# io.github.dappros/ethora-mcp-server (remote · mcp.chat.ethora.com)

Ethora chat platform MCP: apps, users, rooms, AI agents, chat widgets. Hosted or stdio.

- Trust score: 67/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- remote · `mcp.chat.ethora.com`: 67/100 (this document), [markdown](https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp.md), [page](https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp)
- remote · `mcp.chat.ethora.com`: 38/100, [markdown](https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp-oauth.md), [page](https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp-oauth)
- npm · `@ethora/mcp-server`: 83/100, [markdown](https://verifymcp.io/servers/dappros-ethora-mcp-server/ethora-mcp-server.md), [page](https://verifymcp.io/servers/dappros-ethora-mcp-server/ethora-mcp-server)

## Channel facts

- Endpoint: `https://mcp.chat.ethora.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `26.9.3`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (ethora-files-delete-v2).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 77/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 21324 tokens (~224/item across 95 items; 91 tools + 4 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 15/100
  - Stability check failed: schema churn in the 5 days we've observed: 1 tool removals, 1 breaking changes, 0 auth/transport breaks, 2 additions.
- **Tool Coverage**: 97/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 90% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 13 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 93 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.github.dappros/ethora-mcp-server server?

io.github.dappros/ethora-mcp-server is a hosted endpoint at https://mcp.chat.ethora.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http dappros-ethora-mcp-server 'https://mcp.chat.ethora.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "dappros-ethora-mcp-server": {
      "url": "https://mcp.chat.ethora.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "dappros-ethora-mcp-server": {
      "type": "http",
      "url": "https://mcp.chat.ethora.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.dappros-ethora-mcp-server]
url = "https://mcp.chat.ethora.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dappros-ethora-mcp-server": {
      "type": "remote",
      "url": "https://mcp.chat.ethora.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add dappros-ethora-mcp-server --url 'https://mcp.chat.ethora.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  dappros-ethora-mcp-server:
    url: "https://mcp.chat.ethora.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "dappros-ethora-mcp-server": {
      "Transport": "http",
      "Url": "https://mcp.chat.ethora.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add dappros-ethora-mcp-server -t streamable-http -u 'https://mcp.chat.ethora.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "dappros-ethora-mcp-server": {
      "type": "http",
      "url": "https://mcp.chat.ethora.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 8 to 12.

### 2026-09-17 (score 66, 0)

- [security regression] Stability: 0.03 → fail
- [security regression] A breaking change shipped without a version bump: still 26.9.1
- [security regression] Tool “ethora-wallet-get-balance” was removed
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “ethora-bot-disable-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-clone-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-create-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-delete-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-export-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-get-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-import-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-update-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-api-key-revoke” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-create” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-create-chat” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-delete” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-delete-chat” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-export-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-get-default-rooms-with-app-id” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-import-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-list” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-tokens-revoke-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-tokens-rotate-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-app-update” rewrote its description, which is the text the model reads
- [security] Tool “ethora-b2b-bot-enable” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-enable-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-get-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-instance-diag” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-instance-leave-chat” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-instance-status” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-instance-test-message” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-instances-list” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-update-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-bot-widget-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-chats-broadcast-job-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-chats-broadcast-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-chats-history-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-chats-message-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-files-delete-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-files-get-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-generate-chat-component-app-tsx” rewrote its description, which is the text the model reads
- [security] Tool “ethora-messages-context-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-messages-search-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-run-recipe” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-delete” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-delete-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-list-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-tags-update-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-upload” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-docs-upload-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-crawl-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-crawl-v2-wait” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-delete-url-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-delete-url-v2-batch” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-list-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-reindex-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-reindex-v2-wait” rewrote its description, which is the text the model reads
- [security] Tool “ethora-sources-site-tags-update-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-unread-counts-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-users-batch-job-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-wait-broadcast-job-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-wait-users-batch-job-v2” rewrote its description, which is the text the model reads
- [security] Tool “ethora-widget-embed-snippet” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agent-invite-to-chat” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agent-set-visibility” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agent-soul-append” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agent-soul-set” rewrote its description, which is the text the model reads
- [security] Tool “ethora-agents-activate-v2” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 192 → 224
- [functional regression] Schema quality: 192 → 222
- [functional regression] “ethora-agents-import-v2” made “bundle” required, so existing callers break
- [functional] Server version: 26.9.1 → 26.9.3
- [functional] New tool “ethora-feedback-submit”
- [functional] New tool “ethora-app-credentials”
- [cosmetic] “ethora-agents-activate-v2” added an optional parameter “agentIdOrAddress”
- [cosmetic] “ethora-agents-clone-v2” added an optional parameter “agentIdOrAddress”
- [cosmetic] “ethora-agents-create-v2” added an optional parameter “flowsYaml”
- [cosmetic] “ethora-agents-delete-v2” added an optional parameter “agentId”
- [cosmetic] “ethora-agents-export-v2” added an optional parameter “agentId”
- [cosmetic] “ethora-agents-get-v2” added an optional parameter “agentIdOrAddress”
- [cosmetic] “ethora-agents-update-v2” added an optional parameter “agentIdOrAddress”
- [cosmetic] “ethora-agents-update-v2” added an optional parameter “flowsYaml”
- [cosmetic] “ethora-app-update” added an optional parameter “appTagline”
- [cosmetic] “ethora-bot-instance-diag” added an optional parameter “agentId”
- [cosmetic] “ethora-bot-instance-leave-chat” added an optional parameter “agentId”
- [cosmetic] “ethora-bot-instance-test-message” added an optional parameter “agentId”
- [cosmetic] “ethora-bot-instances-list” added an optional parameter “agentIdOrAddress”
- [cosmetic] “ethora-agent-invite-to-chat” added an optional parameter “agentId”
- [cosmetic] “ethora-agent-set-visibility” added an optional parameter “agentId”
- [cosmetic] “ethora-agent-soul-append” added an optional parameter “agentId”
- [cosmetic] “ethora-agent-soul-set” added an optional parameter “agentId”
- [cosmetic] “ethora-agents-import-v2” reworded the description of “bundle”
- [cosmetic] “ethora-app-update” reworded the description of “appDescription”
- [cosmetic] “ethora-sources-site-crawl-v2-wait” reworded the description of “timeoutMs”
- [cosmetic] “ethora-sources-site-reindex-v2-wait” reworded the description of “timeoutMs”
- [cosmetic] “ethora-agents-activate-v2” made “agentId” optional
- [cosmetic] “ethora-agents-clone-v2” made “agentId” optional
- [cosmetic] “ethora-agents-delete-v2” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agents-export-v2” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agents-get-v2” made “agentId” optional
- [cosmetic] “ethora-agents-update-v2” made “agentId” optional
- [cosmetic] “ethora-bot-instance-diag” made “agentIdOrAddress” optional
- [cosmetic] “ethora-bot-instance-leave-chat” made “agentIdOrAddress” optional
- [cosmetic] “ethora-bot-instance-test-message” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agent-invite-to-chat” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agent-set-visibility” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agent-soul-append” made “agentIdOrAddress” optional
- [cosmetic] “ethora-agent-soul-set” made “agentIdOrAddress” optional

### 2026-09-16 (score 66, 0)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-15 (score 66)

First indexed and scored.

## MCP tools (91)

### `ethora-configure` (~306 tokens)

Configure Connection

Set the Ethora API URL and credentials for this MCP session. Stores values in memory only; each call merges with omitted fields kept. Alternative to env vars (ETHORA_API_URL / ETHORA_APP_JWT / ETHORA_APP_TOKEN / ETHORA_B2B_TOKEN). On a hosted server `apiUrl` is fixed and cannot be changed; credentials are per session.
Auth: none required — this establishes auth material. Errors: only if a value is structurally invalid. Follow with an `ethora-auth-use-*` tool to pick the active mode.

Input parameters:

- `apiUrl` (string): Full Ethora API URL including the version path, e.g. `https://api.chat.ethora.com/v1` or `http://localhost:8080/v1`. If you only have the host, set ETHORA_BASE_URL env instead and the server appends…
- `appJwt` (string): Ethora App JWT, used only to bootstrap login/register in user-auth mode. Usually starts with `JWT `. Secret — never commit it.
- `appToken` (string): Per-app appToken for app-scoped flows (broadcast, sources, bot). Setting this makes app-token auth available via `ethora-auth-use-app`. Secret.
- `b2bToken` (string): B2B server token for tenant-actor `x-custom-token` auth (a JWT with `type=server`). Required for B2B provisioning flows. Secret.

### `ethora-status` (~97 tokens)

Session Status

Report the current Ethora MCP session state: configured API URL, active auth mode, which credentials are present (booleans like `hasAppJwt` — values never echoed), the selected appId/agentId, and `hosted`/`sessionId` on the hosted (Streamable HTTP) server.
Auth: none required. Errors: effectively none. Related: `ethora-doctor` for an active connectivity check.

### `ethora-help` (~113 tokens)

Help and Next Steps

Task-oriented orientation for this MCP server: explains the three Ethora auth modes (user / app-token / B2B) and recommends next tool calls + recipes based on current session state.
Auth: none required — inspects state, no API calls. Errors: effectively none. Related: pass a recommended recipe id to `ethora-run-recipe`.

Input parameters:

- `goal` (string): Goal hint to tailor the recommendations and recipe list. Omit or use `auto` to get recommendations inferred from the current session state.

### `ethora-run-recipe` (~303 tokens)

Run Recipe

Execute a built-in recipe — an ordered sequence of this server's own tool calls — by id. Recipes capture common flows (B2B bootstrap, broadcast, sources ingest). Use `dryRun: true` to preview resolved steps. Omit `recipeId` to list runnable recipes for a `goal`.
Requires: the inputs the chosen recipe lists; call without `recipeId` first to see the recipes and their required inputs.
Auth: depends on the recipe's steps — configure those first (see `ethora-help`). Errors: stops at the first failing step and returns the partial log; a missing required `vars` entry fails fast before any step runs.

Input parameters:

- `dryRun` (boolean): If true, resolve and return the step list with `vars` substituted but execute nothing. Use this to preview a recipe before running it for real.
- `goal` (string): Goal scope used to look up recipes when `recipeId` is omitted. Defaults to `auto`.
- `recipeId` (string): Id of the recipe to run. Omit to instead list the runnable recipes for the selected `goal` (get ids from `ethora-help`).
- `vars` (object): Key/value substitutions injected into recipe steps (e.g. appId, appToken, b2bToken, appJwt, email, password, apiUrl). A recipe declares which vars it requires; missing required vars fail the run befo…

### `ethora-doctor` (~124 tokens)

Connection Doctor

Diagnose the session: validate the config is internally consistent for the active auth mode and ping the Ethora API (`GET /v1/ping`). Returns `{ state, checks, ping, suggestions }`.
Auth: none required; report is tailored to whatever credentials are set. Errors: rarely throws — instead returns `suggestions` and a `ping.ok: false` block when the API is unreachable.

Input parameters:

- `timeoutMs` (integer): HTTP timeout in milliseconds for the ping request. Defaults to 3000. Raise it on slow links, lower it to fail fast.

### `ethora-auth-use-app` (~93 tokens)

Use App Token Auth

Switch this session's active auth mode to app-token, so subsequent app-scoped calls authenticate with the configured `appToken`.
Auth: requires an `appToken` to already be configured (via `ethora-configure`, ETHORA_APP_TOKEN env, or `ethora-app-select`). Errors: returns an error if no `appToken` is configured. Related: use after `ethora-app-select`.

### `ethora-auth-use-user` (~94 tokens)

Use User Auth

Switch this session's active auth mode to user-session, so subsequent calls authenticate as a logged-in Ethora user.
Auth: the switch needs nothing, but user-auth tools only work once `ethora-user-login` stores a user token (login also needs a configured `appJwt`). Errors: none on the switch; downstream tools return 401 until login succeeds. Related: follow with `ethora-user-login`.

### `ethora-auth-use-b2b` (~135 tokens)

Use B2B Auth

Switch this session's active auth mode to B2B, so subsequent calls authenticate as a tenant actor via the `x-custom-token` header.
Auth: requires a `b2bToken` (JWT with `type=server`) to already be configured (via `ethora-configure` or ETHORA_B2B_TOKEN env). Errors: returns an error if no `b2bToken` is configured. Related: server-side automation — pairs with `ethora-b2b-app-create`, `ethora-users-batch-create-v2`, `ethora-app-tokens-*-v2`.

### `ethora-app-select` (~239 tokens)

Select App

Set the current app context for this session so app-scoped tools can omit their `appId` argument. Stores `currentAppId` and, if given, `appToken` (which defaults the auth mode to app-token unless `authMode` overrides).
Auth: none required to set the context. Errors: effectively none — a non-existent `appId` is not validated here; the first app-scoped API call surfaces the 404. Related: pairs with `ethora-auth-use-app`.

Input parameters:

- `appId` (string, required): 24-char hex Ethora appId to set as the current context. Get it from `ethora-app-list`, `ethora-app-create`, or a B2B create/provision response.
- `appToken` (string): Per-app appToken to store alongside the appId. If provided, the active auth mode switches to app-token (unless `authMode` says otherwise). Secret.
- `authMode` (string): Auth mode to keep after selecting the app. Omit to let the mode default to app-token when an `appToken` is given, or stay unchanged otherwise.

### `ethora-chats-broadcast-v2` (~298 tokens)

Broadcast Message

Enqueue an asynchronous broadcast job posting a message to one or more chat rooms of an app — returns a `jobId`; messages are not sent synchronously. Targeting is exclusive: `allRooms`, `chatIds`, or `chatNames`, not a mix.
Requires: a selected app with at least one room (`ethora-app-create-chat`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 400 no target or conflicting targets; 404 unknown `appId` or room. Related: track with `ethora-wait-broadcast-job-v2`.

Input parameters:

- `allRooms` (boolean): If true, broadcast to every room in the app. Mutually exclusive with `chatIds` and `chatNames`.
- `appId` (string): 24-char hex appId to broadcast in. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode (the token determines the app).
- `chatIds` (array): Explicit list of chat ids to target. Mutually exclusive with `allRooms` and `chatNames`.
- `chatNames` (array): Explicit list of chat JIDs or localparts to target. Mutually exclusive with `allRooms` and `chatIds`.
- `text` (string, required): Plain-text message body to broadcast to the targeted rooms.

### `ethora-chats-broadcast-job-v2` (~198 tokens)

Get Broadcast Job

Fetch the current status and per-room results of a broadcast job by `jobId` (one-shot, no polling). Returns the job object with its `state` (pending/running/completed/failed).
Requires: a selected app with at least one room (`ethora-app-create-chat`).
Auth: app-token mode OR B2B mode with an explicit `appId` — must match the auth used to enqueue the job. Errors: 401/403 wrong auth; 404 unknown `jobId`. Related: `ethora-wait-broadcast-job-v2` for a blocking wait.

Input parameters:

- `appId` (string): 24-char hex appId the job belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `jobId` (string, required): Job id returned by `ethora-chats-broadcast-v2`.

### `ethora-wait-broadcast-job-v2` (~262 tokens)

Wait for Broadcast Job

Block until a broadcast job reaches a terminal state (`completed` or `failed`) or until `timeoutMs` — read-only polling wrapper around `ethora-chats-broadcast-job-v2`. Returns `{ done, state, job }`, or `{ done: false, reason: "timeout" }` on timeout.
Requires: a `jobId` returned by `ethora-chats-broadcast-job-v2`.
Auth: app-token mode OR B2B mode with an explicit `appId` — must match the auth used to enqueue the job. Errors: 401/403 wrong auth; 404 unknown `jobId`.

Input parameters:

- `appId` (string): 24-char hex appId the job belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `intervalMs` (integer): Delay between status checks, in milliseconds. Default 1000. Lower = more responsive but more API calls.
- `jobId` (string, required): Job id returned by `ethora-chats-broadcast-v2`.
- `timeoutMs` (integer): Maximum time to wait, in milliseconds. Default 60000. Caps at 300000 (5 min).

### `ethora-files-upload-v2` (~134 tokens)

Upload File

Upload 1–5 files to the authenticated user's Ethora file storage (`POST /v2/files`). Each upload is a new record (no overwrite-by-name); files passed as base64, 50MB max each.
Auth: user-auth mode with an active user session (`ethora-user-login` first). Errors: 401 not logged in; 413 size limit exceeded; 422 unsupported mime type. Related: manage with `ethora-files-get-v2` / `ethora-files-delete-v2`.

Input parameters:

- `files` (array, required): 1 to 5 files to upload in this call.

### `ethora-files-get-v2` (~122 tokens)

Get File

List the authenticated user's files, or fetch one file's metadata by id (`GET /v2/files`). Returns an array when `id` is omitted, a single record when given.
Requires: a file id from `ethora-files-upload-v2`.
Auth: user-auth mode with an active user session. Errors: 401 not logged in; 404 unknown `id` or not owned by the user.

Input parameters:

- `id` (string): File id to fetch a single record. Omit to list all files owned by the logged-in user.

### `ethora-files-delete-v2` (~127 tokens)

Delete File

Permanently delete one of the authenticated user's files by id (`DELETE /v2/files/:id`). Removes the record and its stored content; not reversible.
Requires: a file id from `ethora-files-upload-v2`.
Auth: user-auth mode with an active user session. Errors: 401 not logged in; 403 not owned by the user; 404 unknown `id`. Related: get ids from `ethora-files-get-v2`.

Input parameters:

- `id` (string, required): Id of the file to delete. Get it from `ethora-files-get-v2`.

### `ethora-sources-docs-upload` (~188 tokens)

Upload Knowledge Document (Legacy)

Upload documents (1–5; PDF, text, etc.) into an app's RAG sources (legacy user-auth route). Async — content becomes queryable once indexing finishes; files passed as base64, 50MB max each.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: user-auth mode, active session; the user must own the app. Errors: 401 not logged in; 403 not owner; 413 too large; 422 unsupported document type. Related: app-token/B2B flows use `ethora-sources-docs-upload-v2`.

Input parameters:

- `appId` (string): 24-char hex appId to ingest into. Optional — defaults to the app set via `ethora-app-select`.
- `files` (array, required): 1 to 5 documents to ingest in this call.

### `ethora-sources-docs-delete` (~199 tokens)

Delete Knowledge Document (Legacy)

Remove a previously ingested document from an app's RAG sources by `docId` (legacy user-auth route). Deletes the document record and its embeddings; not reversible.
Requires: a document id from `ethora-sources-docs-list-v2`.
Auth: user-auth mode, active session; the user must own the app. Errors: 401 not logged in; 403 not owner; 404 unknown `docId`. Related: get `docId` from `ethora-sources-docs-list-v2`; app-token/B2B uses `ethora-sources-docs-delete-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the document belongs to. Optional — defaults to the app set via `ethora-app-select`.
- `docId` (string, required): Id of the ingested document to delete. Get it from `ethora-sources-docs-list-v2`.

### `ethora-sources-site-crawl-v2` (~239 tokens)

Crawl Website Source

Crawl a website URL and ingest its content into an app's RAG sources (app-token / B2B variant of `ethora-sources-site-crawl`). Async — returns once the job is accepted; `followLink: true` follows in-domain links and can ingest many pages.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 400 malformed `url`; 404 unknown `appId`. Related: `ethora-sources-site-crawl-v2-wait` (block until done).

Input parameters:

- `appId` (string): 24-char hex appId to ingest into. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `followLink` (boolean): If true, also crawl in-domain links reachable from `url`. Can ingest many pages — use with care.
- `url` (string, required): Absolute URL to crawl, e.g. `https://example.com/docs`.

### `ethora-sources-site-reindex-v2` (~246 tokens)

Reindex Website Source

Re-crawl and re-embed a previously crawled URL by its `urlId`, refreshing its RAG content (app-token / B2B variant of `ethora-sources-site-reindex`). Async — the existing source record is updated in place once indexing finishes.
Requires: an indexed site URL from `ethora-sources-site-list-v2` (crawled with `ethora-sources-site-crawl-v2`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId` or `urlId`. Related: get `urlId` from `ethora-sources-site-list-v2`; `ethora-sources-site-reindex-v2-wait` blocks until done.

Input parameters:

- `appId` (string): 24-char hex appId the URL belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `urlId` (string, required): Id of a previously crawled URL record. Get it from `ethora-sources-site-list-v2`.

### `ethora-sources-site-crawl-v2-wait` (~323 tokens)

Crawl Website Source and Wait

Crawl a website URL and wait for the crawl to finish: enqueues the job, then polls it until it reports `completed` or `failed`. Returns `{ done, status, jobId, polls, durationMs, result }`; `done: false` with a `note` means the budget ran out while the job was still running (it usually finishes server-side anyway).
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 400 malformed `url`; 504/timeout if it takes longer than `timeoutMs` (the job may still complete server-side — check with `ethora-sources-site-list-v2`).

Input parameters:

- `appId` (string): 24-char hex appId to ingest into. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `followLink` (boolean): If true, also crawl in-domain links reachable from `url`. Can ingest many pages — use with care.
- `timeoutMs` (integer): How long to poll for the crawl to finish, in milliseconds. Default 45000, chosen to stay under the ~60s request timeout most MCP clients enforce. Caps at 600000 (10 min) for clients that allow longer…
- `url` (string, required): Absolute URL to crawl, e.g. `https://example.com/docs`.

### `ethora-sources-site-reindex-v2-wait` (~331 tokens)

Reindex Website Source and Wait

Re-crawl and re-embed a previously crawled URL and wait for it to finish: enqueues the job, then polls it until it reports `completed` or `failed`. Returns `{ done, status, jobId, polls, durationMs, result }`; `done: false` with a `note` means the budget ran out while the job was still running.
Requires: an indexed site URL from `ethora-sources-site-list-v2` (crawled with `ethora-sources-site-crawl-v2`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId` or `urlId`; 504/timeout if it takes longer than `timeoutMs` (the job may still complete server-side). Related: get `urlId` from `ethora-sources-site-list-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the URL belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `timeoutMs` (integer): How long to poll for the reindex to finish, in milliseconds. Default 45000, chosen to stay under the ~60s request timeout most MCP clients enforce. Caps at 600000 (10 min) for clients that allow long…
- `urlId` (string, required): Id of a previously crawled URL record. Get it from `ethora-sources-site-list-v2`.

### `ethora-sources-site-list-v2` (~176 tokens)

List Website Sources

List an app's crawled website sources, including each source's id, URL, and current RAG tags. Their ids feed `ethora-sources-site-tags-update-v2`, `ethora-sources-site-delete-url-v2-batch`, and `ethora-sources-site-reindex-v2`.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`; empty list if nothing has been crawled.

Input parameters:

- `appId` (string): 24-char hex appId to list sources for. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.

### `ethora-sources-site-tags-update-v2` (~275 tokens)

Update Website Source Tags

Set the RAG retrieval tags on a crawled website source — replaces the source's tag set with the provided `tags` array (not additive; pass `[]` to clear all). Tags let the bot's `ragTags` narrow retrieval.
Requires: an indexed site URL from `ethora-sources-site-list-v2` (crawled with `ethora-sources-site-crawl-v2`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId` or `sourceId`. Related: get `sourceId` from `ethora-sources-site-list-v2`; doc equivalent is `ethora-sources-docs-tags-update-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the source belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `sourceId` (string, required): Id of the crawled site source to tag. Get it from `ethora-sources-site-list-v2`.
- `tags` (array, required): The complete desired tag set for this source (replaces any existing tags). Up to 50 tags; pass `[]` to clear all.

### `ethora-sources-site-delete-url-v2` (~251 tokens)

Delete Website Source URL

Remove a single crawled URL from an app's RAG sources, matched by its exact url string (app-token / B2B variant of `ethora-sources-site-delete-url`). Deletes the source record and its embeddings; not reversible. Matches on the exact stored URL string.
Requires: an indexed site URL from `ethora-sources-site-list-v2` (crawled with `ethora-sources-site-crawl-v2`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 `url` not a crawled source. Related: get the stored value from `ethora-sources-site-list-v2`; bulk-by-id is `ethora-sources-site-delete-url-v2-batch`.

Input parameters:

- `appId` (string): 24-char hex appId the URL belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `url` (string, required): Exact crawled URL string to remove (must match what was stored — get it from `ethora-sources-site-list-v2`).

### `ethora-sources-docs-upload-v2` (~218 tokens)

Upload Knowledge Document

Upload documents (1–5; PDF, text, etc.) into an app's RAG sources (app-token / B2B variant of `ethora-sources-docs-upload`). Async — content becomes queryable once indexing finishes; files passed as base64, 50MB max each.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`; 413 too large; 422 unsupported document type. Related: `ethora-sources-docs-list-v2`, `ethora-sources-docs-delete-v2`.

Input parameters:

- `appId` (string): 24-char hex appId to ingest into. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `files` (array, required): 1 to 5 documents to ingest in this call.

### `ethora-sources-docs-list-v2` (~180 tokens)

List Knowledge Documents

List an app's ingested documents, including each document's id, name, and current RAG tags. Their ids feed `ethora-sources-docs-tags-update-v2` and `ethora-sources-docs-delete-v2`.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`; empty list if nothing has been uploaded. Related: website-sources equivalent is `ethora-sources-site-list-v2`.

Input parameters:

- `appId` (string): 24-char hex appId to list documents for. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.

### `ethora-sources-docs-tags-update-v2` (~259 tokens)

Update Knowledge Document Tags

Set the RAG retrieval tags on an ingested document — replaces the document's tag set with the provided `tags` array (not additive; pass `[]` to clear all). Tags let the bot's `ragTags` narrow retrieval.
Requires: a document id from `ethora-sources-docs-list-v2`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId` or `docId`. Related: get `docId` from `ethora-sources-docs-list-v2`; website-source equivalent is `ethora-sources-site-tags-update-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the document belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `docId` (string, required): Id of the ingested document to tag. Get it from `ethora-sources-docs-list-v2`.
- `tags` (array, required): The complete desired tag set for this document (replaces any existing tags). Up to 50 tags; pass `[]` to clear all.

### `ethora-sources-docs-delete-v2` (~206 tokens)

Delete Knowledge Document

Remove a previously ingested document from an app's RAG sources by `docId` (app-token / B2B variant of `ethora-sources-docs-delete`). Deletes the document record and its embeddings; not reversible.
Requires: a document id from `ethora-sources-docs-list-v2`.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId` or `docId`. Related: get `docId` from `ethora-sources-docs-list-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the document belongs to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `docId` (string, required): Id of the ingested document to delete. Get it from `ethora-sources-docs-list-v2`.

### `ethora-users-batch-create-v2` (~215 tokens)

Batch Create Users

Provision many Ethora users (1–100) in one asynchronous batch job — the bulk equivalent of `ethora-user-register`. Enqueues a background job (HTTP 202); the job reports per-user conflicts rather than failing the whole batch. Returns `{ jobId, statusUrl }`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode; 422 `usersList` validation. Related: track with `ethora-wait-users-batch-job-v2`.

Input parameters:

- `bypassEmailConfirmation` (boolean): If true, created users skip email verification and are immediately usable. If false/omitted, each user receives a verification link.
- `timeoutMs` (integer): HTTP timeout for the job-creation request (not the job itself), in milliseconds. Default 30000.
- `usersList` (array, required): The users to create, 1–100 per batch.

### `ethora-users-batch-job-v2` (~198 tokens)

Get Users Batch Job

Fetch the current status and per-user results of a users batch job by `jobId` (one-shot, no polling). Returns the job object with its `state` (pending/running/completed/failed) and per-user outcomes.
Requires: a `jobId` returned by `ethora-users-batch-create-v2`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`) — must match the auth used to create the job. Errors: 401/403 not in B2B mode; 404 unknown `jobId`. Related: `ethora-wait-users-batch-job-v2` for a blocking wait.

Input parameters:

- `jobId` (string, required): Job id returned by `ethora-users-batch-create-v2`.
- `timeoutMs` (integer): HTTP timeout for this status request, in milliseconds. Default 10000.

### `ethora-wait-users-batch-job-v2` (~223 tokens)

Wait for Users Batch Job

Block until a users batch job reaches a terminal state (`completed` or `failed`) or `timeoutMs` — read-only polling wrapper around `ethora-users-batch-job-v2`. Returns `{ done, state, job }`, or `{ done: false, reason: "timeout" }` on timeout.
Requires: a `jobId` returned by `ethora-users-batch-create-v2`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`) — must match the auth used to create the job. Errors: 401/403 not in B2B mode; 404 unknown `jobId`.

Input parameters:

- `intervalMs` (integer): Delay between status checks, in milliseconds. Default 1000.
- `jobId` (string, required): Job id returned by `ethora-users-batch-create-v2`.
- `timeoutMs` (integer): Maximum time to wait, in milliseconds. Default 60000. Caps at 300000 (5 min).

### `ethora-app-tokens-list-v2` (~164 tokens)

List App Tokens

List the app tokens issued for an app — metadata only (`tokenId`, label, created/rotated timestamps, status); the secret token values are never returned (only shown once at create/rotate time).
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode; 400 no `appId` and none selected; 404 unknown `appId`.

Input parameters:

- `appId` (string): 24-char hex appId to list tokens for. Optional — defaults to the app set via `ethora-app-select`.
- `timeoutMs` (integer): HTTP timeout for this request, in milliseconds. Default 10000.

### `ethora-app-tokens-create-v2` (~232 tokens)

Create App Token

Mint a new app token for an app. The secret token value is returned exactly once and cannot be retrieved again — capture it immediately. Returns the new token including its one-time secret value and `tokenId`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode; 400 no `appId` and none selected; 404 unknown `appId`. Related: manage with `ethora-app-tokens-list-v2` / `-rotate-v2` / `-revoke-v2`.

Input parameters:

- `appId` (string): 24-char hex appId to mint the token for. Optional — defaults to the app set via `ethora-app-select`.
- `label` (string): Human-readable label to identify this token later (e.g. `staging`, `ci`). Shown in `ethora-app-tokens-list-v2`.
- `timeoutMs` (integer): HTTP timeout for this request, in milliseconds. Default 10000.

### `ethora-app-tokens-rotate-v2` (~262 tokens)

Rotate App Token

Rotate an app token: revoke an existing token and issue a replacement in one step. The old `tokenId` is revoked immediately — anything using it stops working at once. The new secret value is returned exactly once — capture it immediately.
Requires: a token id from `ethora-app-tokens-list-v2`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode; 400 no `appId` and none selected; 404 unknown `appId` or `tokenId`. Related: `ethora-app-tokens-revoke-v2` to revoke without a replacement.

Input parameters:

- `appId` (string): 24-char hex appId the token belongs to. Optional — defaults to the app set via `ethora-app-select`.
- `label` (string): Label for the replacement token. Omit to inherit the old token's label.
- `timeoutMs` (integer): HTTP timeout for this request, in milliseconds. Default 10000.
- `tokenId` (string, required): Id of the token to revoke and replace. Get it from `ethora-app-tokens-list-v2`.

### `ethora-app-tokens-revoke-v2` (~238 tokens)

Revoke App Token

Permanently revoke an app token by `tokenId` — it stops working immediately; any client, SDK, or MCP session still using it gets auth failures. No replacement is issued.
Requires: a token id from `ethora-app-tokens-list-v2`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode; 400 no `appId` and none selected; 404 unknown `appId`. Related: get `tokenId` from `ethora-app-tokens-list-v2`; `ethora-app-tokens-rotate-v2` for revoke-and-replace.

Input parameters:

- `appId` (string): 24-char hex appId the token belongs to. Optional — defaults to the app set via `ethora-app-select`.
- `timeoutMs` (integer): HTTP timeout for this request, in milliseconds. Default 10000.
- `tokenId` (string, required): Id of the token to revoke. Get it from `ethora-app-tokens-list-v2`.

### `ethora-b2b-app-provision` (~401 tokens)

Provision App (B2B)

One-call B2B orchestrator: create an app, mint one or more app tokens, provision default chat rooms, then configure and enable its AI bot. Later-step failures don't undo earlier steps. Returns a per-step log including `appId` and the created tokens (returned once — capture them).
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: aborts with the partial step log if app creation fails; previous auth mode restored best-effort. Related: `ethora-b2b-app-bootstrap-ai` does sources+bot but not tokens/rooms.

Input parameters:

- `botGreetingMessage` (string): Greeting message the bot posts when a conversation starts.
- `botPrompt` (string): System prompt for the new app's bot.
- `botTrigger` (string): Bot trigger: `any_message` (every message) or `/bot` (only /bot-prefixed messages).
- `displayName` (string, required): Display name for the new app.
- `enableBot` (boolean): If true, enable the new app's bot using the first minted app token.
- `llmModel` (string): LLM model id for the bot, e.g. `gpt-4o-mini`. Must be available for the chosen provider.
- `llmProvider` (string): LLM provider for the bot, e.g. `openai` or `openai-compatible`. Must be enabled in your Ethora backend.
- `rooms` (array): Default chat rooms to create in the new app. Up to 20.
- `savedAgentId` (string): Optional id of an existing saved agent to bind as the new app's active bot, instead of setting prompt fields by hand.
- `tokenLabels` (array): Labels for the app tokens to mint, one token per label. Default: ['default']. 1–5 tokens.

### `ethora-user-login` (~280 tokens)

Log In

Authenticate as an existing Ethora user with email + password. Stores the user session token in this MCP session and unlocks user-auth tools (`ethora-app-list`, `ethora-files-*`, `ethora-wallet-*`).
Auth: user-auth mode (`ethora-auth-use-user` first) and a configured `appJwt`. Errors: 401/403 bad credentials; 404 email not registered; 429 per-IP rate limit — retry with backoff.

Input parameters:

- `apiKeyName` (string): Label for the API key when `createApiKey` is true (e.g. `claude-code-laptop`).
- `apiKeyTtlDays` (integer): Lifetime of the API key in days when `createApiKey` is true. Server default applies when omitted.
- `createApiKey` (boolean): When true, also mint a long-lived API key for this user and return it once, so headless clients / agents can reconnect with `Authorization: Bearer <key>` instead of logging in again. Default false.
- `email` (string, required): User's registered email address (RFC 5322). Must match an account created via `ethora-user-register`.
- `password` (string, required): Plain-text password the user set during registration. Sent over TLS to the Ethora API; never echoed back or logged.

### `ethora-user-register` (~333 tokens)

Register Account

Create a new Ethora user account by email + first/last name, then log in and bind the session. A password is generated when omitted and returned once. By default also mints a long-lived API key so an agent can reconnect later with `Authorization: Bearer <key>` (no human step needed).
Auth: user-auth mode and a configured `appJwt` (on a hosted server this is preset). Errors: 401 no `appJwt`; 422 email already registered or password shorter than 6 chars; 429 rate limited. Related: bulk provisioning uses `ethora-users-batch-create-v2`.

Input parameters:

- `apiKeyName` (string): Label for the API key (default `mcp-signup`).
- `apiKeyTtlDays` (integer): API key lifetime in days. Server default applies when omitted.
- `createApiKey` (boolean): Mint a long-lived API key right after signup and return it once. Default true. Set false if you only need this session.
- `email` (string, required): Email address for the new user. Must be RFC-5322 valid and not already registered within this app. No confirmation click is required to log in; the address is used for password reset.
- `firstName` (string, required): First name shown in the user's profile and message attributions across chat rooms and the app UI.
- `lastName` (string, required): Last name shown in the user's profile.
- `password` (string): Password for the account (min 6 chars). Omit to have a strong random password generated and returned once in the result.

### `ethora-api-key-create` (~143 tokens)

Create API Key

Mint a long-lived, revocable API key for the currently logged-in user. The key is a user token: send it as `Authorization: Bearer <key>` to the hosted MCP endpoint (or set it in the stdio client) to skip `ethora-user-login`. Shown once.
Auth: user auth (logged in). Errors: 401 not logged in; 404 on backends without API key support.

Input parameters:

- `name` (string): Label to recognise the key later (e.g. `ci-runner`, `claude-desktop`).
- `ttlDays` (integer): Lifetime in days. Server default applies when omitted.

### `ethora-api-key-list` (~39 tokens)

List API Keys

List the current user's API keys (id, name, createdAt, expiresAt). Token values are never returned.
Auth: user auth.

### `ethora-api-key-revoke` (~92 tokens)

Revoke API Key

Revoke one of the current user's API keys by id. Clients using that key stop working immediately.
Requires: a key id from `ethora-api-key-list` or `ethora-api-key-create`.
Auth: user auth. Errors: 404 unknown id.

Input parameters:

- `id` (string, required): API key id as returned by `ethora-api-key-create` / `ethora-api-key-list`.

### `ethora-app-credentials` (~233 tokens)

Reveal App Token

Reveal the appToken of an app the caller owns, for a chat-component snippet or a widget config. Every other tool redacts appToken, appSecret and tenantSecret from its results because tool output enters the model's context and client logs; this tool returns exactly { appId, appToken, note } and nothing else. The App Secret is never returned over MCP: it is shown only in the web dashboard (app settings, API tab), and backend integrations should use revocable server tokens from that tab instead of the secret.
Requires: an app you own (`ethora-app-create` or `ethora-app-list`) and `confirm: true`.
Auth: user auth (app owner). Errors: 401 not logged in; 403 not the owner; 404 unknown `appId`; validation error unless `confirm` is `true`.

Input parameters:

- `appId` (string): 24-char hex app id. Defaults to the app selected with `ethora-app-select`.
- `confirm` (boolean, required): Must be `true`: acknowledges that the token is a credential and will appear in this conversation.

### `ethora-feedback-submit` (~403 tokens)

Send Feedback

Send feedback about Ethora to the Ethora team: something that does not work, behaves differently from what the tool description promised, is missing, or is badly documented. It reaches the team directly, so prefer it over guessing or silently giving up when a tool fails. Recent failures in this session (tool, error code, request id) are attached automatically when `includeRecentErrors` is true, which is what makes a report from here more useful than a web form: the team can join it to the server-side log. Works whether or not you are signed in, so a problem that blocks sign-up can still be reported. Do not put credentials, API keys or end-user personal data in `message`; credential-shaped values in the attached context are redacted before sending.
Requires: nothing.
Auth: none. Works anonymously; when the session is authenticated the report is attributed to that account. Errors: 422 if `message` is shorter than 5 characters or looks like spam; 429 if too many reports were sent from this address.

Input parameters:

- `category` (string): What kind of report this is: `bug` (something is broken), `unexpected` (it works but not as described), `feature` (a request), `docs` (a description or guide is wrong or missing), `other`. Defaults t…
- `email` (string): Reply address. Only useful when the session is not signed in; an authenticated report already carries the account, so leave this out unless the user offers an address.
- `includeRecentErrors` (boolean): Attach this session's last few tool failures (tool name, error code, request id) so the team can trace them. Default true; set false if the report is unrelated to a failure.
- `message` (string, required): What happened, in the user's own words where possible: what was attempted, what was expected, what occurred instead. No credentials or end-user personal data.

### `ethora-widget-embed-snippet` (~495 tokens)

Widget Embed Snippet

Generate the <script> tag that embeds the Ethora AI chat widget (the floating launcher + chat panel that website visitors use) for an app, plus the prerequisites that must hold before it answers. No API call; pure generator using this deployment's hosted widget URL and public API base. The widget answers with the app's ACTIVE bot: for API-created apps run `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2 { agentId, chatJid }` first, otherwise `POST /v2/widget/sessions` returns 422 and the widget stays silent.
Requires: an activated agent on the app (`ethora-agents-activate-v2`); without it the widget opens but never answers.
Auth: none required (uses the selected app when `appId` is omitted). Errors: effectively none; when no hosted widget is configured the snippet carries a `<WIDGET_URL>` placeholder. Related: `ethora-agents-activate-v2`, `ethora-bot-widget-v2` (legacy per-app bot only).

Input parameters:

- `apiBase` (string): Override the public API base (`data-api-base`). Defaults to this deployment's public API URL.
- `appId` (string): App the widget belongs to (24-char hex). Defaults to the app from `ethora-app-select`.
- `botAvatar` (string): Avatar image URL shown for the bot (`data-bot-avatar`).
- `botId` (string): Legacy `data-bot-id` (bot XMPP address); only for old embeds. Prefer `appId`: the backend picks the active agent from the app.
- `botName` (string): Display name shown in the widget header (`data-bot-name`), e.g. the agent's name.
- `greeting` (string): Greeting shown when the panel opens (`data-greeting-message`).
- `locale` (string): UI locale (`data-locale`), e.g. `en`, `fr`, `es`.
- `position` (string): Launcher corner (`data-position`).
- `primaryColor` (string): Brand colour for launcher and bubbles (`data-primary-color`), e.g. `#0052CC`.
- `widgetUrl` (string): Override the widget bundle base URL (the script is `<widgetUrl>/assistant.js`).

### `ethora-app-list` (~153 tokens)

List Apps

List all Ethora apps (tenants) owned by the currently logged-in user. Returns an array with `appId` (24-char hex), `displayName`, `domainName`, ownership and bot-status metadata. Credential fields (appSecret, tenantSecret, appToken, passwords) are redacted in the result; call `ethora-app-credentials { appId, confirm: true }` to reveal an app's appToken.
Auth: user-auth mode, active session (`ethora-user-login` first). Errors: 401 not logged in; empty list if the user owns no apps. Related: feed `appId` into `ethora-app-update` / `ethora-app-select`.

### `ethora-app-create` (~184 tokens)

Create App

Create a new Ethora app (tenant) owned by the currently logged-in user. Allocates a fresh 24-char hex `appId` and sets the caller as owner; counts against the owner's plan limit. Returns the new app object including `appId`. The returned app has its credential fields redacted; call `ethora-app-credentials { appId, confirm: true }` when a snippet needs the appToken.
Auth: user-auth mode, active session (`ethora-user-login` first). Errors: 401 not logged in; 402/403 plan limit reached; 422 invalid `displayName`. Related: server-side provisioning uses `ethora-b2b-app-create`.

Input parameters:

- `displayName` (string, required): Human-readable app name shown to users in the app picker and on the public landing page. Not required to be unique across accounts.

### `ethora-app-update` (~373 tokens)

Update App

Update mutable fields on an app the caller owns (displayName, domainName, appTagline, primaryColor, botStatus). Partial update — omitted fields are left unchanged.
Requires: an `appId` from `ethora-app-list` or `ethora-app-create`.
Auth: user-auth mode, active session; the caller must own the app. Errors: 401 not logged in; 403 not owner; 404 unknown `appId`; 422 validation (e.g. `domainName` taken, `primaryColor` not `#RRGGBB`).

Input parameters:

- `appDescription` (string): Deprecated alias for `appTagline`, kept so older callers keep working. Prefer `appTagline`.
- `appId` (string): 24-char hex ObjectId of the app to update. Optional — defaults to the app most recently passed to `ethora-app-select`.
- `appTagline` (string): Short tagline shown on the public app landing page.
- `botStatus` (string): `on` enables the AI bot for new conversations (requires a configured prompt — see `ethora-bot-update-v2`); `off` disables it. Does not change the bot's configured prompt or sources.
- `displayName` (string): New human-readable app name. Visible in the app picker and on the public landing page.
- `domainName` (string): Subdomain to host the web app at. Setting `abcd` makes the web app available at `abcd.ethora.com`. Must be unique across all Ethora apps; lower-case alphanumerics and dashes only.
- `primaryColor` (string): Primary brand color in hex `#RRGGBB` format (e.g. `#F54927`). Used throughout the app UI.

### `ethora-app-get-default-rooms` (~106 tokens)

Get Default Rooms

List the default chat rooms (MUC rooms) of the currently selected Ethora app — every new user auto-joins these. Returns rooms with their JIDs and titles.
Auth: user-auth mode, active session; operates against the app set via `ethora-app-select`. Errors: 400 no app currently selected; 401 not logged in. Related: `ethora-app-get-default-rooms-with-app-id` to pass `appId` explicitly.

### `ethora-app-create-chat` (~264 tokens)

Create Chat Room

Create a new chat room (MUC room) inside an app the caller owns. Every room created this way is listed in the app's rooms (`defaultRooms`); `pinned: true` additionally makes new users auto-join it (existing users are not added), `pinned: false` (default) keeps it opt-in. Returns the new room object including its JID.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.
Auth: user-auth mode, active session; the caller must own the app. Errors: 401 not logged in; 403 not owner; 404 unknown `appId`; 422 invalid `title`.

Input parameters:

- `appId` (string): 24-char hex ObjectId of the app to create the chat room in. Optional — defaults to the app most recently passed to `ethora-app-select`.
- `pinned` (boolean): If `true`, the room is added to the app's default rooms list — every new user of the app auto-joins it. If `false`, the room exists but users must be added explicitly.
- `title` (string, required): Display name for the new chat room. Visible to all members; not required to be unique within the app.

### `ethora-app-delete-chat` (~217 tokens)

Delete Chat Room

Permanently delete a chat room from an app the caller owns — removes the MUC room, its message archive, and all member affiliations. Irreversible; gated behind ETHORA_MCP_ENABLE_DANGEROUS_TOOLS=true.
Requires: a room from `ethora-app-get-default-rooms` or `ethora-app-create-chat`.
Auth: user-auth mode, active session; the caller must own the app. Errors: 401 not logged in; 403 not owner; 404 `chatJid` not a room in the app.

Input parameters:

- `appId` (string): 24-char hex ObjectId of the app the chat room belongs to. Optional — defaults to the app most recently passed to `ethora-app-select`.
- `chatJid` (string, required): Room JID (XMPP address) of the chat to delete, e.g. `<roomId>@conference.<host>`. Obtain from `ethora-app-get-default-rooms` or the response of `ethora-app-create-chat`.

### `ethora-app-get-default-rooms-with-app-id` (~163 tokens)

Get Default Rooms for App

List the default chat rooms of a specific Ethora app, passed via `appId` (or the currently selected app). Returns rooms with their JIDs and titles.
Requires: an `appId` from `ethora-app-list` or `ethora-app-create`.
Auth: user-auth mode, active session; the caller needs read access (ownership or room membership). Errors: 400 no `appId` and none selected; 401 not logged in; 403 no read access; 404 unknown `appId`.

Input parameters:

- `appId` (string): 24-char hex ObjectId of the app whose default rooms you want to read. Optional — defaults to the app most recently passed to `ethora-app-select`.

### `ethora-app-delete` (~182 tokens)

Delete App

Permanently delete an Ethora app the caller owns — removes its chat rooms, files, indexed RAG sources, and bot config; end users are immediately signed out. Irreversible; gated behind ETHORA_MCP_ENABLE_DANGEROUS_TOOLS=true.
Requires: an `appId` from `ethora-app-list` or `ethora-app-create`.
Auth: user-auth mode, active session; the caller must own the app. Errors: 401 not logged in; 403 not owner; 404 unknown `appId`. Related: to just deactivate the bot use `ethora-app-update` with `botStatus: "off"`.

Input parameters:

- `appId` (string, required): 24-char hex MongoDB ObjectId of the app to delete. Obtain from `ethora-app-list` or the response of `ethora-app-create`.

### `ethora-sources-site-delete-url-v2-batch` (~225 tokens)

Delete Website Source URLs

Bulk-remove crawled website sources (1–100) from an app in one call, matched by their source record ids. Deletes each matching record and its embeddings; not reversible. Ids not present are skipped.
Requires: an indexed site URL from `ethora-sources-site-list-v2` (crawled with `ethora-sources-site-crawl-v2`).
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`. Related: matches on source ids (not URL strings) — get them from `ethora-sources-site-list-v2`.

Input parameters:

- `appId` (string): 24-char hex appId the sources belong to. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `ids` (array, required): Site source record ids to delete, 1–100 per call. Get them from `ethora-sources-site-list-v2`.

### `ethora-agents-delete-v2` (~131 tokens)

Delete Agent

Delete an Agent (DELETE /v2/agents/:idOrAddress). Destructive — removes the saved Agent and its BotInstances. Gated behind ETHORA_MCP_ENABLE_DANGEROUS_TOOLS.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string): Mongo _id (24 hex chars) or EOA-style address.

### `ethora-b2b-app-create` (~180 tokens)

Create App (B2B)

Create a new Ethora app (tenant) server-side using B2B auth — the partner/integrator equivalent of `ethora-app-create`. Allocates a fresh 24-char hex `appId`; does not create tokens, rooms, or a bot. Returns the new app object including `appId`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`). Errors: 401/403 not in B2B mode or invalid `b2bToken`; 422 invalid `displayName`. Related: all-in-one path is `ethora-b2b-app-bootstrap-ai` / `ethora-b2b-app-provision`.

Input parameters:

- `displayName` (string, required): Human-readable app name shown to users in the app picker and on the public landing page.

### `ethora-b2b-bot-enable` (~259 tokens)

Enable Legacy Bot (B2B)

Enable the LEGACY per-app aiBot (B2B auth). NOTE: apps created via the API/B2B no longer auto-provision a legacy aiBot, so this returns 422 BOT_NOT_INITIALIZED on a clean app. The forward path for B2B AI is the Agents API — use `ethora-b2b-app-bootstrap-ai` or `ethora-agents-create-v2` + `ethora-agent-invite-to-chat`. This tool remains valid for apps that already have a legacy aiBot (e.g. admin-panel apps created with a default chat).
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.

Input parameters:

- `appId` (string): 24-char hex appId whose bot to enable. Optional — defaults to the app set via `ethora-app-select`.
- `botTrigger` (string): When the bot responds: `/bot` (only messages starting with /bot) or `any_message` (every message). Omit to leave the existing trigger unchanged.

### `ethora-bot-get-v2` (~186 tokens)

Get Legacy Bot

Read the current AI bot configuration for an app: status, trigger, prompt, greeting, LLM provider/model, RAG settings, widget config.
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`. Related: change config with `ethora-bot-update-v2`.

Input parameters:

- `appId` (string): 24-char hex appId. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode (the token determines the app).

### `ethora-bot-update-v2` (~675 tokens)

Update Legacy Bot

Configure the AI bot for an app — prompt, LLM, trigger, greeting, RAG behavior, identity, and public widget settings. Partial update — omitted fields are left unchanged. `status: "on"` activates the bot (best-effort; needs a prompt + LLM and a backend AI service).
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`; 422 validation (e.g. an `llmProvider`/`llmModel` not enabled). Related: `ethora-bot-get-v2`, `ethora-agents-activate-v2`.

Input parameters:

- `appId` (string): 24-char hex appId. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `botAvatarUrl` (string): Public URL of the bot's avatar image.
- `botDisplayName` (string): Bot's display name shown in chat.
- `botFirstName` (string): Bot's first name in its user profile.
- `botLastName` (string): Bot's last name in its user profile.
- `chatId` (string): Restrict the bot to a single chat by id. Omit to apply app-wide.
- `greetingMessage` (string): Message the bot posts when a conversation starts.
- `isRAG` (boolean): If true, the bot retrieves from the app's indexed RAG sources (see the `ethora-sources-*` tools) when answering.
- `llmModel` (string): LLM model id, e.g. `gpt-4o-mini`. Must be available for the chosen `llmProvider`.
- `llmProvider` (string): LLM provider, e.g. `openai` or `openai-compatible`. Must be enabled in your Ethora backend's AI service config.
- `prompt` (string): System prompt that defines the bot's persona and behavior.
- `ragTags` (array): Restrict RAG retrieval to sources tagged with these tags (see `ethora-sources-site-tags-update-v2` / `ethora-sources-docs-tags-update-v2`).
- `savedAgentId` (string): Id of a saved agent whose config should back this bot. Alternative to setting prompt/LLM/RAG fields individually.
- `status` (string): `on` activates the bot, `off` deactivates it. Omit to leave the current status unchanged.
- `trigger` (string): When the bot responds: `any_message` (replies to every message) or `/bot` (only messages starting with /bot).
- `widgetPublicEnabled` (boolean): If true, expose the bot through a public embeddable chat widget.
- `widgetPublicUrl` (string): Public URL for the embeddable widget. Usually read via `ethora-bot-widget-v2` rather than set here.

### `ethora-bot-enable-v2` (~237 tokens)

Enable Legacy Bot

Enable the LEGACY per-app aiBot using app-token or B2B auth. NOTE: clean API/B2B-created apps have no legacy aiBot, so this returns 422 BOT_NOT_INITIALIZED there — use the Agents API (`ethora-agents-create-v2` + `ethora-agent-invite-to-chat`, or `ethora-b2b-app-bootstrap-ai`) for B2B AI. Valid for apps that already have a legacy aiBot.
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.

Input parameters:

- `appId` (string): 24-char hex appId. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.
- `trigger` (string): When the bot responds: `any_message` (every message) or `/bot` (only /bot-prefixed messages). Omit to leave the existing trigger unchanged.

### `ethora-bot-disable-v2` (~199 tokens)

Disable Legacy Bot

Turn the AI bot off for an app (sets bot `status: "off"`) — it stops responding. The configured prompt/LLM/RAG and any activated agent are preserved, so re-enabling restores the same behavior.
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.
Auth: app-token mode OR B2B mode with an explicit `appId`. Errors: 401/403 wrong auth; 404 unknown `appId`. Related: `ethora-bot-enable-v2` to turn back on.

Input parameters:

- `appId` (string): 24-char hex appId. Required in B2B mode unless already set via `ethora-app-select`; ignored in app-token mode.

### `ethora-bot-widget-v2` (~201 tokens)

Get Legacy Bot Widget

LEGACY: read the per-app bot widget config (`GET /v2/bot/widget`); only apps that already have a legacy aiBot have one, API-created apps get 422. For the embeddable AI chat widget use `ethora-widget-embed-snippet` instead — the widget config and public widget URL metadata needed to embed the bot on a website.
Requires: an app with a legacy per-app aiBot (dashboard-created). API-created apps have none: use `ethora-agents-create-v2` -> `ethora-agent-invite-to-chat` -> `ethora-agents-activate-v2` instead.
Auth: app-token mode (after `ethora-app-select` + `ethora-auth-use-app`). Errors: 401/403 not in app-token mode or invalid appToken. Related: enable/disable via `widgetPublicEnabled` in `ethora-bot-update-v2`.

### `ethora-agents-list-v2` (~173 tokens)

List Agents

List the reusable saved agents of an app (`GET /v2/apps/:appId/agents`, or `GET /v2/agents` for the token's own app) — a saved agent is a reusable bot definition. Returns an array of agents with ids, names, and config.
Auth: app-token mode (after `ethora-app-select` + `ethora-auth-use-app`). Errors: 401/403 not in app-token mode or invalid appToken; empty list if the app has no saved agents.

Input parameters:

- `appId` (string): 24-char hex appId whose agents to list (`GET /v2/apps/:appId/agents`). Defaults to the app selected with `ethora-app-select`; without either, lists the agents of the token's own app.

### `ethora-agents-get-v2` (~201 tokens)

Get Agent

Fetch one reusable saved agent's full config by id (`GET /v2/agents/:agentId`) — prompt, LLM, RAG settings, visibility. Also sets this agent as the session's current agent context (no server-side change).
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.
Auth: app-token mode (after `ethora-app-select` + `ethora-auth-use-app`). Errors: 401/403 wrong auth; 404 `agentId` not an agent of the current app. Related: get ids from `ethora-agents-list-v2`.

Input parameters:

- `agentId` (string): Id of the saved agent to fetch. Get it from `ethora-agents-list-v2`.
- `agentIdOrAddress` (string): Alias for `agentId` - either name is accepted, pass whichever you have.

### `ethora-agents-create-v2` (~911 tokens)

Create Agent

Create a reusable AI agent (POST /v2/apps/:appId/agents). Works in user auth mode (the normal hosted mode) or B2B mode; app-token mode is not accepted by the backend. Each agent is a persona — name, avatar, system prompt, LLM config, plus response-gate settings (responseMode, cooldownSec) that control when it speaks in a room. For multi-agent scenarios (two or more personas conversing in one chat) create each one separately, then `ethora-agent-invite-to-chat` them into the same room. See the `ethora-agents-quickstart` prompt for the end-to-end recipe.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`; the agent is owned by that app.

Input parameters:

- `appId` (string): 24-char hex appId the agent belongs to (`POST /v2/apps/:appId/agents`). Defaults to the app selected with `ethora-app-select`. Pass it when you just created an app so the agent lands there rather tha…
- `botAvatarUrl` (string): URL of the avatar image shown next to bot messages.
- `botDisplayName` (string): Display name used inside the chat UI. Defaults to `name`.
- `categories` (array): Free-form category tags for agent directory listings.
- `cooldownSec` (integer): Minimum seconds between this agent's replies in a given room. Damped 2x for bot-to-bot. Set 0 for quick turn-taking in multi-agent scenarios.
- `flowsYaml` (string): Deterministic scripted conversation for this agent, as YAML. Drives the agent through a fixed sequence (opening menu, appointment request, intake questionnaire, survey) instead of leaving every turn…
- `greetingMessage` (string): Optional message the agent posts when it first joins a room.
- `isPublished` (boolean): Convenience alias for setting visibility='public'.
- `isRAG` (boolean): Enable retrieval-augmented generation from indexed sources.
- `llmModel` (string): LLM model override (e.g. 'gpt-4o-mini').
- `llmProvider` (string): LLM provider override (e.g. 'openai'). Defaults to the app's configured provider.
- `name` (string): Short display name. For multi-agent scenarios, prefer single-word names (e.g. 'Hannibal', 'Varro') — the @-mention matcher uses the exact display name with word-boundary matching.
- `prompt` (string): System prompt — the agent's persona, role, style of speech, and behaviour rules. For multi-agent scenarios, instruct the agent to end every message with an @-mention of who speaks next; that's how tu…
- `ragTags` (array): Optional RAG tag filter — restrict retrieval to sources matching these tags.
- `responseMode` (string): When the agent decides to reply. 'always' = every room message; 'mentioned' = only when @-mentioned by display name or via /bot (recommended for multi-agent turn-taking); 'smart' = a mini LLM gate de…
- `responseProbability` (number): If responseMode='probability', odds (0-1) of replying to each message. Damped 0.6x for bot-to-bot messages.
- `slug` (string): URL-safe slug (auto-generated from name if omitted).
- `summary` (string): Short bio shown in agent lists.
- `trigger` (string): Legacy trigger field. Prefer the newer `responseMode` for new agents.
- `visibility` (string): 'private' (only invitable inside the owning app) or 'public' (cross-app invitable).

### `ethora-agents-update-v2` (~709 tokens)

Update Agent

Update a saved AI agent (PUT /v2/agents/:agentId). All fields are optional — only what you pass is updated. Common uses: tune the system `prompt` after a test run, switch `responseMode` to control turn-taking in multi-agent rooms, or adjust `cooldownSec`. See `ethora-agents-quickstart` prompt for the end-to-end recipe.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Mongo _id (24 hex chars) of the agent to update.
- `agentIdOrAddress` (string): Alias for `agentId` - either name is accepted, pass whichever you have.
- `botAvatarUrl` (string): Avatar image URL.
- `botDisplayName` (string): Display name in chat UI.
- `categories` (array): Category tags for directory listings.
- `cooldownSec` (integer): Minimum seconds between this agent's replies in a given room. Damped 2x for bot-to-bot. Set 0 for quick turn-taking.
- `flowsYaml` (string): Deterministic scripted conversation for this agent, as YAML. Drives the agent through a fixed sequence (opening menu, appointment request, intake questionnaire, survey) instead of leaving every turn…
- `greetingMessage` (string): Message the agent posts when it first joins a new room.
- `isPublished` (boolean): Convenience alias for visibility='public'.
- `isRAG` (boolean): Enable RAG retrieval.
- `llmModel` (string): LLM model override.
- `llmProvider` (string): LLM provider override.
- `name` (string): New display name. For multi-agent scenarios prefer single-word names — the @-mention matcher uses exact display-name match with word-boundary.
- `prompt` (string): Updated system prompt (persona + behaviour). For multi-agent rooms instruct the agent to end every message with an @-mention of the next speaker — that's how turn-handoff works through the response g…
- `ragTags` (array): RAG tag filter.
- `responseMode` (string): When the agent replies. 'always' = every message; 'mentioned' = only @-mention or /bot (best for multi-agent turn-taking); 'smart' = mini-LLM decides; 'probability' = coin-flip using `responseProbabi…
- `responseProbability` (number): If responseMode='probability', odds (0-1) of replying. Damped 0.6x for bot-to-bot.
- `slug` (string): URL-safe slug.
- `summary` (string): Short bio.
- `trigger` (string): Legacy trigger field. Prefer `responseMode`.
- `visibility` (string): 'private' or 'public' (cross-app invitable).

### `ethora-agents-clone-v2` (~264 tokens)

Clone Agent

Duplicate an existing saved agent into a new agent, optionally overriding its name/slug/summary (`POST /v2/agents/:agentId/clone`). The source agent is unchanged; the new clone becomes the session's current agent context.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.
Auth: app-token mode (after `ethora-app-select` + `ethora-auth-use-app`). Errors: 401/403 wrong auth; 404 source `agentId` not found; 422 overridden `slug` collides.

Input parameters:

- `agentId` (string): Id of the source agent to clone. Get it from `ethora-agents-list-v2`.
- `agentIdOrAddress` (string): Alias for `agentId` - either name is accepted, pass whichever you have.
- `name` (string): Name for the clone. Omit to inherit the source agent's name.
- `slug` (string): URL-safe unique slug for the clone. Omit to let the server derive one; must not collide with an existing agent.
- `summary` (string): Summary for the clone. Omit to inherit the source agent's summary.

### `ethora-agents-activate-v2` (~397 tokens)

Activate Agent for Widget

Make an agent the app's ACTIVE widget bot: sets `App.defaultBotInstanceId` (and `botStatus: on`), which is what `POST /v2/widget/sessions` uses to decide who answers website visitors. Required before an embedded widget can answer on an API-created app. Preconditions: the agent was invited into a room of this app with `ethora-agent-invite-to-chat` (that creates its bot instance). Works in user auth (app update route); falls back to the app-token `/v2/agents/:id/activate` route when an appToken is stored.
Requires: an agent already invited into a room of the selected app (`ethora-agents-create-v2` -> `ethora-app-create-chat` -> `ethora-agent-invite-to-chat`); the invite creates the bot instance this tool binds as the app's default responder.
Auth: user session (owner of the app). Errors: 404 no bot instance for this agent in the app (invite first); 403 not the app owner. Related: `ethora-widget-embed-snippet` next, `ethora-bot-instances-list` to inspect.

Input parameters:

- `agentId` (string): Id (or address) of the agent to activate. Get it from `ethora-agents-list-v2` / `ethora-agents-create-v2`.
- `agentIdOrAddress` (string): Alias for `agentId` - either name is accepted, pass whichever you have.
- `appId` (string): App to activate the agent for. Defaults to the app from `ethora-app-select`.
- `chatJid` (string): Room JID `${appId}_${chatId}` (with or without `@conference...`) that becomes the widget chat. Required for API-created apps; omit only for dashboard-created apps that already have an AI Widget chat…

### `ethora-agent-set-visibility` (~109 tokens)

Set Agent Visibility

Set an Agent's visibility (private | unlisted | public). Public agents can be invited cross-app by anyone who knows the address.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `visibility` (string, required)

### `ethora-agent-invite-to-chat` (~277 tokens)

Invite Agent to Chat

Invite an Agent into a chat room. Multiple agents can coexist in the same room — call this tool once per agent and they will all appear as members able to converse. Lazily creates a per-App BotInstance (an Ethora user with isBot:true) if one does not already exist for (agent, app). Spawns the XMPP client live; no ai-service restart required. For the full multi-agent recipe see the `ethora-agents-quickstart` prompt.
Requires: an agent (`ethora-agents-create-v2`) and a room (`ethora-app-create-chat`) in the selected app.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string): Either Mongo _id (24 hex chars) or EOA-style address.
- `appId` (string): Required in B2B mode unless already selected via ethora-app-select.
- `chatId` (string): Mongo Chat _id (preferred when invoking from admin).
- `chatJid` (string): Room JID `${appId}_${chatId}` (optionally with `@conference.<host>`), exactly the `jid` returned by `ethora-app-create-chat`. Preferred over `chatId`.

### `ethora-agent-soul-append` (~122 tokens)

Append to Agent Prompt

Append a fragment to an Agent's SOUL.MD (its evolving identity / private notes). Operator-driven; the Agent itself can also self-edit via the same endpoint when called by ai-service.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `append` (string, required)

### `ethora-agent-soul-set` (~116 tokens)

Set Agent Prompt

Replace an Agent's SOUL.MD with the provided markdown. Operator-driven; alternative to -append.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `soulMd` (string, required): Replace SOUL.MD contents. Pass empty string to clear.

### `ethora-bot-instances-list` (~101 tokens)

List Bot Instances

List BotInstances. Filter by appId (caller's App by default) and/or agentId.
Requires: at least one invited agent in the app (`ethora-agent-invite-to-chat`); otherwise the list is empty.

Input parameters:

- `agentId` (string)
- `agentIdOrAddress` (string): Alias for `agentId` - either name is accepted, pass whichever you have.
- `appId` (string)

### `ethora-bot-instance-status` (~86 tokens)

Bot Instance Status

Turn a specific BotInstance on or off. Off detaches it from XMPP; on re-spawns the XMPP client live.
Requires: a bot instance id from `ethora-bot-instances-list` (instances are created by `ethora-agent-invite-to-chat`).

Input parameters:

- `botInstanceId` (string, required)
- `status` (string, required)

### `ethora-agents-export-v2` (~145 tokens)

Export Agent

Export an Agent as a portable bundle (GET /v2/agents/:idOrAddress/export). format=json returns the bundle object directly; feed it back to `ethora-agents-import-v2` to recreate the Agent in another App/tenant.
Requires: an agent id or address from `ethora-agents-list-v2` or `ethora-agents-create-v2`.

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `format` (string): Defaults to json. Prefer json for MCP round-trips.

### `ethora-agents-import-v2` (~129 tokens)

Import Agent

Import an Agent from a bundle produced by `ethora-agents-export-v2` (POST /v2/agents/import, application/json body IS the bundle). Optionally scope the new Agent to an owning App via ownerAppId.
Requires: a bundle produced by `ethora-agents-export-v2` with format json.

Input parameters:

- `bundle` (object, required): The bundle object returned by `ethora-agents-export-v2` with format=json. Pass it through unchanged.
- `ownerAppId` (string): Owning App for the imported Agent (defaults server-side).

### `ethora-bot-instance-diag` (~133 tokens)

Diagnose Bot Instance

Diagnose a specific BotInstance for an Agent (GET /v2/agents/:idOrAddress/bot-instances/:botInstanceId/diag). Returns live XMPP/ai-service status and recent activity for troubleshooting.
Requires: a bot instance id from `ethora-bot-instances-list` (instances are created by `ethora-agent-invite-to-chat`).

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `botInstanceId` (string, required)

### `ethora-bot-instance-test-message` (~184 tokens)

Send Test Message to Bot

Send a test message from a BotInstance (POST /v2/agents/:idOrAddress/bot-instances/:botInstanceId/test-message). Omit roomJid to fan out to every room the BotInstance is in. Requires the ai-service to be running.
Requires: a bot instance id from `ethora-bot-instances-list` (instances are created by `ethora-agent-invite-to-chat`).

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `botInstanceId` (string, required)
- `roomJid` (string): Target a specific room JID; omit to broadcast to all the bot's rooms.
- `text` (string): Message body. Optional/empty is allowed.

### `ethora-bot-instance-leave-chat` (~149 tokens)

Remove Bot from Chat

Remove a BotInstance from a chat room (POST /v2/agents/:idOrAddress/bot-instances/:botInstanceId/leave-chat). The inverse of `ethora-agent-invite-to-chat`.
Requires: a bot instance id from `ethora-bot-instances-list` (instances are created by `ethora-agent-invite-to-chat`).

Input parameters:

- `agentId` (string): Alias for `agentIdOrAddress` - either name is accepted, pass whichever you have.
- `agentIdOrAddress` (string)
- `botInstanceId` (string, required)
- `chatJid` (string, required): Fully-qualified room JID to leave.

### `ethora-messages-search-v2` (~173 tokens)

Search Messages

Search an App's chat messages (GET /v2/apps/:appId/messages/search). B2B / tenant-actor auth. Filter by room (chatId), author (fromUserId), and time window.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.

Input parameters:

- `appId` (string): Required in B2B mode unless already selected via ethora-app-select.
- `chatId` (string)
- `fromUserId` (string)
- `limit` (integer)
- `mode` (string)
- `offset` (integer)
- `q` (string, required): Search query.
- `since` (string): ISO date lower bound.
- `sort` (string)
- `until` (string): ISO date upper bound.

### `ethora-messages-context-v2` (~138 tokens)

Get Message Context

Fetch the messages surrounding a target message (GET /v2/apps/:appId/chats/:chatId/messages/context). Provide either aroundStanzaId or aroundMessageId; radius controls how many messages before/after.
Requires: a message id from `ethora-messages-search-v2` or `ethora-chats-history-v2`.

Input parameters:

- `appId` (string): Required in B2B mode unless already selected via ethora-app-select.
- `aroundMessageId` (string)
- `aroundStanzaId` (string)
- `chatId` (string, required)
- `radius` (integer)

### `ethora-unread-counts-v2` (~149 tokens)

Get Unread Counts

Batch per-room unread message counts for a set of users (POST /v2/apps/:appId/users/unread-counts). mode=count returns numbers (capped); mode=flag returns booleans. Requires Mongo message archiving enabled on the deployment.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.

Input parameters:

- `appId` (string): Required in B2B mode unless already selected via ethora-app-select.
- `cap` (integer)
- `concurrency` (integer)
- `mode` (string)
- `userIds` (array, required): uuid / Mongo _id / xmppUsername, 1..200.

### `ethora-app-export-v2` (~146 tokens)

Export App

Export an App as a portable bundle (GET /v2/apps/:appId/export). format=json returns the bundle object directly. Use `include` to select sections (e.g. 'chats,users,sources,botInstances'). Feed the result to `ethora-app-import-v2`.
Requires: a selected app (`ethora-app-select`) or an explicit `appId`.

Input parameters:

- `appId` (string): Required in B2B mode unless already selected via ethora-app-select.
- `format` (string)
- `include` (string): Comma-separated sections to include, e.g. 'chats,users,sources,botInstances'.

### `ethora-app-import-v2` (~107 tokens)

Import App

Import an App from a bundle produced by `ethora-app-export-v2` (POST /v2/apps/import, application/json body IS the bundle). B2B / tenant-actor auth. domainNameOverride renames the imported App's domain.
Requires: a bundle produced by `ethora-app-export-v2`.

Input parameters:

- `bundle`: The exported bundle object (the json export output).
- `domainNameOverride` (string): Rename the imported App's domainName.

### `ethora-chats-message-v2` (~500 tokens)

Send Chat Message

Post a message into a chat room of an app (POST /v2/apps/:appId/chats/broadcast targeting one room). The message is attributed to the app's broadcast sender (override the shown name with `senderName`). Use it to seed or test a conversation, e.g. right after `ethora-agent-invite-to-chat`, and set `waitForReplySec` (up to 60) to wait for an AI agent's answer; replies are returned in `replies`. Identify the room by `roomJid` (`${appId}_${chatId}`, exactly what `ethora-app-create-chat` returns as `jid`) or by the bare `chatId` plus the selected app.
Requires: a room in the selected app (`ethora-app-create-chat`); for `replies`, an agent invited into it (`ethora-agent-invite-to-chat`).
Auth: user auth (the default on the hosted server) or B2B; app-token mode is not accepted by this route. Errors: 401 not logged in; 403 not the app owner; 404 unknown app/room; 422 empty text. Reply detection needs the message archive (MAM) on the deployment; when it is unavailable `replies` is null and `historyUnavailable` is true.

Input parameters:

- `appId` (string): 24-char hex appId. Optional when `roomJid` carries it or an app is selected.
- `chatId` (string): Chat id: either the Mongo chat `_id` (as listed by the app's chat list) or the suffix after `${appId}_` in the room JID. Needs an app: pass `appId` or select one with `ethora-app-select`.
- `roomJid` (string): Room JID `${appId}_${chatId}` (optionally with `@conference.<host>`), as returned by `ethora-app-create-chat`. Either this or `chatId` is required.
- `senderName` (string): Display name shown as the message sender (defaults to the app's broadcast sender / app name).
- `text` (string, required): Message body to post (1-4000 chars).
- `waitForReplySec` (integer): Seconds to wait for a reply from someone else in the room (an AI agent, typically). 0 (default) returns right after posting.

### `ethora-chats-history-v2` (~325 tokens)

Get Chat History

Read the archived messages of a chat room (GET /v2/apps/:appId/chats/:chatId/messages, newest last). Returns `results` with `from`, `nick`, `body`, `ts` (ms) plus a `nextBefore` cursor for older pages. Identify the room by `roomJid` (`${appId}_${chatId}`) or bare `chatId` plus the selected app.
Requires: a room in the selected app (`ethora-app-create-chat`).
Auth: user auth (default on the hosted server) or B2B; app-token mode is not accepted. Errors: 401 not logged in; 403 not the app owner; 404 unknown app/room; 502 MAM_READ_FAILED or `mamUnavailable: true` when the deployment has no message archive.

Input parameters:

- `appId` (string): 24-char hex appId. Optional when `roomJid` carries it or an app is selected.
- `before` (integer): Pagination cursor: only messages older than this timestamp (ms), from a previous `nextBefore`.
- `chatId` (string): Bare chat id. Needs an app: pass `appId` or select one with `ethora-app-select`.
- `limit` (integer): Maximum number of most-recent messages to return (default 100).
- `roomJid` (string): Room JID `${appId}_${chatId}` (optionally with `@conference.<host>`). Either this or `chatId` is required.

### `ethora-b2b-app-bootstrap-ai` (~496 tokens)

Bootstrap AI App (B2B)

One-call B2B orchestrator: create an app, set it as the current context, index RAG sources, then configure and enable its AI bot. Source ingest and bot activation are best-effort (the app is still created if a later step fails); crawl/embedding continues asynchronously after this returns. Returns a per-step log including the new `appId`.
Auth: B2B mode (`ethora-auth-use-b2b` + a configured `b2bToken`); internally switches to app-token mode for source-ingest steps. Errors: aborts with the partial step log if app creation fails; previous auth mode restored best-effort. Related: rooms+tokens variant is `ethora-b2b-app-provision`.

Input parameters:

- `agentDisplayName` (string): Phase 1: create a new Agent with this display name as part of bootstrap.
- `agentPrompt` (string): Phase 1: persona/instructions for the newly-created Agent.
- `agentVisibility` (string): Phase 1: visibility for the newly-created Agent.
- `botTrigger` (string): Optional bot trigger (e.g. '/bot' or 'any_message')
- `crawlUrl` (string): Optional website URL to crawl and index into the new app's RAG sources.
- `displayName` (string, required): Display name for the new app.
- `docs` (array): Optional docs to ingest (base64)
- `enableBot` (boolean): If true, enables botStatus=on (best-effort AI service activation)
- `followLink` (boolean): For `crawlUrl`: also follow in-domain links (default true). Can ingest many pages.
- `inviteToDefaultRoom` (boolean): Phase 1: if true (default), invite the newly-created Agent into the App's first default room.
- `llmModel` (string): Optional generation model for the default AI bot (example: 'gpt-4o-mini').
- `llmProvider` (string): Optional generation provider for the default AI bot (example: 'openai' or 'openai-compatible').
- `savedAgentId` (string): Optional saved agent to bind as the active bot for the new app.
- `setAsCurrent` (boolean): If true (default), set the new app as the session's current app and switch to app-token auth so follow-up tools can omit appId.

### `ethora-generate-chat-component-app-tsx` (~234 tokens)

Generate Chat Component App.tsx

Generate a ready-to-paste React `App.tsx` snippet that mounts `@ethora/chat-component`. Returns `{ filename: "App.tsx", snippet }`; unpassed values are emitted as placeholders. Does not write any file. Get the appToken from `ethora-app-credentials { appId, confirm: true }` (other tools redact it).
Auth: none required — pure code generator, no API calls. Errors: effectively none. Security note: the snippet includes `appToken` inline only as a quickstart convenience — do not ship hardcoded tokens to production.

Input parameters:

- `apiUrl` (string): Ethora API base URL to embed in the snippet, e.g. `https://api.chat.ethora.com/v1`. Omit to emit a placeholder.
- `appToken` (string): appToken to embed in the snippet for quickstart testing. Omit to emit a placeholder. Do NOT hardcode real tokens in production source.
- `roomJid` (string): Room JID to open on load. Omit to emit a commented-out placeholder.

### `ethora-generate-env-examples` (~144 tokens)

Generate Env Examples

Generate `.env.example` templates for the three common Ethora integration targets: the frontend chat component, the backend SDK, and this MCP server. Returns `{ target, template }` when `target` is given, or `{ templates }` with all three. Placeholder values only; does not write any file.
Auth: none required — pure text generator, no API calls. Errors: effectively none.

Input parameters:

- `target` (string): Which template to return: `frontend-chat-component` (Vite env), `backend-sdk` (@ethora/sdk-backend env), or `mcp` (this server's env). Omit to return all three.

### `ethora-generate-b2b-bootstrap-runbook` (~186 tokens)

Generate B2B Bootstrap Runbook

Generate a human-readable runbook listing this server's tool calls in the right order for a B2B bootstrap, with example payloads. Documentation only — does not write any file or execute any step.
Auth: none required — pure text generator, no API calls. Errors: effectively none. Related: to actually run the sequence use `ethora-run-recipe` or `ethora-b2b-app-bootstrap-ai`.

Input parameters:

- `apiUrl` (string): Ethora API base URL to show in the runbook's configure step. Omit to emit a placeholder.
- `crawlUrl` (string): Website URL to show in the runbook's source-ingest step. Omit to emit a placeholder.
- `displayName` (string): App display name to show in the runbook's create-app step. Omit to emit a placeholder.

### `search` (~133 tokens)

Search Docs

Search the Ethora documentation and tool reference: auth model (app JWT vs app token vs B2B token vs API keys), hosted-server getting started, chat-component and backend SDK quickstarts, recipes, and a reference entry for every tool with its inputs. Use it for any "how do I ..." question about Ethora before guessing; then call `fetch` with a result id to read the full text.
Auth: none required.

Input parameters:

- `query` (string, required): Free-text query, e.g. 'create an app', 'invite agent to chat', 'api key bearer header'. Empty returns the getting-started guides.

### `fetch` (~82 tokens)

Fetch Doc

Fetch the full text of a documentation section or tool reference entry by the id returned from `search` (e.g. `tool:ethora-app-create`, `doc:auth-map#app-jwt`, `doc:hosted-guide`).
Auth: none required. Errors: unknown id.

Input parameters:

- `id` (string, required): Document id from a `search` result.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp#diagnostics

## Score history

- 2026-09-20: 67
- 2026-09-19: 67
- 2026-09-18: 66
- 2026-09-17: 66
- 2026-09-16: 66
- 2026-09-15: 66

## Common questions

### What is the io.github.dappros/ethora-mcp-server server?

io.github.dappros/ethora-mcp-server is listed in the public MCP registry as io.github.dappros/ethora-mcp-server. Ethora chat platform MCP: apps, users, rooms, AI agents, chat widgets. Hosted or stdio. This page covers its hosted endpoint (https://mcp.chat.ethora.com/mcp).

### Is the io.github.dappros/ethora-mcp-server server safe to use?

io.github.dappros/ethora-mcp-server scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.dappros/ethora-mcp-server server expose?

io.github.dappros/ethora-mcp-server exposes 91 tools: ethora-configure, ethora-status, ethora-help, ethora-run-recipe, ethora-doctor, and 86 more. Their descriptions and schemas cost roughly 20,641 tokens of context every time the server is loaded.

### Does the io.github.dappros/ethora-mcp-server server require authentication?

No. We connected to io.github.dappros/ethora-mcp-server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the io.github.dappros/ethora-mcp-server server still maintained?

io.github.dappros/ethora-mcp-server is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.chat.ethora.com/mcp
- Repository: https://github.com/dappros/ethora-mcp-server
- Website: https://ethora.com/ai-sdk/mcp-server/
- Changelog RSS feed: https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp.json
- HTML version of this page: https://verifymcp.io/servers/dappros-ethora-mcp-server/mcp
