> ## Documentation Index
> Fetch the complete documentation index at: https://docs.goosybear.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Call desk.build_card

> Write a small custom card for this workspace — a little self-contained page, coded from the brief you give it, rendered in a sandbox and readable at its own address. Use it when what is wanted is not one of the ordinary elements: a bespoke view, a calculator, a countdown, a table shaped a particular way. Carry the operator's own sentence into brief; it is the whole instruction the card is written from. If the card needs live data, pass every Data table it may read in data_table_ids — a table you do not pass is a table the card can never see. This runs a PAID authoring session, so it takes two calls: the first describes what would be built, charges nothing and returns a confirmation id, and the second — carrying that id back — is what actually builds it. It returns the card and does NOT put it on any board: placing an element is a desk action, and there is no verb here that can do it.

Every result names the workspace it ran in. Say which workspace the answer is about. When the account has more than one workspace and none is selected, this tool refuses with `workspace_ambiguous` and lists the choices — offer them, never pick one.



## OpenAPI

````yaml /openapi.json post /api/v1/tools/desk.build_card
openapi: 3.1.0
info:
  title: Goosy Bear API
  version: 1.0.0-beta
  summary: Manage workspace content, projects, Data tables, Pages, library and credits.
  description: >-
    BETA. This API is in beta: paths, request shapes and response envelopes may
    change, and every response carries an `x-goosy-api: beta` header for as long
    as that is true. Pin the OpenAPI document you generated against and
    re-generate when it changes.
servers:
  - url: https://app.goosybear.ai
    description: Production
security:
  - tenantApiKey: []
paths:
  /api/v1/tools/desk.build_card:
    post:
      tags:
        - desk
      summary: Call desk.build_card
      description: >-
        Write a small custom card for this workspace — a little self-contained
        page, coded from the brief you give it, rendered in a sandbox and
        readable at its own address. Use it when what is wanted is not one of
        the ordinary elements: a bespoke view, a calculator, a countdown, a
        table shaped a particular way. Carry the operator's own sentence into
        brief; it is the whole instruction the card is written from. If the card
        needs live data, pass every Data table it may read in data_table_ids — a
        table you do not pass is a table the card can never see. This runs a
        PAID authoring session, so it takes two calls: the first describes what
        would be built, charges nothing and returns a confirmation id, and the
        second — carrying that id back — is what actually builds it. It returns
        the card and does NOT put it on any board: placing an element is a desk
        action, and there is no verb here that can do it.


        Every result names the workspace it ran in. Say which workspace the
        answer is about. When the account has more than one workspace and none
        is selected, this tool refuses with `workspace_ambiguous` and lists the
        choices — offer them, never pick one.
      operationId: call_desk_build_card
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                title:
                  type: string
                  minLength: 1
                  maxLength: 120
                  description: What to call the card — its label on the desk.
                brief:
                  type: string
                  minLength: 1
                  maxLength: 4000
                  description: What the card should show, in the member's own words.
                data_table_ids:
                  type: array
                  items:
                    type: string
                    format: uuid
                  maxItems: 8
                  description: >-
                    Every Data table this card may read, and the only ones.
                    Leave it out for a card that reads nothing.
                confirmation_id:
                  type: string
                  format: uuid
                  description: >-
                    Leave this out on the first call: the answer describes what
                    would be built, charges nothing and hands you an id. Send
                    that id back, unchanged, to actually build it.
                workspace:
                  type: string
                  minLength: 1
                  description: >-
                    Which workspace to run in — its slug. Omit to use your
                    default. With more than one reachable workspace and no
                    default, the call is refused and the choices are listed.
              required:
                - title
                - brief
              additionalProperties: false
      responses:
        '200':
          description: >-
            The call was admitted and dispatched. `ok` says whether the tool
            succeeded — a refusal the tool itself produced is still a 200,
            exactly as it is a successful JSON-RPC result over MCP.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-goosy-tool-error:
              description: >-
                `true` when a boundary step refused the call — workspace
                resolution failed or could not be read. A tool that ran and
                returned its own typed `ok: false` reports `false` here.
                **Branch on `ok` in the body for the outcome; this header is the
                transport-level hint.**
              schema:
                type: string
                enum:
                  - 'true'
                  - 'false'
          content:
            application/json:
              schema:
                oneOf:
                  - type: object
                    description: The tool ran and answered.
                    properties:
                      ok:
                        type: boolean
                        const: true
                      state:
                        type: string
                        enum:
                          - confirmation_required
                          - built
                        description: >-
                          confirmation_required — nothing was written and
                          nothing was charged; built — the card exists.
                      title:
                        type: string
                        description: What the card is called.
                      confirmation_id:
                        type: string
                        format: uuid
                        description: Present only while confirmation is required.
                      expires_in_seconds:
                        type: integer
                        exclusiveMinimum: 0
                        description: How long that confirmation stays usable.
                      request_summary:
                        type: string
                        description: >-
                          Present only while confirmation is required — what
                          will be built, in one sentence, for a person to
                          approve.
                      card_id:
                        type: string
                        format: uuid
                        description: Present once built — the card's durable identity.
                      revision:
                        type: string
                        description: Present once built — the build this card is now on.
                      entry:
                        type: string
                        description: Bundle-relative path of the document the frame loads.
                      file_count:
                        type: integer
                        minimum: 0
                      bytes:
                        type: integer
                        minimum: 0
                      reads:
                        type: array
                        items:
                          type: string
                        description: >-
                          What this build declared it may read, and the only
                          ones.
                      door_url:
                        type:
                          - string
                          - 'null'
                        description: >-
                          Present once built — a short-lived address that
                          renders this card. Null when one could not be signed
                          for this environment; the card is still built. Treat
                          it as a secret: it is a bearer capability and it
                          expires.
                      workspace:
                        type: string
                        description: The slug of the workspace this call ran in.
                      working_in:
                        type: object
                        properties:
                          label:
                            type: string
                            description: 'The chip words — e.g. "working in: Acme Main".'
                          note:
                            type: string
                            description: >-
                              Why this workspace — e.g. "your default", "this
                              call only".
                          workspace:
                            type: string
                            description: The resolved workspace's slug.
                          source:
                            type: string
                            enum:
                              - call-override
                              - key-pin
                              - stored-default
                              - sole-reachable
                            description: >-
                              Which rung of the R7 precedence resolved the
                              workspace.
                        required:
                          - label
                          - note
                          - workspace
                          - source
                        additionalProperties: false
                        description: >-
                          Which workspace this call ran in, and how that was
                          decided. Present on every workspace-scoped result.
                    required:
                      - ok
                      - state
                      - title
                      - working_in
                      - workspace
                  - $ref: '#/components/schemas/ToolRefusal'
        '400':
          description: >-
            The request body could not be used: it is present but not a JSON
            object (`tenant_api.malformed_body`), or it is a top-level array
            carrying more messages than this endpoint accepts
            (`tenant_mcp.batch_too_large`). Send the tool's arguments as a JSON
            object, or omit the body entirely.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            No bearer credential, or one that did not resolve. Deliberately ONE
            undifferentiated answer for absent / unknown / revoked / expired, so
            the endpoint is never an oracle over the key space.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            The credential is good but the surface is not open to it — the
            platform or account API switch is off, or the holder lacks the
            `api.access` capability. The `code` says which.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            No such tool. The body names no tool and is identical for every
            unrecognised name.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            Over this key's per-minute cap. Carries `Retry-After` and
            `error.retry_after_seconds`.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            Retry-After:
              description: Whole seconds to wait before retrying.
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ToolRefusal:
      type: object
      properties:
        ok:
          type: boolean
          const: false
        code:
          type: string
          description: >-
            The typed reason — e.g. `workspace_ambiguous`, `invalid_arguments`,
            or the tool's own failure code.
        message:
          type: string
          description: A sentence a person can act on.
        workspaces:
          type: array
          items:
            type: string
          description: 'On a workspace refusal: the slugs this key may pass as `workspace`.'
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              message:
                type: string
            required:
              - path
              - message
            additionalProperties: false
          description: 'On `invalid_arguments`: which fields failed, and why.'
      required:
        - ok
        - code
        - message
      additionalProperties: false
      description: A call that was admitted and dispatched, and did not succeed.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: >-
                The typed refusal code — e.g. `tenant_mcp.surface_disabled`,
                `tenant_mcp.rate_limited`.
            message:
              type: string
              description: A sentence a person can act on.
            retry_after_seconds:
              type: number
              description: 'On a 429: whole seconds to wait. Mirrors `Retry-After`.'
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        A request the boundary refused before dispatching anything. The same
        shape the MCP endpoint answers its own refusals with, so one client
        branch covers both transports.
  securitySchemes:
    tenantApiKey:
      type: http
      scheme: bearer
      description: >-
        An API key minted at Settings › API & MCP. Send it as `Authorization:
        Bearer <key>`. A key carries its holder's own permissions, resolved on
        every call — revoking a membership closes the key's reach immediately.
        Keep it in an environment variable (`GOOSY_API_KEY`), never in a
        committed file.

````