Run a tool
Runs a tool now, as the team. No sign-off wait, whatever the risk: calling this is the decision. The call lands as an approval row at executing; poll GET /tool-approvals/{id} for the result. Input values are the flat scalars manifest schemas declare.
POST
/conversations/{id}/tools/runAuthorization
AuthorizationBearer token · headerrequired`MEDIAN_KEY` from Settings under API, or an MCP OAuth access token. A key acts as the organization; a token acts as the person who approved it.
Path parameters
idstringrequiredA conversation id.
Request body
requiredapplication/jsontoolstringrequiredinputobjectResponses
200The run's approval row, to watch as it settles.
approvalIdstring400The request is malformed, and the message names the field.
errorobjectShow propertiesHide properties
codestringmessagestring401The bearer token is missing, revoked, or expired.
errorobjectShow propertiesHide properties
codestringmessagestring404Not one of yours, or not there at all.
errorobjectShow propertiesHide properties
codestringmessagestring429Too many requests. Wait the seconds in `Retry-After`. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectShow propertiesHide properties
codestringmessagestringRequest
curl -X POST "https://api.median.sh/v1/conversations/string/tools/run" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"tool": "refundOrder",
"input": {
"orderId": "ord_42"
}
}'const response = await fetch("https://api.median.sh/v1/conversations/string/tools/run", {
method: "POST",
headers: {
"Authorization": "Bearer YOUR_TOKEN",
"Content-Type": "application/json"
},
body: JSON.stringify({
"tool": "refundOrder",
"input": {
"orderId": "ord_42"
}
})
});Response
{
"approvalId": "string"
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}