`GET /api/mcp/agents/{agent_id}/tools` — the agent's current tool rules.
Agent-wide (every connector’s rules at once), so a non-agent-manager never
gets the unfiltered view: if they can’t manage the whole agent, the result
is narrowed to only the connector(s) they themselves can manage
(can_manage_agent_connector — reachable, and either already granted to
this agent or the caller has at least ordinary access to it), e.g. so
agent-tools set-rule’s read-modify-write can find that connector’s
existing rules. This works with zero relationship to the agent itself,
e.g. a connector owner whose connector was granted to someone else’s agent.
If that filter finds no manageable connector at all, an empty result is
still a normal 200 as long as the caller has at least ordinary access to
the agent ([can_access_agent] — owner, public, or a plain share): a
freshly shared agent with no rules configured yet is not a permission
failure. Only a caller with neither a manageable connector already here
nor any relationship to the agent at all gets the 403.
Path Parameters
Agent id
Response
The agent's tool rules — data.rules is a list
Doc-only schema for the standard MCP ApiResponse envelope
({"data": …, "status_code": N, "message": "…"}). Most /api/mcp/*
payloads are service-layer serde_json::Value views, so data is
documented as a free-form object; each route's response description says
what it carries.
