Admin MCP tools

The admin MCP is a stateless Streamable-HTTP JSON-RPC endpoint at POST https://api.mozaik-dev.com/mcp (no sessions, no SSE (every POST is answered with JSON). Auth is a bearer mzk_ token only; the store is derived from the token) a store/storeId argument in tool input is refused as a validation error. Every tool call is synthesized into an ordinary HTTP request and replayed through the same router the admin panel uses, so auth, scope gates and the proposal divert are byte-identical to the public API.

initialize negotiates the protocol (2026-07-28 with legacy auto-detect) and enforces the client floor: a clientInfo that identifies as our CLI/Dev MCP below 0.2.0 is refused with -32001 client_too_old and the exact upgrade command (npm i -g @mozaik/cli@0.2.0). Third-party MCP clients are never refused for lacking a version.

Tool names are the registry's dotted ids verbatim: one tool per command, one per catalog route with a non-owner policy (commands.run/commands.list are omitted: commands are 1:1 tools already). The list below is buildToolList() with the full admin scope; a real token sees the scope-filtered subset. Resources: mzk://store, mzk://proposal/current, mzk://draft, mzk://sections-meta, mzk://docs/{path}.

Developer view (Geliştirici token: executes directly)

toolkindpolicysummary
catalog.category.archivecommandproposeArchive a category (products keep their assignment; hidden from active lists).
catalog.category.createcommandproposeCreate a category (flat compliance taxonomy; taksitCap = BDDK installment cap).
catalog.category.updatecommandproposeUpdate a category's name, installment cap, or position.
catalog.collection.archivecommandproposeArchive a collection: its page 404s; product memberships are kept.
catalog.collection.createcommandproposeCreate a collection (handle derived from title when omitted).
catalog.collection.setProductscommandproposeWholesale-replace a collection's product list (order = array order = manual sort).
catalog.collection.updatecommandproposePatch collection fields.
catalog.digital.codes.addcommandproposeAdd e-pin codes to a pooled digital product (sealed at rest; duplicates skipped).
catalog.digital.codes.voidcommandproposeVoid unused pool codes (oldest first): they can never be allocated; nothing is deleted.
catalog.media.commitcommandproposeCommit a staged upload into the media library (variants generated async).
catalog.media.deletecommandproposePermanently delete an UNUSED media file (refused while referenced by catalog, live design, or the draft).
catalog.price.setcommandproposeSet the price (kuruş) of a product (prd_) or variant (var_). compareAt only on products; null clears it. Variant price null = inherit product price.
catalog.product.archivecommandproposeArchive a product: removed from the storefront, history kept.
catalog.product.createcommandproposeCreate a product. price/compareAt in kuruş; stock null = untracked; handle derived from title when omitted.
catalog.product.setDigitalcommandproposeSet a product's digital/shipping posture: requiresShipping, delivered digital content, withdrawal exception.
catalog.product.setMediacommandproposeWholesale-replace a product's media list (order = array order; alt is per-usage).
catalog.product.setVariantscommandproposeWholesale-replace a product's variant STRUCTURE (order = array order). Existing variants update title/sku only; initial price/stock allowed solely for new variants.
catalog.product.updatecommandproposePatch product fields. Price and stock are NOT here: use catalog.price.set / catalog.stock.set.
catalog.stock.adjustcommandproposeAdjust stock by a ± delta (receiving, stocktake, connector sync). Fails on untracked items; expectedStock = compare-and-set.
catalog.stock.setcommandproposeSet stock of a product (prd_) or variant (var_). null = untracked (always available).
channel.listing.setcommandproposeCreate/update marketplace listings for products or variants on a channel: enable, price/list overrides, price lock, buffer, mapping fields (bulk ≤500).
customer.anonymizecommandproposeAnonymize a customer row (KVKK request): order snapshots stay under the statutory retention.
customer.identity.unlinkcommandproposeClear a Mozaik ID pointer from this store's customers (revoke/erasure healing).
design.extpage.addcommandproposeAdd an installed extension's page to the workspace draft under /ek/{slug} (owner-changeable path); the page renders the extension's composite through the active theme.
design.extpage.removecommandproposeRemove an extension page from the workspace draft (menu links to it are dropped).
design.zone.placecommandproposePlace (or reconfigure) an installed extension's storefront block in a zone of the workspace draft: the owner-driven 'Yerleştir'.
design.zone.removecommandproposeRemove an extension block from a storefront zone of the workspace draft.
extension.configurecommandproposeSet an extension's configuration (validated against its schema). Does not enable it.
extension.disablecommandproposeDisable an extension. Its payment method / hooks / panels stop immediately. Channel extensions with listings must state disconnect: 'zero' (push 0 everywhere first) or 'freeze' (leave marketplace stock as is).
extension.enablecommandproposeEnable an installed extension. Requires its secrets set and config valid.
extension.hook.deactivatecommandproposeDeactivate (or reactivate) an extension's hooks without disabling the extension.
extension.installcommandproposeInstall an extension for this store (disabled until configured + enabled). Grants the manifest's scopes.
extension.uninstallcommandproposeUninstall a disabled extension. Config is archived in the audit row; secrets and data are kept.
extension.upgradecommandproposeUpgrade an installed extension to the platform's current manifest version: re-validates (or migrates) the stored config; permission growth (new scopes / PII / required secrets) needs consent: true from the owner: the reconcile sweep applies only additive upgrades by itself.
metafield.definition.createcommandproposeDefine a typed custom field on products, variants, collections, or the store.
metafield.definition.deletecommandproposeDelete a metafield definition AND every value stored under it.
metafield.definition.updatecommandproposeUpdate a metafield definition's label, description, or validations (type/key are immutable).
metafield.setcommandproposeSet a metafield value on a product, variant, collection, or the store.
metafield.unsetcommandproposeRemove a metafield value.
order.cancelcommandproposeCancel an unpaid order (pending_cod/awaiting_transfer): restocks lines. reason 'marketplace' cancels a paid marketplace order (the marketplace refunded the buyer); restock=false skips the restock.
order.cod.collectcommandproposeRecord that the carrier's COD cash for a shipped/delivered order reached the merchant: order becomes paid.
order.note.addcommandproposeAppend a merchant note to an order's timeline.
order.return.approvecommandproposeApprove a return: issues the instructions the shopper sees (snapshotted as evidence).
order.return.receivecommandproposeRecord the returned goods arriving: per-line condition; saleable lines restock (ledgered).
order.return.rejectcommandproposeReject a return with a stated reason (the shopper mail carries the THH/consumer-court recourse).
order.shipcommandproposeCreate a shipment for an order's shippable lines (a cargo extension or a manual carrier): writes the VUK 509 forward fields.
order.shipment.cancelcommandproposeCancel a shipment before carrier handoff completes: resets the order to unfulfilled when nothing else is active.
order.shipment.trackcommandproposeRecord a carrier state transition (webhook/poll/manual) and aggregate the order's fulfillment status.
order.transfer.confirmcommandproposeConfirm a bank-transfer payment arrived: order becomes paid; digital content is released.
proposal.submitcommanddirectSubmit an open proposal for the store owner's review (the owner is mailed a link). The proposalId comes from your first recorded mutation's response: or proposals.list.
proposal.withdrawcommanddirectWithdraw a proposal that has not been applied.
settings.channel.updatecommandproposeUpdate one marketplace channel's policy: push/pull switches, price rule, buffer, resend window, disconnect and buyer-mail policy.
settings.checkout.updatecommandproposeUpdate checkout legal settings: delivery estimate, return-cargo carrier/cost disclosure.
settings.flag.setcommandproposeSet or clear a store readiness flag (ETBİS beyanı, rehber kartları).
settings.identity.updatecommandproposeSet the legal merchant identity (6563 m.3): complete rows only; rendered live in the footer.
settings.stock.updatecommandproposeUpdate store-wide stock policy: default marketplace buffer, untracked quantity, restock-on-cancel/return, zero-when-archived.
settings.store.updatecommandproposeUpdate store settings (display name). Projected to KV tenant records.
store.syncKvcommanddirectRe-project store state (t:, l:, live b:, g:) from Postgres to KV; bumps generation once.
theme.installcommandproposeInstall a theme version for this store (first-party or a visible pack). Does not change the live look until a switch is published: except a newer first-party version re-pins the kit stylesheet the live site links (V1 S2).
theme.page.resetcommandproposeReplace one page (or header/footer) in the workspace draft with the active theme's skeleton for it.
theme.preset.applycommandproposeApply one of the active theme's presets (Varyasyon) to the workspace draft: only the values the preset names change.
theme.pushcommandproposePush a store-private SKIN theme (manifest + linted CSS + variables + presets + skeleton) from the CLI/sandbox: records the immutable pack, stores its stylesheet, installs the version.
theme.switchcommandproposeSwitch the workspace draft to another installed theme (keep-layout or theme-skeleton): lossless: settings kept by id, sections parked never deleted; returns the Geçiş raporu.
theme.uninstallcommandproposeRemove an installed theme version. Refused while the live version, any draft/workspace or an open proposal references it.
theme.upgradecommandproposeMove the workspace draft to a newer version of its active theme: installs the version (kit css pin), applies the pack's migrations (renames) and the new defaults only to values the owner never touched, keeps everything else; returns the Geçiş raporu. Publishing stays a separate step.
audit.listroutereadRecent audit rows for the store (optionally by entity).
cargo.carriers.listroutereadPlatform carrier reference table (codes, labels, tracking availability).
catalog.categories.listroutereadList categories.
catalog.collections.getroutereadGet one collection with members.
catalog.collections.listroutereadList collections.
catalog.products.getroutereadGet one product with variants, media and stock.
catalog.products.listroutereadList products (keyset cursor, filters).
catalog.stockMovements.listroutereadStock ledger rows for a product or variant.
catalog.stockMovements.sinceroutereadStore-wide stock ledger rows after a seq watermark, ascending: the outbox read a connector consumes.
channel.brand.createrouteproposeCreate a brand at the marketplace (multipart: name + 1-3 logo images).
channel.buybox.getroutequoteBuybox rank and top prices for listings (≤100).
channel.catalog.pullrouteproposeImport the marketplace catalog (preview or import): products, variants, images, listings, stock and prices: a durable job.
channel.catalog.pushrouteproposeCreate/update marketplace listings for selected products (pre-flight validated; async batch tracked).
channel.claims.actrouteproposeApprove, reject (reason + file) or raise an issue on a marketplace claim; restock per policy.
channel.claims.listroutequoteMarketplace return/cancel claims with deadlines and fault tags.
channel.connect.testroutequoteProbe the marketplace with the stored credentials (no store mutation): auth, identity header, stage allowlist.
channel.finance.listroutereadImported settlement rows (commission, cargo, fees, payouts) and per-order expected vs settled.
channel.health.getroutereadChannel health: credentials, last sync times, webhook state, budget/429 counters, failed batches, queue depth, unmapped orders.
channel.jobs.cancelrouteproposeCancel a queued/running channel job.
channel.jobs.getroutereadOne channel job with progress, errors and result.
channel.jobs.listroutereadDurable channel jobs (imports, pushes, batch polls, sweeps) with progress.
channel.listing.archiverouteproposeArchive/unarchive listings at the marketplace (archive pushes stock 0 too).
channel.listing.deleterouteproposeDelete listings at the marketplace (irreversible; provider rules apply, e.g. archived > 1 day and not locked).
channel.listings.getroutereadOne listing with its provider mirror (external ids, last push/remote, errors, mapping meta).
channel.listings.listroutereadMarketplace listings of this channel with status, effective price, pushed vs live stock, drift and last error.
channel.package.labelroutequoteFetch the marketplace cargo label for a package (ZPL, or rendered PDF/PNG).
channel.package.oprouteproposeAct on a marketplace package: status (preparing/invoiced), unsupplied (penalty acknowledged), split, invoice hand-off, cargo (carrier/box/warehouse/extend/own-carrier).
channel.packages.labelsroutequoteBulk labels for up to 50 packages (merged PDF).
channel.questions.answerrouteproposeAnswer a customer question (moderated by the marketplace).
channel.questions.listroutequoteCustomer questions awaiting an answer (with deadlines).
channel.remote.attributesroutequoteAttributes a marketplace category requires/allows (required, custom, multi, variant axis).
channel.remote.attributeValuesroutequoteAllowed values of one category attribute.
channel.remote.brandsroutequoteMarketplace brand search by name.
channel.remote.categoriesroutequoteMarketplace category tree search (leaf categories accept products).
channel.remote.productsroutequoteThe seller's products as the marketplace sees them (approval state, remote stock/price, reject reasons).
channel.sync.nowrouteproposeRun a sync task now (stock | price | orders | reconcile | finance | claims | questions), optionally scoped to listings.
channel.unlockrouteproposeRequest unlock of locked listings (after the price/stock cause is fixed).
channel.webhook.registerrouteproposeRegister (or re-activate) the platform webhook at the marketplace with a fresh shared secret.
compat.checkroutequoteCheck an artifact's compatibility with this platform version without installing it: {kind: css|bundle|extension|tree, artifact, kit?, variables?} → verdict {ok, breaking[], warnings[]} with TR messages and alias fixes. Public and side-effect-free (CLI mozaik compat check, Dev MCP).
compat.contracts.getroutereadThe contract manifests this build was released with (storefront + api): every element/part/axis/token/section/zone/block/kit and route/command/scope a theme, skin, bundle or extension may reference. Same JSON as contracts/<kind>/<version>.json in the repo.
design.catalog.getroutereadSection catalog for the add-picker: platform sections, the active theme's sections, store composites, extension blocks.
design.draft.deleterouteworkspaceDiscard the draft (expectedRev).
design.draft.getroutereadRead the draft bundle (rev, hash, body, preview link).
design.draft.putrouteworkspaceReplace the draft bundle under optimistic concurrency (expectedRev).
design.draftFromTemplaterouteworkspaceInstantiate a starter template as the draft.
design.previewUrl.getroutereadSigned preview link: ?hash= freezes a snapshot, ?workspace= follows that workspace's current draft (the dev-loop link).
design.templates.listroutereadStarter template cards.
design.version.getroutereadFull body of a published version.
design.versions.listroutereadPublished version ledger (seq, hash, label, live marker).
ext.cargo.senderrouteproposeCreate the sender address at the cargo provider and store its id in the extension config.
extensions.listroutereadInstalled + available extensions with config, secrets state and manifest UI hints (owner-only).
extensions.ops.getroutereadThe extension's agent contract with LIVE readiness: every op, what it needs (secrets/config/enabled), and exactly what blocks it right now. Secrets appear as keys only.
kit.contract.getroutereadThe Element Contract (elements, anatomy, tokens, zones, limits) the platform renders: same JSON as docs /schemas/kit-contract.json.
media.listroutereadList media objects.
media.uploadrouteworkspaceStage a binary upload (raw body); commit with catalog.media.commit.
meta.getroutereadPlatform build identity and compatibility fingerprint (buildId, registryHash, minCli).
metafields.definitions.listroutereadMetafield definitions (owner-only).
orders.belge.getroutereadFetch a legal document snapshot of an order.
orders.cargo.bookrouteproposeAccept a carrier offer, create the label and ship the order.
orders.cargo.offersroutequoteCreate a provider quote for the order and return carrier offers (no store mutation).
orders.cargo.shiprouteproposeShip with the merchant's own carrier (manual tracking).
orders.cod.collectrouteproposeMark a cash-on-delivery order as collected.
orders.getroutereadGet one order with lines, payment, shipments, returns, timeline.
orders.listroutereadList orders.
orders.note.addrouteproposeAdd a merchant note to the order timeline.
orders.refundrouteproposeRefund part or all of a captured payment through the original PSP extension.
orders.shipment.cancelrouteproposeCancel a shipment before pickup.
orders.shipment.labelroutequoteFetch the shipping label URL from the provider.
orders.shipment.trackrouteproposeRecord a shipment status transition by hand.
orders.shipment.updaterouteproposePoll the provider and apply the current tracking status.
proposals.getroutereadOne proposal with its items, recorded previews and (for design items) a preview link.
proposals.listroutereadList proposals; agent tokens see only their own.
returns.approverouteproposeApprove a return request with shipping instructions; mails the shopper.
returns.getroutereadGet one return request.
returns.listroutereadList return requests.
returns.rejectrouteproposeReject a return request with a reason; mails the shopper.
routes.listroutereadList typed routes with JSON Schemas (the twin of commands.list).
scopes.listroutereadScope registry: TR labels, sensitivity and who may hold each scope (any token / developer tokens / sessions only).
sections.meta.getroutereadSection catalog with props/blocks JSON Schemas and placement rules.
store.checkoutSettings.getroutereadCheckout settings (owner-only).
store.health.getroutereadStore readiness checklist (draft/live, identity, flags).
store.identity.getroutereadLegal identity block (owner-only).
store.stockSettings.getroutereadStore-wide stock policy and per-channel policies (owner-only).
themes.checkroutequoteStatically check a SKIN theme package {manifest, css, variables?, presets?, against?}: manifest + variables schemas, the CSS grammar with the parent kit's variables, size gates, element coverage, V1 value-aware compatibility with this platform version (+ computed requires) and, with against (the previous version), the semver class the change needs. Public and side-effect-free (the CLI's mozaik theme check).
themes.getroutereadOne theme's manifest, variables, presets and install state.
themes.listroutereadInstalled themes + the first-party gallery, with presets/variables and the draft's active theme ref.
tokens.whoamiroutereadDescribe the calling credential: store, kind, scopes, expiry, workspace: what an agent should call first.
updates.listroutereadThe store's update queue (Güncellemeler): pending theme/extension/generation updates with their Geçiş raporu and preview, plus applied/blocked history, and the platform versions this store runs on.
validate.bundleroutequoteValidate a store bundle (schema + referential integrity) without saving anything. Media readiness is checked at draft save, which is the enforcement point.
validate.commandroutequoteValidate a command payload against its registered schema without running it (no preview, no mutation).
validate.manifestroutequoteValidate an extension manifest against zExtensionManifest, including the agent-contract rules.
workspaces.activity.listroutereadThe workspace's append-only activity feed (exec/read/write/backup/refresh with exit codes and durations).
workspaces.adoptrouteworkspaceCopy a workspace draft into the builder's main draft under optimistic concurrency (never a merge).
workspaces.backuprouteworkspaceSnapshot the sandbox's /workspace/store to R2 (7-day TTL); restored automatically on the next cold start.
workspaces.execrouteworkspaceRun one command in the workspace's hosted sandbox (the pinned CLI is preinstalled; cwd defaults to /workspace/store). Output capped at 256 KB.
workspaces.files.listroutequoteList a directory inside the hosted sandbox (confined to /workspace).
workspaces.files.readroutequoteRead a file from the hosted sandbox (≤1 MiB; base64 for binary).
workspaces.files.writerouteworkspaceWrite a file into the hosted sandbox (≤1 MiB; scratch only: store state flows through mozaik push/proposals).
workspaces.listroutereadList draft workspaces: the builder's main draft plus every agent/developer workspace with its draft rev and sandbox state.
workspaces.previewroutereadStable signed preview URL of this workspace's draft on the store hostname (never touches the container).

Agent view (Ajan token: propose tools are recorded, not applied)

The same names; propose tools answer PROPOSED (not applied) and record the call into the token's open proposal for the owner to review.

toolkindpolicyproposal-recordedsummary
catalog.category.archivecommandpropose✓Archive a category (products keep their assignment; hidden from active lists).
catalog.category.createcommandpropose✓Create a category (flat compliance taxonomy; taksitCap = BDDK installment cap).
catalog.category.updatecommandpropose✓Update a category's name, installment cap, or position.
catalog.collection.archivecommandpropose✓Archive a collection: its page 404s; product memberships are kept.
catalog.collection.createcommandpropose✓Create a collection (handle derived from title when omitted).
catalog.collection.setProductscommandpropose✓Wholesale-replace a collection's product list (order = array order = manual sort).
catalog.collection.updatecommandpropose✓Patch collection fields.
catalog.digital.codes.addcommandpropose✓Add e-pin codes to a pooled digital product (sealed at rest; duplicates skipped).
catalog.digital.codes.voidcommandpropose✓Void unused pool codes (oldest first): they can never be allocated; nothing is deleted.
catalog.media.commitcommandpropose✓Commit a staged upload into the media library (variants generated async).
catalog.media.deletecommandpropose✓Permanently delete an UNUSED media file (refused while referenced by catalog, live design, or the draft).
catalog.price.setcommandpropose✓Set the price (kuruş) of a product (prd_) or variant (var_). compareAt only on products; null clears it. Variant price null = inherit product price.
catalog.product.archivecommandpropose✓Archive a product: removed from the storefront, history kept.
catalog.product.createcommandpropose✓Create a product. price/compareAt in kuruş; stock null = untracked; handle derived from title when omitted.
catalog.product.setDigitalcommandpropose✓Set a product's digital/shipping posture: requiresShipping, delivered digital content, withdrawal exception.
catalog.product.setMediacommandpropose✓Wholesale-replace a product's media list (order = array order; alt is per-usage).
catalog.product.setVariantscommandpropose✓Wholesale-replace a product's variant STRUCTURE (order = array order). Existing variants update title/sku only; initial price/stock allowed solely for new variants.
catalog.product.updatecommandpropose✓Patch product fields. Price and stock are NOT here: use catalog.price.set / catalog.stock.set.
catalog.stock.adjustcommandpropose✓Adjust stock by a ± delta (receiving, stocktake, connector sync). Fails on untracked items; expectedStock = compare-and-set.
catalog.stock.setcommandpropose✓Set stock of a product (prd_) or variant (var_). null = untracked (always available).
channel.listing.setcommandpropose✓Create/update marketplace listings for products or variants on a channel: enable, price/list overrides, price lock, buffer, mapping fields (bulk ≤500).
customer.anonymizecommandpropose✓Anonymize a customer row (KVKK request): order snapshots stay under the statutory retention.
customer.identity.unlinkcommandpropose✓Clear a Mozaik ID pointer from this store's customers (revoke/erasure healing).
design.extpage.addcommandpropose✓Add an installed extension's page to the workspace draft under /ek/{slug} (owner-changeable path); the page renders the extension's composite through the active theme.
design.extpage.removecommandpropose✓Remove an extension page from the workspace draft (menu links to it are dropped).
design.zone.placecommandpropose✓Place (or reconfigure) an installed extension's storefront block in a zone of the workspace draft: the owner-driven 'Yerleştir'.
design.zone.removecommandpropose✓Remove an extension block from a storefront zone of the workspace draft.
extension.configurecommandpropose✓Set an extension's configuration (validated against its schema). Does not enable it.
extension.disablecommandpropose✓Disable an extension. Its payment method / hooks / panels stop immediately. Channel extensions with listings must state disconnect: 'zero' (push 0 everywhere first) or 'freeze' (leave marketplace stock as is).
extension.enablecommandpropose✓Enable an installed extension. Requires its secrets set and config valid.
extension.hook.deactivatecommandpropose✓Deactivate (or reactivate) an extension's hooks without disabling the extension.
extension.installcommandpropose✓Install an extension for this store (disabled until configured + enabled). Grants the manifest's scopes.
extension.uninstallcommandpropose✓Uninstall a disabled extension. Config is archived in the audit row; secrets and data are kept.
extension.upgradecommandpropose✓Upgrade an installed extension to the platform's current manifest version: re-validates (or migrates) the stored config; permission growth (new scopes / PII / required secrets) needs consent: true from the owner: the reconcile sweep applies only additive upgrades by itself.
metafield.definition.createcommandpropose✓Define a typed custom field on products, variants, collections, or the store.
metafield.definition.deletecommandpropose✓Delete a metafield definition AND every value stored under it.
metafield.definition.updatecommandpropose✓Update a metafield definition's label, description, or validations (type/key are immutable).
metafield.setcommandpropose✓Set a metafield value on a product, variant, collection, or the store.
metafield.unsetcommandpropose✓Remove a metafield value.
order.cancelcommandpropose✓Cancel an unpaid order (pending_cod/awaiting_transfer): restocks lines. reason 'marketplace' cancels a paid marketplace order (the marketplace refunded the buyer); restock=false skips the restock.
order.cod.collectcommandpropose✓Record that the carrier's COD cash for a shipped/delivered order reached the merchant: order becomes paid.
order.note.addcommandpropose✓Append a merchant note to an order's timeline.
order.return.approvecommandpropose✓Approve a return: issues the instructions the shopper sees (snapshotted as evidence).
order.return.receivecommandpropose✓Record the returned goods arriving: per-line condition; saleable lines restock (ledgered).
order.return.rejectcommandpropose✓Reject a return with a stated reason (the shopper mail carries the THH/consumer-court recourse).
order.shipcommandpropose✓Create a shipment for an order's shippable lines (a cargo extension or a manual carrier): writes the VUK 509 forward fields.
order.shipment.cancelcommandpropose✓Cancel a shipment before carrier handoff completes: resets the order to unfulfilled when nothing else is active.
order.shipment.trackcommandpropose✓Record a carrier state transition (webhook/poll/manual) and aggregate the order's fulfillment status.
order.transfer.confirmcommandpropose✓Confirm a bank-transfer payment arrived: order becomes paid; digital content is released.
proposal.submitcommanddirectSubmit an open proposal for the store owner's review (the owner is mailed a link). The proposalId comes from your first recorded mutation's response: or proposals.list.
proposal.withdrawcommanddirectWithdraw a proposal that has not been applied.
settings.channel.updatecommandpropose✓Update one marketplace channel's policy: push/pull switches, price rule, buffer, resend window, disconnect and buyer-mail policy.
settings.checkout.updatecommandpropose✓Update checkout legal settings: delivery estimate, return-cargo carrier/cost disclosure.
settings.flag.setcommandpropose✓Set or clear a store readiness flag (ETBİS beyanı, rehber kartları).
settings.identity.updatecommandpropose✓Set the legal merchant identity (6563 m.3): complete rows only; rendered live in the footer.
settings.stock.updatecommandpropose✓Update store-wide stock policy: default marketplace buffer, untracked quantity, restock-on-cancel/return, zero-when-archived.
settings.store.updatecommandpropose✓Update store settings (display name). Projected to KV tenant records.
store.syncKvcommanddirectRe-project store state (t:, l:, live b:, g:) from Postgres to KV; bumps generation once.
theme.installcommandpropose✓Install a theme version for this store (first-party or a visible pack). Does not change the live look until a switch is published: except a newer first-party version re-pins the kit stylesheet the live site links (V1 S2).
theme.page.resetcommandpropose✓Replace one page (or header/footer) in the workspace draft with the active theme's skeleton for it.
theme.preset.applycommandpropose✓Apply one of the active theme's presets (Varyasyon) to the workspace draft: only the values the preset names change.
theme.pushcommandpropose✓Push a store-private SKIN theme (manifest + linted CSS + variables + presets + skeleton) from the CLI/sandbox: records the immutable pack, stores its stylesheet, installs the version.
theme.switchcommandpropose✓Switch the workspace draft to another installed theme (keep-layout or theme-skeleton): lossless: settings kept by id, sections parked never deleted; returns the Geçiş raporu.
theme.uninstallcommandpropose✓Remove an installed theme version. Refused while the live version, any draft/workspace or an open proposal references it.
theme.upgradecommandpropose✓Move the workspace draft to a newer version of its active theme: installs the version (kit css pin), applies the pack's migrations (renames) and the new defaults only to values the owner never touched, keeps everything else; returns the Geçiş raporu. Publishing stays a separate step.
audit.listroutereadRecent audit rows for the store (optionally by entity).
cargo.carriers.listroutereadPlatform carrier reference table (codes, labels, tracking availability).
catalog.categories.listroutereadList categories.
catalog.collections.getroutereadGet one collection with members.
catalog.collections.listroutereadList collections.
catalog.products.getroutereadGet one product with variants, media and stock.
catalog.products.listroutereadList products (keyset cursor, filters).
catalog.stockMovements.listroutereadStock ledger rows for a product or variant.
catalog.stockMovements.sinceroutereadStore-wide stock ledger rows after a seq watermark, ascending: the outbox read a connector consumes.
channel.brand.createroutepropose✓Create a brand at the marketplace (multipart: name + 1-3 logo images).
channel.buybox.getroutequoteBuybox rank and top prices for listings (≤100).
channel.catalog.pullroutepropose✓Import the marketplace catalog (preview or import): products, variants, images, listings, stock and prices: a durable job.
channel.catalog.pushroutepropose✓Create/update marketplace listings for selected products (pre-flight validated; async batch tracked).
channel.claims.actroutepropose✓Approve, reject (reason + file) or raise an issue on a marketplace claim; restock per policy.
channel.claims.listroutequoteMarketplace return/cancel claims with deadlines and fault tags.
channel.connect.testroutequoteProbe the marketplace with the stored credentials (no store mutation): auth, identity header, stage allowlist.
channel.finance.listroutereadImported settlement rows (commission, cargo, fees, payouts) and per-order expected vs settled.
channel.health.getroutereadChannel health: credentials, last sync times, webhook state, budget/429 counters, failed batches, queue depth, unmapped orders.
channel.jobs.cancelroutepropose✓Cancel a queued/running channel job.
channel.jobs.getroutereadOne channel job with progress, errors and result.
channel.jobs.listroutereadDurable channel jobs (imports, pushes, batch polls, sweeps) with progress.
channel.listing.archiveroutepropose✓Archive/unarchive listings at the marketplace (archive pushes stock 0 too).
channel.listing.deleteroutepropose✓Delete listings at the marketplace (irreversible; provider rules apply, e.g. archived > 1 day and not locked).
channel.listings.getroutereadOne listing with its provider mirror (external ids, last push/remote, errors, mapping meta).
channel.listings.listroutereadMarketplace listings of this channel with status, effective price, pushed vs live stock, drift and last error.
channel.package.labelroutequoteFetch the marketplace cargo label for a package (ZPL, or rendered PDF/PNG).
channel.package.oproutepropose✓Act on a marketplace package: status (preparing/invoiced), unsupplied (penalty acknowledged), split, invoice hand-off, cargo (carrier/box/warehouse/extend/own-carrier).
channel.packages.labelsroutequoteBulk labels for up to 50 packages (merged PDF).
channel.questions.answerroutepropose✓Answer a customer question (moderated by the marketplace).
channel.questions.listroutequoteCustomer questions awaiting an answer (with deadlines).
channel.remote.attributesroutequoteAttributes a marketplace category requires/allows (required, custom, multi, variant axis).
channel.remote.attributeValuesroutequoteAllowed values of one category attribute.
channel.remote.brandsroutequoteMarketplace brand search by name.
channel.remote.categoriesroutequoteMarketplace category tree search (leaf categories accept products).
channel.remote.productsroutequoteThe seller's products as the marketplace sees them (approval state, remote stock/price, reject reasons).
channel.sync.nowroutepropose✓Run a sync task now (stock | price | orders | reconcile | finance | claims | questions), optionally scoped to listings.
channel.unlockroutepropose✓Request unlock of locked listings (after the price/stock cause is fixed).
channel.webhook.registerroutepropose✓Register (or re-activate) the platform webhook at the marketplace with a fresh shared secret.
compat.checkroutequoteCheck an artifact's compatibility with this platform version without installing it: {kind: css|bundle|extension|tree, artifact, kit?, variables?} → verdict {ok, breaking[], warnings[]} with TR messages and alias fixes. Public and side-effect-free (CLI mozaik compat check, Dev MCP).
compat.contracts.getroutereadThe contract manifests this build was released with (storefront + api): every element/part/axis/token/section/zone/block/kit and route/command/scope a theme, skin, bundle or extension may reference. Same JSON as contracts/<kind>/<version>.json in the repo.
design.catalog.getroutereadSection catalog for the add-picker: platform sections, the active theme's sections, store composites, extension blocks.
design.draft.deleterouteworkspaceDiscard the draft (expectedRev).
design.draft.getroutereadRead the draft bundle (rev, hash, body, preview link).
design.draft.putrouteworkspaceReplace the draft bundle under optimistic concurrency (expectedRev).
design.draftFromTemplaterouteworkspaceInstantiate a starter template as the draft.
design.previewUrl.getroutereadSigned preview link: ?hash= freezes a snapshot, ?workspace= follows that workspace's current draft (the dev-loop link).
design.templates.listroutereadStarter template cards.
design.version.getroutereadFull body of a published version.
design.versions.listroutereadPublished version ledger (seq, hash, label, live marker).
ext.cargo.senderroutepropose✓Create the sender address at the cargo provider and store its id in the extension config.
extensions.listroutereadInstalled + available extensions with config, secrets state and manifest UI hints (owner-only).
extensions.ops.getroutereadThe extension's agent contract with LIVE readiness: every op, what it needs (secrets/config/enabled), and exactly what blocks it right now. Secrets appear as keys only.
kit.contract.getroutereadThe Element Contract (elements, anatomy, tokens, zones, limits) the platform renders: same JSON as docs /schemas/kit-contract.json.
media.listroutereadList media objects.
media.uploadrouteworkspaceStage a binary upload (raw body); commit with catalog.media.commit.
meta.getroutereadPlatform build identity and compatibility fingerprint (buildId, registryHash, minCli).
metafields.definitions.listroutereadMetafield definitions (owner-only).
orders.belge.getroutereadFetch a legal document snapshot of an order.
orders.cargo.bookroutepropose✓Accept a carrier offer, create the label and ship the order.
orders.cargo.offersroutequoteCreate a provider quote for the order and return carrier offers (no store mutation).
orders.cargo.shiproutepropose✓Ship with the merchant's own carrier (manual tracking).
orders.cod.collectroutepropose✓Mark a cash-on-delivery order as collected.
orders.getroutereadGet one order with lines, payment, shipments, returns, timeline.
orders.listroutereadList orders.
orders.note.addroutepropose✓Add a merchant note to the order timeline.
orders.refundroutepropose✓Refund part or all of a captured payment through the original PSP extension.
orders.shipment.cancelroutepropose✓Cancel a shipment before pickup.
orders.shipment.labelroutequoteFetch the shipping label URL from the provider.
orders.shipment.trackroutepropose✓Record a shipment status transition by hand.
orders.shipment.updateroutepropose✓Poll the provider and apply the current tracking status.
proposals.getroutereadOne proposal with its items, recorded previews and (for design items) a preview link.
proposals.listroutereadList proposals; agent tokens see only their own.
returns.approveroutepropose✓Approve a return request with shipping instructions; mails the shopper.
returns.getroutereadGet one return request.
returns.listroutereadList return requests.
returns.rejectroutepropose✓Reject a return request with a reason; mails the shopper.
routes.listroutereadList typed routes with JSON Schemas (the twin of commands.list).
scopes.listroutereadScope registry: TR labels, sensitivity and who may hold each scope (any token / developer tokens / sessions only).
sections.meta.getroutereadSection catalog with props/blocks JSON Schemas and placement rules.
store.checkoutSettings.getroutereadCheckout settings (owner-only).
store.health.getroutereadStore readiness checklist (draft/live, identity, flags).
store.identity.getroutereadLegal identity block (owner-only).
store.stockSettings.getroutereadStore-wide stock policy and per-channel policies (owner-only).
themes.checkroutequoteStatically check a SKIN theme package {manifest, css, variables?, presets?, against?}: manifest + variables schemas, the CSS grammar with the parent kit's variables, size gates, element coverage, V1 value-aware compatibility with this platform version (+ computed requires) and, with against (the previous version), the semver class the change needs. Public and side-effect-free (the CLI's mozaik theme check).
themes.getroutereadOne theme's manifest, variables, presets and install state.
themes.listroutereadInstalled themes + the first-party gallery, with presets/variables and the draft's active theme ref.
tokens.whoamiroutereadDescribe the calling credential: store, kind, scopes, expiry, workspace: what an agent should call first.
updates.listroutereadThe store's update queue (Güncellemeler): pending theme/extension/generation updates with their Geçiş raporu and preview, plus applied/blocked history, and the platform versions this store runs on.
validate.bundleroutequoteValidate a store bundle (schema + referential integrity) without saving anything. Media readiness is checked at draft save, which is the enforcement point.
validate.commandroutequoteValidate a command payload against its registered schema without running it (no preview, no mutation).
validate.manifestroutequoteValidate an extension manifest against zExtensionManifest, including the agent-contract rules.
workspaces.activity.listroutereadThe workspace's append-only activity feed (exec/read/write/backup/refresh with exit codes and durations).
workspaces.adoptrouteworkspaceCopy a workspace draft into the builder's main draft under optimistic concurrency (never a merge).
workspaces.backuprouteworkspaceSnapshot the sandbox's /workspace/store to R2 (7-day TTL); restored automatically on the next cold start.
workspaces.execrouteworkspaceRun one command in the workspace's hosted sandbox (the pinned CLI is preinstalled; cwd defaults to /workspace/store). Output capped at 256 KB.
workspaces.files.listroutequoteList a directory inside the hosted sandbox (confined to /workspace).
workspaces.files.readroutequoteRead a file from the hosted sandbox (≤1 MiB; base64 for binary).
workspaces.files.writerouteworkspaceWrite a file into the hosted sandbox (≤1 MiB; scratch only: store state flows through mozaik push/proposals).
workspaces.listroutereadList draft workspaces: the builder's main draft plus every agent/developer workspace with its draft rev and sandbox state.
workspaces.previewroutereadStable signed preview URL of this workspace's draft on the store hostname (never touches the container).
Generated from the live platform registries at build time: reference pages cannot go stale. Markdown variant: /reference/mcp-tools.md