Skip to content

Tools

zorvik mcp offers 38 tools. Agents read their full JSON schemas (every field, unit and placeholder) from tools/list; this page is the human overview. The Asks column says when you are asked, with the default settings (see Permissions and safety):

  • no: never asks.
  • edit: an edit. Allowed by default; asks when Edits by agents is Ask me.
  • traffic: sends network requests. Asks for hosts outside this computer and private networks by default (Requests sent by agents).
  • always: always asks.

Every tool is annotated for the client: readOnlyHint (reads only), destructiveHint (only delete_items) and openWorldHint (talks to other systems).

  • Paths of requests and folders are relative to the workspace’s requests/ folder, with / between folders, exactly as list_requests shows them: Users/Get user.yaml, Users/Admin. "" means the whole collection.
  • Names of environments, load tests and servers match without regard to case; their file id works too.
  • Long calls (run_collection, run_load_test, the status tools) wait up to waitSeconds (default 45, at most 600) and then return a runId to poll. Some agents give up on a call after 60 seconds, hence the default.
  • Strict input: save_requests, send_request (with request), save_server and save_load_test refuse fields they don’t know, name the nearest known one (“did you mean status?”) and save nothing, so a typo is never saved silently.
  • Redaction: secret variable values come back as {{name}} and credential headers as ••••••, in results and errors alike. See Redaction.
  • No workspace open: tools that need one fail with a message telling the agent to ask you which folder to use and call open_workspace.
ToolWhat it doesMain inputsAsks
get_workspaceThe open workspace: name, folder, request and folder counts, environments and the active one, collection variable names, load test and server counts. With none open: the recent workspaces. The agent is told to call this first.noneno
open_workspaceOpen another workspace folder, or create a workspace there.path (absolute folder), create (make one when the folder isn’t a workspace), name (of a new workspace)always
open_in_appShow something in the Zorvik window: a request, a folder’s runner, a load test, a server or the environments. It opens even when Follow agents is off.one of request, runner (folder path), loadTest, server, environments: trueno
ToolWhat it doesMain inputsAsks
list_requestsFolders and requests of the collection or one folder, with method and URL.folderno
read_requestEverything saved in one or more requests: URL, query and path parameters, headers, body, auth, scripts, settings, docs, examples.path, or paths (up to 50)no
save_requestsCreate or update up to 200 requests. Each goes into folder (created when missing) under its name; a request with that name there is updated. Only the fields given change, unless replace: true. Give path to update that exact request.requests[]: name, folder or path, kind, method, url, query, pathParams, headers, body, auth, scripts, settings, grpc, docs, examples; replaceedit
save_folder_settingsAuth, headers, scripts and docs that requests in a folder inherit, merged into what is there. folder: "" is the collection, which also has variables (merged by key).folder, auth, headers, scripts, docs, variablesedit
move_itemMove a request or folder to another folder and/or rename it. Load tests that send it follow.path, toFolder, newNameedit
delete_itemsMove requests, folders, environments, load tests or servers to the trash. Deleting a load test also deletes its run history.paths, environments, loadTests, serversalways
export_requestA request as a ready-to-run command or code: cURL for bash (curl), Windows cmd (curlCmd) or PowerShell (curlPowerShell), or code: javascript (fetch), javascriptAxios, python (requests), pythonHttpx, go, java, kotlin (OkHttp), swift, csharp, php, ruby, rust, dart, c (libcurl), powerShell, httpie or wget. Comments at the top say what the code can’t do that Zorvik does (answer a Digest challenge, sign each request). Variables are filled in unless resolveVariables: false; secret values come back as •••••• (you can copy the full version in Zorvik).path or request (+ folder), format, resolveVariablesno

Request fields for save_requests and send_request:

FieldNotes
kindhttp (default), grpc, dns, websocket, socketio, sse, tcp, udp, mqtt, mcp. GraphQL is http with a graphql body. For mcp, url is the MCP server’s URL or the command that starts it.
methodHTTP method (default GET). gRPC: package.Service/Method. DNS: the record type.
urlFull URL with {{variables}}; :name path segments take pathParams. gRPC: grpc:// or grpcs://. DNS: the name.
query[{key, value, enabled, description}]: enabled ones replace the URL’s query string, disabled ones are kept switched off.
pathParams[{key, value, description}] for :name segments.
headers[{key, value, enabled}] (an object of name → value works too).
bodytype (none, json, text, xml, formUrlencoded, multipart, binary, graphql) and text, contentType, form, multipart, file or graphql {query, variables, operationName}.
authtype (inherit, none, basic, bearer, apiKey, oauth2, oauth1, jwt, digest, ntlm, awsSigV4, hawk, akamaiEdgeGrid, asap) and its fields, as in the workspace files. Secrets belong in secret variables ({{awsSecretKey}}).
scriptspreRequest, postResponse (Postman pm API).
settingstimeoutMs, followRedirects, verifyTls.
grpcprotoFiles (inside the workspace; empty: server reflection).
mcpcall (tool, resource or prompt), name (the tool or prompt, or the resource URI), arguments (a JSON object, or JSON text), transport (auto, streamableHttp, sse, stdio), and for programs cwd and env ([{key, value}] or an object). See MCP client.
docsMarkdown notes.
examples[{name, status, headers, body}]: saved responses (bodies up to 1 MB). Mocks built from the request answer with them. Replaces the request’s examples.
ToolWhat it doesMain inputsAsks
list_environmentsEnvironments and their variables, the active one, and the collection variables. Values scripts saved are included and marked setByScript. Secret values show as ••••••.noneno
save_environmentCreate an environment or update its variables, merged by key (replace sets exactly these). Mark credentials secret: true: their values stay on this computer.name, variables[] {key, value, secret, enabled}, replace, activateedit
set_active_environmentMake an environment active, or none with "".nameedit
get_variablesThe variables requests use right now, as Zorvik resolves them (active environment, then collection, then globals, with values scripts saved), each with its source. Useful after a run that saved ids or tokens.noneno
ToolWhat it doesMain inputsAsks
importImport a Postman collection or environment, an OpenAPI 3 or Swagger 2 document, or a cURL command, from its text, a URL or an absolute file path. OpenAPI documents are kept in specs/, their path parameters become {{variables}} with example values in a new environment, and responses are checked against the documented schemas.exactly one of text, url, file; folder; baseUrl (OpenAPI without a full server URL)edit; a url also traffic; a file always
update_from_openapiUpdate a folder imported from OpenAPI from a new version of the document: new operations added, changed ones updated field by field where you left the old value, removed ones kept and marked removed. Scripts, settings and names are never touched. Call with preview: true first.folder; one of text, url, file; previewedit; a url also traffic; a file always
ToolWhat it doesMain inputsAsks
send_requestSend a saved request (path), a saved one with changes (path + request, nothing is saved), or an unsaved one (request, optionally inheriting a folder’s auth and headers), with its scripts and tests. Returns status, time, URL, HTTP version, headers, body (up to maxBodyChars), redirects, the request as sent, unresolved variables, test results, console and script errors. The response also shows in Zorvik.path, request, folder, maxBodyChars (default 20,000, at most 80,000), stream, filtertraffic
graphql_schemaThe schema of a GraphQL endpoint by introspection, as SDL.path or request, maxChars (default and at most 60,000)traffic
grpc_describeServices and methods of a gRPC server, from the request’s .proto files or server reflection.path or requesttraffic
mcp_catalogWhat an MCP request’s server offers: its name, version, instructions, tools (with input schemas), resources, resource templates and prompts, to call them with send_request.path or request (kind mcp), maxChars (default and at most 60,000)traffic; a program always asks

send_request supports HTTP, GraphQL, gRPC (unary calls), DNS, MCP and Server-Sent Events. An MCP request makes its one call (a tool, a resource read or a prompt) in one go, and the response’s body is the answer as JSON (status 500 for a JSON-RPC error), so its scripts and tests work as for HTTP. When the request starts a program (a stdio server), the user is asked every time, with the command, folder and environment. An SSE request is read until the first event named stream.untilEvent (message for unnamed events), stream.maxEvents events (default 100; 0 for only the time limit), or stream.timeoutMs (default 10,000, at most 120,000), and returns the events. A GraphQL subscription is read the same way, each result an event named next. WebSocket, Socket.IO, TCP, UDP and MQTT are live sessions that agents can’t use yet: the tool says so.

To keep a large JSON response short, give send_request a filter: {language: "jsonPath", expression: "$.items[*].id"} or {language: "jq", expression: ".items | map(.id)"}. It runs on the whole body; the matches replace body, with filtered: {matches, truncated}, or filterError when the expression is wrong.

ToolWhat it doesMain inputsAsks
run_collectionRun the requests of a folder (or the collection) with their scripts and tests, like the Runner tab, which shows it live. Returns the summary and the failures (up to 50), or a runId if it runs longer than waitSeconds.folder, requests (only these paths, in this order), iterations, delayMs, dataFile (inside the workspace), stopOnFailure, waitSecondstraffic
get_run_statusA run’s summary and failures once finished; waits up to waitSeconds.runId, waitSecondsno
stop_collection_runStop the run in progress.runIdno
ToolWhat it doesMain inputsAsks
list_load_testsSaved load tests (id, name, model, number of targets, duration) and the one running (name, runId, planned time).noneno
read_load_testA load test’s targets, model, stages, thresholds and options.nameno
save_load_testCreate or replace a load test. Latency thresholds in milliseconds, errorRate in percent (1 = 1 %; values outside 0 to 100 are refused), rps in requests per second.name, test {targets, dataFile, model, stages, thinkTimeMs, maxInFlight, keepAlive, timeoutMs, httpVersion, thresholds, docs}edit
run_load_testStart a saved load test and return its results when it ends within waitSeconds (without the per-second chart points); otherwise the runId and a live snapshot. waitSeconds: 0 returns as soon as it starts.name, waitSecondsalways
get_load_test_statusLive numbers of the running test, or the results of a finished run.name, runId, waitSecondsno
stop_load_testStop the running load test. Its result is kept in the history.noneno

The test object uses the load test file format: targets[] {request, weight, enabled, captures[] {variable, from, path}}, stages[] {durationSecs, target}, thresholds[] {metric, op, value, target, enabled} and the options. See Load testing.

ToolWhat it doesMain inputsAsks
list_serversSaved mock APIs and servers (HTTP, MCP, WebSocket, Socket.IO, SSE, TCP, UDP, DNS, relay): kind, address, route count, and which are running.noneno
read_serverA server’s full definition, in the shape save_server takes.nameno
save_serverCreate a server or change one. Changes merge like a JSON Merge Patch: objects merge, arrays (routes, rules, records) replace the whole list, null resets a field; replace: true saves exactly what is given. A running server takes the change at once (a new address, port, TLS or kind needs a restart).name, server (the server format), replaceedit
create_mockBuild a mock API from a folder (each HTTP request becomes a route answering with its saved example response or a 200) or from an OpenAPI 3 / Swagger 2 document (each operation answers with its first 2xx example). Returns the new server; start it with start_server.name (default “Mock API”), one of folder, openapiText, openapiUrl, openapiFile; port (default: the next free port from 4000)edit; openapiUrl also traffic; openapiFile always
start_serverStart a saved server. port overrides the saved port for this run only; 0 picks any free port. When the port is taken, the error names the program holding it.name, portalways
stop_serverStop a running server.nameno
get_server_trafficWhat a running server received and answered, newest last. HTTP mocks: method, path, request headers and body, the matched route (null: no route, the fallback answered), status, response headers and body (bodies up to 4,000 characters), time. Other kinds: connections and messages. The server keeps its last 5,000 entries while it runs.name, limit (default 50, at most 500), sinceId (the lastId of the previous call)no
ToolWhat it doesMain inputsAsks
read_historyRequests sent from Zorvik (by you or by agents), newest first: method, URL, status, time, size, and for the last 50 sends the response headers and body.limit (default 20, at most 100), path, search, maxBodyChars (default 4,000, at most 20,000; 0 for none)no
write_filePut a file of up to 10 MB into the workspace folder: a sample upload, a CSV or JSON data file, a .proto file. An existing file is replaced only with overwrite: true. It can’t write outside the workspace, through a symbolic link, or into zorvik.yaml, requests/, environments/, servers/, loadtests/ or .git.path (relative, / between folders), text or base64, overwriteedit
  • Read or change settings, cookies or secret values. There is no tool for them.
  • Use live sessions: WebSocket, Socket.IO, TCP, UDP and MQTT requests (they can save them, not send them).
  • Delete permanently: deletes go to the trash, after you confirm.
  • Read files outside the workspace during a call, except a file you approve for import, update_from_openapi or create_mock.

See Permissions and safety for the rules behind the Asks column.