Tool reference

Every action an agent can take. Each tool pill has three states: on (blue), requires approval (amber), or off. See the Tool approvals page for how the approval flow works.

Reading the same account with several agents

Reading tools keep a private position per agent. They do not use the read/unread flag, because that flag is shared: if you open a group on your phone, or a second agent reads the same inbox first, the flag flips and the message would otherwise disappear for everyone else. So two agents can watch the same Gmail account or Telegram groups for different purposes and each will see every message once.

Actions are still shared. If one agent archives an email or replies to a chat, that is done for the account, not for the agent. Attach writing tools to one agent per account and let the others read only.

Google (Gmail and Calendar)

ToolWhat it does
read_unread_emailsLists inbox mail that arrived since the agent's last run, oldest first: sender, subject, date and a short preview snippet. Mail you have already opened yourself is still included. Only considers mail received on or after the day the agent was created — older backlog is out of scope. Skips anything this agent already handled, and tells you how many it skipped. Does not include the full body or attachments.
search_emailsSearches with Gmail syntax such as from:bob after:2026/01/01. Unlike reading unread mail, this returns everything that matches - including messages already handled.
send_emailSends a new plain-text email. No formatting, no attachments.
reply_to_emailReplies to a message in its existing thread, so the conversation stays together.
archive_emailRemoves a message from the inbox. It is not deleted and stays in All Mail.
list_calendar_eventsLists events on the primary Google Calendar between two dates. Defaults to today.
create_calendar_eventCreates an event on the primary calendar. Optional attendees get a Google invite.

Telegram Bot

ToolWhat it does
send_telegram_messageSends a message to the one chat that was linked at setup. It cannot choose a recipient.

Telegram Account

ToolWhat it does
send_telegram_messageSends a message to any username or phone number, as you.
read_telegram_messagesEvery new message in your chats and groups since the agent's last run, grouped by chat and oldest first — whether or not you have read them yourself. Each line names the sender (name, @username, #id) and replies quote the message they answer. At most the newest 30 messages per chat; if a busy group had more, the tool says so. Your own messages and media contents are not included (a photo shows as [photo]).

Twilio

ToolWhat it does
send_smsSends an SMS from your Twilio number. Recipients must be in international format, like +14155551234. Every message costs you money.

Slack

ToolWhat it does
post_to_slackPosts a message to the Slack channel linked at setup. Supports plain text and Slack markdown (*bold*, _italic_, `code`, ```block```). Dry-run mode simulates the post without sending.

WhatsApp Business

ToolWhat it does
send_whatsapp_messageSends a text message to a WhatsApp number. Use E.164 format without the leading +, e.g. 15551234567. Only works within 24 hours of the customer's last message — after that the tool returns an error explaining the window is closed.
read_whatsapp_messagesReturns recent inbound WhatsApp messages from customers who have written to your number, newest first.

MCP servers

Tools come from the frozen list on the connector - names and arguments depend on the server (GitHub, Linear, Notion, or a custom URL). Attach the connector on the Agent tab and enable the pills you want. Write-like names start as requiring approval. See the MCP servers page.

Web search

These two are different from the rest: there is no account to connect. Turn them on per agent under Settings, and they appear automatically.

ToolWhat it does
search_webSearches the web and returns titles, links and short snippets. Appears when Web search is on. How many results come back depends on your results setting.
fetch_pageReads a URL. Web pages come back as text with the markup stripped and every link kept as 'label (url)', so the agent can follow a listing through to its detail pages. Data files — CSV, JSON, XML — come back as-is, which is usually the better source when a site publishes one. Long content is truncated. Only appears when Read full pages is also on.

Knowledge

Appears automatically once the agent has at least one indexed document on its Knowledge tab. No document, no tool.

ToolWhat it does
search_knowledgeSearches the documents uploaded to this agent and returns the best-matching passages with the file each came from.
query_dataAppears when a CSV or Excel file is uploaded. Runs one read-only SQL statement over those files as tables — filter, count, sort, join, total — and returns up to 200 rows. The agent is shown every table's columns and a sample row, so instructions should say what to find, not how.

Memory

On by default (Keep exact state in the agent’s Settings). Everything stored is visible and editable on the agent’s Memory tab. See the memory page for when to use this versus Remember past runs.

ToolWhat it does
memory_getReads one stored value by key. The tool's description already lists every key with a short preview, so the agent rarely needs to look before it reads.
memory_setStores or overwrites one value (a number, text, list or object up to 16 KB). Saved immediately — a run that fails later keeps what it stored. Keys starting with shared: are visible to every agent in the workspace.
memory_deleteRemoves one key.
memory_listLists stored keys with previews, optionally filtered by prefix.

Two accounts of the same kind

If an agent has two Gmail accounts attached, the tool names get a suffix so the model can tell them apart - send_email_sales and send_email_support. Mention the account in your instructions when this happens.

A failing tool does not stop the run

When a tool errors, the error text is handed back to the model as the result and the run continues. That is usually what you want - a temporary Gmail hiccup should not abandon the whole job - but it does mean a run can finish as “succeeded” having quietly failed at something. The transcript shows the error.

NextKnowledge files →