Skip to main content
POST
Call web.read

Authorizations

Authorization
string
header
required

An API key minted at Settings › API & MCP. Send it as Authorization: Bearer <key>. A key carries its holder's own permissions, resolved on every call — revoking a membership closes the key's reach immediately. Keep it in an environment variable (GOOSY_API_KEY), never in a committed file.

Body

application/json
url
string
Required string length: 1 - 2048
confirmation_id
string<uuid>

Confirms the stored exact call. When supplied, the stored request replaces all other body fields.

idempotency_key
string

Required for a new non-confirmation managed API call.

Required string length: 1 - 256
workspace
string

Which workspace to run in — its slug. Omit to use your default. With more than one reachable workspace and no default, the call is refused and the choices are listed.

Minimum string length: 1

Response

The call was admitted and dispatched. ok says whether the tool succeeded — a refusal the tool itself produced is still a 200, exactly as it is a successful JSON-RPC result over MCP.

The tool ran and answered.

ok
boolean
required
state
enum<string>
required
Available options:
confirmation_required,
completed,
reconciliation_required,
terminal_replay
workspace
string
required

The slug of the workspace this call ran in.

working_in
object
required

Which workspace this call ran in, and how that was decided. Present on every workspace-scoped result.

confirmation_id
string<uuid> | null
expires_in_seconds
integer
request_id
string<uuid> | null
status
enum<string> | null
Available options:
succeeded,
failed,
uncertain,
running
response
unknown
error_code
string | null