Skip to main content
POST

Authorizations

Authorization
string
header
required

Flowyte secret API key (Authorization: Bearer flowyte_sk_live_…). Scope-gated; is scoped to your organization — a key can never reach another tenant. The listed scopes in each operation's apiKey requirement are the scopes that key must hold. The tokenUrl is nominal: keys are minted in the dashboard.

Path Parameters

agentId
string
required

The agent this resource is scoped to (the UUID returned by createAgent / listAgents).

kind
enum<string>
required

The integration provider (connector). One of the supported connector slugs: native providers (google_calendar, google_sheets, calendly, hubspot, ``, square, opentable, shopify), SQL databases (postgres, mysql), the universal Zapier MCP fallback (zapier), or Composio (composio).

Available options:
google_calendar,
google_sheets,
calendly,
hubspot,
square,
opentable,
shopify,
postgres,
mysql,
zapier,
composio

Body

application/json
toolName
string
required

The LLM-facing tool/function name.

operation
string
required

The provider operation to bind (a read e.g. clients

description
string

The LLM-facing tool description.

isWrite
boolean

Bind a MUTATION. Gated (confirm + non-parallel; verified-identity for update/delete); the skill lands DISABLED for review.

enabled
boolean

Start enabled (reads only; a write always lands disabled).

inputs
object[]

READ: LLM param → provider operation argument.

inputObjectMap
object[]

WRITE: map a caller param OR an operator-pinned constant onto a field of the mutation's input object. Every required input field must be bound-or-const; sensitive PII classes are rejected.

projection
object[]

Provider field path → canonical output leaf (leaf must be a scalar; a write may project the created id; userErrors is never projectable). For a SQL one-hop FK join, use path [relationshipField, targetColumn].

identifiesCaller
boolean

READ: mark this the caller-identity lookup (a phone search that greets a known caller by name). The runtime prefetches it and defaults the phone filter to the inbound caller number.

native_rest READ (a HubSpot-style CRM search): POST .../{object}/search with 1..5 ANDed filters. Use this (not inputs/projection) when the connected provider is a REST/OpenAPI CRM. A value the caller SPEAKS (name, company, subject) should filter with operator CONTAINS_TOKEN (partial match); an EXACT machine identifier (email, id) uses EQ. Find a caller by phone with the live-proven recipe — propertyName phone, operator CONTAINS_TOKEN, transform phone_token, callerIdFallback true (and set identifiesCaller). At least one filter must be caller-anchored (a param or callerIdFallback); a const-only search over-fetches a stranger and is rejected.

associationCap
integer

ASSOCIATION read (to-many): 2..5 returns an ARRAY of associated target rows (e.g. a company's contacts). Cap 1 (the default) returns the single flat target.

associationAs
string

The snake_case array key the associated rows land under (associationCap>1 only).

restWrite
object

native_rest WRITE (a HubSpot-style CRM create, or an update-by-id): map caller params/constants onto the object's OWN writable properties (no mass-assign). Gated (confirm + non-parallel) and lands DISABLED for review. Set findOrCreate to CAPTURE a returning caller without duplicating them.

native_sql READ (deterministic, LLM-free): exactly ONE filter on a LEADING-INDEX column. The transport (native_sql vs /native_rest) is determined by the connected provider's schema; use sqlSearch for postgres/mysql reads.

sqlWrite
object

native_sql WRITE (deterministic): a single-row INSERT, or an UPDATE-by-unique-key (set keyColumn+keyParam). Gated; lands DISABLED for review. PII-classed columns are rejected.

Response

The created skill (, native_rest, or native_sql per the connected provider).

success
boolean
required
data
object
required
message
string
errors
object[]