read_synthetic_account_state
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_synthetic_account_state, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
Read a synthetic account's whole state in one call, by `account`, its id. Platform operator or its harness (the `synthetic_estate` grant or `super_admin`) only. It answers six parts, each in the exact shape its own tool answers and carrying no secret value. They are `account` as `read_account`, `applications` as `list_applications`, `status` as `read_status` for each application with every environment, `versions` as `list_versions` for each application, `tokens` as `list_tokens` with no token value, and `usage` as `read_usage`.
Use it to grade a trial's account from outside the trial machine, where the account's own credentials stay; where you hold the account's own token, call its own tools instead. Under `synthetic_estate` it reaches the batches the caller's credential seeded and every first sign-in's, refusing `account_outside_batches` for anything beyond them, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused `account_not_synthetic` and an id no account stands for `not_found`. The hosted trial's token is refused `grant_required`. Readable while the platform's synthetic-account mode is off; every read is an action record. The rest is on the page /cloud/reference/actions/read-synthetic-account-state/, which `read_documentation` reads as `page` and the platform's origin serves.
More about this action
Each part is the answer its own tool gives for the same account, read through the same code, so a reader of `read_account`, `list_applications`, `read_status`, `list_versions`, `list_tokens`, or `read_usage` reads the part unchanged. Each part carries `contract_version` as that tool's answer does; the call's `reference` stands at the top level alone.
The `account` part is the account's own facts without the four members a session's `read_account` adds, `address`, `grants`, `signed_in_at`, and `passkeys`, because the caller's credential is not the account's. The `status` part is one `read_status` answer per application, its top-level members production's and `environments` holding every environment, with no `tables` member and no `settled` or `waited_ms`, since the read waits for nothing. The `versions` part is one default `list_versions` page per application, newest first across both environments. The `tokens` part is the account's token rows with their identities, scopes, grants, labels, and stamps, and never a value or a hash. The `usage` part is the `read_usage` answer for every application of the account.
The `status` and `versions` parts are arrays in the order `applications` lists the applications, each entry naming its application. An account with no application answers empty arrays, and an empty `applications` list in `usage`.
Access and action metadata
{
"name": "read_synthetic_account_state",
"resource": "account",
"tier": "observe",
"grant": "synthetic_estate",
"summary": "Read a synthetic account's state in one call, by `account`, its id: six parts, each in the shape its own row answers and carrying no secret value. They are the account record as `read_account` answers it, without the caller's credential members, the applications as `list_applications`, and each application's status with every environment as `read_status`, without `tables` and without a wait. They are its versions as `list_versions`, the tokens as `list_tokens`, never a value, a hash, or anything a token could be rebuilt from, and the usage as `read_usage`. Admitted for an account in the caller's reach under `synthetic_estate`, the batches its own credential seeded and every first-sign-in batch, refused 409 `account_outside_batches` otherwise, and for any synthetic account under `super_admin`. Under `synthetic_estate` any account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them, the reach read ahead of the not-synthetic check. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`. Readable with the `SYNTHETIC_ESTATE` mode `off`.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "read_synthetic_account_state",
"tier": "observe",
"scenario": "API-L0-12",
"summary": "Read a synthetic account's whole state in one call, by `account`, its id. Platform operator or its harness (the `synthetic_estate` grant or `super_admin`) only. It answers six parts, each in the exact shape its own tool answers and carrying no secret value. They are `account` as `read_account`, `applications` as `list_applications`, `status` as `read_status` for each application with every environment, `versions` as `list_versions` for each application, `tokens` as `list_tokens` with no token value, and `usage` as `read_usage`.\n\nUse it to grade a trial's account from outside the trial machine, where the account's own credentials stay; where you hold the account's own token, call its own tools instead. Under `synthetic_estate` it reaches the batches the caller's credential seeded and every first sign-in's, refusing `account_outside_batches` for anything beyond them, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused `account_not_synthetic` and an id no account stands for `not_found`. The hosted trial's token is refused `grant_required`. Readable while the platform's synthetic-account mode is off; every read is an action record. The rest is on the page /cloud/reference/actions/read-synthetic-account-state/, which `read_documentation` reads as `page` and the platform's origin serves.",
"owners": [
"MAPI-16"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["account"] Additional properties: false |
| / |
The synthetic account whose state is read, by its id, as seed_synthetic_accounts or read_synthetic_signin_code answered it. Under `synthetic_estate` an account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`. Type: string |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","account","applications","status","versions","tokens","usage"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
The account record as `read_account` answers it, without the caller's credential members, since the caller's credential is not the account's. $ref: #/shapes/read_account |
| / |
The applications as `list_applications` answers them. $ref: #/shapes/list_applications |
| / |
One `read_status` answer per application, in the order `applications` lists them: its top-level members production's and `environments` holding every environment, with no `tables` member and no wait members. Type: array |
| / |
$ref: #/shapes/read_status |
| / |
One default `list_versions` page per application, in the order `applications` lists them. Type: array |
| / |
$ref: #/shapes/list_versions |
| / |
The account's tokens as `list_tokens` answers them: identities, scopes, grants, labels, and stamps, never a value, a hash, or anything a token could be rebuilt from. $ref: #/shapes/list_tokens |
| / |
The usage as `read_usage` answers it for every application of the account. $ref: #/shapes/read_usage |
| / |
What the six parts are and the row each takes its shape from. Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"account"
],
"properties": {
"account": {
"type": "string",
"description": "The synthetic account whose state is read, by its id, as seed_synthetic_accounts or read_synthetic_signin_code answered it. Under `synthetic_estate` an account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"account",
"applications",
"status",
"versions",
"tokens",
"usage"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"account": {
"description": "The account record as `read_account` answers it, without the caller's credential members, since the caller's credential is not the account's.",
"$ref": "#/shapes/read_account"
},
"applications": {
"description": "The applications as `list_applications` answers them.",
"$ref": "#/shapes/list_applications"
},
"status": {
"type": "array",
"description": "One `read_status` answer per application, in the order `applications` lists them: its top-level members production's and `environments` holding every environment, with no `tables` member and no wait members.",
"items": {
"$ref": "#/shapes/read_status"
}
},
"versions": {
"type": "array",
"description": "One default `list_versions` page per application, in the order `applications` lists them.",
"items": {
"$ref": "#/shapes/list_versions"
}
},
"tokens": {
"description": "The account's tokens as `list_tokens` answers them: identities, scopes, grants, labels, and stamps, never a value, a hash, or anything a token could be rebuilt from.",
"$ref": "#/shapes/list_tokens"
},
"usage": {
"description": "The usage as `read_usage` answers it for every application of the account.",
"$ref": "#/shapes/read_usage"
},
"detail": {
"type": "string",
"description": "What the six parts are and the row each takes its shape from."
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md