Skip to content

MCP tools

The MCP server gives an assistant 27 tools. Every tool talks only to Sealcord and acts inside your organization. List tools page with limit (1 to 100, default 20) and offset, and return total, has_more and next_offset. The read tools but sealcord_get_licence_key take response_format: "markdown" (the default) or "json".

Tool What it does Scope Kind
sealcord_list_products Products: prefix, major, machines per seat, public keys products:read Read-only
sealcord_get_product One product products:read Read-only
Tool What it does Scope Kind
sealcord_list_licences Licences by email, by search q (an email prefix, a licence id, an external reference or a pasted key, which is not echoed back), or by a product’s external reference. Filter by product, state, term, source and status licences:read Read-only
sealcord_count_licences Totals by state, term and source, live machines on active or trial licences, and licences issued and revoked since a time, for one product or all licences:read Read-only
sealcord_get_licence One licence with its activations, and no key licences:read Read-only
sealcord_get_licence_key One licence’s key, to resend it to its customer licences:read Read-only
sealcord_get_licence_audit A licence’s audit log, newest or oldest first audit:read Read-only
sealcord_list_activations A licence’s machines: live, deactivated or all licences:read Read-only
sealcord_issue_licence Issue a licence, optionally a trial or with an external reference. A repeat names the licence. Returns its key licences:write Changes data, not idempotent
sealcord_reinstate_licence Make a revoked or expired licence active licences:write Changes data, idempotent
sealcord_revoke_licence Revoke a licence (refund, chargeback, abuse) licences:write Destructive, idempotent
sealcord_expire_licence Expire a licence now (its term ended) licences:write Destructive, idempotent
sealcord_deactivate_activation Free one machine’s seat licences:write Destructive, idempotent
Tool What it does Scope Kind
sealcord_list_integrations Your payment integrations: status, webhook URL, whether the secret is set. No credential polar:read Read-only
sealcord_list_polar_mappings Which Polar products of one integration grant what polar:read Read-only
sealcord_set_polar_mapping Create or replace a mapping on one integration. It replaces every field except renewal_url, which it leaves as saved polar:write Destructive, idempotent
sealcord_delete_polar_mapping Delete a mapping on one integration polar:write Destructive, idempotent

The mapping tools take the integration_id that sealcord_list_integrations shows. Saving a mapping asks Polar whether the product exists.

Tool What it does Scope Kind
sealcord_get_organization The organization: name, slug, plan and its team places organization:read Read-only
sealcord_list_members Members and their roles. Filter by role or address members:read Read-only
sealcord_list_invitations Invitations not yet accepted or revoked, pending or expired members:read Read-only
sealcord_invite_member Invite an address with a role. It replaces the address’s open invitation and emails it at once members:write Destructive, not idempotent
sealcord_revoke_invitation Revoke an open invitation: its link stops working members:write Destructive, idempotent
sealcord_change_member_role Give a member admin, support or read-only members:write Destructive, idempotent
sealcord_remove_member Remove a member from the organization members:write Destructive, idempotent

The team tools act as a person. members:write is granted only when you sign the assistant in, never to an API key, and each change runs as you with your role at that moment. An admin acts on support and read-only members, an owner on admins too, and nobody can give owner, act on an owner, or change or remove themselves. A refusal answers insufficient_role or forbidden and changes nothing.

Tool What it does Scope Kind
sealcord_list_webhook_endpoints Outgoing webhook endpoints: URL, event types, enabled or why disabled. No secret webhooks:read Read-only
sealcord_list_webhook_deliveries One endpoint’s 100 newest deliveries: status, attempts, last status code or error code. Filter by status webhooks:read Read-only
sealcord_retry_webhook_delivery Queue a delivery again, due now, with attempts back to 0. It is sent with the same event id webhooks:write Changes data, idempotent

An assistant reads and retries webhooks. It never adds, changes or removes an endpoint, or replaces its secret. See webhook retries.

A failed call comes back as a tool result with the API’s error code and HTTP status, its message, the fields or scopes at fault, what to do next, and the request id to quote. See errors. Issuing, reinstating and inviting can answer plan_limit_reached when your plan has no room. Nothing was written.

The ones marked destructive or changes data: issuing, reinstating, revoking and expiring licences, freeing a seat, changing Polar mappings, team changes, and retrying a webhook delivery. Everything else only reads.

Which scope does a read-only assistant need?

Section titled “Which scope does a read-only assistant need?”

Grant products:read, licences:read, audit:read and polar:read for support questions. See scopes.