> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Omit a tool

> Hide a tool from your agents without deleting it. For hand-authored tool sets. Synced sets curate with filters.

`:omit` takes a tool out of circulation without deleting it. It moves to `STATE_OMITTED`, no agent sees it, and [`:restore`](/docs/api-reference/toolservice/restore-a-tool) brings it back.

<CodeGroup>
  ```typescript TypeScript theme={null}
  await client.toolSets.tools.omit(toolSetId, toolId, { workspaceId });
  // state: 'STATE_OMITTED'
  ```

  ```go Go theme={null}
  // state: STATE_OMITTED
  _, err := client.ToolSets.Tools.Omit(ctx, toolSetID, toolID,
  	cadenya.ToolSetToolOmitParams{WorkspaceID: cadenya.String(workspaceID)})
  ```

  ```ruby Ruby theme={null}
  cadenya.tool_sets.tools.omit(tool_id, tool_set_id: tool_set_id, workspace_id: workspace_id)
  # state: STATE_OMITTED
  ```

  ```bash cURL theme={null}
  curl -X POST "https://api.cadenya.com/v1/workspaces/${WORKSPACE_ID}/tool_sets/${TOOL_SET_ID}/tools/${TOOL_ID}:omit" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}" \
    -H "Content-Type: application/json" \
    -d '{}'
  ```
</CodeGroup>

An omitted tool stays in the tool set and still shows in [List tools](/docs/api-reference/toolservice/list-tools) with its omitted state. It is hidden from agents, not gone. An objective run against a set with `GenerateFake` omitted reports exactly this:

```
"I have exactly 2 tools:
 1. GenerateCurseWord
 2. GetFakerOptions"
```

Both `:omit` and `:restore` are idempotent and return `200`.

## Which mechanism, by tool set kind

Curation depends on where the tools come from.

| Tool set         | Tools defined by  | Curate with                                    |
| ---------------- | ----------------- | ---------------------------------------------- |
| `bare`, `http`   | You, by hand      | `:omit` / `:restore`                           |
| `mcp`, `openapi` | The synced source | `excludeTools` / `includeTools` on the adapter |

For a [bare or HTTP tool set](/docs/api-reference/toolservice/create-a-new-tool-set), you own every tool and nothing overwrites your changes, so `:omit` is the natural switch.

For a **synced** tool set, the source is the authority. The adapter re-runs on every sync, so the durable way to hide a tool is a filter that the sync reapplies, not a one-time state change the sync discards.

<Warning>
  On a synced tool set today, `:omit` still returns `200`, but **the next sync flips the tool back to `STATE_AVAILABLE`**, silently. An [OpenAPI](/docs/guides/tool-sets/openapi) source syncs hourly, so an omitted tool can return within the hour with no event to show it.

  Use `excludeTools` for anything on a synced set, especially a dangerous tool. Treat `:omit` there as a temporary mute at best.
</Warning>

## Curate a synced set with a filter

An `excludeTools` filter is reapplied on every sync, so it holds. Measured across three syncs, the excluded tool stayed `STATE_OMITTED` every time, while a manually omitted one flipped back on the first.

```typescript theme={null}
await client.toolSets.update(toolSetId, {
  workspaceId,
  spec: {
    adapter: {
      type: 'mcp',
      mcp: {
        url: 'https://free.cadenya.com/faker-mcp',
        excludeTools: {
          operator: 'OPERATOR_AND',
          filters: [
            {
              attribute: 'ATTRIBUTE_NAME',
              matcher: { type: 'contains', contains: 'GenerateFake', caseSensitive: false },
            },
          ],
        },
      },
    },
  },
});
```

Match on `ATTRIBUTE_NAME`, `ATTRIBUTE_TITLE`, or `ATTRIBUTE_DESCRIPTION`, with a `matcher` whose `type` is `exact`, `contains`, `startsWith`, `endsWith`, or `regex`. `includeTools` is the allowlist form: sync only the tools that match, and drop the rest.

## Related

<CardGroup cols={2}>
  <Card title="Restore a tool" icon="rotate-left" href="/docs/api-reference/toolservice/restore-a-tool">
    Move an omitted tool back to `STATE_AVAILABLE`.
  </Card>

  <Card title="Create a tool set" icon="wrench" href="/docs/api-reference/toolservice/create-a-new-tool-set">
    `excludeTools` and `includeTools`, the filters that survive a sync.
  </Card>

  <Card title="List tools" icon="list" href="/docs/api-reference/toolservice/list-tools">
    Where an omitted tool still shows, with its state.
  </Card>

  <Card title="Deny a tool call" icon="hand" href="/docs/api-reference/objectiveservice/deny-a-tool-call">
    Gate a tool at call time instead of hiding it.
  </Card>
</CardGroup>


## OpenAPI

````yaml post /v1/workspaces/{workspaceId}/tool_sets/{toolSetId}/tools/{id}:omit
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/workspaces/{workspaceId}/tool_sets/{toolSetId}/tools/{id}:omit:
    post:
      tags:
        - ToolService
        - Tools
      summary: Omit a tool
      description: >-
        Transitions a tool to STATE_OMITTED, excluding it from agent use. Fails
        if the tool is currently assigned to agent variations.
      operationId: ToolService_OmitTool
      parameters:
        - name: workspaceId
          in: path
          description: Workspace ID.
          required: true
          schema:
            type: string
            example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
        - name: toolSetId
          in: path
          description: |-
            Tool set ID. Accepts the canonical ts_… form or the
             external_id:<value> form.
          required: true
          schema:
            example: toolset_01HXKD2E5NQM3T9AYWCFNRMN74
            type: string
        - name: id
          in: path
          description: |-
            Tool ID. Accepts the canonical tool_… form or the
             external_id:<value> form.
          required: true
          schema:
            example: tool_01HXKD2E5NQM3T9AYWCFWVYY9K
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OmitToolRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Tool'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import Cadenya from '@cadenya/cadenya';

            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });

            const tool = await client.toolSets.tools.omit(
              'toolset_01HXKD2E5NQM3T9AYWCFNRMN74',
              'tool_01HXKD2E5NQM3T9AYWCFWVYY9K',
              { workspaceId: 'workspace_01HXKD2E5NQM3T9AYWCF133E3Q' },
            );

            console.log(tool.metadata);
        - lang: Python
          source: |-
            import os
            from cadenya import Cadenya

            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )
            tool = client.tool_sets.tools.omit(
                tool_set_id="toolset_01HXKD2E5NQM3T9AYWCFNRMN74",
                id="tool_01HXKD2E5NQM3T9AYWCFWVYY9K",
                workspace_id="workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
            )
            print(tool.metadata)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\ttool, err := client.ToolSets.Tools.Omit(\n\t\tcontext.TODO(),\n\t\t\"toolset_01HXKD2E5NQM3T9AYWCFNRMN74\",\n\t\t\"tool_01HXKD2E5NQM3T9AYWCFWVYY9K\",\n\t\tcadenya.ToolSetToolOmitParams{\n\t\t\tWorkspaceID: cadenya.String(\"workspace_01HXKD2E5NQM3T9AYWCF133E3Q\"),\n\t\t},\n\t)\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", tool.Metadata)\n}\n"
        - lang: Ruby
          source: |-
            require "cadenya"

            cadenya = Cadenya::Client.new(api_key: "My API Key")

            tool = cadenya.tool_sets.tools.omit(
              "toolset_01HXKD2E5NQM3T9AYWCFNRMN74",
              "tool_01HXKD2E5NQM3T9AYWCFWVYY9K",
              workspace_id: "workspace_01HXKD2E5NQM3T9AYWCF133E3Q"
            )

            puts(tool)
        - lang: CLI
          source: |-
            cadenya tool-sets:tools omit \
              --api-key 'My API Key' \
              --workspace-id workspace_01HXKD2E5NQM3T9AYWCF133E3Q \
              --tool-set-id toolset_01HXKD2E5NQM3T9AYWCFNRMN74 \
              --id tool_01HXKD2E5NQM3T9AYWCFWVYY9K
components:
  schemas:
    OmitToolRequest:
      type: object
      properties:
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: Workspace ID.
        toolSetId:
          readOnly: true
          example: toolset_01HXKD2E5NQM3T9AYWCFNRMN74
          type: string
          description: |-
            Tool set ID. Accepts the canonical ts_… form or the
             external_id:<value> form.
        id:
          readOnly: true
          example: tool_01HXKD2E5NQM3T9AYWCFWVYY9K
          type: string
          description: |-
            Tool ID. Accepts the canonical tool_… form or the
             external_id:<value> form.
      description: Omit tool request
    Tool:
      required:
        - metadata
        - spec
        - state
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/ResourceMetadata'
        spec:
          $ref: '#/components/schemas/ToolSpec'
        info:
          $ref: '#/components/schemas/ToolInfo'
        state:
          readOnly: true
          enum:
            - STATE_UNSPECIFIED
            - STATE_AVAILABLE
            - STATE_OMITTED
            - STATE_ARCHIVED
          type: string
          description: >-
            The current lifecycle state of the tool. Output only. Use the :omit
            and
             :restore actions to transition; tool set syncs may also update it.
          format: enum
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    ResourceMetadata:
      required:
        - id
        - accountId
        - workspaceId
        - name
        - profileId
        - createdAt
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "agent_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: >-
            Workspace this resource belongs to for organizational grouping
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
          description: ID of the actor (user or service account) that created this resource
        createdAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was created
          format: date-time
        updatedAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was last updated
          format: date-time
      description: >-
        Standard metadata for persistent, named resources (e.g., agents, tools,
        prompts)
    ToolSpec:
      required:
        - description
        - parameters
        - config
        - requiresApproval
      type: object
      properties:
        description:
          type: string
        requiresApproval:
          type: boolean
        parameters:
          type: object
          additionalProperties: true
          description: >-
            The tool's JSON Schema, as handed to the LLM. Required, but may be
            the
             empty object `{}` for a tool that takes no arguments. Requiring it rather
             than defaulting it means a misspelled field name (`inputSchema`, say) is a
             400 instead of a silently parameterless tool.
        config:
          allOf:
            - $ref: '#/components/schemas/ToolSpec_Config'
          description: >-
            Configuration for this specific tool. Transport/Protocol are derived
            from the tool set adapter, while specifics
             such as endpoint, method, etc, are stored on the tool itself.

             Required, and exactly one adapter must be set.
        llmToolName:
          type: string
          description: >-
            The name provided to the LLM, which may differ from the
            metadata.name on the tool.
             LLMs have specific length and format requirements, and tool set sources may not comply
             with them, so Cadenya does its best to format names into a usable format.
    ToolInfo:
      type: object
      properties:
        toolSet:
          $ref: '#/components/schemas/ResourceMetadata'
        createdBy:
          $ref: '#/components/schemas/Profile'
        signature:
          readOnly: true
          type: string
          description: >-
            Content signature identifying the tool within its tool set: a hash
            of the
             sanitized llm_tool_name, description, and canonical parameters. Two tools
             with the same llm_tool_name but different parameters or description (as
             MCP servers may return per user) have distinct signatures.
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
    ToolSpec_Config:
      oneOf:
        - $ref: '#/components/schemas/ToolSpec_Config_Http'
        - $ref: '#/components/schemas/ToolSpec_Config_Mcp'
        - $ref: '#/components/schemas/ToolSpec_Config_Openapi'
        - $ref: '#/components/schemas/ToolSpec_Config_Bare'
      discriminator:
        propertyName: type
        mapping:
          http:
            $ref: '#/components/schemas/ToolSpec_Config_Http'
          mcp:
            $ref: '#/components/schemas/ToolSpec_Config_Mcp'
          openapi:
            $ref: '#/components/schemas/ToolSpec_Config_Openapi'
          bare:
            $ref: '#/components/schemas/ToolSpec_Config_Bare'
      description: |-
        Config defines the adapter to use for the tool.
         This is used to determine how the tool is called.
         For example, if the tool is an HTTP tool, the adapter will be Http.
         If the tool is an inline tool, the adapter will be Inline.
    Profile:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/ProfileSpec'
      description: |-
        A profile identifies a user or non-human principal (such as an API key)
         at the account level. Profiles are account-scoped and can be granted access
         to multiple workspaces.
    ToolSpec_Config_Http:
      type: object
      required:
        - type
        - http
      properties:
        type:
          type: string
          enum:
            - http
        http:
          $ref: '#/components/schemas/Config_HTTP'
    ToolSpec_Config_Mcp:
      type: object
      required:
        - type
        - mcp
      properties:
        type:
          type: string
          enum:
            - mcp
        mcp:
          $ref: '#/components/schemas/Config_MCP'
    ToolSpec_Config_Openapi:
      type: object
      required:
        - type
        - openapi
      properties:
        type:
          type: string
          enum:
            - openapi
        openapi:
          $ref: '#/components/schemas/Config_OpenAPI'
    ToolSpec_Config_Bare:
      type: object
      required:
        - type
        - bare
      properties:
        type:
          type: string
          enum:
            - bare
        bare:
          $ref: '#/components/schemas/Config_Bare'
    AccountResourceMetadata:
      required:
        - id
        - accountId
        - name
        - profileId
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "apikey_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
        createdAt:
          readOnly: true
          type: string
          format: date-time
      description: >-
        AccountResourceMetadata is used to represent a resource that is
        associated to an account but not to a workspace.
    ProfileSpec:
      required:
        - type
      type: object
      properties:
        email:
          type: string
          description: >-
            Email address of the profile. Required and unique within an account
            for
             user profiles.
        name:
          type: string
          description: Display name (e.g., "Bobby Tables").
        type:
          enum:
            - PROFILE_TYPE_UNSPECIFIED
            - PROFILE_TYPE_USER
            - PROFILE_TYPE_API_KEY
            - PROFILE_TYPE_SYSTEM
          type: string
          description: >-
            Whether this profile represents a human user, an API key, or a
            system
             principal.
          format: enum
      description: Configuration for a profile.
    Config_HTTP:
      required:
        - requestMethod
      type: object
      properties:
        requestMethod:
          enum:
            - HTTP_METHOD_UNSPECIFIED
            - GET
            - POST
            - PUT
            - PATCH
            - DELETE
          type: string
          format: enum
        path:
          type: string
        query:
          type: string
        headers:
          type: object
          additionalProperties:
            type: string
        requestBodyTemplate:
          type: string
          description: These are only used when the request method is a POST, PUT, or PATCH
        requestBodyContentType:
          type: string
    Config_MCP:
      type: object
      properties:
        annotations:
          allOf:
            - $ref: '#/components/schemas/MCP_Annotations'
          description: Tool behavior annotations from the MCP server, captured during sync.
    Config_OpenAPI:
      type: object
      properties:
        path:
          type: string
        method:
          type: string
    Config_Bare:
      type: object
      properties: {}
      description: |-
        Marks the tool as bare: it has no execution adapter of its own and
         relies on the parent tool set being a Bare tool set. Present so a
         webhook consumer can tell a tool is bare from the tool data alone,
         without cross-referencing the tool set.
      x-stainless-empty-object: true
    MCP_Annotations:
      type: object
      properties:
        title:
          type: string
          description: A human-readable title for the tool.
        readOnlyHint:
          type: boolean
          description: If true, the tool does not modify its environment.
        destructiveHint:
          type: boolean
          description: >-
            If true, the tool may perform destructive updates to its
            environment.
             Only meaningful when read_only_hint is false.
        idempotentHint:
          type: boolean
          description: |-
            If true, calling the tool repeatedly with the same arguments has no
             additional effect. Only meaningful when read_only_hint is false.
        openWorldHint:
          type: boolean
          description: |-
            If true, the tool may interact with an "open world" of external
             entities (e.g. web search); if false, its domain is closed.
      description: |-
        Behavior hints synced from the MCP server's tool definition
         (ToolAnnotations in the MCP specification). All hints are advisory:
         servers are not required to send them, and clients should not rely
         on them for security decisions. Absent hints keep the MCP spec
         defaults (destructiveHint and openWorldHint default to true;
         readOnlyHint and idempotentHint default to false).
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````