openapi: 3.2.0 info: title: Pipeshub Connector API version: 1.0.0 contact: name: API Support email: support@pipeshub.com description: 'Operations tagged Connector across 2 of this provider''s published API definitions: pipeshub-openapi.yaml, pipeshub-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL security: - bearerAuth: [] - oauth2: [] tags: - name: Connector description: Connector-related operations paths: /connectors/record/{recordId}/content: get: tags: - Connector summary: Get a record's full parsed content and metadata description: 'Retrieve the full parsed content and metadata of a single record — the same content PipesHub''s own RAG/chat pipeline uses to answer questions, returned directly instead of via chat. **When to use this vs. the other record endpoints:** - `GET /knowledgeBase/record/{recordId}` returns metadata only (name, type, indexing status, size) — no content. - `GET /knowledgeBase/stream/record/{recordId}` returns the original, unparsed file bytes — use it to download/open the source file. - **This endpoint** returns the record''s full parsed content as a single plain-text `content` string (a metadata header, then the block/table text in reading order, then any foreign-key related tables) — use it when you need the record''s actual textual/tabular content without downloading and re-parsing the original file yourself. **Typical flow:** obtain a `recordId` from a `pipeshub_search` hit or a chat citation''s `recordId`, then call this endpoint to read the full content when the search snippet or citation excerpt isn''t enough to answer the question. **Permission scoping:** The requesting user/token must have access to the record; access is verified via the knowledge graph before content is returned — a caller with a valid scope but no access to this specific record gets a `403`.' operationId: getRecordContent x-pipeshub-sdk: true security: - bearerAuth: [] - oauth2: - connector:read parameters: - name: recordId in: path required: true description: Record ID to fetch. Obtain it from a `pipeshub_search` result (`hits[*].recordId`) or a chat citation (`citations[*].recordId`). schema: type: string responses: '200': description: 'Successful operation. When the record has no available content (e.g. not indexed), `content` is the literal `No record found` rather than an error status. ' content: application/json: schema: $ref: '#/components/schemas/GetRecordContentResponseSchema' '401': description: Missing, invalid, expired, or revoked authentication content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '403': description: 'OAuth token is missing the `connector:read` scope, or the authenticated user does not have access to this record. ' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '500': description: Internal server error while fetching record content content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '503': description: Connector service unavailable or connection refused content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /connectors/navigate: get: tags: - Connector summary: Browse the knowledge graph from a node description: 'Open a node in the knowledge graph and see what is inside it — a file explorer across every connected source. Call it with no `nodeId` for a flat listing of every record group and record the caller can reach, newest first. This is a starting point to pick a node from, not a roster of connected apps — app nodes are never returned in a listing, though an app''s `id` is accepted as a `nodeId` and lists that app''s record groups. Pass a node''s `id` to descend: record groups contain records and folders, and a record contains its own children — comments, attachments, sub-tasks — plus a `related` section of cross-referenced records, such as the Confluence page linked from a Jira ticket. `nodeId` is tolerant: a URL or an issue key such as `PA-1787` is resolved to its record before navigating, so a link can be pasted straight in without a separate lookup call. The response carries a rendered `text` view — breadcrumbs, the current node, the children listing, `Related:`, and a closing `Next:` line naming a follow-up call. The structured fields carry the same information for programmatic use. **When to use this vs. the other record endpoints:** - **This endpoint** is for structural exploration — "what is in this project", "what is attached to this ticket", "what else links to this page". It returns names, types and IDs; it never returns document text. - `GET /connectors/record/{recordId}/content` returns one record''s actual parsed text. Use it once navigation has identified the record you want to read. - `GET /connectors/record/lookup` is the way in when you hold a URL or an issue key rather than a position in the tree. **Typical flow:** call with no `nodeId` to see what is reachable → pass a record group''s `id` to list its records → take a row whose `is_record` is true and call `GET /connectors/record/{recordId}/content` to read it. **Paging and depth:** results are paginated; `pagination.has_next` tells you whether to request the next `page`. `depth` above 1 returns all descendants down to that level as one flat list, each row carrying its own `level`, instead of only direct children. **Scope:** everything the caller can read, across both connectors and Knowledge Base collections. No connector-level filter is applied — the listing is bounded by per-node permissions alone. **Permission scoping:** `rows` and `related` carry only nodes the caller can see, and the opened node itself is access-checked before any of its details are returned. A node that does not exist and a node the caller cannot access are deliberately indistinguishable — both return an empty view rather than an error. `breadcrumbs` is the exception: the ancestor trail is resolved by id alone, without a permission check. For a record shared directly with the caller, it can therefore name ancestors the caller cannot open. Treat breadcrumb entries as labels, not as nodes guaranteed to be navigable.' operationId: navigateKnowledgeGraph x-pipeshub-sdk: true security: - bearerAuth: [] - oauth2: - connector:read parameters: - name: nodeId in: query required: false description: 'The node to open. Take it from an `id` in a previous navigate or lookup response. Omit it entirely for the flat listing of everything reachable — the usual starting point. A URL or an issue key such as `PA-1787` also works: it is resolved to its record automatically.' schema: type: string minLength: 1 maxLength: 2048 - name: page in: query required: false description: Page number, 1-indexed. schema: type: integer minimum: 1 default: 1 - name: limit in: query required: false description: Children per page. The minimum is 50 — smaller values are rejected rather than silently raised. schema: type: integer minimum: 50 maximum: 200 default: 50 - name: depth in: query required: false description: Levels of descendants to return in one call. Above 1, `rows` is a flat list of all descendants down to that level rather than only direct children, and each row carries its own `level`. schema: type: integer minimum: 1 maximum: 3 default: 1 - name: nodeTypes in: query required: false description: 'Restrict children to these node types. Repeat the parameter for multiple types: `?nodeTypes=record&nodeTypes=folder`.' schema: type: array items: type: string - name: createdAfter in: query required: false description: Filter children by source creation time. ISO 8601 `YYYY-MM-DD`, or a full datetime that MUST carry a timezone offset — a naive datetime is rejected rather than assumed to be UTC. schema: type: string - name: createdBefore in: query required: false description: Filter children by source creation time. `YYYY-MM-DD` is inclusive of the whole day. schema: type: string - name: modifiedAfter in: query required: false description: Filter children by source modification time. schema: type: string - name: modifiedBefore in: query required: false description: Filter children by source modification time. schema: type: string responses: '200': description: 'Successful operation. A node that does not exist or is not accessible returns an empty view (null `current`, empty `rows`) rather than an error. ' content: application/json: schema: $ref: '#/components/schemas/NavigateKnowledgeGraphResponseSchema' '400': description: 'A parameter failed validation: `page` below 1, `limit` outside 50-200, `depth` outside 1-3, an empty `nodeId`, or a date that is not valid ISO 8601, carries no timezone offset, forms an inverted range, or has `createdAfter` in the future. ' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '401': description: Missing, invalid, expired, or revoked authentication content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '403': description: OAuth token is missing both the `kb:read` and `connector:read` scopes. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '404': description: The authenticated user could not be resolved content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '500': description: Internal server error while navigating the knowledge graph content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '503': description: Connector service unavailable or connection refused content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /connectors/record/lookup: get: tags: - Connector summary: Resolve a URL, issue key or external ID to a Record ID description: 'Turn an external reference into the matching PipesHub record. Accepts a pasted link, a Jira-style issue key, or a bare external system ID from any connected source. Repeat `identifiers` to batch-resolve up to ten in one call. The response carries a rendered `text` view — each match''s metadata block followed by a `Next:` line naming a follow-up call. The structured fields carry the same information for programmatic use. **Accepted identifiers** - Jira issue URL — `https://acme.atlassian.net/browse/PA-1787` - Jira issue key — `PA-1787` - Confluence page URL — `https://acme.atlassian.net/wiki/spaces/SD/pages/450625553/Agent+Loop` - Google Drive / Docs URL — `https://docs.google.com/document/d/1AbC.../edit` - Slack message link — `https://acme.slack.com/archives/C0123/p1720000000000100` - Bare external system ID — `450625553` **When to use this vs. the other record endpoints:** - **This endpoint** converts an *external* reference into an internal Record ID. Reach for it whenever you meet a link or ticket key and need the record behind it. - `GET /connectors/record/{recordId}/content` reads a record you have already identified. It needs an internal Record ID, which is exactly what this endpoint returns. - `GET /connectors/navigate` browses the hierarchy when you have a position in the tree rather than a specific identifier. **Typical flow:** call this with the reference, take a match''s `id` from the response, then call `GET /connectors/record/{recordId}/content` to read the record. **Multiple matches:** one identifier can legitimately match more than one record — the same external ID may exist in several connected instances. In that case the response sets `ambiguous: true` and `matches` holds every candidate. Present the choice rather than taking the first; `connectorName` narrows a retry. **Misses are not errors.** Only records the caller can see are returned, and a miss is a `200` with an empty `matches` array and the input echoed in `not_found_identifiers` — not a `404`. The identifier resolved to nothing *or* to something the caller may not access; the two are deliberately indistinguishable, because an identifier is caller-supplied and guessable, and confirming existence would leak records across organizations. `searched_connectors` names what was covered, so a retry with `connectorName` is often the right next move. **Scope:** resolution searches every connector the caller can access, regardless of any source filter used elsewhere.' operationId: lookupRecordByIdentifier x-pipeshub-sdk: true security: - bearerAuth: [] - oauth2: - connector:read parameters: - name: identifiers in: query required: true description: 'The reference(s) to resolve: a URL, an issue key such as `PA-1787`, or a bare external system ID. Repeat the parameter to batch: `?identifiers=PA-1787&identifiers=PA-1788`. Maximum 10.' schema: type: array minItems: 1 maxItems: 10 items: type: string maxLength: 2048 - name: connectorName in: query required: false description: Optional hint that prioritises resolution order, e.g. `JIRA`, `CONFLUENCE`, `DRIVE`, `SLACK`. Allowed values are the `ConnectorNameEnum` values. It cannot widen the search beyond the connectors the caller can already access. Useful on a retry when a lookup came back empty. schema: $ref: '#/components/schemas/ConnectorNameEnum' responses: '200': description: 'Successful operation. Identifiers that resolved to nothing the caller can access are echoed in `not_found_identifiers` rather than producing an error status. ' content: application/json: schema: $ref: '#/components/schemas/LookupRecordResponseSchema' '400': description: No non-blank identifier was supplied, or more than 10 were. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '401': description: Missing, invalid, expired, or revoked authentication content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '403': description: OAuth token is missing both the `kb:read` and `connector:read` scopes. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '404': description: The authenticated user could not be resolved content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '500': description: Internal server error while resolving identifiers content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' '503': description: Connector service unavailable or connection refused content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL components: schemas: KnowledgeGraphPaginationSchema: type: object additionalProperties: false description: Pagination envelope for a navigate listing. required: - page - limit - total - has_next - has_prev properties: page: type: integer limit: type: integer total: type: integer description: Total children of the current node, ignoring pagination. has_next: type: boolean has_prev: type: boolean ConnectorNameEnum: type: string description: 'Name of the source connector. Mirrors the values of the backend `Connectors` enum (`backend/python/app/config/constants/arangodb.py`); records store the enum value (e.g. Google Drive is `DRIVE`, SharePoint Online is `SHAREPOINT ONLINE`), not the enum member name. ' enum: - DRIVE - DRIVE WORKSPACE - GMAIL - GMAIL WORKSPACE - CALENDAR - ONEDRIVE - SHAREPOINT ONLINE - OUTLOOK - OUTLOOK PERSONAL - OUTLOOK CALENDAR - MICROSOFT TEAMS - NOTION - NOTION PERSONAL - SLACK - SLACK WORKSPACE - KB - CONFLUENCE - CONFLUENCE DATA CENTER - CONFLUENCE DATA CENTER PERSONAL - JIRA - JIRA PERSONAL - JIRA DATA CENTER - JIRA DATA CENTER PERSONAL - BOX - NEXTCLOUD - DROPBOX - DROPBOX PERSONAL - WEB - BOOKSTACK - DRUPAL WIKI - GITHUB - GITHUB TEAMS - SERVICENOW - SALESFORCE - S3 - MINIO - GCS - AZURE BLOB - AZURE FILES - LINEAR - ZAMMAD - ZOOM - GITLAB - GITLAB PERSONAL - SNOWFLAKE - POSTGRESQL - MARIADB - UNKNOWN - RSS - LOCAL_FS - CODING_SANDBOX - DATABASE_SANDBOX - IMAGE_GENERATION - ATTACHMENTS example: DRIVE GetRecordContentResponseSchema: type: object additionalProperties: false description: 'Response returned by GET /connectors/record/{recordId}/content. `content` is the record''s full parsed content flattened into a single plain-text string: a metadata header (title, source, key fields, and a short summary), then the record''s block/table text in reading order, and finally a foreign-key related-tables footer for `SQL_TABLE` records. For `TICKET` records (e.g. Jira) the metadata header is refreshed with live ticket fields (status, assignee, comments) at request time rather than the last-indexed snapshot. `content` may be empty for records with no extractable text (e.g. image-only or not-yet-parsed records). ' required: - content properties: content: type: string description: The record's full parsed content as a single plain-text string. KnowledgeGraphLookupMatchSchema: type: object additionalProperties: false description: A single record resolved from an identifier. required: - id - name - record_type - connector_name - web_url - indexing_status - identifier_used properties: id: type: string description: The Record ID. Pass it to GET /connectors/record/{recordId}/content to read the record, or as `nodeId` to GET /connectors/navigate to list what is under it. name: type: string record_type: type: - string - 'null' connector_name: type: - string - 'null' web_url: type: - string - 'null' indexing_status: type: - string - 'null' identifier_used: type: string description: Which of the supplied identifiers produced this match. external_id: type: - string - 'null' description: e.g. `PA-1787`, a Confluence page id, a Drive file id. context_block: type: - string - 'null' description: Type-specific metadata for the record — for a ticket, status, assignee, priority and dates. KnowledgeGraphNodeRefSchema: type: object additionalProperties: false description: Minimal identity reference for a node in the knowledge graph. required: - id - name - node_type - sub_type - is_record properties: id: type: string description: Node identifier. Pass it back as `nodeId` to open this node. When `is_record` is true it is also the Record ID accepted by GET /connectors/record/{recordId}/content. name: type: string node_type: type: string description: One of `app`, `recordGroup`, `folder`, `record`. sub_type: type: - string - 'null' description: e.g. `TICKET`, `CONFLUENCE_PAGE`, `PROJECT`, `COLLECTION`. is_record: type: boolean description: True for record and folder nodes — the nodes whose content can be read via GET /connectors/record/{recordId}/content. KnowledgeGraphNodeRowSchema: type: object additionalProperties: false description: 'One row in a navigate listing. Carries the identity fields of KnowledgeGraphNodeRefSchema (inlined rather than composed, so this object can stay closed) plus display detail. ' required: - id - name - node_type - sub_type - is_record - has_children - detail properties: id: type: string name: type: string node_type: type: string description: One of `recordGroup`, `folder`, `record`. Listings never contain `app` nodes. sub_type: type: - string - 'null' is_record: type: boolean has_children: type: boolean description: Whether this node can itself be opened with `nodeId`. detail: type: - string - 'null' description: e.g. size, indexing status, or relationship type. web_url: type: - string - 'null' description: Link to the record in its source system. Records that carry a relative URL (uploaded/KB records) are resolved against the configured frontend public URL (see POST /configurationManager/frontendPublicUrl). The value is null when that host is not configured. indexing_status: type: - string - 'null' source_created_at: type: - integer - 'null' format: int64 description: Creation time in the source system, epoch milliseconds. Null when the underlying node did not carry one. source_modified_at: type: - integer - 'null' format: int64 level: type: integer description: 1-based nesting depth from the navigated parent. Always 1 for a `depth=1` listing; 2 or 3 for deeper rows when `depth` > 1. context_summary: type: - string - 'null' ErrorResponse: type: object additionalProperties: false description: 'Standard error envelope returned by all errors routed through `ErrorMiddleware`. Applies to all `BaseError` subclasses including `HttpError`, `ValidationError`, and others. The `code` field is a machine-readable string identifying the error type (e.g. `HTTP_UNAUTHORIZED`, `HTTP_NOT_FOUND`, `VALIDATION_ERROR`, `INTERNAL_ERROR`). ' properties: error: type: object additionalProperties: false required: - code - message properties: requestId: type: string description: 'Identifier for this request, echoed so a bug report can quote it. Absent when the request never reached the middleware that assigns one. ' code: type: string description: 'Machine-readable error code. For application errors it takes the form `HTTP_` For unhandled runtime errors (e.g. database unavailable) it is `INTERNAL_ERROR`. ' example: HTTP_BAD_REQUEST message: type: string description: Human-readable description of the error example: Admin access required metadata: type: object description: Additional context (only present in development environments) additionalProperties: true required: - error LookupRecordResponseSchema: type: object additionalProperties: false description: 'Response returned by GET /connectors/record/lookup. Field names are snake_case, matching the knowledge graph''s internal view models. A miss is a 200 with an empty `matches` and the input echoed in `not_found_identifiers` — see the endpoint description. ' required: - matches - ambiguous - not_found_identifiers - text properties: matches: type: array items: $ref: '#/components/schemas/KnowledgeGraphLookupMatchSchema' ambiguous: type: boolean description: True when one identifier resolved to more than one accessible record. Present the choice rather than taking the first, or retry with `connectorName`. not_found_identifiers: type: array description: Identifiers that resolved to nothing the caller can access. items: type: string searched_connectors: type: object description: Per-identifier list of the connector types that were searched, so a miss can be retried against a different `connectorName`. Keys are the identifiers exactly as supplied. additionalProperties: type: array items: type: string text: type: string description: Flat-text rendering of the matches — each match's metadata block followed by a `Next:` line naming a follow-up call — and a line per miss naming the connectors that were searched. Capped at 25,000 bytes. NavigateKnowledgeGraphResponseSchema: type: object additionalProperties: false description: 'Response returned by GET /connectors/navigate. Field names are snake_case, matching the knowledge graph''s internal view models. `text` carries the same flat-text rendering PipesHub''s own agent sees for this node; the remaining fields carry the same information in structured form. ' required: - current - breadcrumbs - rows - related - pagination - web_url - indexing_status - connector - text properties: current: allOf: - $ref: '#/components/schemas/KnowledgeGraphNodeRefSchema' description: The node that was opened. Null at the root listing. breadcrumbs: type: array description: Root to parent, not including `current`. items: $ref: '#/components/schemas/KnowledgeGraphNodeRefSchema' rows: type: array description: The current node's children for this page. With `depth` > 1 this is a flat list of all descendants up to that depth, each row carrying its own `level`. items: $ref: '#/components/schemas/KnowledgeGraphNodeRowSchema' related: type: array description: Cross-referenced records (non-containment edges), e.g. the Confluence page linked from a Jira ticket. Page 1 only. items: $ref: '#/components/schemas/KnowledgeGraphNodeRowSchema' pagination: allOf: - $ref: '#/components/schemas/KnowledgeGraphPaginationSchema' web_url: type: - string - 'null' indexing_status: type: - string - 'null' connector: type: - string - 'null' context_block: type: - string - 'null' description: Type-specific metadata for the current node when it is a record — for a ticket, status, assignee, priority and dates. text: type: string description: 'Flat-text rendering of this view: breadcrumbs, the current node''s metadata, the children listing with an id per row, `Related:`, and a closing `Next:` line naming a follow-up call. Shape depends on the page: pages after the first omit the header, breadcrumbs and related rows to stay compact, while the structured fields above remain complete. Capped at 25,000 bytes, with a truncation marker appended when exceeded. ' securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'JWT Bearer token for authenticated requests. A personal access token (see the **Personal Access Tokens** tag) is a `phpat_`-prefixed variant of this same JWT — e.g. `phpat_eyJhbGci...`. The prefix is display-only, added for secret-scanner detectability; the gateway strips it before verifying the token, so send it exactly as issued, prefix included. ' scopedToken: type: http scheme: bearer bearerFormat: JWT description: 'Scoped JWT token for service-to-service authentication. Format: "Bearer {scoped_token}" Required scopes vary by endpoint. ' oauth2: type: oauth2 description: 'OAuth 2.0 authentication with fine-grained scopes. Supports authorization_code (with PKCE) and client_credentials flows. OAuth tokens are Bearer JWTs — use the same Authorization header as regular tokens. For **client_credentials**, machine JWTs may use `userId === client_id`; the Node gateway resolves the OAuth app creator — see **OAuth Provider** tag. ' flows: authorizationCode: authorizationUrl: /api/v1/oauth2/authorize tokenUrl: /api/v1/oauth2/token refreshUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:read: Read semantic search results and history semantic:write: Execute semantic search semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs crawl:delete: Delete crawling jobs clientCredentials: tokenUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:write: Execute semantic search semantic:read: Read semantic search results and history semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs x-refined-from: - pipeshub-openapi.yaml - pipeshub-openapi.yml