read_synthetic_account_state

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_synthetic_account_state, with a bearer credential and the action's payload as the JSON body. It also accepts GET.

Contract description

Read a synthetic account's whole state in one call, by `account`, its id. Platform operator or its harness (the `synthetic_estate` grant or `super_admin`) only. It answers six parts, each in the exact shape its own tool answers and carrying no secret value. They are `account` as `read_account`, `applications` as `list_applications`, `status` as `read_status` for each application with every environment, `versions` as `list_versions` for each application, `tokens` as `list_tokens` with no token value, and `usage` as `read_usage`.

Use it to grade a trial's account from outside the trial machine, where the account's own credentials stay; where you hold the account's own token, call its own tools instead. Under `synthetic_estate` it reaches the batches the caller's credential seeded and every first sign-in's, refusing `account_outside_batches` for anything beyond them, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused `account_not_synthetic` and an id no account stands for `not_found`. The hosted trial's token is refused `grant_required`. Readable while the platform's synthetic-account mode is off; every read is an action record. The rest is on the page /cloud/reference/actions/read-synthetic-account-state/, which `read_documentation` reads as `page` and the platform's origin serves.

More about this action

Each part is the answer its own tool gives for the same account, read through the same code, so a reader of `read_account`, `list_applications`, `read_status`, `list_versions`, `list_tokens`, or `read_usage` reads the part unchanged. Each part carries `contract_version` as that tool's answer does; the call's `reference` stands at the top level alone.

The `account` part is the account's own facts without the four members a session's `read_account` adds, `address`, `grants`, `signed_in_at`, and `passkeys`, because the caller's credential is not the account's. The `status` part is one `read_status` answer per application, its top-level members production's and `environments` holding every environment, with no `tables` member and no `settled` or `waited_ms`, since the read waits for nothing. The `versions` part is one default `list_versions` page per application, newest first across both environments. The `tokens` part is the account's token rows with their identities, scopes, grants, labels, and stamps, and never a value or a hash. The `usage` part is the `read_usage` answer for every application of the account.

The `status` and `versions` parts are arrays in the order `applications` lists the applications, each entry naming its application. An account with no application answers empty arrays, and an empty `applications` list in `usage`.

Access and action metadata

{
  "name": "read_synthetic_account_state",
  "resource": "account",
  "tier": "observe",
  "grant": "synthetic_estate",
  "summary": "Read a synthetic account's state in one call, by `account`, its id: six parts, each in the shape its own row answers and carrying no secret value. They are the account record as `read_account` answers it, without the caller's credential members, the applications as `list_applications`, and each application's status with every environment as `read_status`, without `tables` and without a wait. They are its versions as `list_versions`, the tokens as `list_tokens`, never a value, a hash, or anything a token could be rebuilt from, and the usage as `read_usage`. Admitted for an account in the caller's reach under `synthetic_estate`, the batches its own credential seeded and every first-sign-in batch, refused 409 `account_outside_batches` otherwise, and for any synthetic account under `super_admin`. Under `synthetic_estate` any account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them, the reach read ahead of the not-synthetic check. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`. Readable with the `SYNTHETIC_ESTATE` mode `off`.",
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "read_synthetic_account_state",
  "tier": "observe",
  "scenario": "API-L0-12",
  "summary": "Read a synthetic account's whole state in one call, by `account`, its id. Platform operator or its harness (the `synthetic_estate` grant or `super_admin`) only. It answers six parts, each in the exact shape its own tool answers and carrying no secret value. They are `account` as `read_account`, `applications` as `list_applications`, `status` as `read_status` for each application with every environment, `versions` as `list_versions` for each application, `tokens` as `list_tokens` with no token value, and `usage` as `read_usage`.\n\nUse it to grade a trial's account from outside the trial machine, where the account's own credentials stay; where you hold the account's own token, call its own tools instead. Under `synthetic_estate` it reaches the batches the caller's credential seeded and every first sign-in's, refusing `account_outside_batches` for anything beyond them, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused `account_not_synthetic` and an id no account stands for `not_found`. The hosted trial's token is refused `grant_required`. Readable while the platform's synthetic-account mode is off; every read is an action record. The rest is on the page /cloud/reference/actions/read-synthetic-account-state/, which `read_documentation` reads as `page` and the platform's origin serves.",
  "owners": [
    "MAPI-16"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["account"]
Additional properties: false
/properties/account The synthetic account whose state is read, by its id, as seed_synthetic_accounts or read_synthetic_signin_code answered it. Under `synthetic_estate` an account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`.

Type: string

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","account","applications","status","versions","tokens","usage"]
/properties/contract_version Required value: 1
/properties/reference The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call.

Type: string
Pattern: ^[0-9a-f]{10}$
/properties/account The account record as `read_account` answers it, without the caller's credential members, since the caller's credential is not the account's.

$ref: #/shapes/read_account
/properties/applications The applications as `list_applications` answers them.

$ref: #/shapes/list_applications
/properties/status One `read_status` answer per application, in the order `applications` lists them: its top-level members production's and `environments` holding every environment, with no `tables` member and no wait members.

Type: array
/properties/status/items $ref: #/shapes/read_status
/properties/versions One default `list_versions` page per application, in the order `applications` lists them.

Type: array
/properties/versions/items $ref: #/shapes/list_versions
/properties/tokens The account's tokens as `list_tokens` answers them: identities, scopes, grants, labels, and stamps, never a value, a hash, or anything a token could be rebuilt from.

$ref: #/shapes/list_tokens
/properties/usage The usage as `read_usage` answers it for every application of the account.

$ref: #/shapes/read_usage
/properties/detail What the six parts are and the row each takes its shape from.

Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "account"
    ],
    "properties": {
      "account": {
        "type": "string",
        "description": "The synthetic account whose state is read, by its id, as seed_synthetic_accounts or read_synthetic_signin_code answered it. Under `synthetic_estate` an account outside the caller's reach is refused 409 `account_outside_batches`, a standing customer account and an id no account stands for among them. Under `super_admin` a standing account that is not synthetic is refused 409 `account_not_synthetic` and an id no account stands for 404 `not_found`."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "account",
      "applications",
      "status",
      "versions",
      "tokens",
      "usage"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "reference": {
        "type": "string",
        "pattern": "^[0-9a-f]{10}$",
        "description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
      },
      "account": {
        "description": "The account record as `read_account` answers it, without the caller's credential members, since the caller's credential is not the account's.",
        "$ref": "#/shapes/read_account"
      },
      "applications": {
        "description": "The applications as `list_applications` answers them.",
        "$ref": "#/shapes/list_applications"
      },
      "status": {
        "type": "array",
        "description": "One `read_status` answer per application, in the order `applications` lists them: its top-level members production's and `environments` holding every environment, with no `tables` member and no wait members.",
        "items": {
          "$ref": "#/shapes/read_status"
        }
      },
      "versions": {
        "type": "array",
        "description": "One default `list_versions` page per application, in the order `applications` lists them.",
        "items": {
          "$ref": "#/shapes/list_versions"
        }
      },
      "tokens": {
        "description": "The account's tokens as `list_tokens` answers them: identities, scopes, grants, labels, and stamps, never a value, a hash, or anything a token could be rebuilt from.",
        "$ref": "#/shapes/list_tokens"
      },
      "usage": {
        "description": "The usage as `read_usage` answers it for every application of the account.",
        "$ref": "#/shapes/read_usage"
      },
      "detail": {
        "type": "string",
        "description": "What the six parts are and the row each takes its shape from."
      }
    }
  }
}

Shared contracts