Logo
Search
Docs

Fields & validation

Every field with its exact validation rule, nullability, and the database column that stores it.

Tool

FieldTypeRequiredNullableRules (verbatim)DB column
namestringyesnorequired|string|max:100tools.name
typestringyesnorequired|string|in:apiRequest,function,transferCall,endCall,dtmf,voicemail,handoff,query,mcptools.type
user_idintegernoyesnullable|integer|exists:users,id (admins only)tools.user_id
reseller_idstringnoyesnullable|uuid|exists:resellers,id (super admins only)tools.reseller_id
isGlobalbooleannoyesnullable|boolean (super-admin only — sets user_id to null)—
functionNamestringnoyesnullable|string|max:64|regex:/^[a-zA-Z0-9_-]+$/tools.function_def
descriptionstringnoyesnullable|string|max:2000tools.description
parametersarraynoyesnullable|array — validated as a whole treetools.function_def
parametersLockSchemabooleannoyesnullable|booleantools.function_def
strictbooleannoyesnullable|booleantools.function_def
serverobjectnoyesnullable|arraytools.server
variableExtractionPlanobjectnoyesnullable|arraytools.variable_extraction_plan
destinationsarraynoyesnullable|arraytools.destinations
knowledgeBasesarraynoyesnullable|array — query tools; stored on function_deftools.function_def
rejectionPlanobjectnoyesnullable|arraytools.rejection_plan
messagesarraynoyesnullable|arraytools.messages
asyncbooleannoyesnullable|booleantools.async
metadataobjectnoyesnullable|arraytools.metadata

server (apiRequest / function)

FieldRules (verbatim)
server.urlnullable|url|max:2000
server.methodnullable|string|in:GET,POST,PUT,PATCH,DELETE
server.timeoutSecondsnullable|integer|min:1|max:300
server.headersrows of {key, value} — blank keys are dropped
server.bodyPropertiesrecursive tree of {name, type, description, required, enum, value, itemType, children}; type in string,number,integer,boolean,object,array; children only for object/array-of-object nodes
server.staticFieldsrows of {key, type, value}, type in string,number,boolean,object
server.lockSchemanullable|boolean
server.encryptedFields.*string|max:200
server.backoffPlan.typenullable|string|in:fixed,exponential
server.backoffPlan.maxRetriesnullable|integer|min:0|max:10
server.backoffPlan.baseDelaySecondsnullable|integer|min:0|max:300
server.backoffPlan.excludedStatusCodes.*integer|min:100|max:599
server.credentialIdnullable|string|max:100 — a personal credential's public id
server.staticIpAddressesEnablednullable|boolean
server.serverEncryptedPaths.*string|max:200
server.sipInfoDtmfEnablednullable|boolean — dtmf tools only
server.beepDetectionEnablednullable|boolean — voicemail tools only

variableExtractionPlan (apiRequest)

FieldRules (verbatim)
variableExtractionPlan.properties.*.namenullable|string|max:100
variableExtractionPlan.properties.*.typenullable|string|in:string,number,integer,boolean,object,array
variableExtractionPlan.properties.*.descriptionnullable|string|max:1000
variableExtractionPlan.properties.*.requirednullable|boolean
variableExtractionPlan.properties.*.enumarray of strings, or comma-separated string
variableExtractionPlan.aliases.*.key / .valuerows of {key, value} — blank keys are dropped

destinations (transferCall / handoff)

FieldRules (verbatim)
destinations.*.typenullable|string|in:number,sip,assistant,dynamic,squad
destinations.*.numbernullable|string|max:50
destinations.*.extensionnullable|string|max:20
destinations.*.callerIdnullable|string|max:50
destinations.*.sipUrinullable|string|max:255
destinations.*.assistantId / .assistantNamenullable|string|max:100 / max:255
destinations.*.squadIdnullable|string|max:100
destinations.*.entryAssistantNamenullable|string|max:255
destinations.*.transferModenullable|string|in:rolling-history,swap-system-message-in-history,swap-system-message-in-history-and-remove-transfer-tool-messages,delete-history
destinations.*.messagenullable|string|max:1000
destinations.*.descriptionnullable|string|max:2000
destinations.*.numberE164CheckEnablednullable|boolean
destinations.*.sipHeadersrows of {key, value}
destinations.*.server.urlnullable|url|max:2000 — handoff dynamic destinations only
destinations.*.server.timeoutSecondsnullable|integer|min:1|max:300
destinations.*.contextEngineeringPlan.typenullable|string|in:none,all,lastNMessages,userAndAssistantMessages,previousAssistantMessages
destinations.*.contextEngineeringPlan.maxMessagesnullable|integer|min:1|max:1000
destinations.*.transferPlan.modenullable|string|max:80
destinations.*.transferPlan.messagenullable|string|max:1000
destinations.*.transferPlan.sipVerbnullable|string|in:refer,bye,dial
destinations.*.transferPlan.timeout / .dialTimeoutnullable|integer|min:1|max:600
destinations.*.transferPlan.holdAudioUrl / .transferCompleteAudioUrlnullable|string|max:2000
destinations.*.transferPlan.twimlnullable|string|max:4000
destinations.*.transferPlan.sipHeadersInReferToEnablednullable|boolean

A destination is only kept if it carries a real target: a number, sipUri, assistantName/assistantId, squadId, or dynamic server.url.

rejectionPlan & messages

FieldRules (verbatim)
rejectionPlan.conditions.*.typenullable|string|in:regex,liquid
rejectionPlan.conditions.*.valuenullable|string|max:2000
messages.*.typerequired_with:messages|string|in:request-start,request-complete,request-failed,request-response-delayed
messages.*.modenullable|string|in:default,none,custom — request-start only
messages.*.contentnullable|string|max:1000
messages.*.contents.*.textnullable|string|max:1000 — one of several variants, picked at random
messages.*.blockingnullable|boolean
messages.*.rolenullable|string|in:assistant,system
messages.*.endCallAfterSpokenEnablednullable|boolean
messages.*.timingMillisecondsnullable|integer|min:100|max:120000 — request-response-delayed only
messages.*.conditions.*.operatornullable|string|in:eq,neq,gt,gte,lt,lte

Only the fields each message type actually supports upstream are kept — e.g. role is dropped from a request-start message.

Credential (Credentials group)

FieldRequiredRules (verbatim)
provideryes*required|string|in:custom-credential,webhook — *defaults to custom-credential when omitted
namenonullable|string|max:40
authenticationPlanyesrequired|array
authenticationPlan.typeyesrequired|string|in:bearer,oauth2,hmac — immutable after creation
authenticationPlan.tokenbearer"Token is required." when missing
authenticationPlan.url, .clientId, .clientSecretoauth2"Token URL, Client ID and Client Secret are required." when any is missing
authenticationPlan.secretKey, .algorithmhmac"Secret Key and Algorithm are required." when either is missing
encryptionPlan.publicKeynooptional PEM public key — encrypts the stored secret

Constraints the rules cannot express

  • type is fixed at creation — the update endpoint validates it but strips it before writing to the live platform, so it can never change an existing tool's type.
  • function_def.name (the callable name) always exists, even for apiRequest tools: it's the explicit functionName, or a sanitised slug of name, capped at 64 characters.
  • Drafts (POST /tools/draft, PUT /tools/{id}/draft) accept any partial shape — the strict ruleset above only applies on publish (store/update/publish).
  • A destination is dropped entirely if it has no real target after normalisation.
  • Only super admins can set isGlobal or assign reseller_id; only content admins/super admins can assign user_id to someone else.
  • A credential's authenticationPlan.type cannot change across an update — a differing type is rejected with 422.
  • The live platform is written first on publish; on failure nothing is saved locally.