Admin MCP tools
The admin MCP is a stateless Streamable-HTTP JSON-RPC endpoint at POST https://api.mozaik-dev.com/mcp (no sessions, no SSE (every POST is answered with JSON). Auth is a bearer mzk_ token only; the store is derived from the token) a store/storeId argument in tool input is refused as a validation error. Every tool call is synthesized into an ordinary HTTP request and replayed through the same router the admin panel uses, so auth, scope gates and the proposal divert are byte-identical to the public API.
initialize negotiates the protocol (2026-07-28 with legacy auto-detect) and enforces the client floor: a clientInfo that identifies as our CLI/Dev MCP below 0.2.0 is refused with -32001 client_too_old and the exact upgrade command (npm i -g @mozaik/cli@0.2.0). Third-party MCP clients are never refused for lacking a version.
Tool names are the registry's dotted ids verbatim: one tool per command, one per catalog route with a non-owner policy (commands.run/commands.list are omitted: commands are 1:1 tools already). The list below is buildToolList() with the full admin scope; a real token sees the scope-filtered subset. Resources: mzk://store, mzk://proposal/current, mzk://draft, mzk://sections-meta, mzk://docs/{path}.
Developer view (Geliştirici token: executes directly)
| tool | kind | policy | summary |
|---|---|---|---|
catalog.category.archive | command | propose | Archive a category (products keep their assignment; hidden from active lists). |
catalog.category.create | command | propose | Create a category (flat compliance taxonomy; taksitCap = BDDK installment cap). |
catalog.category.update | command | propose | Update a category's name, installment cap, or position. |
catalog.collection.archive | command | propose | Archive a collection: its page 404s; product memberships are kept. |
catalog.collection.create | command | propose | Create a collection (handle derived from title when omitted). |
catalog.collection.setProducts | command | propose | Wholesale-replace a collection's product list (order = array order = manual sort). |
catalog.collection.update | command | propose | Patch collection fields. |
catalog.digital.codes.add | command | propose | Add e-pin codes to a pooled digital product (sealed at rest; duplicates skipped). |
catalog.digital.codes.void | command | propose | Void unused pool codes (oldest first): they can never be allocated; nothing is deleted. |
catalog.media.commit | command | propose | Commit a staged upload into the media library (variants generated async). |
catalog.media.delete | command | propose | Permanently delete an UNUSED media file (refused while referenced by catalog, live design, or the draft). |
catalog.price.set | command | propose | Set the price (kuruş) of a product (prd_) or variant (var_). compareAt only on products; null clears it. Variant price null = inherit product price. |
catalog.product.archive | command | propose | Archive a product: removed from the storefront, history kept. |
catalog.product.create | command | propose | Create a product. price/compareAt in kuruş; stock null = untracked; handle derived from title when omitted. |
catalog.product.setDigital | command | propose | Set a product's digital/shipping posture: requiresShipping, delivered digital content, withdrawal exception. |
catalog.product.setMedia | command | propose | Wholesale-replace a product's media list (order = array order; alt is per-usage). |
catalog.product.setVariants | command | propose | Wholesale-replace a product's variant STRUCTURE (order = array order). Existing variants update title/sku only; initial price/stock allowed solely for new variants. |
catalog.product.update | command | propose | Patch product fields. Price and stock are NOT here: use catalog.price.set / catalog.stock.set. |
catalog.stock.adjust | command | propose | Adjust stock by a ± delta (receiving, stocktake, connector sync). Fails on untracked items; expectedStock = compare-and-set. |
catalog.stock.set | command | propose | Set stock of a product (prd_) or variant (var_). null = untracked (always available). |
channel.listing.set | command | propose | Create/update marketplace listings for products or variants on a channel: enable, price/list overrides, price lock, buffer, mapping fields (bulk ≤500). |
customer.anonymize | command | propose | Anonymize a customer row (KVKK request): order snapshots stay under the statutory retention. |
customer.identity.unlink | command | propose | Clear a Mozaik ID pointer from this store's customers (revoke/erasure healing). |
design.extpage.add | command | propose | Add an installed extension's page to the workspace draft under /ek/{slug} (owner-changeable path); the page renders the extension's composite through the active theme. |
design.extpage.remove | command | propose | Remove an extension page from the workspace draft (menu links to it are dropped). |
design.zone.place | command | propose | Place (or reconfigure) an installed extension's storefront block in a zone of the workspace draft: the owner-driven 'Yerleştir'. |
design.zone.remove | command | propose | Remove an extension block from a storefront zone of the workspace draft. |
extension.configure | command | propose | Set an extension's configuration (validated against its schema). Does not enable it. |
extension.disable | command | propose | Disable an extension. Its payment method / hooks / panels stop immediately. Channel extensions with listings must state disconnect: 'zero' (push 0 everywhere first) or 'freeze' (leave marketplace stock as is). |
extension.enable | command | propose | Enable an installed extension. Requires its secrets set and config valid. |
extension.hook.deactivate | command | propose | Deactivate (or reactivate) an extension's hooks without disabling the extension. |
extension.install | command | propose | Install an extension for this store (disabled until configured + enabled). Grants the manifest's scopes. |
extension.uninstall | command | propose | Uninstall a disabled extension. Config is archived in the audit row; secrets and data are kept. |
extension.upgrade | command | propose | Upgrade an installed extension to the platform's current manifest version: re-validates (or migrates) the stored config; permission growth (new scopes / PII / required secrets) needs consent: true from the owner: the reconcile sweep applies only additive upgrades by itself. |
metafield.definition.create | command | propose | Define a typed custom field on products, variants, collections, or the store. |
metafield.definition.delete | command | propose | Delete a metafield definition AND every value stored under it. |
metafield.definition.update | command | propose | Update a metafield definition's label, description, or validations (type/key are immutable). |
metafield.set | command | propose | Set a metafield value on a product, variant, collection, or the store. |
metafield.unset | command | propose | Remove a metafield value. |
order.cancel | command | propose | Cancel an unpaid order (pending_cod/awaiting_transfer): restocks lines. reason 'marketplace' cancels a paid marketplace order (the marketplace refunded the buyer); restock=false skips the restock. |
order.cod.collect | command | propose | Record that the carrier's COD cash for a shipped/delivered order reached the merchant: order becomes paid. |
order.note.add | command | propose | Append a merchant note to an order's timeline. |
order.return.approve | command | propose | Approve a return: issues the instructions the shopper sees (snapshotted as evidence). |
order.return.receive | command | propose | Record the returned goods arriving: per-line condition; saleable lines restock (ledgered). |
order.return.reject | command | propose | Reject a return with a stated reason (the shopper mail carries the THH/consumer-court recourse). |
order.ship | command | propose | Create a shipment for an order's shippable lines (a cargo extension or a manual carrier): writes the VUK 509 forward fields. |
order.shipment.cancel | command | propose | Cancel a shipment before carrier handoff completes: resets the order to unfulfilled when nothing else is active. |
order.shipment.track | command | propose | Record a carrier state transition (webhook/poll/manual) and aggregate the order's fulfillment status. |
order.transfer.confirm | command | propose | Confirm a bank-transfer payment arrived: order becomes paid; digital content is released. |
proposal.submit | command | direct | Submit an open proposal for the store owner's review (the owner is mailed a link). The proposalId comes from your first recorded mutation's response: or proposals.list. |
proposal.withdraw | command | direct | Withdraw a proposal that has not been applied. |
settings.channel.update | command | propose | Update one marketplace channel's policy: push/pull switches, price rule, buffer, resend window, disconnect and buyer-mail policy. |
settings.checkout.update | command | propose | Update checkout legal settings: delivery estimate, return-cargo carrier/cost disclosure. |
settings.flag.set | command | propose | Set or clear a store readiness flag (ETBİS beyanı, rehber kartları). |
settings.identity.update | command | propose | Set the legal merchant identity (6563 m.3): complete rows only; rendered live in the footer. |
settings.stock.update | command | propose | Update store-wide stock policy: default marketplace buffer, untracked quantity, restock-on-cancel/return, zero-when-archived. |
settings.store.update | command | propose | Update store settings (display name). Projected to KV tenant records. |
store.syncKv | command | direct | Re-project store state (t:, l:, live b:, g:) from Postgres to KV; bumps generation once. |
theme.install | command | propose | Install a theme version for this store (first-party or a visible pack). Does not change the live look until a switch is published: except a newer first-party version re-pins the kit stylesheet the live site links (V1 S2). |
theme.page.reset | command | propose | Replace one page (or header/footer) in the workspace draft with the active theme's skeleton for it. |
theme.preset.apply | command | propose | Apply one of the active theme's presets (Varyasyon) to the workspace draft: only the values the preset names change. |
theme.push | command | propose | Push a store-private SKIN theme (manifest + linted CSS + variables + presets + skeleton) from the CLI/sandbox: records the immutable pack, stores its stylesheet, installs the version. |
theme.switch | command | propose | Switch the workspace draft to another installed theme (keep-layout or theme-skeleton): lossless: settings kept by id, sections parked never deleted; returns the Geçiş raporu. |
theme.uninstall | command | propose | Remove an installed theme version. Refused while the live version, any draft/workspace or an open proposal references it. |
theme.upgrade | command | propose | Move the workspace draft to a newer version of its active theme: installs the version (kit css pin), applies the pack's migrations (renames) and the new defaults only to values the owner never touched, keeps everything else; returns the Geçiş raporu. Publishing stays a separate step. |
audit.list | route | read | Recent audit rows for the store (optionally by entity). |
cargo.carriers.list | route | read | Platform carrier reference table (codes, labels, tracking availability). |
catalog.categories.list | route | read | List categories. |
catalog.collections.get | route | read | Get one collection with members. |
catalog.collections.list | route | read | List collections. |
catalog.products.get | route | read | Get one product with variants, media and stock. |
catalog.products.list | route | read | List products (keyset cursor, filters). |
catalog.stockMovements.list | route | read | Stock ledger rows for a product or variant. |
catalog.stockMovements.since | route | read | Store-wide stock ledger rows after a seq watermark, ascending: the outbox read a connector consumes. |
channel.brand.create | route | propose | Create a brand at the marketplace (multipart: name + 1-3 logo images). |
channel.buybox.get | route | quote | Buybox rank and top prices for listings (≤100). |
channel.catalog.pull | route | propose | Import the marketplace catalog (preview or import): products, variants, images, listings, stock and prices: a durable job. |
channel.catalog.push | route | propose | Create/update marketplace listings for selected products (pre-flight validated; async batch tracked). |
channel.claims.act | route | propose | Approve, reject (reason + file) or raise an issue on a marketplace claim; restock per policy. |
channel.claims.list | route | quote | Marketplace return/cancel claims with deadlines and fault tags. |
channel.connect.test | route | quote | Probe the marketplace with the stored credentials (no store mutation): auth, identity header, stage allowlist. |
channel.finance.list | route | read | Imported settlement rows (commission, cargo, fees, payouts) and per-order expected vs settled. |
channel.health.get | route | read | Channel health: credentials, last sync times, webhook state, budget/429 counters, failed batches, queue depth, unmapped orders. |
channel.jobs.cancel | route | propose | Cancel a queued/running channel job. |
channel.jobs.get | route | read | One channel job with progress, errors and result. |
channel.jobs.list | route | read | Durable channel jobs (imports, pushes, batch polls, sweeps) with progress. |
channel.listing.archive | route | propose | Archive/unarchive listings at the marketplace (archive pushes stock 0 too). |
channel.listing.delete | route | propose | Delete listings at the marketplace (irreversible; provider rules apply, e.g. archived > 1 day and not locked). |
channel.listings.get | route | read | One listing with its provider mirror (external ids, last push/remote, errors, mapping meta). |
channel.listings.list | route | read | Marketplace listings of this channel with status, effective price, pushed vs live stock, drift and last error. |
channel.package.label | route | quote | Fetch the marketplace cargo label for a package (ZPL, or rendered PDF/PNG). |
channel.package.op | route | propose | Act on a marketplace package: status (preparing/invoiced), unsupplied (penalty acknowledged), split, invoice hand-off, cargo (carrier/box/warehouse/extend/own-carrier). |
channel.packages.labels | route | quote | Bulk labels for up to 50 packages (merged PDF). |
channel.questions.answer | route | propose | Answer a customer question (moderated by the marketplace). |
channel.questions.list | route | quote | Customer questions awaiting an answer (with deadlines). |
channel.remote.attributes | route | quote | Attributes a marketplace category requires/allows (required, custom, multi, variant axis). |
channel.remote.attributeValues | route | quote | Allowed values of one category attribute. |
channel.remote.brands | route | quote | Marketplace brand search by name. |
channel.remote.categories | route | quote | Marketplace category tree search (leaf categories accept products). |
channel.remote.products | route | quote | The seller's products as the marketplace sees them (approval state, remote stock/price, reject reasons). |
channel.sync.now | route | propose | Run a sync task now (stock | price | orders | reconcile | finance | claims | questions), optionally scoped to listings. |
channel.unlock | route | propose | Request unlock of locked listings (after the price/stock cause is fixed). |
channel.webhook.register | route | propose | Register (or re-activate) the platform webhook at the marketplace with a fresh shared secret. |
compat.check | route | quote | Check an artifact's compatibility with this platform version without installing it: {kind: css|bundle|extension|tree, artifact, kit?, variables?} → verdict {ok, breaking[], warnings[]} with TR messages and alias fixes. Public and side-effect-free (CLI mozaik compat check, Dev MCP). |
compat.contracts.get | route | read | The contract manifests this build was released with (storefront + api): every element/part/axis/token/section/zone/block/kit and route/command/scope a theme, skin, bundle or extension may reference. Same JSON as contracts/<kind>/<version>.json in the repo. |
design.catalog.get | route | read | Section catalog for the add-picker: platform sections, the active theme's sections, store composites, extension blocks. |
design.draft.delete | route | workspace | Discard the draft (expectedRev). |
design.draft.get | route | read | Read the draft bundle (rev, hash, body, preview link). |
design.draft.put | route | workspace | Replace the draft bundle under optimistic concurrency (expectedRev). |
design.draftFromTemplate | route | workspace | Instantiate a starter template as the draft. |
design.previewUrl.get | route | read | Signed preview link: ?hash= freezes a snapshot, ?workspace= follows that workspace's current draft (the dev-loop link). |
design.templates.list | route | read | Starter template cards. |
design.version.get | route | read | Full body of a published version. |
design.versions.list | route | read | Published version ledger (seq, hash, label, live marker). |
ext.cargo.sender | route | propose | Create the sender address at the cargo provider and store its id in the extension config. |
extensions.list | route | read | Installed + available extensions with config, secrets state and manifest UI hints (owner-only). |
extensions.ops.get | route | read | The extension's agent contract with LIVE readiness: every op, what it needs (secrets/config/enabled), and exactly what blocks it right now. Secrets appear as keys only. |
kit.contract.get | route | read | The Element Contract (elements, anatomy, tokens, zones, limits) the platform renders: same JSON as docs /schemas/kit-contract.json. |
media.list | route | read | List media objects. |
media.upload | route | workspace | Stage a binary upload (raw body); commit with catalog.media.commit. |
meta.get | route | read | Platform build identity and compatibility fingerprint (buildId, registryHash, minCli). |
metafields.definitions.list | route | read | Metafield definitions (owner-only). |
orders.belge.get | route | read | Fetch a legal document snapshot of an order. |
orders.cargo.book | route | propose | Accept a carrier offer, create the label and ship the order. |
orders.cargo.offers | route | quote | Create a provider quote for the order and return carrier offers (no store mutation). |
orders.cargo.ship | route | propose | Ship with the merchant's own carrier (manual tracking). |
orders.cod.collect | route | propose | Mark a cash-on-delivery order as collected. |
orders.get | route | read | Get one order with lines, payment, shipments, returns, timeline. |
orders.list | route | read | List orders. |
orders.note.add | route | propose | Add a merchant note to the order timeline. |
orders.refund | route | propose | Refund part or all of a captured payment through the original PSP extension. |
orders.shipment.cancel | route | propose | Cancel a shipment before pickup. |
orders.shipment.label | route | quote | Fetch the shipping label URL from the provider. |
orders.shipment.track | route | propose | Record a shipment status transition by hand. |
orders.shipment.update | route | propose | Poll the provider and apply the current tracking status. |
proposals.get | route | read | One proposal with its items, recorded previews and (for design items) a preview link. |
proposals.list | route | read | List proposals; agent tokens see only their own. |
returns.approve | route | propose | Approve a return request with shipping instructions; mails the shopper. |
returns.get | route | read | Get one return request. |
returns.list | route | read | List return requests. |
returns.reject | route | propose | Reject a return request with a reason; mails the shopper. |
routes.list | route | read | List typed routes with JSON Schemas (the twin of commands.list). |
scopes.list | route | read | Scope registry: TR labels, sensitivity and who may hold each scope (any token / developer tokens / sessions only). |
sections.meta.get | route | read | Section catalog with props/blocks JSON Schemas and placement rules. |
store.checkoutSettings.get | route | read | Checkout settings (owner-only). |
store.health.get | route | read | Store readiness checklist (draft/live, identity, flags). |
store.identity.get | route | read | Legal identity block (owner-only). |
store.stockSettings.get | route | read | Store-wide stock policy and per-channel policies (owner-only). |
themes.check | route | quote | Statically check a SKIN theme package {manifest, css, variables?, presets?, against?}: manifest + variables schemas, the CSS grammar with the parent kit's variables, size gates, element coverage, V1 value-aware compatibility with this platform version (+ computed requires) and, with against (the previous version), the semver class the change needs. Public and side-effect-free (the CLI's mozaik theme check). |
themes.get | route | read | One theme's manifest, variables, presets and install state. |
themes.list | route | read | Installed themes + the first-party gallery, with presets/variables and the draft's active theme ref. |
tokens.whoami | route | read | Describe the calling credential: store, kind, scopes, expiry, workspace: what an agent should call first. |
updates.list | route | read | The store's update queue (Güncellemeler): pending theme/extension/generation updates with their Geçiş raporu and preview, plus applied/blocked history, and the platform versions this store runs on. |
validate.bundle | route | quote | Validate a store bundle (schema + referential integrity) without saving anything. Media readiness is checked at draft save, which is the enforcement point. |
validate.command | route | quote | Validate a command payload against its registered schema without running it (no preview, no mutation). |
validate.manifest | route | quote | Validate an extension manifest against zExtensionManifest, including the agent-contract rules. |
workspaces.activity.list | route | read | The workspace's append-only activity feed (exec/read/write/backup/refresh with exit codes and durations). |
workspaces.adopt | route | workspace | Copy a workspace draft into the builder's main draft under optimistic concurrency (never a merge). |
workspaces.backup | route | workspace | Snapshot the sandbox's /workspace/store to R2 (7-day TTL); restored automatically on the next cold start. |
workspaces.exec | route | workspace | Run one command in the workspace's hosted sandbox (the pinned CLI is preinstalled; cwd defaults to /workspace/store). Output capped at 256 KB. |
workspaces.files.list | route | quote | List a directory inside the hosted sandbox (confined to /workspace). |
workspaces.files.read | route | quote | Read a file from the hosted sandbox (≤1 MiB; base64 for binary). |
workspaces.files.write | route | workspace | Write a file into the hosted sandbox (≤1 MiB; scratch only: store state flows through mozaik push/proposals). |
workspaces.list | route | read | List draft workspaces: the builder's main draft plus every agent/developer workspace with its draft rev and sandbox state. |
workspaces.preview | route | read | Stable signed preview URL of this workspace's draft on the store hostname (never touches the container). |
Agent view (Ajan token: propose tools are recorded, not applied)
The same names; propose tools answer PROPOSED (not applied) and record the call into the token's open proposal for the owner to review.
| tool | kind | policy | proposal-recorded | summary |
|---|---|---|---|---|
catalog.category.archive | command | propose | ✓ | Archive a category (products keep their assignment; hidden from active lists). |
catalog.category.create | command | propose | ✓ | Create a category (flat compliance taxonomy; taksitCap = BDDK installment cap). |
catalog.category.update | command | propose | ✓ | Update a category's name, installment cap, or position. |
catalog.collection.archive | command | propose | ✓ | Archive a collection: its page 404s; product memberships are kept. |
catalog.collection.create | command | propose | ✓ | Create a collection (handle derived from title when omitted). |
catalog.collection.setProducts | command | propose | ✓ | Wholesale-replace a collection's product list (order = array order = manual sort). |
catalog.collection.update | command | propose | ✓ | Patch collection fields. |
catalog.digital.codes.add | command | propose | ✓ | Add e-pin codes to a pooled digital product (sealed at rest; duplicates skipped). |
catalog.digital.codes.void | command | propose | ✓ | Void unused pool codes (oldest first): they can never be allocated; nothing is deleted. |
catalog.media.commit | command | propose | ✓ | Commit a staged upload into the media library (variants generated async). |
catalog.media.delete | command | propose | ✓ | Permanently delete an UNUSED media file (refused while referenced by catalog, live design, or the draft). |
catalog.price.set | command | propose | ✓ | Set the price (kuruş) of a product (prd_) or variant (var_). compareAt only on products; null clears it. Variant price null = inherit product price. |
catalog.product.archive | command | propose | ✓ | Archive a product: removed from the storefront, history kept. |
catalog.product.create | command | propose | ✓ | Create a product. price/compareAt in kuruş; stock null = untracked; handle derived from title when omitted. |
catalog.product.setDigital | command | propose | ✓ | Set a product's digital/shipping posture: requiresShipping, delivered digital content, withdrawal exception. |
catalog.product.setMedia | command | propose | ✓ | Wholesale-replace a product's media list (order = array order; alt is per-usage). |
catalog.product.setVariants | command | propose | ✓ | Wholesale-replace a product's variant STRUCTURE (order = array order). Existing variants update title/sku only; initial price/stock allowed solely for new variants. |
catalog.product.update | command | propose | ✓ | Patch product fields. Price and stock are NOT here: use catalog.price.set / catalog.stock.set. |
catalog.stock.adjust | command | propose | ✓ | Adjust stock by a ± delta (receiving, stocktake, connector sync). Fails on untracked items; expectedStock = compare-and-set. |
catalog.stock.set | command | propose | ✓ | Set stock of a product (prd_) or variant (var_). null = untracked (always available). |
channel.listing.set | command | propose | ✓ | Create/update marketplace listings for products or variants on a channel: enable, price/list overrides, price lock, buffer, mapping fields (bulk ≤500). |
customer.anonymize | command | propose | ✓ | Anonymize a customer row (KVKK request): order snapshots stay under the statutory retention. |
customer.identity.unlink | command | propose | ✓ | Clear a Mozaik ID pointer from this store's customers (revoke/erasure healing). |
design.extpage.add | command | propose | ✓ | Add an installed extension's page to the workspace draft under /ek/{slug} (owner-changeable path); the page renders the extension's composite through the active theme. |
design.extpage.remove | command | propose | ✓ | Remove an extension page from the workspace draft (menu links to it are dropped). |
design.zone.place | command | propose | ✓ | Place (or reconfigure) an installed extension's storefront block in a zone of the workspace draft: the owner-driven 'Yerleştir'. |
design.zone.remove | command | propose | ✓ | Remove an extension block from a storefront zone of the workspace draft. |
extension.configure | command | propose | ✓ | Set an extension's configuration (validated against its schema). Does not enable it. |
extension.disable | command | propose | ✓ | Disable an extension. Its payment method / hooks / panels stop immediately. Channel extensions with listings must state disconnect: 'zero' (push 0 everywhere first) or 'freeze' (leave marketplace stock as is). |
extension.enable | command | propose | ✓ | Enable an installed extension. Requires its secrets set and config valid. |
extension.hook.deactivate | command | propose | ✓ | Deactivate (or reactivate) an extension's hooks without disabling the extension. |
extension.install | command | propose | ✓ | Install an extension for this store (disabled until configured + enabled). Grants the manifest's scopes. |
extension.uninstall | command | propose | ✓ | Uninstall a disabled extension. Config is archived in the audit row; secrets and data are kept. |
extension.upgrade | command | propose | ✓ | Upgrade an installed extension to the platform's current manifest version: re-validates (or migrates) the stored config; permission growth (new scopes / PII / required secrets) needs consent: true from the owner: the reconcile sweep applies only additive upgrades by itself. |
metafield.definition.create | command | propose | ✓ | Define a typed custom field on products, variants, collections, or the store. |
metafield.definition.delete | command | propose | ✓ | Delete a metafield definition AND every value stored under it. |
metafield.definition.update | command | propose | ✓ | Update a metafield definition's label, description, or validations (type/key are immutable). |
metafield.set | command | propose | ✓ | Set a metafield value on a product, variant, collection, or the store. |
metafield.unset | command | propose | ✓ | Remove a metafield value. |
order.cancel | command | propose | ✓ | Cancel an unpaid order (pending_cod/awaiting_transfer): restocks lines. reason 'marketplace' cancels a paid marketplace order (the marketplace refunded the buyer); restock=false skips the restock. |
order.cod.collect | command | propose | ✓ | Record that the carrier's COD cash for a shipped/delivered order reached the merchant: order becomes paid. |
order.note.add | command | propose | ✓ | Append a merchant note to an order's timeline. |
order.return.approve | command | propose | ✓ | Approve a return: issues the instructions the shopper sees (snapshotted as evidence). |
order.return.receive | command | propose | ✓ | Record the returned goods arriving: per-line condition; saleable lines restock (ledgered). |
order.return.reject | command | propose | ✓ | Reject a return with a stated reason (the shopper mail carries the THH/consumer-court recourse). |
order.ship | command | propose | ✓ | Create a shipment for an order's shippable lines (a cargo extension or a manual carrier): writes the VUK 509 forward fields. |
order.shipment.cancel | command | propose | ✓ | Cancel a shipment before carrier handoff completes: resets the order to unfulfilled when nothing else is active. |
order.shipment.track | command | propose | ✓ | Record a carrier state transition (webhook/poll/manual) and aggregate the order's fulfillment status. |
order.transfer.confirm | command | propose | ✓ | Confirm a bank-transfer payment arrived: order becomes paid; digital content is released. |
proposal.submit | command | direct | Submit an open proposal for the store owner's review (the owner is mailed a link). The proposalId comes from your first recorded mutation's response: or proposals.list. | |
proposal.withdraw | command | direct | Withdraw a proposal that has not been applied. | |
settings.channel.update | command | propose | ✓ | Update one marketplace channel's policy: push/pull switches, price rule, buffer, resend window, disconnect and buyer-mail policy. |
settings.checkout.update | command | propose | ✓ | Update checkout legal settings: delivery estimate, return-cargo carrier/cost disclosure. |
settings.flag.set | command | propose | ✓ | Set or clear a store readiness flag (ETBİS beyanı, rehber kartları). |
settings.identity.update | command | propose | ✓ | Set the legal merchant identity (6563 m.3): complete rows only; rendered live in the footer. |
settings.stock.update | command | propose | ✓ | Update store-wide stock policy: default marketplace buffer, untracked quantity, restock-on-cancel/return, zero-when-archived. |
settings.store.update | command | propose | ✓ | Update store settings (display name). Projected to KV tenant records. |
store.syncKv | command | direct | Re-project store state (t:, l:, live b:, g:) from Postgres to KV; bumps generation once. | |
theme.install | command | propose | ✓ | Install a theme version for this store (first-party or a visible pack). Does not change the live look until a switch is published: except a newer first-party version re-pins the kit stylesheet the live site links (V1 S2). |
theme.page.reset | command | propose | ✓ | Replace one page (or header/footer) in the workspace draft with the active theme's skeleton for it. |
theme.preset.apply | command | propose | ✓ | Apply one of the active theme's presets (Varyasyon) to the workspace draft: only the values the preset names change. |
theme.push | command | propose | ✓ | Push a store-private SKIN theme (manifest + linted CSS + variables + presets + skeleton) from the CLI/sandbox: records the immutable pack, stores its stylesheet, installs the version. |
theme.switch | command | propose | ✓ | Switch the workspace draft to another installed theme (keep-layout or theme-skeleton): lossless: settings kept by id, sections parked never deleted; returns the Geçiş raporu. |
theme.uninstall | command | propose | ✓ | Remove an installed theme version. Refused while the live version, any draft/workspace or an open proposal references it. |
theme.upgrade | command | propose | ✓ | Move the workspace draft to a newer version of its active theme: installs the version (kit css pin), applies the pack's migrations (renames) and the new defaults only to values the owner never touched, keeps everything else; returns the Geçiş raporu. Publishing stays a separate step. |
audit.list | route | read | Recent audit rows for the store (optionally by entity). | |
cargo.carriers.list | route | read | Platform carrier reference table (codes, labels, tracking availability). | |
catalog.categories.list | route | read | List categories. | |
catalog.collections.get | route | read | Get one collection with members. | |
catalog.collections.list | route | read | List collections. | |
catalog.products.get | route | read | Get one product with variants, media and stock. | |
catalog.products.list | route | read | List products (keyset cursor, filters). | |
catalog.stockMovements.list | route | read | Stock ledger rows for a product or variant. | |
catalog.stockMovements.since | route | read | Store-wide stock ledger rows after a seq watermark, ascending: the outbox read a connector consumes. | |
channel.brand.create | route | propose | ✓ | Create a brand at the marketplace (multipart: name + 1-3 logo images). |
channel.buybox.get | route | quote | Buybox rank and top prices for listings (≤100). | |
channel.catalog.pull | route | propose | ✓ | Import the marketplace catalog (preview or import): products, variants, images, listings, stock and prices: a durable job. |
channel.catalog.push | route | propose | ✓ | Create/update marketplace listings for selected products (pre-flight validated; async batch tracked). |
channel.claims.act | route | propose | ✓ | Approve, reject (reason + file) or raise an issue on a marketplace claim; restock per policy. |
channel.claims.list | route | quote | Marketplace return/cancel claims with deadlines and fault tags. | |
channel.connect.test | route | quote | Probe the marketplace with the stored credentials (no store mutation): auth, identity header, stage allowlist. | |
channel.finance.list | route | read | Imported settlement rows (commission, cargo, fees, payouts) and per-order expected vs settled. | |
channel.health.get | route | read | Channel health: credentials, last sync times, webhook state, budget/429 counters, failed batches, queue depth, unmapped orders. | |
channel.jobs.cancel | route | propose | ✓ | Cancel a queued/running channel job. |
channel.jobs.get | route | read | One channel job with progress, errors and result. | |
channel.jobs.list | route | read | Durable channel jobs (imports, pushes, batch polls, sweeps) with progress. | |
channel.listing.archive | route | propose | ✓ | Archive/unarchive listings at the marketplace (archive pushes stock 0 too). |
channel.listing.delete | route | propose | ✓ | Delete listings at the marketplace (irreversible; provider rules apply, e.g. archived > 1 day and not locked). |
channel.listings.get | route | read | One listing with its provider mirror (external ids, last push/remote, errors, mapping meta). | |
channel.listings.list | route | read | Marketplace listings of this channel with status, effective price, pushed vs live stock, drift and last error. | |
channel.package.label | route | quote | Fetch the marketplace cargo label for a package (ZPL, or rendered PDF/PNG). | |
channel.package.op | route | propose | ✓ | Act on a marketplace package: status (preparing/invoiced), unsupplied (penalty acknowledged), split, invoice hand-off, cargo (carrier/box/warehouse/extend/own-carrier). |
channel.packages.labels | route | quote | Bulk labels for up to 50 packages (merged PDF). | |
channel.questions.answer | route | propose | ✓ | Answer a customer question (moderated by the marketplace). |
channel.questions.list | route | quote | Customer questions awaiting an answer (with deadlines). | |
channel.remote.attributes | route | quote | Attributes a marketplace category requires/allows (required, custom, multi, variant axis). | |
channel.remote.attributeValues | route | quote | Allowed values of one category attribute. | |
channel.remote.brands | route | quote | Marketplace brand search by name. | |
channel.remote.categories | route | quote | Marketplace category tree search (leaf categories accept products). | |
channel.remote.products | route | quote | The seller's products as the marketplace sees them (approval state, remote stock/price, reject reasons). | |
channel.sync.now | route | propose | ✓ | Run a sync task now (stock | price | orders | reconcile | finance | claims | questions), optionally scoped to listings. |
channel.unlock | route | propose | ✓ | Request unlock of locked listings (after the price/stock cause is fixed). |
channel.webhook.register | route | propose | ✓ | Register (or re-activate) the platform webhook at the marketplace with a fresh shared secret. |
compat.check | route | quote | Check an artifact's compatibility with this platform version without installing it: {kind: css|bundle|extension|tree, artifact, kit?, variables?} → verdict {ok, breaking[], warnings[]} with TR messages and alias fixes. Public and side-effect-free (CLI mozaik compat check, Dev MCP). | |
compat.contracts.get | route | read | The contract manifests this build was released with (storefront + api): every element/part/axis/token/section/zone/block/kit and route/command/scope a theme, skin, bundle or extension may reference. Same JSON as contracts/<kind>/<version>.json in the repo. | |
design.catalog.get | route | read | Section catalog for the add-picker: platform sections, the active theme's sections, store composites, extension blocks. | |
design.draft.delete | route | workspace | Discard the draft (expectedRev). | |
design.draft.get | route | read | Read the draft bundle (rev, hash, body, preview link). | |
design.draft.put | route | workspace | Replace the draft bundle under optimistic concurrency (expectedRev). | |
design.draftFromTemplate | route | workspace | Instantiate a starter template as the draft. | |
design.previewUrl.get | route | read | Signed preview link: ?hash= freezes a snapshot, ?workspace= follows that workspace's current draft (the dev-loop link). | |
design.templates.list | route | read | Starter template cards. | |
design.version.get | route | read | Full body of a published version. | |
design.versions.list | route | read | Published version ledger (seq, hash, label, live marker). | |
ext.cargo.sender | route | propose | ✓ | Create the sender address at the cargo provider and store its id in the extension config. |
extensions.list | route | read | Installed + available extensions with config, secrets state and manifest UI hints (owner-only). | |
extensions.ops.get | route | read | The extension's agent contract with LIVE readiness: every op, what it needs (secrets/config/enabled), and exactly what blocks it right now. Secrets appear as keys only. | |
kit.contract.get | route | read | The Element Contract (elements, anatomy, tokens, zones, limits) the platform renders: same JSON as docs /schemas/kit-contract.json. | |
media.list | route | read | List media objects. | |
media.upload | route | workspace | Stage a binary upload (raw body); commit with catalog.media.commit. | |
meta.get | route | read | Platform build identity and compatibility fingerprint (buildId, registryHash, minCli). | |
metafields.definitions.list | route | read | Metafield definitions (owner-only). | |
orders.belge.get | route | read | Fetch a legal document snapshot of an order. | |
orders.cargo.book | route | propose | ✓ | Accept a carrier offer, create the label and ship the order. |
orders.cargo.offers | route | quote | Create a provider quote for the order and return carrier offers (no store mutation). | |
orders.cargo.ship | route | propose | ✓ | Ship with the merchant's own carrier (manual tracking). |
orders.cod.collect | route | propose | ✓ | Mark a cash-on-delivery order as collected. |
orders.get | route | read | Get one order with lines, payment, shipments, returns, timeline. | |
orders.list | route | read | List orders. | |
orders.note.add | route | propose | ✓ | Add a merchant note to the order timeline. |
orders.refund | route | propose | ✓ | Refund part or all of a captured payment through the original PSP extension. |
orders.shipment.cancel | route | propose | ✓ | Cancel a shipment before pickup. |
orders.shipment.label | route | quote | Fetch the shipping label URL from the provider. | |
orders.shipment.track | route | propose | ✓ | Record a shipment status transition by hand. |
orders.shipment.update | route | propose | ✓ | Poll the provider and apply the current tracking status. |
proposals.get | route | read | One proposal with its items, recorded previews and (for design items) a preview link. | |
proposals.list | route | read | List proposals; agent tokens see only their own. | |
returns.approve | route | propose | ✓ | Approve a return request with shipping instructions; mails the shopper. |
returns.get | route | read | Get one return request. | |
returns.list | route | read | List return requests. | |
returns.reject | route | propose | ✓ | Reject a return request with a reason; mails the shopper. |
routes.list | route | read | List typed routes with JSON Schemas (the twin of commands.list). | |
scopes.list | route | read | Scope registry: TR labels, sensitivity and who may hold each scope (any token / developer tokens / sessions only). | |
sections.meta.get | route | read | Section catalog with props/blocks JSON Schemas and placement rules. | |
store.checkoutSettings.get | route | read | Checkout settings (owner-only). | |
store.health.get | route | read | Store readiness checklist (draft/live, identity, flags). | |
store.identity.get | route | read | Legal identity block (owner-only). | |
store.stockSettings.get | route | read | Store-wide stock policy and per-channel policies (owner-only). | |
themes.check | route | quote | Statically check a SKIN theme package {manifest, css, variables?, presets?, against?}: manifest + variables schemas, the CSS grammar with the parent kit's variables, size gates, element coverage, V1 value-aware compatibility with this platform version (+ computed requires) and, with against (the previous version), the semver class the change needs. Public and side-effect-free (the CLI's mozaik theme check). | |
themes.get | route | read | One theme's manifest, variables, presets and install state. | |
themes.list | route | read | Installed themes + the first-party gallery, with presets/variables and the draft's active theme ref. | |
tokens.whoami | route | read | Describe the calling credential: store, kind, scopes, expiry, workspace: what an agent should call first. | |
updates.list | route | read | The store's update queue (Güncellemeler): pending theme/extension/generation updates with their Geçiş raporu and preview, plus applied/blocked history, and the platform versions this store runs on. | |
validate.bundle | route | quote | Validate a store bundle (schema + referential integrity) without saving anything. Media readiness is checked at draft save, which is the enforcement point. | |
validate.command | route | quote | Validate a command payload against its registered schema without running it (no preview, no mutation). | |
validate.manifest | route | quote | Validate an extension manifest against zExtensionManifest, including the agent-contract rules. | |
workspaces.activity.list | route | read | The workspace's append-only activity feed (exec/read/write/backup/refresh with exit codes and durations). | |
workspaces.adopt | route | workspace | Copy a workspace draft into the builder's main draft under optimistic concurrency (never a merge). | |
workspaces.backup | route | workspace | Snapshot the sandbox's /workspace/store to R2 (7-day TTL); restored automatically on the next cold start. | |
workspaces.exec | route | workspace | Run one command in the workspace's hosted sandbox (the pinned CLI is preinstalled; cwd defaults to /workspace/store). Output capped at 256 KB. | |
workspaces.files.list | route | quote | List a directory inside the hosted sandbox (confined to /workspace). | |
workspaces.files.read | route | quote | Read a file from the hosted sandbox (≤1 MiB; base64 for binary). | |
workspaces.files.write | route | workspace | Write a file into the hosted sandbox (≤1 MiB; scratch only: store state flows through mozaik push/proposals). | |
workspaces.list | route | read | List draft workspaces: the builder's main draft plus every agent/developer workspace with its draft rev and sandbox state. | |
workspaces.preview | route | read | Stable signed preview URL of this workspace's draft on the store hostname (never touches the container). |