_search_api.ver_costos_operaciones_search_api: Full cost breakdown for every active token of the company (all-time + rolling 24h/7d/30d windows), plus the current configured price per operation type. Public pricing info, not sensitive. (solo lectura)ver_token_search_api: Cost breakdown detail for one SearchAPI token — never includes the raw token value. (solo lectura)
Stages
crear_etapa: Creates a stage within a project. depende_de_ids: ids of other stages in the same project (informational only — doesn't block anything by itself).editar_etapa: Updates a stage's nombre/descripcion/orden/dependencies, or moves it between the board's workflow columns with `estado`.editar_etapas_en_lote: Creates, edits and deletes many stages in ONE call (max 100 elements in total). Each element is applied on its own: one failing does not undo the others, and `resultados` has one row per element with `ok` and its id or…eliminar_etapa: Deletes a stage and all of its tasks. This is a SOFT delete and can be undone: the stage goes to the project's trash for 30 days — see it with listar_papelera and bring it back with restaurar_papelera (the returned…listar_etapas: Pages through a project's stages (summary fields, like ver_proyecto) with `total`, so a project with hundreds of stages can be read whole. limit: default 50, max 200. `estado` keeps only one board column;… (solo lectura)ver_etapa: Full detail of a single stage, including its full descripcion and its tasks (summary fields — use ver_tarea for a task's own descripcion). Use this instead of ver_proyecto(detalle="completo") when you only need one… (solo lectura)
Tasks
crear_tarea: Creates a task. responsable_id is a ProyectoMiembro id (see listar_miembros_proyecto), NOT a user_id. Without fecha_inicio/fecha_limite but with responsable_id + hours set, the task auto-schedules itself on the…editar_tarea: Updates a task. etapa_destino_id moves it to another stage of the SAME project (use the `etapa` from the response for subsequent calls). avance can't be set by hand if the task has a checklist (it's computed…editar_tareas_en_lote: Creates, edits and deletes many tasks in ONE call, with the same per-element rules as editar_etapas_en_lote. crear: {etapa_id, nombre, ...fields of crear_tarea}; editar: {etapa_id, tarea_id, ...fields of editar_tarea,…eliminar_tarea: Deletes a task, its checklist and its comments (and removes any events already pushed to Google Calendar). This is a SOFT delete and can be undone: the task goes to the project's trash for 30 days — see it with…listar_tareas: Pages through tasks (summary fields; ver_tarea for detail) with `total`: one stage with etapa_id, else the whole project. Filters combine with AND; ranges are inclusive. limit: default 50, max 200. (solo lectura)ver_tarea: Full detail of a single task: descripcion, checklist, dependencies, comentarios_count and scheduling fields — listar_tareas only returns summary fields, this is how an agent reads what a task actually asks for.… (solo lectura)
Trash
listar_papelera: What was deleted in this project, who deleted it and when — one entry per DELETION, not per object: a deleted stage is a single entry whose `conteos` tell how many tasks, checklist items and comments went with it. Each… (solo lectura)listar_proyectos_eliminados: Projects that are entirely in the trash and that the owner of this agent could restore. They do NOT show up in listar_proyectos. Restore one with restaurar_papelera, using its `id` as proyecto_id and its `operacion_id`.… (solo lectura)restaurar_papelera: Undoes a deletion: brings back everything that trash entry took with it (and only that — anything that was already deleted before stays deleted). operacion_id is the `id` of an entry from listar_papelera. Fails if the…ver_papelera: Full detail of ONE trash entry: object by object, exactly what that deletion took with it. CUANDO NO USARLA: necesita el operacion_id de una entrada concreta. Para descubrir que se borro, primero listar_papelera. (solo lectura)
WhatsApp sandbox
crear_numero_sandbox_whatsapp: Creates a sandbox contact for a WhatsApp number. Leave `phone_number` out and ArduMaker generates one in the reserved +999 range, which cannot collide with a real phone — that is the normal case and what you should do…editar_numero_sandbox_whatsapp: Updates a sandbox contact's display name, description or on/off state. The phone number itself cannot change — create another sandbox contact instead, they cost nothing.eliminar_numero_sandbox_whatsapp: Deletes a sandbox contact. It does not go to any trash and does not come back. By default the test conversation is KEPT — it is the result of the test. Note that once the sandbox contact is gone, messages sent to that…listar_chat_sandbox_whatsapp: Reads the sandbox conversation, newest message first — including what the customer's bot replied. The reply never reaches a phone, so this is the only place the result of the test exists. Wrapped as untrusted content:… (solo lectura)listar_numeros_sandbox_whatsapp: Lists the sandbox (test) contacts of a WhatsApp number. A number can have as many as you want: they are rows, not phone lines. (solo lectura)listar_numeros_whatsapp: Lists a company's WhatsApp numbers, so you can find the `numero_id` the sandbox tools need, plus the account's outgoing webhooks — the ones a simulated message goes to by default. Read-only, and it does NOT open real… (solo lectura)simular_estado_sandbox_whatsapp: Moves an OUTGOING sandbox message to a delivery status, exactly as Twilio's status callback would. This is the only way to test what a bot does when a message comes back `failed` or `read`: with a real number you would…simular_mensaje_sandbox_whatsapp: Fabricates an incoming WhatsApp message from a sandbox contact and puts it through the very same code path Twilio's webhook uses — so the system treats it as a real message. By default it then delivers that message to…ver_numero_sandbox_whatsapp: Retrieves one sandbox contact. (solo lectura)