export_account
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/export_account, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
Export the account's declarations as one JSON document, stamped with the time of the read and read in one pass with no snapshot across the reads. The document holds the account record with its identities, standing, and product profiles, every application with its manifest, plan, environments, current version, and deploy state, and each end-user realm's configuration (never its users) with its registered-device counts by platform. It also holds each environment's push configuration with the providers' identifiers and secret names (never values), the storage area declarations, the secret names (never values), the upstream declarations, and the minted-token records (never values).
The data archive is not included: each application's database contents and stored files leave through `request_export`, one application and one environment per export, and `read_export` reads its manifest. The source stays with the builder throughout. Usable at any time, and offered before `delete_account`.
Access and action metadata
{
"name": "export_account",
"resource": "account",
"tier": "observe",
"summary": "The export escape: the account's declarations as one JSON document — the account record, the applications with their manifests, the realm configurations with their device counts, the push configurations, the storage area declarations, the secret names (never values), the upstream declarations, and the token records — stamped with the time of the read. The databases' contents and the areas' files leave per application and environment through `request_export`.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "export_account",
"tier": "observe",
"scenario": "CHI-L0-12",
"summary": "Export the account's declarations as one JSON document, stamped with the time of the read and read in one pass with no snapshot across the reads. The document holds the account record with its identities, standing, and product profiles, every application with its manifest, plan, environments, current version, and deploy state, and each end-user realm's configuration (never its users) with its registered-device counts by platform. It also holds each environment's push configuration with the providers' identifiers and secret names (never values), the storage area declarations, the secret names (never values), the upstream declarations, and the minted-token records (never values).\n\nThe data archive is not included: each application's database contents and stored files leave through `request_export`, one application and one environment per export, and `read_export` reads its manifest. The source stays with the builder throughout. Usable at any time, and offered before `delete_account`.",
"owners": [
"ACB-L0-47"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Additional properties: false |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","export"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
Type: object Required fields: ["read_at","account","applications","realms","areas","custody","upstreams","tokens","push"] |
| / |
Type: string |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object Required fields: ["id","name","label","created_at","plan","manifest","environments","state","version"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: ["object","null"] |
| / |
Type: array |
| / |
Type: string |
| / |
Allowed values: ["deployed","failed","never_deployed"] |
| / |
Type: ["integer","null"] |
| / |
Type: array |
| / |
Type: object Required fields: ["realm","sign_in_methods","creation","limits","invitation_days","session_days","devices"] |
| / |
Type: string |
| / |
Type: array |
| / |
Type: string |
| / |
Allowed values: ["open","invited"] |
| / |
Type: object Required fields: ["creation_ceiling","signin_starts_per_hour","code_sends_per_hour"] |
| / |
Type: ["integer","null"] |
| / |
Type: integer |
| / |
Type: integer |
| / |
Type: integer |
| / |
Type: integer |
| / |
Type: object Required fields: ["tenant","client_id","client_secret_name"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
The realm's Sign in with Apple route (the accounts service's work-account statement): the Services ID, the team and key identifiers, and the NAME of the signing key in the application's custody scope — never a value. Type: object Required fields: ["services_id","team_id","key_id","key_secret_name"] Additional properties: false |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: integer Minimum: 1 Maximum: 730 |
| / |
The declared native clients, each without any secret: a native client holds none. Type: array Maximum items: 10 |
| / |
Type: object Required fields: ["client_id","redirect_uris"] Additional properties: false |
| / |
The client's identifier, which it presents at the authorization, token, and revocation endpoints; letters, digits, dots, underscores, colons, and hyphens. Type: string |
| / |
The redirect URIs the client presents, each matched exactly, a loopback URI's port excepted: a reverse-domain custom scheme such as `com.example.app:/callback`, an `https` URI on one of the application's own hostnames, or a loopback `http` URI on `localhost`, `[::1]`, or 127.0.0.0/8. Any other form is refused `invalid_redirect_uri`. Type: array Minimum items: 1 Maximum items: 20 |
| / |
Type: string |
| / |
Optional. The iOS app's bundle identifier and its ten-character team identifier, for the association files and the native ID-token exchange that later changes serve. Type: object Required fields: ["bundle_id","team_id"] Additional properties: false |
| / |
Type: string |
| / |
Type: string |
| / |
Optional. The Android app's package name and its signing-certificate SHA-256 fingerprints, each 32 upper-case hex pairs separated by colons, for the asset links and the passkey origin that later changes serve. Type: object Required fields: ["package","sha256_cert_fingerprints"] Additional properties: false |
| / |
Type: string |
| / |
Type: array Minimum items: 1 Maximum items: 10 |
| / |
Type: string |
| / |
Optional. The Google client identifiers a Google ID token names as its audience, for the native ID-token exchange a later change serves. Type: array Maximum items: 10 |
| / |
Type: string |
| / |
Optional. The oldest app version the router admits, as `major.minor.patch`; a request stating a lower version is refused `client_upgrade_required`. Type: string |
| / |
Optional. An `https` URL where a refused client is sent to update. Type: string |
| / |
The realm's device registration counts by platform (PSH-L0-06); never a token or a user. Type: object Required fields: ["ios","android","invalid"] Additional properties: false |
| / |
Type: integer |
| / |
Type: integer |
| / |
Type: integer |
| / |
Type: array |
| / |
Type: object Required fields: ["name","account_keyed","version_keeping","application","created_at"] |
| / |
Type: string |
| / |
Type: boolean |
| / |
Type: boolean |
| / |
Type: ["string","null"] |
| / |
Type: string |
| / |
Type: array |
| / |
Type: object Required fields: ["name","scope","created_at"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08). Type: ["string","null"] |
| / |
Type: array |
| / |
Type: object Required fields: ["name","base_url","credential_name","auth_header","auth_format","token_shape","application"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
Type: array |
| / |
Type: object Required fields: ["id","scope_kind","application","grants","label","created_at","expires_at","revoked_at","last_used_at"] |
| / |
Type: string |
| / |
Allowed values: ["account","application"] |
| / |
Type: ["string","null"] |
| / |
Type: array |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
The space the issues grant names; present on a token that carries the grant alone. Type: string Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ |
| / |
The level the issues grant reaches its space at: report, contribute, or owner; present on a token that carries the grant alone. Allowed values: ["report","contribute","owner"] |
| / |
The account's own records at the issue service, read whole through the projection with the person named as the reading actor (ACB-L0-47): its own reports, each with its issue projected, the comments it wrote, its signals, and its asks. Present where the platform is configured with the service's origin, and absent otherwise; a read that fails refuses the export whole as issue_service_unreachable. Its `spaces` member carries the same four halves for each space the account owns, binds, or holds in custody for an application. Type: object Required fields: ["issues","comments","signals","asks","spaces"] |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
The account's own records in each issue space it owns, binds, or holds in custody for an application, one entry per space (ACB-L0-47): a space of the account's own, an application's own space, and each space of an application's per-environment pair. Each space is read under its own token through the projection, as the platform's space is read. A token that does not answer, or a space that could not be read, refuses the export whole as issue_service_unreachable. Type: array |
| / |
Type: object Required fields: ["space","kind","application","environment","issues","comments","signals","asks"] |
| / |
The space's identifier, a lower-case UUID. Type: string |
| / |
`account` for a space of the account's own, `application` for an application's own space or one space of its per-environment pair. Type: string Allowed values: ["account","application"] |
| / |
The application whose space this is, null for a space of the account's own. Type: ["string","null"] |
| / |
The environment one space of an application's per-environment pair serves, null for a space serving both. Type: ["string","null"] Pattern: ^(development|production)$ |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
Type: array |
| / |
Type: object |
| / |
Each environment's push configuration of each application: the providers' identifiers and secret NAMES, never a value (PSH-L0-06). Type: array |
| / |
Type: object Required fields: ["application","environment","apns","fcm"] Additional properties: false |
| / |
Type: string |
| / |
Type: string Allowed values: ["development","production"] |
| / |
Type: ["object","null"] Required fields: ["team_id","key_id","bundle_id","key_secret_name","environment"] Additional properties: false |
| / |
The ten-character Apple team identifier. Type: string |
| / |
The ten-character identifier of the APNs signing key. Type: string |
| / |
The app's bundle identifier, the notification's topic. Type: string |
| / |
The custody NAME of the stored .p8 signing key at this environment scope; never a value. Type: string |
| / |
Which of Apple's two gateways this environment's pushes go to. Type: string Allowed values: ["production","sandbox"] |
| / |
Type: ["object","null"] Required fields: ["project_id","service_account_secret_name"] Additional properties: false |
| / |
The Firebase project identifier. Type: string |
| / |
The custody NAME of the stored service-account JSON file at this environment scope; never a value. Type: string |
| / |
Type: string |
| / |
$ref: #/shapes/page |
Complete payload contract
{
"request": {
"type": "object",
"properties": {},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"export"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"export": {
"type": "object",
"required": [
"read_at",
"account",
"applications",
"realms",
"areas",
"custody",
"upstreams",
"tokens",
"push"
],
"properties": {
"read_at": {
"type": "string"
},
"account": {
"type": "object"
},
"applications": {
"type": "array",
"items": {
"type": "object",
"required": [
"id",
"name",
"label",
"created_at",
"plan",
"manifest",
"environments",
"state",
"version"
],
"properties": {
"id": {
"type": "string"
},
"name": {
"type": "string"
},
"label": {
"type": "string"
},
"created_at": {
"type": "string"
},
"plan": {
"type": "string"
},
"manifest": {
"type": [
"object",
"null"
]
},
"environments": {
"type": "array",
"items": {
"type": "string"
}
},
"state": {
"enum": [
"deployed",
"failed",
"never_deployed"
]
},
"version": {
"type": [
"integer",
"null"
]
}
}
}
},
"realms": {
"type": "array",
"items": {
"type": "object",
"required": [
"realm",
"sign_in_methods",
"creation",
"limits",
"invitation_days",
"session_days",
"devices"
],
"properties": {
"realm": {
"type": "string"
},
"sign_in_methods": {
"type": "array",
"items": {
"type": "string"
}
},
"creation": {
"enum": [
"open",
"invited"
]
},
"limits": {
"type": "object",
"required": [
"creation_ceiling",
"signin_starts_per_hour",
"code_sends_per_hour"
],
"properties": {
"creation_ceiling": {
"type": [
"integer",
"null"
]
},
"signin_starts_per_hour": {
"type": "integer"
},
"code_sends_per_hour": {
"type": "integer"
}
}
},
"invitation_days": {
"type": "integer"
},
"session_days": {
"type": "integer"
},
"entra": {
"type": "object",
"required": [
"tenant",
"client_id",
"client_secret_name"
],
"properties": {
"tenant": {
"type": "string"
},
"client_id": {
"type": "string"
},
"client_secret_name": {
"type": "string"
}
}
},
"apple": {
"type": "object",
"description": "The realm's Sign in with Apple route (the accounts service's work-account statement): the Services ID, the team and key identifiers, and the NAME of the signing key in the application's custody scope — never a value.",
"required": [
"services_id",
"team_id",
"key_id",
"key_secret_name"
],
"properties": {
"services_id": {
"type": "string"
},
"team_id": {
"type": "string"
},
"key_id": {
"type": "string"
},
"key_secret_name": {
"type": "string"
}
},
"additionalProperties": false
},
"session_cap_days": {
"type": "integer",
"minimum": 1,
"maximum": 730
},
"clients": {
"type": "array",
"maxItems": 10,
"description": "The declared native clients, each without any secret: a native client holds none.",
"items": {
"type": "object",
"required": [
"client_id",
"redirect_uris"
],
"properties": {
"client_id": {
"type": "string",
"description": "The client's identifier, which it presents at the authorization, token, and revocation endpoints; letters, digits, dots, underscores, colons, and hyphens."
},
"redirect_uris": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"items": {
"type": "string"
},
"description": "The redirect URIs the client presents, each matched exactly, a loopback URI's port excepted: a reverse-domain custom scheme such as `com.example.app:/callback`, an `https` URI on one of the application's own hostnames, or a loopback `http` URI on `localhost`, `[::1]`, or 127.0.0.0/8. Any other form is refused `invalid_redirect_uri`."
},
"ios": {
"type": "object",
"required": [
"bundle_id",
"team_id"
],
"properties": {
"bundle_id": {
"type": "string"
},
"team_id": {
"type": "string"
}
},
"additionalProperties": false,
"description": "Optional. The iOS app's bundle identifier and its ten-character team identifier, for the association files and the native ID-token exchange that later changes serve."
},
"android": {
"type": "object",
"required": [
"package",
"sha256_cert_fingerprints"
],
"properties": {
"package": {
"type": "string"
},
"sha256_cert_fingerprints": {
"type": "array",
"minItems": 1,
"maxItems": 10,
"items": {
"type": "string"
}
}
},
"additionalProperties": false,
"description": "Optional. The Android app's package name and its signing-certificate SHA-256 fingerprints, each 32 upper-case hex pairs separated by colons, for the asset links and the passkey origin that later changes serve."
},
"google_client_ids": {
"type": "array",
"maxItems": 10,
"items": {
"type": "string"
},
"description": "Optional. The Google client identifiers a Google ID token names as its audience, for the native ID-token exchange a later change serves."
},
"minimum_version": {
"type": "string",
"description": "Optional. The oldest app version the router admits, as `major.minor.patch`; a request stating a lower version is refused `client_upgrade_required`."
},
"update_url": {
"type": "string",
"description": "Optional. An `https` URL where a refused client is sent to update."
}
},
"additionalProperties": false
}
},
"devices": {
"type": "object",
"required": [
"ios",
"android",
"invalid"
],
"properties": {
"ios": {
"type": "integer"
},
"android": {
"type": "integer"
},
"invalid": {
"type": "integer"
}
},
"additionalProperties": false,
"description": "The realm's device registration counts by platform (PSH-L0-06); never a token or a user."
}
}
}
},
"areas": {
"type": "array",
"items": {
"type": "object",
"required": [
"name",
"account_keyed",
"version_keeping",
"application",
"created_at"
],
"properties": {
"name": {
"type": "string"
},
"account_keyed": {
"type": "boolean"
},
"version_keeping": {
"type": "boolean"
},
"application": {
"type": [
"string",
"null"
]
},
"created_at": {
"type": "string"
}
}
}
},
"custody": {
"type": "array",
"items": {
"type": "object",
"required": [
"name",
"scope",
"created_at"
],
"properties": {
"name": {
"type": "string"
},
"scope": {
"type": "string"
},
"created_at": {
"type": "string"
},
"rotated_at": {
"type": [
"string",
"null"
]
},
"application": {
"type": [
"string",
"null"
]
},
"environment": {
"type": [
"string",
"null"
],
"description": "The environment of the application scope that holds the value, `development` or `production`; null at the account scope (SCRT-L0-08)."
}
}
}
},
"upstreams": {
"type": "array",
"items": {
"type": "object",
"required": [
"name",
"base_url",
"credential_name",
"auth_header",
"auth_format",
"token_shape",
"application"
],
"properties": {
"name": {
"type": "string"
},
"base_url": {
"type": "string"
},
"credential_name": {
"type": "string"
},
"auth_header": {
"type": "string"
},
"auth_format": {
"type": "string"
},
"token_shape": {
"type": [
"string",
"null"
]
},
"application": {
"type": [
"string",
"null"
]
}
}
}
},
"tokens": {
"type": "array",
"items": {
"type": "object",
"required": [
"id",
"scope_kind",
"application",
"grants",
"label",
"created_at",
"expires_at",
"revoked_at",
"last_used_at"
],
"properties": {
"id": {
"type": "string"
},
"scope_kind": {
"enum": [
"account",
"application"
]
},
"application": {
"type": [
"string",
"null"
]
},
"grants": {
"type": "array",
"items": {
"type": "string"
}
},
"label": {
"type": [
"string",
"null"
]
},
"created_at": {
"type": "string"
},
"expires_at": {
"type": [
"string",
"null"
]
},
"revoked_at": {
"type": [
"string",
"null"
]
},
"last_used_at": {
"type": [
"string",
"null"
]
},
"space": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
"description": "The space the issues grant names; present on a token that carries the grant alone."
},
"level": {
"enum": [
"report",
"contribute",
"owner"
],
"description": "The level the issues grant reaches its space at: report, contribute, or owner; present on a token that carries the grant alone."
}
}
}
},
"feedback": {
"type": "object",
"description": "The account's own records at the issue service, read whole through the projection with the person named as the reading actor (ACB-L0-47): its own reports, each with its issue projected, the comments it wrote, its signals, and its asks. Present where the platform is configured with the service's origin, and absent otherwise; a read that fails refuses the export whole as issue_service_unreachable. Its `spaces` member carries the same four halves for each space the account owns, binds, or holds in custody for an application.",
"required": [
"issues",
"comments",
"signals",
"asks",
"spaces"
],
"properties": {
"issues": {
"type": "array",
"items": {
"type": "object"
}
},
"comments": {
"type": "array",
"items": {
"type": "object"
}
},
"signals": {
"type": "array",
"items": {
"type": "object"
}
},
"asks": {
"type": "array",
"items": {
"type": "object"
}
},
"spaces": {
"type": "array",
"description": "The account's own records in each issue space it owns, binds, or holds in custody for an application, one entry per space (ACB-L0-47): a space of the account's own, an application's own space, and each space of an application's per-environment pair. Each space is read under its own token through the projection, as the platform's space is read. A token that does not answer, or a space that could not be read, refuses the export whole as issue_service_unreachable.",
"items": {
"type": "object",
"required": [
"space",
"kind",
"application",
"environment",
"issues",
"comments",
"signals",
"asks"
],
"properties": {
"space": {
"type": "string",
"description": "The space's identifier, a lower-case UUID."
},
"kind": {
"type": "string",
"enum": [
"account",
"application"
],
"description": "`account` for a space of the account's own, `application` for an application's own space or one space of its per-environment pair."
},
"application": {
"type": [
"string",
"null"
],
"description": "The application whose space this is, null for a space of the account's own."
},
"environment": {
"type": [
"string",
"null"
],
"pattern": "^(development|production)$",
"description": "The environment one space of an application's per-environment pair serves, null for a space serving both."
},
"issues": {
"type": "array",
"items": {
"type": "object"
}
},
"comments": {
"type": "array",
"items": {
"type": "object"
}
},
"signals": {
"type": "array",
"items": {
"type": "object"
}
},
"asks": {
"type": "array",
"items": {
"type": "object"
}
}
}
}
}
}
},
"push": {
"type": "array",
"description": "Each environment's push configuration of each application: the providers' identifiers and secret NAMES, never a value (PSH-L0-06).",
"items": {
"type": "object",
"required": [
"application",
"environment",
"apns",
"fcm"
],
"properties": {
"application": {
"type": "string"
},
"environment": {
"type": "string",
"enum": [
"development",
"production"
]
},
"apns": {
"type": [
"object",
"null"
],
"required": [
"team_id",
"key_id",
"bundle_id",
"key_secret_name",
"environment"
],
"properties": {
"team_id": {
"type": "string",
"description": "The ten-character Apple team identifier."
},
"key_id": {
"type": "string",
"description": "The ten-character identifier of the APNs signing key."
},
"bundle_id": {
"type": "string",
"description": "The app's bundle identifier, the notification's topic."
},
"key_secret_name": {
"type": "string",
"description": "The custody NAME of the stored .p8 signing key at this environment scope; never a value."
},
"environment": {
"type": "string",
"enum": [
"production",
"sandbox"
],
"description": "Which of Apple's two gateways this environment's pushes go to."
}
},
"additionalProperties": false
},
"fcm": {
"type": [
"object",
"null"
],
"required": [
"project_id",
"service_account_secret_name"
],
"properties": {
"project_id": {
"type": "string",
"description": "The Firebase project identifier."
},
"service_account_secret_name": {
"type": "string",
"description": "The custody NAME of the stored service-account JSON file at this environment scope; never a value."
}
},
"additionalProperties": false
}
},
"additionalProperties": false
}
}
}
},
"detail": {
"type": "string"
},
"page": {
"$ref": "#/shapes/page"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md