Capability catalog
3,145 typed capabilities across 79 domains — each one a workflow with a validated schema, callable from the console, the API or an agent over MCP. The list comes straight from the public catalog and refreshes each time the site is published.
A sample of 222 capabilities, 3,145 in the full catalog
abacatepay.catalog.ensure-product
AbacatePayDAGIdempotently ensure a product exists for an externalId.
abacatepay.charge.hosted
AbacatePayDAGEnsure customer/products then create a hosted checkout (optional await).
abacatepay.charge.pix-embedded
AbacatePayDAGCreate embedded PIX transparent charge and await payment.
agents.agent-config.clone
AgentsActionClone an existing agent configuration
agents.agent-config.create
AgentsActionCreate a new agent configuration
agents.agent-config.delete
AgentsActionSoft-delete an agent configuration
ai-provider.delete
AI providersActionPermanently deletes an AI provider configuration. Refuses to delete an enabled config — disable it first (the DB guarantees the org default is always enabled, so the default is transitively protected). Built for cleaning up configs orphaned by connection soft-delete.
ai-provider.disable
AI providersActionDisables an AI provider configuration (sets enabled=False). Refuses to disable the last enabled default — caller must promote another config first. Idempotent: already-disabled configs complete with disabled=False and no DB mutation.
ai-provider.enable
AI providersActionEnables an AI provider configuration (sets enabled=True). Refuses to enable a config whose cloud connection is missing or soft-deleted (orphaned config). Idempotent: already-enabled configs complete with enabled=False and no DB mutation. Counterpart of ai-provider.disable.
ai.chat
AIActionSend a chat completion via the org's AI CloudConnection (provider-agnostic)
ai.chat.complete
AIActionOpenAI-compatible chat completion (any provider), with optional provider web search and citations
appdata.backup.create
App DataQueryBack up the app's own Postgres instance to encrypted blob storage (customer tier, billed as storage)
appdata.backup.list
App DataQueryread-onlyList an app's encrypted backups: tier, status, stored size, checksum, expiry
appdata.backup.policy.get
App DataQueryread-onlyRead an app's customer backup policy and when it next and last ran
apphost.addon.apply
App HostDAGEnsure Nostr Buzz (WebSocket relay + Redis + MinIO) on a claimed AppHost site: Redis, MinIO, and relay are created if missing and updated on re-apply. Re-apply keeps the live RELAY_URL host: that hostname is the Buzz community, and changing it would seed an empty one. Destroy is apphost.addon.remove, not apply. This is not native Chat Relay, not Orkestia AppData conversations, and not DPWAI Chat Relay REST/SSE. Postgres is the site's AppData instance (not Neon, not in-cluster). Forces the Machine always-on. Does not steal the CloudFront site host.
apphost.addon.logs
App HostDAGRead the last lines of the Buzz relay pod on a claimed AppHost site. One-shot tail, not a stream.
apphost.addon.media.contract
App HostDAGSupported upload/download path for Buzz attachments on a claimed site: durable MinIO PVC, Buzz /media with NIP-42, not shared document workflows. No kubeconfig. No secrets.
approval.request.collect-and-expire
ApprovalDAGCreate an approval request, notify approvers, collect decision events, and expire the request when timeout elapses.
aria.provision
AriaActionCreate a draft hosted MCP service owned by the calling organization.
aria.publish
AriaActionValidate a hosted service's draft and publish it as an immutable revision.
aria.resume
AriaActionResume a suspended service on the revision it was serving.
audit.audit-run.archive
AuditQueryArchive an audit scan run using the soft-delete lifecycle.
audit.audit-run.delete
AuditQuerySoft-delete an audit scan run.
audit.audit-run.get
AuditQueryread-onlyGet one audit scan run for an organization.
aws.acm.add_tags_to_certificate
AWSActionCall AWS ACM AddTagsToCertificate using a CloudConnection UUID.
aws.acm.delete_certificate
AWSActionCall AWS ACM DeleteCertificate using a CloudConnection UUID.
aws.acm.describe_certificate
AWSActionread-onlyCall AWS ACM DescribeCertificate using a CloudConnection UUID.
azure.acr.cache_rule.delete
AzureActionDelete an ACR cache rule.
azure.acr.cache_rule.get
AzureActionRead an ACR cache rule.
azure.acr.cache_rule.upsert
AzureActionCreate or update an ACR cache rule (pull-through mirror of an upstream repository).
bling.cancel-nfse
BlingActionCancel an authorized NFS-e at Bling and reflect the cancellation on the commerce_entity row. Requires a justification.
bling.create-journal-entry
BlingActionDirect creation of a Bling lançamento. Caller supplies the Bling-side linked_receivable_external_ref or linked_payable_external_ref + amount; this workflow POSTs to /contas/{kind}/{id}/lancamentos and persists the result into commerce_entity.
bling.create-payable
BlingActionCreate a new accounts-payable row at Bling (POST /contas/pagar). Persists the result into commerce_entity (entity_type='payable').
bunnycdn.auth.validate_token
BunnyCDNActionread-onlyValidate a Bunny CDN API key
buzz.actor.attach
buzzActionPut a Staff actor into an app chat. The actor must already hold a paid end-user seat in the app (identity.end-user.bind-actor). It gets a server-held relay key, joins the listed channels as bot, and answers mentions, DMs, or every message in its channels. Its stored definition must act as the space's app (on_invoke.input_data.act_as_identity_app_uuid), unless the attachment replies as the organization (reply_principal organization: org admins only, allowlisted orgs and authors)
buzz.actor.dm-open
buzzActionOpen (or reuse) a direct-message channel between an attached actor and 1-8 members of the space, signed by the actor's key. Returns the DM channel id to post into. Same callers as buzz.message.post
buzz.actor.notify
buzzActionSend a chat message as yourself, the attached Staff actor, from outside the chat (a schedule, an event, another workflow). target is '#channel', a channel name, a person's display name ('@name') or a member id: a person gets a direct message (opened if needed), a channel gets a post. Optional mention names one member. Ambiguous or unknown names fail listing candidates. Humans and the system pass as_actor_uuid
chat.conversation.create
ChatActionCreate a new chat conversation owned by a member or an app end-user
chat.conversation.send-message
ChatDAGAppend a user turn to a chat conversation and return the assistant reply
chat.engine.find-similar-failures
ChatActionread-onlyLook up previously-resolved Lumen error groups similar to a query error message so the agent can reuse prior root_cause/solution knowledge instead of re-investigating from scratch.
checkout.analytics.summary
Agentic CheckoutQueryread-onlySummarise a catalog's last N days: orders by status, revenue and average ticket from paid orders, items sold, a per-day series and the top products.
checkout.cart.add-item
Agentic CheckoutActionAdd quantity of a product to the shopper's open cart, creating the cart if needed. Same product + same options merges into one line.
checkout.cart.get
Agentic CheckoutQueryread-onlyRead a shopper's open cart with lines and totals. Never creates one.
cloudflare.auth.validate_token
CloudflareActionread-onlyValidate a Cloudflare API token
cloudflare.cache.purge
CloudflareActionPurge Cloudflare CDN cache for specific URLs or entire zone
cloudflare.dns.delete_record
CloudflareActionDelete a Cloudflare DNS record by record ID
cluster.aws-vm.collect-kubeconfig
ClustersActionCollect Kubernetes kubeconfig from an AWS VM through SSM Run Command.
cluster.azure-vm.collect-kubeconfig
ClustersActionCollect the admin kubeconfig produced by a Azure VM Kubernetes bootstrap process.
cluster.bootstrap-orkestia-access
ClustersActionEnsure standard namespace, service account, RBAC binding, and optional manifests for Orkestia access.
composition.activate
CompositionQueryRe-validate a composition against the live registry and set it active
composition.archive
CompositionQueryArchive a composition (no longer startable)
composition.delete-archived
CompositionQuerySoft-delete archived compositions for an organization
connection.deere.sync-assets
ConnectionsActionRefresh John Deere Operations Center organizations for a connection via GET /organizations using the stored OAuth access token
connection.disconnect
ConnectionsActionDisconnects a cloud provider connection: scrubs its secrets and soft-deletes the CloudConnection record
connection.get
ConnectionsActionread-onlyGet a single cloud connection by UUID
control.collection.distinct
Control flowActionread-onlyDrop duplicate elements (optionally by a field), preserving order
control.collection.filter
Control flowActionread-onlyKeep the list elements matching one comparison predicate
control.collection.flatten
Control flowActionread-onlyFlatten nested lists up to a given depth (-1 = fully flat)
data.agents.budget-status
DataActionread-onlyReport budget utilisation for an organisation for a given period
data.agents.cost-by-config
DataActionread-onlyAggregate agent cost by config for an org, optionally filtered by date range
data.agents.cost-by-model
DataActionread-onlyAggregate agent LLM cost and token usage by model for an org
deploy.backend.immediate
DeployActionProvision backend container capacity immediately
deploy.cloudrun.rollback
DeployDAGRestore Cloud Run traffic to a previously stable revision.
deploy.cloudrun.rollout-canary
DeployActionRoll out a Cloud Run revision through staged traffic percentages with rollback support.
dgi.action.query-connections
DGIActionread-onlyQuery active connections (read-only; scoped to organization)
dgi.action.show-dag
DGIActionread-onlyExtract and return DAG structure
dgi.action.think
DGIActionCall the org's LLM for a one-shot reasoning turn (via ai.chat)
docusign.archive-completed-envelope
DocuSignDAGVerify a DocuSign envelope is completed, then stream its signed PDF and certificate of completion into the customer bucket as audit-tracked objects (verify → presign → download)
docusign.create-envelope
DocuSignActionCreate a DocuSign envelope from documents fetched by presigned URL — draft by default, sent with send=true
docusign.create-envelope-from-template
DocuSignActionCreate a DocuSign envelope from a server template with role assignments — draft by default, sent with send=true
exchange.buyer-policy.set
exchangeActionSet the organization's buyer policy for the Agent Exchange.
exchange.deal.cancel
exchangeActionCancel an open Agent Exchange deal. Settled one_shot deals cannot be cancelled here (refunds arrive from the PSP). Settled subscriptions revoke the lease without calling a live PSP.
exchange.deal.start
exchangeDAGStart an Agent Exchange deal. Same-org hires settle on rail=internal with no provider objects. Hosted checkout on live PSP rails is deferred.
failguard.clone_repo
FailGuardActionClone repo for FailGuard indexing (DAG step)
failguard.create_data_source
FailGuardActionCreate Bedrock Data Source for FailGuard project (DAG step)
failguard.create_kb
FailGuardActionCreate Bedrock KB for FailGuard project (DAG step)
firecrawl.billing.get-credit-usage
FirecrawlActionGet remaining credits for the authenticated team
firecrawl.billing.get-token-usage
FirecrawlActionGet remaining tokens for the authenticated team (Extract only)
firecrawl.crawling.cancel-crawl
FirecrawlActionCancel a crawl job
gcp.artifactregistry.image.delete
Google CloudActionDelete an Artifact Registry package (image) and all versions; idempotent when already absent.
gcp.artifactregistry.remote_repository.describe
Google CloudActionread-onlyDescribe a GCP Artifact Registry remote repository
gcp.artifactregistry.repository.delete
Google CloudActionDelete an Artifact Registry repository; idempotent when already absent.
git.remote-binding.activate
GitActionActivate one immutable trusted Git-remote binding.
git.remote-binding.create
GitActionCreate an immutable repository-to-trusted-broker binding version without storing a remote URL or credential.
git.remote-binding.get
GitQueryread-onlyGet an organization-scoped trusted Git-remote binding.
github.actions.get_job_log_tail
GitHubActionRead bounded metadata and tail logs for one GitHub Actions job.
github.actions.trigger_workflow
GitHubActionTrigger a GitHub Actions workflow_dispatch run through an installed GitHub App connection.
github.auth.validate_installation
GitHubActionGenerate a GitHub App installation access token
gitops.application.create
GitOpsActionBind a GitHub repo path to a Kubernetes cluster and start GitOps sync
gitops.application.delete
GitOpsActionSoft-delete a GitOpsApplication and stop its controller (optional cascade prune)
gitops.application.pause
GitOpsActionPause reconciliation for a GitOpsApplication
google.ads.campaign.create-paused
GoogleActionScaffold: create a paused Google Ads campaign draft. Always returns status=PAUSED / enabled=false. Never sets ACTIVE (SOCIAL-004). No live API yet.
google.ads.campaign.request-review
GoogleActionCreate a Staff ActorOutboxEnvelope for Google Ads spend enable (SOCIAL-004 hard inbox gate).
google.ads.creative.attach
GoogleActionScaffold: accept a StorageObject UUID for Google Ads creative attach. Does not upload or enable spend. No live Google Ads API yet.
hook.acknowledge-event
HookActionAcknowledge webhook event delivery from DevKit to local target
hook.create-redirect
HookActionCreate new webhook redirect with signed UUID
hook.delete-redirect
HookActionSoft delete webhook redirect and cleanup pending events
identity.api-token.create
IdentityActionGenerate a new API token for the current user
identity.api-token.query
IdentityActionread-onlyList API tokens for the current user
identity.api-token.revoke
IdentityActionRevoke (hard-delete) an API token for the current user
ifood.connection.begin-authorization
iFoodActionStart a merchant's authorization of the registered iFood application
ifood.connection.complete-authorization
iFoodActionExchange a merchant's authorization code for a durable iFood grant
ifood.connection.validate
iFoodQueryread-onlyValidate iFood authentication and merchant visibility
k8s.app.deploy
K8s (manifests)DAGDeploy a containerised app: Namespace + ConfigMap + Secret + Deployment + Service, with optional PVC / HPA / PDB / Ingress
k8s.app.set-image
K8s (manifests)DAGPatch a Deployment's container image and wait for rollout to be Available. Helm-safe — only touches the image field.
k8s.app.teardown
K8s (manifests)DAGTear down a containerised app: Ingress/HPA/PDB + Service + Deployment + ConfigMap + Secret; PVCs only when delete_pvcs=true
kubernetes.cluster.api_resources
KubernetesActionread-onlyList all API resources advertised by the cluster (kubectl api-resources equivalent)
kubernetes.cluster.version
KubernetesActionread-onlyRead Kubernetes API server version.
kubernetes.clusterrole.delete
KubernetesActionDelete a ClusterRole (cluster-scoped, rbac.authorization.k8s.io/v1)
kv.bind-env
KVActionResolve KV keys into runtime secret_env / Pages secrets (references only)
kv.key.resolve
KVActionread-onlyResolve an Orkestia KV key to a reference (value only on explicit reveal)
kv.key.set
KVActionWrite one Orkestia KV key as a new version via LTIP (value redacted)
linkedin.ads.campaign.create-paused
LinkedInActionScaffold: record a paused LinkedIn Ads campaign draft. Never sets ACTIVE or spends (SOCIAL-004). No live Campaign Manager write yet.
linkedin.ads.campaign.request-review
LinkedInActionCreate a Staff ActorOutboxEnvelope for LinkedIn Ads spend enable (SOCIAL-004 hard inbox gate).
linkedin.ads.conversion.campaign.associate
LinkedInActionAssociate a sponsored campaign with a Conversions API rule (PUT /rest/campaignConversions). Required before event attribution.
lovable.project.bootstrap-auth
LovableDAGProvision Sign in with Orkestia for a Lovable project
lovable.project.go-live
LovableDAGBuild a Lovable project's synced repo and deploy it to production
lovable.project.wire-payments
LovableDAGCreate the payment webhook that grants a Lovable app's end-users access
lumen.alert-rule.create
LumenActionCreates a Lumen alert rule that dispatches webhook, Slack, or email notifications — or opens a native Orkestia incident ticket (channel=ticket) — when fingerprint_log detects a new_group, regressed, or threshold event.
lumen.alert-rule.delete
LumenActionPermanently delete a Lumen alert rule by its public UUID.
Source: public catalog at workflow-api.orkestia.dev — updated on every deploy
