undeclare_upstream
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/undeclare_upstream, with a bearer credential and the action's payload as the JSON body.
Contract description
End one upstream by name, whether `declare_upstream` or the manifest's `upstreams` member declared it. It frees the name and ends the upstream's egress keys in both environments; a failed call ends nothing. The proxy then refuses its calls from any running copy once its short cache interval passes. The answer names the environments whose deployed copies lost a key, and those whose serving version or deploy in flight was given the upstream's `settings`. The stored key stays in custody, and `delete_secret` can then delete it where nothing else names it. Submitting a manifest never ends an upstream. An upstream the application's manifest names in `upstreams` is refused `manifest_owned_field`: remove the entry, submit the manifest, and promote the version that no longer calls the upstream, then call this tool. An undeclared name answers unchanged. To bring it back, call `declare_upstream` again, then deploy or promote each environment.
Access and action metadata
{
"name": "undeclare_upstream",
"resource": "upstream",
"tier": "reversible",
"summary": "End one upstream declaration by name: the declaration is removed and the name freed, and the upstream's egress keys end in both environments; a call that fails ends nothing. The gateways then refuse its calls from any running copy once their short cache interval passes. The stored key stays in custody, and delete_secret is then admitted where nothing else names it. An upstream the bound application's manifest names in `upstreams` is refused `manifest_owned_field`: remove the entry, submit the manifest, and promote the version that no longer calls the upstream first. No submission ends an upstream. An absent name answers unchanged.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "undeclare_upstream",
"tier": "reversible",
"scenario": "EGW-L0-09",
"summary": "End one upstream by name, whether `declare_upstream` or the manifest's `upstreams` member declared it. It frees the name and ends the upstream's egress keys in both environments; a failed call ends nothing. The proxy then refuses its calls from any running copy once its short cache interval passes. The answer names the environments whose deployed copies lost a key, and those whose serving version or deploy in flight was given the upstream's `settings`. The stored key stays in custody, and `delete_secret` can then delete it where nothing else names it. Submitting a manifest never ends an upstream. An upstream the application's manifest names in `upstreams` is refused `manifest_owned_field`: remove the entry, submit the manifest, and promote the version that no longer calls the upstream, then call this tool. An undeclared name answers unchanged. To bring it back, call `declare_upstream` again, then deploy or promote each environment.",
"owners": [
"EGW-L0-01",
"EGW-L0-02",
"SEC-L0-18"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["name"] |
| / |
The name of the upstream to end, as `list_upstreams` names it. An upstream the bound application's manifest names in `upstreams` is refused `manifest_owned_field` until the entry is removed and the manifest submitted. Afterwards the name is free, and a later declaration under it is a new upstream. Type: string Pattern: ^[a-zA-Z0-9][a-zA-Z0-9_-]{0,63}$ |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","upstream","outcome"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
The declaration removed, as it stood; null where no upstream by the name was declared. Type: ["object","null"] |
| / |
`removed` where the declaration was removed and the name freed; `unchanged` where no upstream by the name was declared, so a second call answers the same state. Type: string Pattern: ^(removed|unchanged)$ |
| / |
Present where the declaration was removed: the count of the upstream's egress keys ended, in both environments, zero where no deployed copy held one. A deployed copy that held one has no working key for the upstream, and the detail names its environment. Type: integer Minimum: 0 |
| / |
Type: string |
| / |
$ref: #/shapes/page |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"name"
],
"properties": {
"name": {
"type": "string",
"pattern": "^[a-zA-Z0-9][a-zA-Z0-9_-]{0,63}$",
"description": "The name of the upstream to end, as `list_upstreams` names it. An upstream the bound application's manifest names in `upstreams` is refused `manifest_owned_field` until the entry is removed and the manifest submitted. Afterwards the name is free, and a later declaration under it is a new upstream."
}
}
},
"response": {
"type": "object",
"required": [
"contract_version",
"upstream",
"outcome"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"upstream": {
"type": [
"object",
"null"
],
"description": "The declaration removed, as it stood; null where no upstream by the name was declared."
},
"outcome": {
"type": "string",
"pattern": "^(removed|unchanged)$",
"description": "`removed` where the declaration was removed and the name freed; `unchanged` where no upstream by the name was declared, so a second call answers the same state."
},
"egress_keys_ended": {
"type": "integer",
"minimum": 0,
"description": "Present where the declaration was removed: the count of the upstream's egress keys ended, in both environments, zero where no deployed copy held one. A deployed copy that held one has no working key for the upstream, and the detail names its environment."
},
"detail": {
"type": "string"
},
"page": {
"$ref": "#/shapes/page"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md