MCP tools
The MCP server gives an assistant 27 tools. Every tool talks only to Sealcord and acts
inside your organization. List tools page with limit (1 to 100, default 20) and offset, and
return total, has_more and next_offset. The read tools but sealcord_get_licence_key take
response_format: "markdown" (the default) or "json".
Products
Section titled “Products”| Tool | What it does | Scope | Kind |
|---|---|---|---|
sealcord_list_products |
Products: prefix, major, machines per seat, public keys | products:read |
Read-only |
sealcord_get_product |
One product | products:read |
Read-only |
Licences and machines
Section titled “Licences and machines”| Tool | What it does | Scope | Kind |
|---|---|---|---|
sealcord_list_licences |
Licences by email, by search q (an email prefix, a licence id, an external reference or a pasted key, which is not echoed back), or by a product’s external reference. Filter by product, state, term, source and status |
licences:read |
Read-only |
sealcord_count_licences |
Totals by state, term and source, live machines on active or trial licences, and licences issued and revoked since a time, for one product or all | licences:read |
Read-only |
sealcord_get_licence |
One licence with its activations, and no key | licences:read |
Read-only |
sealcord_get_licence_key |
One licence’s key, to resend it to its customer | licences:read |
Read-only |
sealcord_get_licence_audit |
A licence’s audit log, newest or oldest first | audit:read |
Read-only |
sealcord_list_activations |
A licence’s machines: live, deactivated or all | licences:read |
Read-only |
sealcord_issue_licence |
Issue a licence, optionally a trial or with an external reference. A repeat names the licence. Returns its key | licences:write |
Changes data, not idempotent |
sealcord_reinstate_licence |
Make a revoked or expired licence active | licences:write |
Changes data, idempotent |
sealcord_revoke_licence |
Revoke a licence (refund, chargeback, abuse) | licences:write |
Destructive, idempotent |
sealcord_expire_licence |
Expire a licence now (its term ended) | licences:write |
Destructive, idempotent |
sealcord_deactivate_activation |
Free one machine’s seat | licences:write |
Destructive, idempotent |
Payment integrations
Section titled “Payment integrations”| Tool | What it does | Scope | Kind |
|---|---|---|---|
sealcord_list_integrations |
Your payment integrations: status, webhook URL, whether the secret is set. No credential | polar:read |
Read-only |
sealcord_list_polar_mappings |
Which Polar products of one integration grant what | polar:read |
Read-only |
sealcord_set_polar_mapping |
Create or replace a mapping on one integration. It replaces every field except renewal_url, which it leaves as saved |
polar:write |
Destructive, idempotent |
sealcord_delete_polar_mapping |
Delete a mapping on one integration | polar:write |
Destructive, idempotent |
The mapping tools take the integration_id that sealcord_list_integrations shows. Saving a
mapping asks Polar whether the product exists.
| Tool | What it does | Scope | Kind |
|---|---|---|---|
sealcord_get_organization |
The organization: name, slug, plan and its team places | organization:read |
Read-only |
sealcord_list_members |
Members and their roles. Filter by role or address | members:read |
Read-only |
sealcord_list_invitations |
Invitations not yet accepted or revoked, pending or expired | members:read |
Read-only |
sealcord_invite_member |
Invite an address with a role. It replaces the address’s open invitation and emails it at once | members:write |
Destructive, not idempotent |
sealcord_revoke_invitation |
Revoke an open invitation: its link stops working | members:write |
Destructive, idempotent |
sealcord_change_member_role |
Give a member admin, support or read-only | members:write |
Destructive, idempotent |
sealcord_remove_member |
Remove a member from the organization | members:write |
Destructive, idempotent |
The team tools act as a person. members:write is granted only when you sign the assistant in,
never to an API key, and each change runs as you with your role at that moment. An admin acts on
support and read-only members, an owner on admins too, and nobody can give owner, act on an
owner, or change or remove themselves. A refusal answers insufficient_role or forbidden and
changes nothing.
Webhooks
Section titled “Webhooks”| Tool | What it does | Scope | Kind |
|---|---|---|---|
sealcord_list_webhook_endpoints |
Outgoing webhook endpoints: URL, event types, enabled or why disabled. No secret | webhooks:read |
Read-only |
sealcord_list_webhook_deliveries |
One endpoint’s 100 newest deliveries: status, attempts, last status code or error code. Filter by status | webhooks:read |
Read-only |
sealcord_retry_webhook_delivery |
Queue a delivery again, due now, with attempts back to 0. It is sent with the same event id | webhooks:write |
Changes data, idempotent |
An assistant reads and retries webhooks. It never adds, changes or removes an endpoint, or replaces its secret. See webhook retries.
Errors
Section titled “Errors”A failed call comes back as a tool result with the API’s error code and HTTP status, its message,
the fields or scopes at fault, what to do next, and the request id to quote. See
errors. Issuing, reinstating and inviting can answer plan_limit_reached
when your plan has no room. Nothing was written.
Questions
Section titled “Questions”Which tools can change or delete things?
Section titled “Which tools can change or delete things?”The ones marked destructive or changes data: issuing, reinstating, revoking and expiring licences, freeing a seat, changing Polar mappings, team changes, and retrying a webhook delivery. Everything else only reads.
Which scope does a read-only assistant need?
Section titled “Which scope does a read-only assistant need?”Grant products:read, licences:read, audit:read and polar:read for support questions. See
scopes.