Tools and routes
Everything this door offers: each tool with its title, whether it reads or writes, who may call it, whether it reads a project you name, and how it fails; each route with who may call it.
One MCP address
Every organization is reached at the same address. Add it to your AI client as a remote MCP server; the client opens sharingu's sign-in (OAuth) and you sign in with your email and passphrase. No header and no key go in the client's configuration.
https://agent.sharingu.xyz/mcp35 tools (18 read, 17 write) and 87 routes, listed below from the door's own inventory.
35 tools
Each tool carries its title and the four MCP annotations. A tool that reads a project takes the project you name, checked against your seats on every call.
| Tool | Title | Kind | Who may call it | Reads a named project | Annotations | How it fails |
|---|---|---|---|---|---|---|
ask | Ask the owner | write | anyone signed in, with a key or grant that may write | no | not destructive · closed world | not-authenticated, not-allowed |
brief | Brief | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
broadcast | Broadcast | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
build | Build | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
changes | What changed | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
create_project | Create a project | write | the owner, with a key or grant that may write | no | destructive · idempotent · closed world | not-authenticated, not-allowed |
decide_contribution | Decide a contribution | write | the owner, with a key or grant that may write | no | destructive · idempotent · closed world | not-authenticated, not-allowed |
decisions | Decisions | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
equip | Equip from Broadcast | write | anyone signed in, with a key or grant that may write | no | destructive · idempotent · closed world | not-authenticated, not-allowed |
file | File | write | anyone signed in, with a key or grant that may write | no | destructive · idempotent · closed world | not-authenticated, not-allowed |
formats | Formats | read | anyone signed in | no | read-only · idempotent · closed world | not-authenticated |
goals | Goals | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
gtm | GTM | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
home | Home | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
impact | Impact | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
map | Map | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
missing | What is missing | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
open_items | Open items | write | anyone signed in, with a key or grant that may write | no | destructive · closed world | not-authenticated, not-allowed |
pick_up | Pick up | write | anyone signed in, with a key or grant that may write | no | destructive · idempotent · closed world | not-authenticated, not-allowed |
preview | Preview a filing | write | anyone signed in | yes | not destructive · closed world | not-authenticated, not-allowed |
publish | Publish to Broadcast | write | anyone signed in, with a key or grant that may write | no | not destructive · idempotent · closed world | not-authenticated, not-allowed |
publish_version | Publish a version | write | the owner, with a key or grant that may write | yes | not destructive · closed world | not-authenticated, not-allowed |
read | Read | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
read_file | Read a file | read | anyone signed in | no | read-only · idempotent · closed world | not-authenticated |
regrade | Regrade from the pages | write | anyone signed in, with a key or grant that may write | yes | not destructive · closed world | not-authenticated, not-allowed |
respond | Answer a question | write | anyone signed in, with a key or grant that may write | yes | destructive · closed world | not-authenticated, not-allowed |
restore_version | Restore a version | write | the owner, with a key or grant that may write | yes | destructive · idempotent · closed world | not-authenticated, not-allowed |
rule_question | Rule a question | write | the owner, with a key or grant that may write | yes | destructive · closed world | not-authenticated, not-allowed |
save_file | Save a file | write | anyone signed in, with a key or grant that may write | no | not destructive · closed world | not-authenticated, not-allowed |
search | Search | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
submit_grade | Grade a check | write | anyone signed in, with a key or grant that may write | yes | not destructive · closed world | not-authenticated, not-allowed |
updates | What changed for you | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
versions | Versions | read | anyone signed in | yes | read-only · idempotent · closed world | not-authenticated, not-allowed |
whoami | Who am I | read | anyone signed in | no | read-only · idempotent · closed world | not-authenticated |
wrap_up | Wrap up a session | write | anyone signed in, with a key or grant that may write | no | not destructive · open world | not-authenticated, not-allowed |
87 routes
The same door over HTTP, each route with who may call it.
| Route | Kind | Who may call it | How it fails |
|---|---|---|---|
POST /artifact | write | anyone signed in (a key or a session) | not-authenticated |
GET /artifact/:id | read | anyone signed in (a key or a session) | not-authenticated |
GET /artifacts | read | anyone signed in (a key or a session) | not-authenticated |
POST /ask | write | anyone signed in (a key or a session) | not-authenticated |
GET /audit | read | anyone signed in (a key or a session) | not-authenticated |
POST /backfill | write | the owner | not-authenticated, not-allowed |
POST /backup-dump | write | the owner | not-authenticated, not-allowed |
GET /brief | read | anyone signed in (a key or a session) | not-authenticated |
GET /broadcast | read | anyone signed in (a key or a session) | not-authenticated |
POST /broadcast/equip | write | anyone signed in (a key or a session) | not-authenticated |
GET /broadcast/live | read | anyone signed in (a key or a session) | not-authenticated |
POST /broadcast/publish | write | anyone signed in (a key or a session) | not-authenticated |
GET /broadcast/starter/:slug | read | anyone signed in (a key or a session) | not-authenticated |
GET /build | read | anyone signed in (a key or a session) | not-authenticated |
GET /canvas.json | read | anyone signed in (a key or a session) | not-authenticated |
GET /capabilities | read | anyone signed in (a key or a session) | not-authenticated |
GET /changes | read | anyone signed in (a key or a session) | not-authenticated |
GET /contract | read | anyone signed in (a key or a session) | not-authenticated |
GET /contribution/:id | read | anyone signed in (a key or a session) | not-authenticated |
POST /contribution/:id/decide | write | the owner | not-authenticated, not-allowed |
GET /contribution/:id/impact | read | anyone signed in (a key or a session) | not-authenticated |
POST /contribution/:id/pick-up | write | anyone signed in (a key or a session) | not-authenticated |
GET /control | read | anyone signed in (a key or a session) | not-authenticated |
POST /control | write | the owner | not-authenticated, not-allowed |
GET /control/measures | read | the owner | not-authenticated, not-allowed |
GET /control/people | read | anyone signed in (a key or a session) | not-authenticated |
GET /decisions | read | anyone signed in (a key or a session) | not-authenticated |
GET /doc/:path | read | anyone signed in (a key or a session) | not-authenticated |
GET /docs | read | anyone | |
GET /favicon.svg | read | anyone | |
POST /file | write | anyone signed in (a key or a session) | not-authenticated |
GET /fonts/:file | read | anyone | |
GET /formats | read | anyone signed in (a key or a session) | not-authenticated |
GET /goals | read | anyone signed in (a key or a session) | not-authenticated |
GET /goals/:ref | read | anyone signed in (a key or a session) | not-authenticated |
POST /grade | write | anyone signed in (a key or a session) | not-authenticated |
GET /gtm | read | anyone signed in (a key or a session) | not-authenticated |
GET /health | read | anyone | |
GET /home | read | anyone signed in (a key or a session) | not-authenticated |
GET /home/summary | read | anyone signed in (a key or a session) | not-authenticated |
GET /impact | read | anyone signed in (a key or a session) | not-authenticated |
GET /install | read | anyone | |
GET /library | read | anyone signed in (a key or a session) | not-authenticated |
GET /log | read | the owner | not-authenticated, not-allowed |
GET /login | read | anyone | |
POST /login | write | anyone | |
GET /logout | read | anyone | |
GET /map | read | anyone signed in (a key or a session) | not-authenticated |
GET /map/:plane | read | anyone signed in (a key or a session) | not-authenticated |
GET /map/lights | read | anyone signed in (a key or a session) | not-authenticated |
GET /map/node | read | anyone signed in (a key or a session) | not-authenticated |
GET /map/screens | read | anyone signed in (a key or a session) | not-authenticated |
POST /mcp | write | anyone signed in (a key or a session) | not-authenticated |
GET /missing | read | anyone | |
POST /open-items | write | anyone signed in (a key or a session) | not-authenticated |
GET /orgs | read | anyone signed in (a key or a session) | not-authenticated |
POST /orgs | write | anyone | |
GET /orgs/new | read | anyone | |
POST /orgs/seat | write | a signed-in browser | not-authenticated, not-allowed |
POST /preview | write | anyone signed in (a key or a session) | not-authenticated |
GET /preview/:id | read | anyone signed in (a key or a session) | not-authenticated |
GET /profile | read | anyone signed in (a key or a session) | not-authenticated |
POST /profile | write | anyone signed in (a key or a session) | not-authenticated |
POST /project | write | anyone signed in (a key or a session) | not-authenticated |
GET /projects | read | anyone signed in (a key or a session) | not-authenticated |
GET /question/:qid | read | anyone signed in (a key or a session) | not-authenticated |
POST /questions/:qid/rule | write | the owner | not-authenticated, not-allowed |
POST /rank | write | anyone signed in (a key or a session) | not-authenticated |
GET /read | read | anyone signed in (a key or a session) | not-authenticated |
POST /regrade | write | anyone signed in (a key or a session) | not-authenticated |
GET /render/:hash | read | anyone signed in (a key or a session) | not-authenticated |
POST /render/restore | write | anyone signed in (a key or a session) | not-authenticated |
POST /respond | write | anyone signed in (a key or a session) | not-authenticated |
POST /round | write | anyone signed in (a key or a session) | not-authenticated |
GET /search | read | anyone signed in (a key or a session) | not-authenticated |
POST /signout | write | anyone signed in (a key or a session) | not-authenticated |
GET /signup | read | anyone | |
POST /signup | write | anyone | |
GET /storage | read | the owner | not-authenticated, not-allowed |
GET /updates | read | anyone signed in (a key or a session) | not-authenticated |
GET /versions | read | anyone signed in (a key or a session) | not-authenticated |
GET /versions/:v | read | anyone signed in (a key or a session) | not-authenticated |
POST /versions/publish | write | the owner | not-authenticated, not-allowed |
POST /versions/restore | write | the owner | not-authenticated, not-allowed |
GET /view | read | anyone signed in (a key or a session) | not-authenticated |
GET /whoami | read | anyone signed in (a key or a session) | not-authenticated |
POST /wrap-up | write | anyone signed in (a key or a session) | not-authenticated |
3 failure classes
not-authenticated- No valid credential reached this door — no session cookie, and no valid Authorization: Bearer token resolved to a person (a key in the address signs no one in). Next: Authenticate — sign in, send a valid bearer token, or a valid reader key — then retry the exact same call.
not-allowed- The caller authenticated fine, but its role, scope, or ownership may not do this specific thing (an owner-only door, a read-only OAuth grant on a write tool, a credential that doesn't own the resource). Next: Do not retry unchanged — this is a role/scope/ownership gate, not a transient failure. Use a credential that holds the right role or scope, or ask its holder.
not-found- The door authenticated the caller fine, but the id/ref/key asked for does not exist, or isn't visible to this caller. Next: Check the id/ref for a typo or staleness; do not retry the exact same call unchanged.
Support
Email [email protected], or see the support page. Never send a passphrase, key or one-time code.
How sharingu handles your organization's data: the privacy notice.