Catálogo de capacidades
3.227 capacidades tipadas en 83 dominios — cada una es un workflow con un schema validado, que llamas desde la consola, la API o un agente por MCP. La lista sale directo del catálogo público y se actualiza cada vez que se publica el sitio.
Una muestra de 233 capacidades, 3.227 en el catálogo completo
abacatepay.catalog.ensure-product
AbacatePayDAGIdempotently ensure a product exists for an externalId.
abacatepay.charge.hosted
AbacatePayDAGEnsure customer/products then create a hosted checkout (optional await).
abacatepay.charge.pix-embedded
AbacatePayDAGCreate embedded PIX transparent charge and await payment.
agents.agent-config.clone
AgentsAcciónClone an existing agent configuration
agents.agent-config.create
AgentsAcciónCreate a new agent configuration
agents.agent-config.delete
AgentsAcciónSoft-delete an agent configuration
ai-provider.delete
Proveedores de IAAcciónPermanently deletes an AI provider configuration. Refuses to delete an enabled config — disable it first (the DB guarantees the org default is always enabled, so the default is transitively protected). Built for cleaning up configs orphaned by connection soft-delete.
ai-provider.disable
Proveedores de IAAcciónDisables an AI provider configuration (sets enabled=False). Refuses to disable the last enabled default — caller must promote another config first. Idempotent: already-disabled configs complete with disabled=False and no DB mutation.
ai-provider.enable
Proveedores de IAAcciónEnables an AI provider configuration (sets enabled=True). Refuses to enable a config whose cloud connection is missing or soft-deleted (orphaned config). Idempotent: already-enabled configs complete with enabled=False and no DB mutation. Counterpart of ai-provider.disable.
ai.chat
IAAcciónSend a chat completion via the org's AI CloudConnection (provider-agnostic)
ai.chat.complete
IAAcciónOpenAI-compatible chat completion (any provider), with optional provider web search and citations
appdata.backup.create
App DataConsultaBack up the app's own Postgres instance to encrypted blob storage (customer tier, billed as storage)
appdata.backup.list
App DataConsultasolo lecturaList an app's encrypted backups (its Postgres instance and its Buzz relay media): workload kind, tier, status, stored size, checksum, expiry
appdata.backup.policy.get
App DataConsultasolo lecturaRead an app's customer backup policy and when it next and last ran
apphost.addon.apply
App HostDAGEnsure Nostr Buzz (WebSocket relay + Redis + MinIO) on a claimed AppHost site: Redis, MinIO, and relay are created if missing and updated on re-apply. Re-apply keeps the live RELAY_URL host: that hostname is the Buzz community, and changing it would seed an empty one. Destroy is apphost.addon.remove, not apply. This is not native Chat Relay, not Orkestia AppData conversations, and not DPWAI Chat Relay REST/SSE. Postgres is the site's AppData instance (not Neon, not in-cluster). Forces the Machine always-on. Does not steal the CloudFront site host.
apphost.addon.logs
App HostDAGRead the last lines of the Buzz relay pod on a claimed AppHost site. One-shot tail, not a stream.
apphost.addon.media.contract
App HostDAGSupported upload/download path for Buzz attachments on a claimed site: durable MinIO PVC, Buzz /media with NIP-42, not shared document workflows. No kubeconfig. No secrets.
approval.request.collect-and-expire
AprobaciónDAGCreate an approval request, notify approvers, collect decision events, and expire the request when timeout elapses.
aria.provision
AriaAcciónCreate a draft hosted MCP service owned by the calling organization.
aria.publish
AriaAcciónValidate a hosted service's draft and publish it as an immutable revision.
aria.resume
AriaAcciónResume a suspended service on the revision it was serving.
audit.audit-run.archive
AuditoríaConsultaArchive an audit scan run using the soft-delete lifecycle.
audit.audit-run.delete
AuditoríaConsultaSoft-delete an audit scan run.
audit.audit-run.get
AuditoríaConsultasolo lecturaGet one audit scan run for an organization.
aws.acm.add_tags_to_certificate
AWSAcciónCall AWS ACM AddTagsToCertificate using a CloudConnection UUID.
aws.acm.delete_certificate
AWSAcciónCall AWS ACM DeleteCertificate using a CloudConnection UUID.
aws.acm.describe_certificate
AWSAcciónsolo lecturaCall AWS ACM DescribeCertificate using a CloudConnection UUID.
azure.acr.cache_rule.delete
AzureAcciónDelete an ACR cache rule.
azure.acr.cache_rule.get
AzureAcciónRead an ACR cache rule.
azure.acr.cache_rule.upsert
AzureAcciónCreate or update an ACR cache rule (pull-through mirror of an upstream repository).
bling.cancel-nfse
BlingAcciónCancel an authorized NFS-e at Bling and reflect the cancellation on the commerce_entity row. Requires a justification.
bling.create-journal-entry
BlingAcciónDirect creation of a Bling lançamento. Caller supplies the Bling-side linked_receivable_external_ref or linked_payable_external_ref + amount; this workflow POSTs to /contas/{kind}/{id}/lancamentos and persists the result into commerce_entity.
bling.create-payable
BlingAcciónCreate a new accounts-payable row at Bling (POST /contas/pagar). Persists the result into commerce_entity (entity_type='payable').
bunnycdn.auth.validate_token
BunnyCDNAcciónsolo lecturaValidate a Bunny CDN API key
buzz.actor.attach
buzzAcciónPut a Staff actor into an app chat. The actor must already hold a paid end-user seat in the app (identity.end-user.bind-actor). It gets a server-held relay key, joins the listed channels as bot, and answers mentions, DMs, or every message in its channels. Its stored definition must act as the space's app (on_invoke.input_data.act_as_identity_app_uuid), unless the attachment replies as the organization (reply_principal organization: org admins only, allowlisted orgs and authors)
buzz.actor.dm-open
buzzAcciónOpen (or reuse) a direct-message channel between an attached actor and 1-8 members of the space, signed by the actor's key. Returns the DM channel id to post into. Same callers as buzz.message.post
buzz.actor.notify
buzzAcciónSend a chat message as yourself, the attached Staff actor, from outside the chat (a schedule, an event, another workflow). target is '#channel', a channel name, a person's display name ('@name') or a member id: a person gets a direct message (opened if needed), a channel gets a post. Optional mention names one member. Optional quick_replies (up to 5 short labels) are offered as tappable buttons: a tap posts the label verbatim as the person's own message, answered like a typed line. Ambiguous or unknown names fail listing candidates. Humans and the system pass as_actor_uuid
chat.conversation.create
ChatAcciónCreate a new chat conversation owned by a member or an app end-user
chat.conversation.send-message
ChatDAGAppend a user turn to a chat conversation and return the assistant reply
chat.engine.find-similar-failures
ChatAcciónsolo lecturaLook up previously-resolved Lumen error groups similar to a query error message so the agent can reuse prior root_cause/solution knowledge instead of re-investigating from scratch.
checkout.analytics.summary
Agentic CheckoutConsultasolo lecturaSummarise a catalog's last N days: orders by status, revenue and average ticket from paid orders, items sold, a per-day series and the top products.
checkout.cart.add-item
Agentic CheckoutAcciónAdd quantity of a product to the shopper's open cart, creating the cart if needed. Same product + same options merges into one line.
checkout.cart.get
Agentic CheckoutConsultasolo lecturaRead a shopper's open cart with lines and totals. Never creates one.
cloudflare.auth.validate_token
CloudflareAcciónsolo lecturaValidate a Cloudflare API token
cloudflare.cache.purge
CloudflareAcciónPurge Cloudflare CDN cache for specific URLs or entire zone
cloudflare.dns.delete_record
CloudflareAcciónDelete a Cloudflare DNS record by record ID
cluster.aws-vm.collect-kubeconfig
ClustersAcciónCollect Kubernetes kubeconfig from an AWS VM through SSM Run Command.
cluster.azure-vm.collect-kubeconfig
ClustersAcciónCollect the admin kubeconfig produced by a Azure VM Kubernetes bootstrap process.
cluster.bootstrap-orkestia-access
ClustersAcciónEnsure standard namespace, service account, RBAC binding, and optional manifests for Orkestia access.
composition.activate
ComposiciónConsultaRe-validate a composition against the live registry and set it active
composition.archive
ComposiciónConsultaArchive a composition (no longer startable)
composition.delete-archived
ComposiciónConsultaSoft-delete archived compositions for an organization by uuid, uuid list or lineage name
connection.deere.sync-assets
ConexionesAcciónRefresh John Deere Operations Center organizations for a connection via GET /organizations using the stored OAuth access token
connection.disconnect
ConexionesAcciónDisconnects a cloud provider connection: scrubs its secrets and soft-deletes the CloudConnection record
connection.get
ConexionesAcciónsolo lecturaGet a single cloud connection by UUID
control.collection.distinct
Flujo de controlAcciónsolo lecturaDrop duplicate elements (optionally by a field), preserving order
control.collection.filter
Flujo de controlAcciónsolo lecturaKeep the list elements matching one comparison predicate
control.collection.flatten
Flujo de controlAcciónsolo lecturaFlatten nested lists up to a given depth (-1 = fully flat)
data.agents.budget-status
DatosAcciónsolo lecturaReport budget utilisation for an organisation for a given period
data.agents.cost-by-config
DatosAcciónsolo lecturaAggregate agent cost by config for an org, optionally filtered by date range
data.agents.cost-by-model
DatosAcciónsolo lecturaAggregate agent LLM cost and token usage by model for an org
deploy.backend.immediate
DeployAcciónProvision backend container capacity immediately
deploy.cloudrun.rollback
DeployDAGRestore Cloud Run traffic to a previously stable revision.
deploy.cloudrun.rollout-canary
DeployAcciónRoll out a Cloud Run revision through staged traffic percentages with rollback support.
dgi.action.query-connections
DGIAcciónsolo lecturaQuery active connections (read-only; scoped to organization)
dgi.action.show-dag
DGIAcciónsolo lecturaExtract and return DAG structure
dgi.action.think
DGIAcciónCall the org's LLM for a one-shot reasoning turn (via ai.chat)
docusign.archive-completed-envelope
DocuSignDAGVerify a DocuSign envelope is completed, then stream its signed PDF and certificate of completion into the customer bucket as audit-tracked objects (verify → presign → download)
docusign.create-envelope
DocuSignAcciónCreate a DocuSign envelope from documents fetched by presigned URL — draft by default, sent with send=true
docusign.create-envelope-from-template
DocuSignAcciónCreate a DocuSign envelope from a server template with role assignments — draft by default, sent with send=true
exchange.buyer-policy.set
exchangeAcciónSet the organization's buyer policy for the Agent Exchange.
exchange.deal.cancel
exchangeAcciónCancel an open Agent Exchange deal. Settled one_shot deals cannot be cancelled here (refunds arrive from the PSP). Settled subscriptions revoke the lease without calling a live PSP.
exchange.deal.start
exchangeDAGStart an Agent Exchange deal. Same-org hires settle on rail=internal with no provider objects. Hosted checkout on live PSP rails is deferred.
failguard.clone_repo
FailGuardAcciónClone repo for FailGuard indexing (DAG step)
failguard.create_data_source
FailGuardAcciónCreate Bedrock Data Source for FailGuard project (DAG step)
failguard.create_kb
FailGuardAcciónCreate Bedrock KB for FailGuard project (DAG step)
firecrawl.billing.get-credit-usage
FirecrawlAcciónGet remaining credits for the authenticated team
firecrawl.billing.get-token-usage
FirecrawlAcciónGet remaining tokens for the authenticated team (Extract only)
firecrawl.crawling.cancel-crawl
FirecrawlAcciónCancel a crawl job
gcp.artifactregistry.image.delete
Google CloudAcciónDelete an Artifact Registry package (image) and all versions; idempotent when already absent.
gcp.artifactregistry.remote_repository.describe
Google CloudAcciónsolo lecturaDescribe a GCP Artifact Registry remote repository
gcp.artifactregistry.repository.delete
Google CloudAcciónDelete an Artifact Registry repository; idempotent when already absent.
git.remote-binding.activate
GitAcciónActivate one immutable trusted Git-remote binding.
git.remote-binding.create
GitAcciónCreate an immutable repository-to-trusted-broker binding version without storing a remote URL or credential.
git.remote-binding.get
GitConsultasolo lecturaGet an organization-scoped trusted Git-remote binding.
github.actions.get_job_log_tail
GitHubAcciónRead bounded metadata and tail logs for one GitHub Actions job.
github.actions.rerun_failed_jobs
GitHubAcciónRe-run only the failed jobs of one or more GitHub Actions workflow runs, as a new attempt on the same commit. Needs the installation's Actions write permission; best_effort reports a provider refusal per run instead of failing.
github.actions.trigger_workflow
GitHubAcciónTrigger a GitHub Actions workflow_dispatch run through an installed GitHub App connection.
gitops.application.create
GitOpsAcciónBind a GitHub repo path to a Kubernetes cluster and start GitOps sync
gitops.application.delete
GitOpsAcciónSoft-delete a GitOpsApplication and stop its controller (optional cascade prune)
gitops.application.pause
GitOpsAcciónPause reconciliation for a GitOpsApplication
google.ads.campaign.create-paused
GoogleAcciónScaffold: create a paused Google Ads campaign draft. Always returns status=PAUSED / enabled=false. Never sets ACTIVE (SOCIAL-004). No live API yet.
google.ads.campaign.request-review
GoogleAcciónCreate a Staff ActorOutboxEnvelope for Google Ads spend enable (SOCIAL-004 hard inbox gate).
google.ads.creative.attach
GoogleAcciónScaffold: accept a StorageObject UUID for Google Ads creative attach. Does not upload or enable spend. No live Google Ads API yet.
hook.acknowledge-event
HookAcciónAcknowledge webhook event delivery from DevKit to local target
hook.create-redirect
HookAcciónCreate new webhook redirect with signed UUID
hook.delete-redirect
HookAcciónSoft delete webhook redirect and cleanup pending events
identity.api-token.create
IdentidadAcciónGenerate a new API token for the current user
identity.api-token.query
IdentidadAcciónsolo lecturaList API tokens for the current user
identity.api-token.revoke
IdentidadAcciónRevoke (hard-delete) an API token for the current user
ifood.connection.begin-authorization
iFoodAcciónStart a merchant's authorization of the registered iFood application
ifood.connection.complete-authorization
iFoodAcciónExchange a merchant's authorization code for a durable iFood grant
ifood.connection.validate
iFoodAcciónValidate iFood authentication and merchant visibility
k8s.app.deploy
K8s (manifests)DAGDeploy a containerised app: Namespace + ConfigMap + Secret + Deployment + Service, with optional PVC / HPA / PDB / Ingress
k8s.app.set-image
K8s (manifests)DAGPatch a Deployment's container image and wait for rollout to be Available. Helm-safe — only touches the image field.
k8s.app.teardown
K8s (manifests)DAGTear down a containerised app: Ingress/HPA/PDB + Service + Deployment + ConfigMap + Secret; PVCs only when delete_pvcs=true
kubernetes.cluster.api_resources
KubernetesAcciónsolo lecturaList all API resources advertised by the cluster (kubectl api-resources equivalent)
kubernetes.cluster.version
KubernetesAcciónsolo lecturaRead Kubernetes API server version.
kubernetes.clusterrole.delete
KubernetesAcciónDelete a ClusterRole (cluster-scoped, rbac.authorization.k8s.io/v1)
kv.bind-env
KVAcciónResolve KV keys into runtime secret_env / Pages secrets (references only)
kv.key.resolve
KVAcciónsolo lecturaResolve an Orkestia KV key to a reference (value only on explicit reveal)
kv.key.set
KVAcciónWrite one Orkestia KV key as a new version via LTIP (value redacted)
linkedin.ads.campaign.create-paused
LinkedInAcciónScaffold: record a paused LinkedIn Ads campaign draft. Never sets ACTIVE or spends (SOCIAL-004). No live Campaign Manager write yet.
linkedin.ads.campaign.request-review
LinkedInAcciónCreate a Staff ActorOutboxEnvelope for LinkedIn Ads spend enable (SOCIAL-004 hard inbox gate).
linkedin.ads.conversion.campaign.associate
LinkedInAcciónAssociate a sponsored campaign with a Conversions API rule (PUT /rest/campaignConversions). Required before event attribution.
lovable.project.bootstrap-auth
LovableDAGProvision Sign in with Orkestia for a Lovable project
lovable.project.go-live
LovableDAGBuild a Lovable project's synced repo and deploy it to production
lovable.project.wire-payments
LovableDAGCreate the payment webhook that grants a Lovable app's end-users access
lumen.alert-rule.create
LumenAcciónCreates a Lumen alert rule that dispatches webhook, Slack, or email notifications — or opens a native Orkestia incident ticket (channel=ticket) — when fingerprint_log detects a new_group, regressed, or threshold event.
lumen.alert-rule.delete
LumenAcciónPermanently delete a Lumen alert rule by its public UUID.
Fuente: catálogo público en workflow-api.orkestia.dev — actualizado en cada deploy
