AI agent/Live technical MCP reference
updated 2026-10-07
AI agent

Live technical MCP reference

The canonical list of the tools your AI agent can call on Protocol — 23 intent verbs grouped by access level, the entities they read and write, and the connection facts (MCP standard, connector URL, server version). For power users and developers wiring up an MCP client.

Advanced  This page is the technical reference for the tools your connected assistant actually has. The other AI agent guides explain the feature in plain language; this one lists the exact verbs (MCP tools) Protocol exposes, what each reads or writes, and the connection facts you’d want when wiring up a developer MCP client. If you just want to use the feature, start with Connecting your assistant — you don’t need anything here.

The surface is deliberately small. Protocol exposes 23 intent verbs, not hundreds of CRUD endpoints. Each verb is a high-level coaching action (“build a workout,” “review this client,” “schedule something”) that does the right thing under the hood. A small, sharp surface is easier for an AI to use well — and easier for you to reason about. This list is generated from the same definitions the live server serves, so it stays true to the product.

Connection facts

Protocol speaks the open MCP (Model Context Protocol) standard — any MCP-capable client can connect
Connector URL shown on the AI agent page (open it from your profile menu); ends in /mcp
Auth browser sign-in & approve (OAuth-style), or a manual key (pk_…) as the bearer token
Server name / version protocol · 1.0.0
Transport remote MCP over HTTP
Tools served 23 verbs, filtered by the access level you granted (read / write / send)

Every connecting client also receives a short server instruction that tells the assistant to write like a thoughtful human coach (realistic, round real-world numbers — never calculator-perfect fractions), to mirror your existing style, and — when it hits a wall — to tell you plainly and offer to file a note to Protocol’s developers rather than fake a result. That escalation now files a tracked support ticket you can follow in the dashboard — see Getting help and filing a ticket.

The 23 verbs at a glance

Verbs are grouped by the lowest access level that can call them. Access is cumulative — a send key can call everything; a write key can call read + write; a read key can call only the reads. (How you pick a level: Safety, scopes & privacy.)

Access level Verbs
Read (6) find · get · review_client · report · message · guide
Write (17) manage_client · build_program · assign_program · build_workout · build_nutrition · record_progress · manage_library · manage_forms · manage_tasks · review_inbox · manage_media · manage_content · manage_support · manage_shop · report_to_developers · schedule · manage_automations, plus message action=draft
Send (4 actions, no whole verb) schedule action=send_reminder · schedule action=reminder · manage_automations action=run · manage_shop action=create_purchase

Read verbs

Never mutate anything — safe for a research-only connection.

Verb What it does Key inputs
find List or search any kind of entity (the polymorphic list verb). kind (required) + filters: query, clientId, formId, isTemplate, status, limit
get Fetch one entity by id, in full detail. kind (required), id (required)
review_client One call returns a whole client context bundle: profile, programs, nutrition, recent progress, upcoming appointments, open tasks, insights, the tracking summary (90-day counts, days since the last biometrics reading, 30-day habit completion) and the latest 10 events from the client’s history. clientId (required)
report Aggregate a window of history into a report: training (sessions, volume, per-exercise progression), checkin, body, nutrition, engagement, business. Read the coverage block it returns — some kinds say plainly what they can’t compute from your data rather than returning a zero that reads as real. kind (required), subject: roster · client, clientId, from, to
message Read your inbox and conversations, with the same filters as the dashboard (unread, drafts, client labels, stage, reminder owner). With write access it can also leave a draft in a conversation for you to send (action=draft). It can never send a client a message. action: list · read · draft; conversationId, clientId, unread, hasDraft, labelNames, lifecycleStageId, reminderAssigneeId, content, limit
guide Serves the same playbooks and reference files the plugin bundles, for a connection made without the plugin. topic

Entity kinds for find and get

find and get both take a kind. Most kinds support both; a few are list-only.

Kind find get
client ✓ ✓
program ✓ ✓
workout ✓ ✓
nutrition ✓ ✓
exercise ✓ ✓
food ✓ ✓
appointment ✓ ✓
form ✓ ✓
task ✓ ✓
board ✓ ✓
automation ✓ ✓
progress ✓ ✓
purchase ✓ ✓
media ✓ ✓
report ✓ ✓
submission ✓ ✓
transcript ✓ ✓
support_ticket ✓ ✓
article ✓ ✓
audience ✓ —
conversation ✓ —
lifecycle_stage ✓ —
lab ✓ —
health_metric ✓ —
automation_run ✓ —
automation_kind ✓ —
task_label ✓ —
client_label ✓ —
client_history ✓ —
workout_session ✓ —
client_media ✓ —
habit ✓ —
recent_exercise ✓ —
product ✓ —

The fifteen list-only kinds are read in context, through message, review_client, a client’s bundle, or the record they belong to, rather than fetched one by id. The newest ones read the client record the way the dashboard shows it:

  • client_history: the client’s history timeline (stage and label changes, programs, check-ins, forms, purchases, payments, emails, and who made each change), newest first.
  • workout_session: what the client actually logged, session by session, with every set when asked.
  • client_media: the files a client sent you (check-in photos, form uploads, chat attachments, meal photos), in folders.
  • habit: the habits a habit form can offer, the standard ones and your own custom habits.
  • recent_exercise: the exercises you used most recently. Exercise results also say which ones you starred.
  • product: your shop’s products, which manage_shop can sell to a client.

Write verbs

Direct, live writes — there’s no draft queue and no Apply step. They’re the reversible, everyday kind of change (you can edit or undo them in the dashboard). No verb permanently deletes; the only delete actions are manage_content delete_article and delete_audience, and both delete nothing without confirm: true. An edit that would remove existing weeks or rows from a program, workout or nutrition template is refused until it is repeated with confirmDelete: true, and every agent edit to those three is saved in the item’s version history so it can be restored.

A top-level argument a verb does not take - or one the chosen action does not read - is refused with the list of arguments it does take, and nothing is written. It used to be ignored while the call reported success.

Verb What it does Notable inputs / actions
manage_client Create or update a client in one call — core details, the three profiles (health / fitness / nutrition), lifecycle stage, trainer assignment, access tier, and the tenant’s stage list. create {…}, clientId, healthProfile, fitnessProfile, nutritionProfile, lifecycleStageId, assignTrainerId, accessTier: LEAD · LOW_TICKET · CLIENT; nested lifecycleStage action: create · update · reorder
build_program Create or edit a program’s structure (sections, phases, content), copy one into your library, or translate it. Copying onto a client is assign_program. action: build · translate; programType: WORKOUT · NUTRITION · FULL; name, sections, phases, metadata (incl. startDate, endDate), duplicateFrom, targetLocale, confirmDelete, importWorkoutId
assign_program Lifecycle & assignment on a program — deep-copies a template onto a client, activates, pauses, expires, etc. action: assign · activate · deactivate · expire · move · unlink; copyFromProgramId, userId, startDate
build_workout Create or edit a workout — as a reusable template or straight onto a client — or copy one into your library. difficulty: EASY · MODERATE · HARD · VERY_HARD; goal: WEIGHT_LOSS · MUSCLE_GAIN · STRENGTH · ENDURANCE · FLEXIBILITY · SPORT_SPECIFIC · GENERAL_FITNESS · REHABILITATION; exercises, isTemplate, duplicateFrom, confirmDelete
build_nutrition Create or edit a nutrition template, or copy one into your library; macros are computed from the items. name, items (meal headers + food rows), userId, duplicateFrom, confirmDelete
record_progress Record a progress entry, draft/approve a progress report (one or a batch), take back a sent one, or add a meeting note. action: entry · report · note; report sub-action: update · approve · approve_many · discard · unsend
manage_library Tenant library: create/update an exercise, resolve food names to library foods, or star/unstar an exercise in your Favorites. action: create_exercise · update_exercise · resolve_foods · favorite_exercise · unfavorite_exercise
manage_forms Create or update a form (questions, theme, settings). A habit form can include your own custom habits. action: create · update; presentationType: SINGLE_PAGE · MULTI_PAGE · HABIT_TRACKING · PROGRESS_TRACKING · INTAKE
manage_tasks The whole kanban surface — tasks (including repeating and private ones), subtasks, boards, columns, labels. action (16): create_task, update_task, complete_task, move_task, archive_completed, create_subtask, update_subtask, toggle_subtask, reorder_subtasks, create_board, update_board, create_column, update_column, reorder_columns, create_label, update_label
review_inbox The coach’s “what needs me” bundle (dashboard, notifications, unread count, insights) plus triage. action: overview · mark_read · mark_all_read · dismiss_insight · mark_insight_read
manage_media Media library — register a hosted URL, manage categories, and shares. Never emails. action: attach · update · create_category · update_category · share · update_share
manage_content Articles: write from Markdown, edit, publish (checked against the claims rules first), attach to a program, and save audiences. action: create_article · update_article · publish_article · unpublish_article · attach_to_program · create_audience
manage_support Work a support ticket that’s already been filed — add a comment to its thread. Moving status or priority is Protocol-team-only and is refused for a coach’s key. Reading is find / get with kind=support_ticket. action: comment · set_status; ticketId, body
manage_shop Shop bookkeeping: record money a client already paid against their purchase (record_payment). Recording a sale to a client (create_purchase) needs send access, see below. Never charges a card, refunds, or sends an invoice. action: create_purchase · record_payment; purchaseId, invoiceId, amount, date, note
report_to_developers Escalate a gap to Protocol’s developers — files a tracked support ticket on your account (and notifies our internal inbox). Never reaches a client. summary (required), goal, toolOrArea, error

Send verbs

No whole verb needs the send level. schedule, manage_automations and manage_shop all work at read + write: booking, cancelling, configuring, creating and pausing automations, and recording a payment are all ordinary internal writes.

Four individual actions, and three flags, reach a person outside your account and need read + write + send, so reaching a person is always a deliberate choice. The actions:

  • schedule with action: send_reminder, which fires a client reminder now.
  • schedule with action: reminder, which arms a recurring client reminder. It reads like a passive setting and is not one: it fires within minutes if the start time is now or in the past.
  • manage_automations with action: run, whose follow-up steps can email or message a client.
  • manage_shop with action: create_purchase, which records a sale to a client. It never charges a card, but the purchase shows in the client’s app, and an installment plan or a time-limited purchase can trigger payment and expiry reminders to the client if you have those switched on.

The flags, each off by default, turn an ordinary write into an outward one:

  • schedule create / update / cancel with notifyParticipants: true emails every guest an invitation, update or cancellation with a calendar file.
  • record_progress report approve / approve_many with notifyClient: true pushes the client.
  • manage_client create with sendAccessInstructions: true emails the new client a login code.

At read + write, those specific calls are refused, and the same calls without the flag work.

Verb What it does The outward action
schedule Calendar — create / update / cancel appointments, configure booking, and manage reminders. action: create · update · cancel · reminder · booking_config · gcal_disconnect · send_reminder — send_reminder fires a client reminder now, and reminder arms a recurring one (it fires within minutes if the start time is now or past)
manage_automations Build and operate automations. action: create · update · activate · pause · archive · run — run dispatches an execution
manage_shop Record a sale or a payment received. action: create_purchase · record_payment - create_purchase bills a client (no card is charged)

What’s deliberately not in the surface

  • The legacy CRUD tools. Under the hood these 23 verbs delegate to a larger internal library of fine-grained operations. Those are an implementation detail — they’re not exposed to your assistant, by design. You drive intent; Protocol composes the steps.
  • The four hard limits, at any access level, on this MCP verb surface. No verb exists to send a client a message (the agent can only leave a draft for you to send), charge, refund or invoice (the shop verb is bookkeeping only), permanently delete a record, or generate with Protocol’s own AI. These have no tool at all here, for an agent key at any access level. A REST API key is a different credential with no verb surface at all; see Safety, scopes & privacy.

Stability

The verb names, kinds, and actions above are the stable contract your assistant builds against. We add capability inside existing verbs (new kinds, new actions) far more often than we add new verbs — so a client written against this surface keeps working. This page is bumped whenever the surface changes; the last-reviewed date at the top tells you when it last matched the live server.


Back to: AI agent overview · Connecting your assistant · Safety, scopes & privacy

Protocol is a wellness and optimization platform. It is not a medical device and does not diagnose, treat, cure or prevent any disease. Ranges and trends shown in the product are wellness reference points, not clinical thresholds. Always discuss your health, and any result that concerns you, with a qualified healthcare provider.