> ## Documentation Index
> Fetch the complete documentation index at: https://docs.goosybear.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Call page.list_files

> Show which FILES a site is actually built from — 'what files does this site have?', 'show me the code', 'which file is the hero in?', 'where does the pricing copy live?'. No site id is needed — it works on the site the member has open on screen. Reach for it to find where something lives before changing it, or when the member wants to see the source itself. It is the same tree the Files board shows, for every site whose files we hold, however it was made or brought in. A site we hold no source for answers kind: no_source_snapshot; say so rather than inventing files. A BIG PROJECT ANSWERS IN PAGES: total is the real file count, and when truncated is true the result carries next_offset — call again with offset: next_offset AND source_ref: the result's source_ref to read on (an offset without source_ref, or one whose files changed in between, is not paged: the answer says tree_changed: true and restarts from the first page — read it over rather than joining the lists), or pass path_prefix (`app/`, `components/`, `src/pages/`) to walk one directory at a time. NEVER guess a path: if you have not seen it listed here, page or narrow until you have. CHECK can_write: when it is false this site's files are READ-ONLY here — read them and answer questions about them, but do not offer or attempt an edit, because page.patch_file and page.edit_file will refuse it. To find WHERE some words live — the date, headline or sentence a member wants changed — pass contains with a short fragment of them: only the files holding it are listed, each with match_line and match_text. Read one with page.read_file before changing it. Not for what is inside one file — that is `page.read_file`.

Every result names the workspace it ran in. Say which workspace the answer is about. When the account has more than one workspace and none is selected, this tool refuses with `workspace_ambiguous` and lists the choices — offer them, never pick one.



## OpenAPI

````yaml /openapi.json post /api/v1/tools/page.list_files
openapi: 3.1.0
info:
  title: Goosy Bear API
  version: 1.0.0-beta
  summary: Manage workspace content, projects, Data tables, Pages, library and credits.
  description: >-
    BETA. This API is in beta: paths, request shapes and response envelopes may
    change, and every response carries an `x-goosy-api: beta` header for as long
    as that is true. A change is additive, or it is deprecated first: a response
    to a call that uses a deprecated feature carries `Deprecation` and `Sunset`
    headers, and nothing is removed until at least 90 days after its
    deprecation. Pin the OpenAPI document you generated against and re-generate
    when it changes.
servers:
  - url: https://app.goosybear.ai
    description: Production
security:
  - tenantApiKey: []
paths:
  /api/v1/tools/page.list_files:
    post:
      tags:
        - page
      summary: Call page.list_files
      description: >-
        Show which FILES a site is actually built from — 'what files does this
        site have?', 'show me the code', 'which file is the hero in?', 'where
        does the pricing copy live?'. No site id is needed — it works on the
        site the member has open on screen. Reach for it to find where something
        lives before changing it, or when the member wants to see the source
        itself. It is the same tree the Files board shows, for every site whose
        files we hold, however it was made or brought in. A site we hold no
        source for answers kind: no_source_snapshot; say so rather than
        inventing files. A BIG PROJECT ANSWERS IN PAGES: total is the real file
        count, and when truncated is true the result carries next_offset — call
        again with offset: next_offset AND source_ref: the result's source_ref
        to read on (an offset without source_ref, or one whose files changed in
        between, is not paged: the answer says tree_changed: true and restarts
        from the first page — read it over rather than joining the lists), or
        pass path_prefix (`app/`, `components/`, `src/pages/`) to walk one
        directory at a time. NEVER guess a path: if you have not seen it listed
        here, page or narrow until you have. CHECK can_write: when it is false
        this site's files are READ-ONLY here — read them and answer questions
        about them, but do not offer or attempt an edit, because page.patch_file
        and page.edit_file will refuse it. To find WHERE some words live — the
        date, headline or sentence a member wants changed — pass contains with a
        short fragment of them: only the files holding it are listed, each with
        match_line and match_text. Read one with page.read_file before changing
        it. Not for what is inside one file — that is `page.read_file`.


        Every result names the workspace it ran in. Say which workspace the
        answer is about. When the account has more than one workspace and none
        is selected, this tool refuses with `workspace_ambiguous` and lists the
        choices — offer them, never pick one.
      operationId: call_page_list_files
      parameters:
        - name: x-request-id
          in: header
          required: false
          description: >-
            Your own id for this request, echoed back and recorded on the audit
            trail. 1–128 characters from `A–Z a–z 0–9 . _ : -`, starting with a
            letter or digit; anything else is replaced by a generated id.
          schema:
            type: string
            maxLength: 128
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                site_id:
                  type: string
                  format: uuid
                path_prefix:
                  type: string
                  maxLength: 1024
                offset:
                  type: integer
                  minimum: 0
                source_ref:
                  type: string
                  maxLength: 1024
                contains:
                  type: string
                  minLength: 1
                  maxLength: 1024
                workspace:
                  type: string
                  minLength: 1
                  description: >-
                    Which workspace to run in — its slug. Omit to use your
                    default. With more than one reachable workspace and no
                    default, the call is refused and the choices are listed.
              additionalProperties: false
      responses:
        '200':
          description: >-
            The call was admitted and dispatched. `ok` says whether the tool
            succeeded — a refusal the tool itself produced is still a 200,
            exactly as it is a successful JSON-RPC result over MCP.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            RateLimit-Limit:
              description: Requests this key may make in a rolling minute.
              schema:
                type: integer
                minimum: 1
            RateLimit-Remaining:
              description: Requests left in the current rolling minute.
              schema:
                type: integer
                minimum: 0
            RateLimit-Reset:
              description: Whole seconds until the window frees more requests.
              schema:
                type: integer
                minimum: 1
            x-goosy-tool-error:
              description: >-
                `true` when a boundary step refused the call — workspace
                resolution failed or could not be read. A tool that ran and
                returned its own typed `ok: false` reports `false` here.
                **Branch on `ok` in the body for the outcome; this header is the
                transport-level hint.**
              schema:
                type: string
                enum:
                  - 'true'
                  - 'false'
          content:
            application/json:
              schema:
                oneOf:
                  - type: object
                    description: The tool ran and answered.
                    properties:
                      ok:
                        type: boolean
                        const: true
                      site_id:
                        type: string
                        format: uuid
                      kind:
                        type: string
                        enum:
                          - source_snapshot
                          - no_source_snapshot
                      source_ref:
                        type: string
                      reason:
                        type: string
                        enum:
                          - bundle
                          - not_generated
                      can_write:
                        type: boolean
                      files:
                        type: array
                        items:
                          type: object
                          properties:
                            path:
                              type: string
                            size:
                              type: integer
                              minimum: 0
                            kind:
                              type: string
                              enum:
                                - page
                                - style
                                - script
                                - config
                                - image
                                - other
                            match_line:
                              type: integer
                              exclusiveMinimum: 0
                            match_text:
                              type: string
                          required:
                            - path
                            - size
                            - kind
                          additionalProperties: false
                      truncated:
                        type: boolean
                      total:
                        type: integer
                        minimum: 0
                      offset:
                        type: integer
                        minimum: 0
                      next_offset:
                        type: integer
                        minimum: 0
                      tree_changed:
                        type: boolean
                      workspace:
                        type: string
                        description: The slug of the workspace this call ran in.
                      working_in:
                        type: object
                        properties:
                          label:
                            type: string
                            description: 'The chip words — e.g. "working in: Acme Main".'
                          note:
                            type: string
                            description: >-
                              Why this workspace — e.g. "your default", "this
                              call only".
                          workspace:
                            type: string
                            description: The resolved workspace's slug.
                          source:
                            type: string
                            enum:
                              - call-override
                              - key-pin
                              - stored-default
                              - sole-reachable
                            description: >-
                              Which rung of the R7 precedence resolved the
                              workspace.
                        required:
                          - label
                          - note
                          - workspace
                          - source
                        additionalProperties: false
                        description: >-
                          Which workspace this call ran in, and how that was
                          decided. Present on every workspace-scoped result.
                    required:
                      - ok
                      - can_write
                      - files
                      - kind
                      - offset
                      - site_id
                      - total
                      - truncated
                      - working_in
                      - workspace
                  - $ref: '#/components/schemas/ToolRefusal'
        '400':
          description: >-
            The request could not be used: the body is present but not a JSON
            object (`tenant_api.malformed_body`); it is a top-level array
            carrying more messages than this endpoint accepts
            (`tenant_mcp.batch_too_large`); or the `Idempotency-Key` header is
            malformed (`tenant_api.idempotency_key_invalid`), disagrees with the
            body's `idempotency_key` (`tenant_api.idempotency_key_conflict`), or
            was sent to an action that cannot replay a retry
            (`tenant_api.idempotency_unsupported`). Nothing ran.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            Deprecation:
              description: >-
                RFC 9745: this refusal's nested `error` object is deprecated,
                since this instant (`@<unix seconds>`).
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594: the nested `error` object may be removed after this
                date (2026-12-31).
              schema:
                type: string
            Link:
              description: The page that says what to read instead (`rel="deprecation"`).
              schema:
                type: string
            RateLimit-Limit:
              description: Requests this key may make in a rolling minute.
              schema:
                type: integer
                minimum: 1
            RateLimit-Remaining:
              description: Requests left in the current rolling minute.
              schema:
                type: integer
                minimum: 0
            RateLimit-Reset:
              description: Whole seconds until the window frees more requests.
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            No bearer credential, or one that did not resolve. Deliberately ONE
            undifferentiated answer for absent / unknown / revoked / expired, so
            the endpoint is never an oracle over the key space.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            Deprecation:
              description: >-
                RFC 9745: this refusal's nested `error` object is deprecated,
                since this instant (`@<unix seconds>`).
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594: the nested `error` object may be removed after this
                date (2026-12-31).
              schema:
                type: string
            Link:
              description: The page that says what to read instead (`rel="deprecation"`).
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            The credential is good but the surface is not open to it — the
            platform or account API switch is off, or the holder lacks the
            `api.access` capability. The `code` says which.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            Deprecation:
              description: >-
                RFC 9745: this refusal's nested `error` object is deprecated,
                since this instant (`@<unix seconds>`).
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594: the nested `error` object may be removed after this
                date (2026-12-31).
              schema:
                type: string
            Link:
              description: The page that says what to read instead (`rel="deprecation"`).
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            No such tool. The body names no tool and is identical for every
            unrecognised name.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            Deprecation:
              description: >-
                RFC 9745: this refusal's nested `error` object is deprecated,
                since this instant (`@<unix seconds>`).
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594: the nested `error` object may be removed after this
                date (2026-12-31).
              schema:
                type: string
            Link:
              description: The page that says what to read instead (`rel="deprecation"`).
              schema:
                type: string
            RateLimit-Limit:
              description: Requests this key may make in a rolling minute.
              schema:
                type: integer
                minimum: 1
            RateLimit-Remaining:
              description: Requests left in the current rolling minute.
              schema:
                type: integer
                minimum: 0
            RateLimit-Reset:
              description: Whole seconds until the window frees more requests.
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            Over this key's per-minute cap. Carries `Retry-After` and
            `error.retry_after_seconds`.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-request-id:
              description: >-
                This request's id: the `x-request-id` you sent when it was well
                formed, otherwise one generated for you. Quote it to support; it
                is recorded on every audit row the call wrote.
              schema:
                type: string
            Deprecation:
              description: >-
                RFC 9745: this refusal's nested `error` object is deprecated,
                since this instant (`@<unix seconds>`).
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594: the nested `error` object may be removed after this
                date (2026-12-31).
              schema:
                type: string
            Link:
              description: The page that says what to read instead (`rel="deprecation"`).
              schema:
                type: string
            RateLimit-Limit:
              description: Requests this key may make in a rolling minute.
              schema:
                type: integer
                minimum: 1
            RateLimit-Remaining:
              description: Requests left in the current rolling minute.
              schema:
                type: integer
                minimum: 0
            RateLimit-Reset:
              description: Whole seconds until the window frees more requests.
              schema:
                type: integer
                minimum: 1
            Retry-After:
              description: Whole seconds to wait before retrying.
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ToolRefusal:
      type: object
      properties:
        ok:
          type: boolean
          const: false
        code:
          type: string
          description: >-
            The typed reason — e.g. `workspace_ambiguous`, `invalid_arguments`,
            or the tool's own failure code.
        message:
          type: string
          description: A sentence a person can act on.
        workspaces:
          type: array
          items:
            type: string
          description: 'On a workspace refusal: the slugs this key may pass as `workspace`.'
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              message:
                type: string
            required:
              - path
              - message
            additionalProperties: false
          description: 'On `invalid_arguments`: which fields failed, and why.'
      required:
        - ok
        - code
        - message
      additionalProperties: false
      description: A call that was admitted and dispatched, and did not succeed.
    Error:
      type: object
      properties:
        ok:
          type: boolean
          const: false
        code:
          type: string
          description: >-
            The typed refusal code — e.g. `tenant_mcp.surface_disabled`,
            `tenant_mcp.rate_limited`.
        message:
          type: string
          description: A sentence a person can act on.
        retry_after_seconds:
          type: number
          description: 'On a 429: whole seconds to wait. Mirrors `Retry-After`.'
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
            retry_after_seconds:
              type: number
          required:
            - code
            - message
          additionalProperties: false
          description: >-
            Deprecated: the same values as the top-level fields, kept until
            2026-12-31. Read `code` and `message` at the top level.
      required:
        - ok
        - code
        - message
        - error
      additionalProperties: false
      description: >-
        A request the boundary refused before dispatching anything. The same
        shape the MCP endpoint answers its own refusals with, and the same
        top-level fields a dispatched call's refusal carries, so one client
        branch covers both.
  securitySchemes:
    tenantApiKey:
      type: http
      scheme: bearer
      description: >-
        An API key minted at Settings › API & MCP. Send it as `Authorization:
        Bearer <key>`. A key carries its holder's own permissions, resolved on
        every call — revoking a membership closes the key's reach immediately.
        Keep it in an environment variable (`GOOSY_API_KEY`), never in a
        committed file.

````