Agent workflows
Scopes and MCP tools
See every agent tool and the scope required to call it.
Each key belongs to one site. The server checks the key’s scopes for every MCP or REST operation. The current contract defines 32 tools.
| Scope | Tools |
|---|---|
sites:read |
sites.get |
site:write |
sites.update, sites.theme.get, sites.theme.update, sites.theme.revert, sites.voice.update, sites.signup_form.update, tags.list |
analytics:read |
analytics.get |
posts:read |
posts.list, posts.search, posts.get, posts.get_by_slug, posts.versions.list, posts.versions.get, posts.format_guide, posts.preview |
posts:create |
posts.create |
posts:update |
posts.update, posts.preview.rotate, posts.unarchive, posts.versions.restore |
posts:publish |
posts.publish, posts.schedule, posts.unschedule |
posts:archive |
posts.archive |
assets:write |
assets.upload, assets.list, assets.get, assets.update |
assets:delete |
assets.delete |
activity:read |
activity.list |
Key levels in Connect
| Level | Granted scopes |
|---|---|
| Write drafts | sites:read, posts:read, posts:create, posts:update, assets:write, activity:read |
| Write and publish | Write drafts scopes plus posts:publish |
| Manage | Write and publish scopes plus posts:archive, site:write, analytics:read |
Manage can archive posts. None of these three levels grants assets:delete. The key’s scope controls whether a call is allowed; ask the person to approve the exact version and time before publishing or scheduling.
Never available to agents: billing, creating or deleting keys, permanently deleting archived posts, and deleting the blog or account.