Platform tools

Platform tools for webhooks, region and product-template discovery, and egress policy, secrets, and audit.

Webhooks

ToolDescription
webhook_createCreate a new webhook endpoint.
webhook_deleteDelete a webhook.
webhook_listList all webhooks registered in the tenant.
webhook_testSend a test event delivery to a webhook endpoint.

Regions and product templates

ToolDescription
product_template_getGet one canonical product template, including size readiness and benchmark lane metadata.
product_template_listList canonical product templates across sandbox, computer, and App Engine appliance products.
product_template_readinessShow size readiness for one canonical product template.
region_listList available regions.

Egress, secrets and audit

ToolDescription
miosa_audit_count_by_hostCount egress audit events grouped by destination host for a given resource and time window. Useful for building allowlists or detecting anomalous traffic patterns.
miosa_audit_getFetch a single audit event by its ID.
miosa_audit_queryQuery the egress audit log. Returns events with host, action (allowed/denied), timestamp, and resource attribution. Supports filtering by resource, host, action, and time range.
miosa_network_allowAdd an allow rule to the egress allowlist for a specific host. Optionally restrict by HTTP methods and path glob. Rules apply to the tenant policy or a specific resource policy.
miosa_network_denyAdd an explicit deny rule to the egress allowlist for a specific host. Deny rules take precedence over allow rules. Use to block known-bad destinations even in observe mode.
miosa_network_list_policiesList all egress policies in the tenant, with their mode and default effect.
miosa_network_list_rulesList allowlist rules for a specific policy. Returns host, methods, path_glob, and effect for each rule.
miosa_network_lockdownSwitch egress policy to enforce mode - all traffic not explicitly allowed will be blocked. Use miosa_network_allow to whitelist destinations before calling this.
miosa_network_observeSwitch egress policy to audit-only (observe) mode - traffic is logged but not blocked. Use this to build an allowlist before enforcing with miosa_network_lockdown.
miosa_network_suggestionsReturn AI-generated allowlist suggestions derived from recently observed egress traffic. Use these as input to miosa_network_allow to build a policy before switching to enforce mode.
miosa_oauth_providers_listList OAuth providers configured and visible to the calling tenant. Use provider slugs from this list as input to miosa_secrets_connect_oauth.
miosa_secrets_connect_oauthStart an OAuth 2.0 connect flow for the given provider. Returns authorize_url (which the user must open in a browser) and a poll_url to check completion status. Call miosa_audit_query or GET the poll_url until status=completed.
miosa_secrets_deleteDelete a secret and remove all associated bindings. Resources that were injecting this secret will no longer receive it.
miosa_secrets_listList secrets visible to the calling tenant. Returns metadata only (name, type, scope, id) - plaintext values are never returned. Filter by scope, workspace, or owner identity.
miosa_secrets_rotateRotate a secret’s value in-place. All existing bindings continue to reference the same secret_id and pick up the new value automatically.
miosa_secrets_setCreate a secret and optionally bind it to a resource so it is injected as an environment variable. Provide expose_as_env + resource_id + resource_type to auto-bind.
Was this page helpful?