> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a tool call

> One tool call, with the result the tool returned. The only single-call endpoint that hydrates a result body.

[Listing tool calls](/docs/api-reference/objectiveservice/list-objective-tool-calls) gives you arguments and status. Fetching one gives you what the tool returned.

<CodeGroup>
  ```typescript TypeScript theme={null}
  const call = await client.objectives.toolCalls.retrieve(toolCallId, { workspaceId, objectiveId });

  const callable = call.data.callable;
  console.log(callable.type);                   // 'tool'
  if (callable.type === 'tool') {
    console.log(callable.tool.name);            // 'GenerateFake'
  }
  console.log(call.executionStatus);            // 'TOOL_CALL_EXECUTION_STATUS_COMPLETED'
  console.log(JSON.stringify(call.result));
  // {"content":[{"type":"text","text":{"text":"{\"name\":\"company.name\",\"value\":\"Weissnat, Weissnat and Weissnat\"}"}}]}
  ```

  ```go Go theme={null}
  call, err := client.Objectives.ToolCalls.Get(ctx, objectiveID, toolCallID,
  	cadenya.ObjectiveToolCallGetParams{WorkspaceID: cadenya.String(workspaceID)})

  fmt.Println(call.Data.Callable.Tool.Name) // GenerateFake
  fmt.Println(call.ExecutionStatus)         // TOOL_CALL_EXECUTION_STATUS_COMPLETED
  fmt.Printf("%+v\n", call.Result)
  ```

  ```ruby Ruby theme={null}
  call = cadenya.objectives.tool_calls.retrieve(
    tool_call_id,
    workspace_id: workspace_id,
    objective_id: objective_id
  )

  puts call.data.callable.tool&.name # GenerateFake
  puts call.execution_status         # TOOL_CALL_EXECUTION_STATUS_COMPLETED
  puts call.result
  ```

  ```bash cURL theme={null}
  curl "https://api.cadenya.com/v1/workspaces/${WORKSPACE_ID}/objectives/${OBJECTIVE_ID}/tool_calls/${TOOL_CALL_ID}" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}"
  ```
</CodeGroup>

## `result` sits at the top level

Not under `data`, where `arguments` and `callable` live. The response schema is named `ObjectiveToolCallWithResult`, and that name is the whole distinction from the list.

```
list item      →  metadata, data, status, executionStatus, info
get by id      →  metadata, data, status, executionStatus, info, result, resolvedSecrets
```

No `includeInfo` is needed. The result hydrates on every fetch, which is why the list leaves it out: paging a long objective stays cheap, and you pay for a body only when a user expands one.

`result.content` is the same block list a [bare tool](/docs/api-reference/objectiveservice/set-a-bare-tool-calls-content) submits: each block's `type` reads `text`, `image`, or `audio`, with the payload under the matching key. Media comes back as a signed URL on the way out, even though it goes in as base64.

## Three ways to reach a result body

| Path                                                                                                   | When                                                                                                                      |
| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- |
| This endpoint                                                                                          | A user expanded one call in a UI                                                                                          |
| `toolResult` event from [List objective events](/docs/api-reference/objectiveservice/list-objective-events) | Rendering a whole transcript                                                                                              |
| The event stream                                                                                       | Never. Results are [stripped](/docs/api-reference/objectiveeventstreamsservice/stream-objective-events) to a bare `toolCallId` |

The stream omits bodies so a tool returning a megabyte of JSON does not push it through every open connection. That makes this endpoint the natural companion to a live UI: stream the timeline, fetch the body on click.

## It resolves built-in tool names

The [`toolCalled` event](/docs/api-reference/objectiveeventstreamsservice/stream-objective-events) ships `cadenyaProvidedTool.name` empty. Here it is populated:

```typescript theme={null}
if (call.data.callable.type === 'cadenyaProvidedTool') {
  call.data.callable.cadenyaProvidedTool.name;  // 'get_memory'
}
```

So a transcript that hits an unnamed built-in can recover the name with one fetch.

## `resolvedSecrets` is the secret audit trail

When a tool's headers reference `${NAME}` [secrets](/docs/guides/store-and-use-secrets), `resolvedSecrets` records which ones the call used and **which scope each came from**, never the value:

```typescript theme={null}
call.resolvedSecrets;
// [{ key: 'STRIPE_API_KEY', source: 'RESOLVED_SECRET_SOURCE_OBJECTIVE' }]
```

`key` is the reference name (not `name`), and `source` is the scope that won under the strict [precedence](/docs/guides/store-and-use-secrets#per-run-secrets), objective over tool set over workspace:

| `source`                           | Resolved from                                                                                    |
| ---------------------------------- | ------------------------------------------------------------------------------------------------ |
| `RESOLVED_SECRET_SOURCE_OBJECTIVE` | A per-run [objective secret](/docs/api-reference/objectiveservice/create-a-new-objective)             |
| `RESOLVED_SECRET_SOURCE_TOOLSET`   | A [tool set secret](/docs/api-reference/toolservice/create-a-new-tool-set-secret)                     |
| `RESOLVED_SECRET_SOURCE_WORKSPACE` | A shared [workspace secret](/docs/api-reference/workspacesecretservice/create-a-new-workspace-secret) |

So a call that used a customer's per-run token reads `RESOLVED_SECRET_SOURCE_OBJECTIVE`, and one that fell through to the shared credential reads `RESOLVED_SECRET_SOURCE_WORKSPACE`. This is how you confirm the right scope won without ever seeing the secret.

## Scoping is strict

The tool call must belong to the objective in the path. A valid ID under the wrong objective is a `404`, not someone else's data:

```
GET /objectives/{right}/tool_calls/{id}   -> 200
GET /objectives/{other}/tool_calls/{id}   -> 404
GET /objectives/{right}/tool_calls/bogus  -> 404
```

`external_id:` resolution does not apply to tool calls. They carry no external ID, so pass the `toolcall_...` value.

## Poll for a settled status

[Approve and deny](/docs/api-reference/objectiveservice/approve-a-tool-call) resolve asynchronously, and their response reports the pre-decision state. This endpoint is where the settled one shows up.

```typescript theme={null}
await client.objectives.toolCalls.approve(toolCallId, { workspaceId, objectiveId });

const settled = await client.objectives.toolCalls.retrieve(toolCallId, { workspaceId, objectiveId });
settled.status;           // TOOL_CALL_STATUS_APPROVED
settled.executionStatus;  // ... then COMPLETED, once the tool runs
```

## Related

<CardGroup cols={2}>
  <Card title="List tool calls" icon="list-check" href="/docs/api-reference/objectiveservice/list-objective-tool-calls">
    Every call, filtered by status, without result bodies.
  </Card>

  <Card title="Approve a tool call" icon="hand" href="/docs/api-reference/objectiveservice/approve-a-tool-call">
    The decision whose outcome you read here.
  </Card>

  <Card title="Set tool call content" icon="reply" href="/docs/api-reference/objectiveservice/set-a-bare-tool-calls-content">
    Where a bare tool's `result.content` comes from.
  </Card>

  <Card title="Stream objective events" icon="tower-broadcast" href="/docs/api-reference/objectiveeventstreamsservice/stream-objective-events">
    Why the stream sends a `toolCallId` and no body.
  </Card>
</CardGroup>


## OpenAPI

````yaml get /v1/workspaces/{workspaceId}/objectives/{objectiveId}/tool_calls/{toolCallId}
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/workspaces/{workspaceId}/objectives/{objectiveId}/tool_calls/{toolCallId}:
    get:
      tags:
        - ObjectiveService
        - Objectives
      summary: Get an objective tool call by ID
      description: >-
        Retrieves a single tool call, including the content the tool returned.
        Media content (images, audio) is served as short-lived signed URLs.
      operationId: ObjectiveService_GetObjectiveToolCall
      parameters:
        - name: workspaceId
          in: path
          required: true
          schema:
            type: string
            example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
        - name: objectiveId
          in: path
          description: >-
            The ID of the objective. Supports "external_id:" prefix for external
            IDs.
          required: true
          schema:
            example: obj_01HXKD2E5NQM3T9AYWCFQAZGFV
            type: string
        - name: toolCallId
          in: path
          description: The ID of the tool call to retrieve
          required: true
          schema:
            example: toolcall_01HXKD2E5NQM3T9AYWCFTANFGV
            type: string
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectiveToolCallWithResult'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: >-
            import Cadenya from '@cadenya/cadenya';


            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });


            const objectiveToolCallWithResult = await
            client.objectives.toolCalls.retrieve(
              'obj_01HXKD2E5NQM3T9AYWCFQAZGFV',
              'toolcall_01HXKD2E5NQM3T9AYWCFTANFGV',
              { workspaceId: 'workspace_01HXKD2E5NQM3T9AYWCF133E3Q' },
            );


            console.log(objectiveToolCallWithResult.data);
        - lang: Python
          source: >-
            import os

            from cadenya import Cadenya


            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )

            objective_tool_call_with_result =
            client.objectives.tool_calls.retrieve(
                objective_id="obj_01HXKD2E5NQM3T9AYWCFQAZGFV",
                tool_call_id="toolcall_01HXKD2E5NQM3T9AYWCFTANFGV",
                workspace_id="workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
            )

            print(objective_tool_call_with_result.data)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tobjectiveToolCallWithResult, err := client.Objectives.ToolCalls.Get(\n\t\tcontext.TODO(),\n\t\t\"obj_01HXKD2E5NQM3T9AYWCFQAZGFV\",\n\t\t\"toolcall_01HXKD2E5NQM3T9AYWCFTANFGV\",\n\t\tcadenya.ObjectiveToolCallGetParams{\n\t\t\tWorkspaceID: cadenya.String(\"workspace_01HXKD2E5NQM3T9AYWCF133E3Q\"),\n\t\t},\n\t)\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", objectiveToolCallWithResult.Data)\n}\n"
        - lang: Ruby
          source: >-
            require "cadenya"


            cadenya = Cadenya::Client.new(api_key: "My API Key")


            objective_tool_call_with_result =
            cadenya.objectives.tool_calls.retrieve(
              "obj_01HXKD2E5NQM3T9AYWCFQAZGFV",
              "toolcall_01HXKD2E5NQM3T9AYWCFTANFGV",
              workspace_id: "workspace_01HXKD2E5NQM3T9AYWCF133E3Q"
            )


            puts(objective_tool_call_with_result)
        - lang: CLI
          source: |-
            cadenya objectives:tool-calls retrieve \
              --api-key 'My API Key' \
              --workspace-id workspace_01HXKD2E5NQM3T9AYWCF133E3Q \
              --objective-id obj_01HXKD2E5NQM3T9AYWCFQAZGFV \
              --tool-call-id toolcall_01HXKD2E5NQM3T9AYWCFTANFGV
components:
  schemas:
    ObjectiveToolCallWithResult:
      required:
        - metadata
        - data
        - status
        - executionStatus
        - info
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/OperationMetadata'
        data:
          $ref: '#/components/schemas/ObjectiveToolCallData'
        status:
          enum:
            - TOOL_CALL_STATUS_UNSPECIFIED
            - TOOL_CALL_STATUS_AUTO_APPROVED
            - TOOL_CALL_STATUS_WAITING_FOR_APPROVAL
            - TOOL_CALL_STATUS_APPROVED
            - TOOL_CALL_STATUS_DENIED
          type: string
          description: Current status of the tool call
          format: enum
        info:
          $ref: '#/components/schemas/ObjectiveToolCallInfo'
        executionStatus:
          readOnly: true
          enum:
            - TOOL_CALL_EXECUTION_STATUS_UNSPECIFIED
            - TOOL_CALL_EXECUTION_STATUS_PENDING
            - TOOL_CALL_EXECUTION_STATUS_RUNNING
            - TOOL_CALL_EXECUTION_STATUS_COMPLETED
            - TOOL_CALL_EXECUTION_STATUS_ERRORED
            - TOOL_CALL_EXECUTION_STATUS_WAITING_FOR_CONTENT
          type: string
          format: enum
        result:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/ObjectiveToolCallResult'
          description: |-
            The content returned by the tool. Only set once execution_status is
             TOOL_CALL_EXECUTION_STATUS_COMPLETED.
        resolvedSecrets:
          readOnly: true
          type: array
          items:
            $ref: '#/components/schemas/ResolvedSecret'
          description: List of resolved secrets used by the tool call
      description: |-
        ObjectiveToolCallWithResult is an ObjectiveToolCall plus the content the
         tool returned. Returned by GetObjectiveToolCall.
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    OperationMetadata:
      required:
        - id
        - accountId
        - workspaceId
        - profileId
        - createdAt
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the operation (prefixed ULID, e.g.,
            "obj_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this operation belongs to for multi-tenant isolation
            (prefixed ULID)
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: >-
            Workspace this operation belongs to for organizational grouping
            (prefixed ULID)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"priority": "high", "source": "api", "workflow": "onboarding"}
        createdAt:
          readOnly: true
          type: string
          description: |-
            Timestamp when this operation was created
             ULID includes timestamp information, but this explicit field enables easier querying
          format: date-time
        externalId:
          type: string
          description: >-
            External ID for the operation (e.g., a workflow ID from an external
            system)
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
          description: >-
            ID of the actor (user or service account) that created this
            operation
      description: >-
        Metadata for ephemeral operations and activities (e.g., objectives,
        executions, runs)
    ObjectiveToolCallData:
      required:
        - callable
      type: object
      properties:
        callable:
          allOf:
            - $ref: '#/components/schemas/CallableTool'
          description: The tool that was called
        arguments:
          type: object
          additionalProperties: true
          description: The arguments passed to the tool
        memo:
          type: string
          description: A memo supplied by the reviewer when denying the tool call
        statusChangedBy:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/Profile'
          description: >-
            The profile that changed the status of this tool call. Set when the
            status is changed to APPROVED or DENIED by a user.
        resolvedSecrets:
          readOnly: true
          type: array
          items:
            $ref: '#/components/schemas/ResolvedSecret'
          description: List of resolved secrets used by the tool call
    ObjectiveToolCallInfo:
      type: object
      properties:
        objective:
          $ref: '#/components/schemas/OperationMetadata'
        createdBy:
          $ref: '#/components/schemas/Profile'
        tool:
          $ref: '#/components/schemas/BareMetadata'
        toolSet:
          $ref: '#/components/schemas/BareMetadata'
    ObjectiveToolCallResult:
      required:
        - content
      type: object
      properties:
        content:
          readOnly: true
          type: array
          items:
            $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock'
      description: |-
        ObjectiveToolCallResult is the content a tool returned after execution.
         Tools can return multiple content blocks, and blocks can be multi-modal
         (text, image, audio). Media blocks are stored by Cadenya and served as
         short-lived signed URLs rather than inline bytes.
    ResolvedSecret:
      type: object
      properties:
        key:
          type: string
        source:
          enum:
            - RESOLVED_SECRET_SOURCE_UNSPECIFIED
            - RESOLVED_SECRET_SOURCE_WORKSPACE
            - RESOLVED_SECRET_SOURCE_TOOLSET
            - RESOLVED_SECRET_SOURCE_OBJECTIVE
          type: string
          format: enum
      description: >-
        ResolvedSecret is a resolved secret value from the workspace, toolset,
        or objective. When a tool is called, it will rely
         on secrets in the order of:
         - Objective
         - Toolset
         - Workspace
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
    CallableTool:
      oneOf:
        - $ref: '#/components/schemas/CallableTool_Tool'
        - $ref: '#/components/schemas/CallableTool_Agent'
        - $ref: '#/components/schemas/CallableTool_CadenyaProvidedTool'
      discriminator:
        propertyName: type
        mapping:
          tool:
            $ref: '#/components/schemas/CallableTool_Tool'
          agent:
            $ref: '#/components/schemas/CallableTool_Agent'
          cadenyaProvidedTool:
            $ref: '#/components/schemas/CallableTool_CadenyaProvidedTool'
      description: >-
        CallableTool is a union that represents a tool that can be called by an
        agent. In Cadenya, a tool that is used within an agent objective
         might be a user-defined tool (IE: MCP, HTTP), another Agent (useful to separate context), or a Cadenya Tool (one Cadenya provides).
    Profile:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/ProfileSpec'
      description: |-
        A profile identifies a user or non-human principal (such as an API key)
         at the account level. Profiles are account-scoped and can be granted access
         to multiple workspaces.
    BareMetadata:
      type: object
      properties:
        id:
          readOnly: true
          type: string
        name:
          readOnly: true
          type: string
          description: >-
            Human-readable name of the referenced resource, populated by the
            server
             on reads for convenience. Absent on references to resources that do not
             have a name (e.g., objective tasks).
      description: |-
        BareMetadata contains the minimal metadata for a resource: the ID and an
         optional human-readable name. These are used for reference fields where the
         full metadata (account scoping, timestamps, labels, external IDs) is not
         needed — e.g., the tool references inside an agent variation spec or the
         tools assigned to an objective. Both fields are server-populated; clients
         provide IDs through sibling fields rather than by constructing a
         BareMetadata themselves.
    ObjectiveToolCallResult_ContentBlock:
      oneOf:
        - $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Text'
        - $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Image'
        - $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Audio'
      discriminator:
        propertyName: type
        mapping:
          text:
            $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Text'
          image:
            $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Image'
          audio:
            $ref: '#/components/schemas/ObjectiveToolCallResult_ContentBlock_Audio'
      description: |-
        ContentBlock is a single block of tool result content. Exactly one of
         the variants is set.
    CallableTool_Tool:
      type: object
      required:
        - type
        - tool
      properties:
        type:
          type: string
          enum:
            - tool
        tool:
          $ref: '#/components/schemas/ResourceMetadata'
    CallableTool_Agent:
      type: object
      required:
        - type
        - agent
      properties:
        type:
          type: string
          enum:
            - agent
        agent:
          $ref: '#/components/schemas/ResourceMetadata'
    CallableTool_CadenyaProvidedTool:
      type: object
      required:
        - type
        - cadenyaProvidedTool
      properties:
        type:
          type: string
          enum:
            - cadenyaProvidedTool
        cadenyaProvidedTool:
          $ref: '#/components/schemas/ResourceMetadata'
    AccountResourceMetadata:
      required:
        - id
        - accountId
        - name
        - profileId
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "apikey_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
        createdAt:
          readOnly: true
          type: string
          format: date-time
      description: >-
        AccountResourceMetadata is used to represent a resource that is
        associated to an account but not to a workspace.
    ProfileSpec:
      required:
        - type
      type: object
      properties:
        email:
          type: string
          description: >-
            Email address of the profile. Required and unique within an account
            for
             user profiles.
        name:
          type: string
          description: Display name (e.g., "Bobby Tables").
        type:
          enum:
            - PROFILE_TYPE_UNSPECIFIED
            - PROFILE_TYPE_USER
            - PROFILE_TYPE_API_KEY
            - PROFILE_TYPE_SYSTEM
          type: string
          description: >-
            Whether this profile represents a human user, an API key, or a
            system
             principal.
          format: enum
      description: Configuration for a profile.
    ObjectiveToolCallResult_ContentBlock_Text:
      type: object
      required:
        - type
        - text
      properties:
        type:
          type: string
          enum:
            - text
        text:
          $ref: '#/components/schemas/ObjectiveToolCallResult_TextBlock'
    ObjectiveToolCallResult_ContentBlock_Image:
      type: object
      required:
        - type
        - image
      properties:
        type:
          type: string
          enum:
            - image
        image:
          $ref: '#/components/schemas/ObjectiveToolCallResult_ImageBlock'
    ObjectiveToolCallResult_ContentBlock_Audio:
      type: object
      required:
        - type
        - audio
      properties:
        type:
          type: string
          enum:
            - audio
        audio:
          $ref: '#/components/schemas/ObjectiveToolCallResult_AudioBlock'
    ResourceMetadata:
      required:
        - id
        - accountId
        - workspaceId
        - name
        - profileId
        - createdAt
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "agent_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: >-
            Workspace this resource belongs to for organizational grouping
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
          description: ID of the actor (user or service account) that created this resource
        createdAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was created
          format: date-time
        updatedAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was last updated
          format: date-time
      description: >-
        Standard metadata for persistent, named resources (e.g., agents, tools,
        prompts)
    ObjectiveToolCallResult_TextBlock:
      required:
        - text
      type: object
      properties:
        text:
          readOnly: true
          type: string
    ObjectiveToolCallResult_ImageBlock:
      required:
        - url
        - mimeType
        - sizeBytes
        - expiresAt
      type: object
      properties:
        url:
          readOnly: true
          type: string
          description: Short-lived signed URL to download the stored image.
        mimeType:
          readOnly: true
          type: string
          description: IANA media type of the stored image, e.g. image/png.
        sizeBytes:
          readOnly: true
          type: string
          description: Size of the stored image in bytes.
        expiresAt:
          readOnly: true
          type: string
          description: When the signed URL expires.
          format: date-time
    ObjectiveToolCallResult_AudioBlock:
      required:
        - url
        - mimeType
        - sizeBytes
        - expiresAt
      type: object
      properties:
        url:
          readOnly: true
          type: string
          description: Short-lived signed URL to download the stored audio.
        mimeType:
          readOnly: true
          type: string
          description: IANA media type of the stored audio, e.g. audio/wav.
        sizeBytes:
          readOnly: true
          type: string
          description: Size of the stored audio in bytes.
        expiresAt:
          readOnly: true
          type: string
          description: When the signed URL expires.
          format: date-time
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````