> ## Documentation Index
> Fetch the complete documentation index at: https://docs.goosybear.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Call page.set_access

> Propose, then confirm, making one page of a site members-only — so only signed-in members of the workspace can open it — or public again: 'make the team page private', 'open /pricing to everyone again'. A live site rebuilds and publishes itself with the change; a draft site's change lands with its next build. It sets one page by its path, never a pattern such as '/admin/*' — relay that refusal, which says a pattern is edited in the site's source. Not for publishing a built version — that is `page.api_publish`.

Every result names the workspace it ran in. Say which workspace the answer is about. When the account has more than one workspace and none is selected, this tool refuses with `workspace_ambiguous` and lists the choices — offer them, never pick one.



## OpenAPI

````yaml /openapi.json post /api/v1/tools/page.set_access
openapi: 3.1.0
info:
  title: Goosy Bear API
  version: 1.0.0-beta
  summary: Manage workspace content, projects, Data tables, Pages, library and credits.
  description: >-
    BETA. This API is in beta: paths, request shapes and response envelopes may
    change, and every response carries an `x-goosy-api: beta` header for as long
    as that is true. Pin the OpenAPI document you generated against and
    re-generate when it changes.
servers:
  - url: https://app.goosybear.ai
    description: Production
security:
  - tenantApiKey: []
paths:
  /api/v1/tools/page.set_access:
    post:
      tags:
        - page
      summary: Call page.set_access
      description: >-
        Propose, then confirm, making one page of a site members-only — so only
        signed-in members of the workspace can open it — or public again: 'make
        the team page private', 'open /pricing to everyone again'. A live site
        rebuilds and publishes itself with the change; a draft site's change
        lands with its next build. It sets one page by its path, never a pattern
        such as '/admin/*' — relay that refusal, which says a pattern is edited
        in the site's source. Not for publishing a built version — that is
        `page.api_publish`.


        Every result names the workspace it ran in. Say which workspace the
        answer is about. When the account has more than one workspace and none
        is selected, this tool refuses with `workspace_ambiguous` and lists the
        choices — offer them, never pick one.
      operationId: call_page_set_access
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                site_id:
                  type: string
                  format: uuid
                path:
                  type: string
                  minLength: 1
                  maxLength: 512
                access:
                  type: string
                  enum:
                    - members
                    - public
                confirmation_id:
                  type: string
                  format: uuid
                workspace:
                  type: string
                  minLength: 1
                  description: >-
                    Which workspace to run in — its slug. Omit to use your
                    default. With more than one reachable workspace and no
                    default, the call is refused and the choices are listed.
              required:
                - site_id
                - path
                - access
              additionalProperties: false
      responses:
        '200':
          description: >-
            The call was admitted and dispatched. `ok` says whether the tool
            succeeded — a refusal the tool itself produced is still a 200,
            exactly as it is a successful JSON-RPC result over MCP.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            x-goosy-tool-error:
              description: >-
                `true` when a boundary step refused the call — workspace
                resolution failed or could not be read. A tool that ran and
                returned its own typed `ok: false` reports `false` here.
                **Branch on `ok` in the body for the outcome; this header is the
                transport-level hint.**
              schema:
                type: string
                enum:
                  - 'true'
                  - 'false'
          content:
            application/json:
              schema:
                oneOf:
                  - type: object
                    description: The tool ran and answered.
                    properties:
                      ok:
                        type: boolean
                        const: true
                      state:
                        type: string
                        enum:
                          - confirmation_required
                          - unchanged
                          - building
                          - publishing
                      site_id:
                        type: string
                        format: uuid
                      path:
                        type: string
                      access:
                        type: string
                        enum:
                          - members
                          - public
                      name:
                        type: string
                      member_routes:
                        type: array
                        items:
                          type: string
                      confirmation_id:
                        type: string
                        format: uuid
                      expires_in_seconds:
                        type: integer
                        exclusiveMinimum: 0
                      workspace:
                        type: string
                        description: The slug of the workspace this call ran in.
                      working_in:
                        type: object
                        properties:
                          label:
                            type: string
                            description: 'The chip words — e.g. "working in: Acme Main".'
                          note:
                            type: string
                            description: >-
                              Why this workspace — e.g. "your default", "this
                              call only".
                          workspace:
                            type: string
                            description: The resolved workspace's slug.
                          source:
                            type: string
                            enum:
                              - call-override
                              - key-pin
                              - stored-default
                              - sole-reachable
                            description: >-
                              Which rung of the R7 precedence resolved the
                              workspace.
                        required:
                          - label
                          - note
                          - workspace
                          - source
                        additionalProperties: false
                        description: >-
                          Which workspace this call ran in, and how that was
                          decided. Present on every workspace-scoped result.
                    required:
                      - ok
                      - access
                      - path
                      - site_id
                      - state
                      - working_in
                      - workspace
                  - $ref: '#/components/schemas/ToolRefusal'
        '400':
          description: >-
            The request body could not be used: it is present but not a JSON
            object (`tenant_api.malformed_body`), or it is a top-level array
            carrying more messages than this endpoint accepts
            (`tenant_mcp.batch_too_large`). Send the tool's arguments as a JSON
            object, or omit the body entirely.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: >-
            No bearer credential, or one that did not resolve. Deliberately ONE
            undifferentiated answer for absent / unknown / revoked / expired, so
            the endpoint is never an oracle over the key space.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            The credential is good but the surface is not open to it — the
            platform or account API switch is off, or the holder lacks the
            `api.access` capability. The `code` says which.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            No such tool. The body names no tool and is identical for every
            unrecognised name.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: >-
            Over this key's per-minute cap. Carries `Retry-After` and
            `error.retry_after_seconds`.
          headers:
            x-goosy-api:
              description: Present while this API is in beta; the value is `beta`.
              schema:
                type: string
                const: beta
            Retry-After:
              description: Whole seconds to wait before retrying.
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ToolRefusal:
      type: object
      properties:
        ok:
          type: boolean
          const: false
        code:
          type: string
          description: >-
            The typed reason — e.g. `workspace_ambiguous`, `invalid_arguments`,
            or the tool's own failure code.
        message:
          type: string
          description: A sentence a person can act on.
        workspaces:
          type: array
          items:
            type: string
          description: 'On a workspace refusal: the slugs this key may pass as `workspace`.'
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              message:
                type: string
            required:
              - path
              - message
            additionalProperties: false
          description: 'On `invalid_arguments`: which fields failed, and why.'
      required:
        - ok
        - code
        - message
      additionalProperties: false
      description: A call that was admitted and dispatched, and did not succeed.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: >-
                The typed refusal code — e.g. `tenant_mcp.surface_disabled`,
                `tenant_mcp.rate_limited`.
            message:
              type: string
              description: A sentence a person can act on.
            retry_after_seconds:
              type: number
              description: 'On a 429: whole seconds to wait. Mirrors `Retry-After`.'
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        A request the boundary refused before dispatching anything. The same
        shape the MCP endpoint answers its own refusals with, so one client
        branch covers both transports.
  securitySchemes:
    tenantApiKey:
      type: http
      scheme: bearer
      description: >-
        An API key minted at Settings › API & MCP. Send it as `Authorization:
        Bearer <key>`. A key carries its holder's own permissions, resolved on
        every call — revoking a membership closes the key's reach immediately.
        Keep it in an environment variable (`GOOSY_API_KEY`), never in a
        committed file.

````