configure_push
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/configure_push, with a bearer credential and the action's payload as the JSON body.
Contract description
Configure an application's push notifications for one environment. The `apns` member names Apple's team and key identifiers, the app's bundle identifier, the gateway (`production` or `sandbox`), and the stored signing key's name. The `fcm` member names the Firebase project and the stored service-account file's name. Store each credential first with `store_secret` naming the application and the environment; the platform proves the name present and never reads it here. Each member is optional and `null` removes that provider. The manifest must declare the push service. An optional `environment` (`development` or `production`; absent, `production`) names which environment the call configures. A provider the manifest's push entry names is refused `manifest_owned_field`.
Access and action metadata
{
"name": "configure_push",
"resource": "push",
"tier": "reversible",
"summary": "Set an application environment's push providers — Apple's team, key, bundle, gateway, and stored signing-key name; Google's project and stored service-account file name — each optional, null removing one; refused by name where the manifest declares no push service, where a named secret is not in custody at that scope, or where the name is an upstream's or a realm route's credential or a setting binds it.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "configure_push",
"tier": "reversible",
"summary": "Configure an application's push notifications for one environment. The `apns` member names Apple's team and key identifiers, the app's bundle identifier, the gateway (`production` or `sandbox`), and the stored signing key's name. The `fcm` member names the Firebase project and the stored service-account file's name. Store each credential first with `store_secret` naming the application and the environment; the platform proves the name present and never reads it here. Each member is optional and `null` removes that provider. The manifest must declare the push service. An optional `environment` (`development` or `production`; absent, `production`) names which environment the call configures. A provider the manifest's push entry names is refused `manifest_owned_field`.",
"owners": [
"PSH-L0-01",
"PLD-L0-40"
],
"scenario": "PSH-L0-01"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application"] Additional properties: false |
| / |
The application id whose push service to configure. A provider its manifest's push entry names is the manifest's, Apple's `environment` apart, and a call that would change or remove one is refused `manifest_owned_field`. Type: string |
| / |
Optional. The environment the call addresses, `development` or `production`; absent, `production`. Type: string Pattern: ^(development|production)$ |
| / |
Optional. Apple's provider: `team_id`, `key_id`, `bundle_id`, `key_secret_name`, and `environment` (`production` or `sandbox`); null removes the provider. The named secret is proved present at this environment's application scope and moved nowhere. Type: ["object","null"] Additional properties: false |
| / |
The ten-character Apple team identifier. Type: string |
| / |
The ten-character identifier of the APNs signing key. Type: string |
| / |
The app's bundle identifier, the notification's topic. Type: string |
| / |
The custody NAME of the stored .p8 signing key at this environment scope; never a value. Type: string |
| / |
Which of Apple's two gateways this environment's pushes go to. Type: string Allowed values: ["production","sandbox"] |
| / |
Optional. Google's provider: `project_id` and `service_account_secret_name`; null removes the provider. The named secret is proved present at this environment's application scope and moved nowhere. Type: ["object","null"] Additional properties: false |
| / |
The Firebase project identifier. Type: string |
| / |
The custody NAME of the stored service-account JSON file at this environment scope; never a value. Type: string |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","push","detail"] Additional properties: false |
| / |
Required value: 1 |
| / |
Type: object Required fields: ["application","environment","apns","fcm"] Additional properties: false |
| / |
Type: string |
| / |
Type: string Allowed values: ["development","production"] |
| / |
Type: ["object","null"] Required fields: ["team_id","key_id","bundle_id","key_secret_name","environment"] Additional properties: false |
| / |
The ten-character Apple team identifier. Type: string |
| / |
The ten-character identifier of the APNs signing key. Type: string |
| / |
The app's bundle identifier, the notification's topic. Type: string |
| / |
The custody NAME of the stored .p8 signing key at this environment scope; never a value. Type: string |
| / |
Which of Apple's two gateways this environment's pushes go to. Type: string Allowed values: ["production","sandbox"] |
| / |
Type: ["object","null"] Required fields: ["project_id","service_account_secret_name"] Additional properties: false |
| / |
The Firebase project identifier. Type: string |
| / |
The custody NAME of the stored service-account JSON file at this environment scope; never a value. Type: string |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application"
],
"properties": {
"application": {
"type": "string",
"description": "The application id whose push service to configure. A provider its manifest's push entry names is the manifest's, Apple's `environment` apart, and a call that would change or remove one is refused `manifest_owned_field`."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Optional. The environment the call addresses, `development` or `production`; absent, `production`."
},
"apns": {
"type": [
"object",
"null"
],
"description": "Optional. Apple's provider: `team_id`, `key_id`, `bundle_id`, `key_secret_name`, and `environment` (`production` or `sandbox`); null removes the provider. The named secret is proved present at this environment's application scope and moved nowhere.",
"properties": {
"team_id": {
"type": "string",
"description": "The ten-character Apple team identifier."
},
"key_id": {
"type": "string",
"description": "The ten-character identifier of the APNs signing key."
},
"bundle_id": {
"type": "string",
"description": "The app's bundle identifier, the notification's topic."
},
"key_secret_name": {
"type": "string",
"description": "The custody NAME of the stored .p8 signing key at this environment scope; never a value."
},
"environment": {
"type": "string",
"enum": [
"production",
"sandbox"
],
"description": "Which of Apple's two gateways this environment's pushes go to."
}
},
"additionalProperties": false
},
"fcm": {
"type": [
"object",
"null"
],
"description": "Optional. Google's provider: `project_id` and `service_account_secret_name`; null removes the provider. The named secret is proved present at this environment's application scope and moved nowhere.",
"properties": {
"project_id": {
"type": "string",
"description": "The Firebase project identifier."
},
"service_account_secret_name": {
"type": "string",
"description": "The custody NAME of the stored service-account JSON file at this environment scope; never a value."
}
},
"additionalProperties": false
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"push",
"detail"
],
"properties": {
"contract_version": {
"const": 1
},
"push": {
"type": "object",
"required": [
"application",
"environment",
"apns",
"fcm"
],
"properties": {
"application": {
"type": "string"
},
"environment": {
"type": "string",
"enum": [
"development",
"production"
]
},
"apns": {
"type": [
"object",
"null"
],
"required": [
"team_id",
"key_id",
"bundle_id",
"key_secret_name",
"environment"
],
"properties": {
"team_id": {
"type": "string",
"description": "The ten-character Apple team identifier."
},
"key_id": {
"type": "string",
"description": "The ten-character identifier of the APNs signing key."
},
"bundle_id": {
"type": "string",
"description": "The app's bundle identifier, the notification's topic."
},
"key_secret_name": {
"type": "string",
"description": "The custody NAME of the stored .p8 signing key at this environment scope; never a value."
},
"environment": {
"type": "string",
"enum": [
"production",
"sandbox"
],
"description": "Which of Apple's two gateways this environment's pushes go to."
}
},
"additionalProperties": false
},
"fcm": {
"type": [
"object",
"null"
],
"required": [
"project_id",
"service_account_secret_name"
],
"properties": {
"project_id": {
"type": "string",
"description": "The Firebase project identifier."
},
"service_account_secret_name": {
"type": "string",
"description": "The custody NAME of the stored service-account JSON file at this environment scope; never a value."
}
},
"additionalProperties": false
}
},
"additionalProperties": false
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md