source_write_grant_list
List the API keys and members allowed to write to a data endpoint, with their operations, writable fields and row predicates.
When to use it
Use source_write_grant_list to list source write grants. This tool operates at workspace scope. It does not require a project context unless a filtering argument explicitly asks for one.
Plugin requirements
Connector dependency depends on the endpoint. These tools manage endpoint configuration, policies or grants; they do not install a connector or add capabilities to it. A plugin-backed endpoint must reference a configured connector installation. Use the plugin setup guides for configuration. Inspect the workspace’s plugin installations and check the installation before executing it.
Arguments
| Name | Type | Required | Default | Constraints |
|---|---|---|---|---|
sourceId | string | Yes | — | Format: uuid; Pattern constraint; see full schema |
View the complete input schema, including nested contracts and alternative shapes. The schema is extracted from the workspace server’s Zod definitions. Runtime validation also enforces custom checks that JSON Schema cannot express.
Response shape
The implementation constructs payloads using these fields: grants. The returned fields depend on the execution path.
MCP returns a text block containing the JSON operation result and a
structuredContent copy. The envelope includes data, completeness,
truncated, freshness, and warnings. Depending on the operation it can also
include nextCursor, evidence, job, or receipt.
Check those fields before treating a conversational summary as the result.
When a job is returned, inspect its status with the appropriate execution tool;
a queued response is not confirmation that work finished. Follow evidence links
when checking the underlying records.
Input methods
This request illustrates the argument structure. Replace every angle-bracket placeholder with a real value and supply any applicable optional fields from the schema. Nested business contracts must match your actual configuration. Send it through an authenticated, initialized MCP client; this JSON alone does not establish a session or sign you in.
Use Semogram’s source_write_grant_list tool to list source write grants. Confirm the workspace and use records I can access. Do not change anything.
Use real resource IDs returned by earlier reads; a resource name is not a UUID. Do not fill missing business inputs with invented values.
Use a workspace API key with org:manage. Set SEMOGRAM_API_KEY in your shell; replace resource placeholders with real IDs. This is an HTTP resource request, not an MCP JSON-RPC message.
curl --request GET "https://platform.semogram.com/api/v1/data-endpoints/<SOURCE_ID_UUID>/source-write-grants" \
--header "Authorization: Bearer ${SEMOGRAM_API_KEY}"This is an MCP tools/call request, not a form to paste into Semogram. Send it through an authenticated, initialized MCP client.
{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "source_write_grant_list",
"arguments": {
"sourceId": "<SOURCE_ID_UUID>"
}
}
}FAQ
What access and approvals are required?
Required permission scopes: org:manage.
OAuth uses current workspace membership; API keys use their assigned scopes
and grants. Discovery can exclude tools the caller cannot use.
Read-only annotation: Yes. Destructive annotation: No. Follow the operation’s declared contract and any applicable server-side approval policy.
How should I handle retries?
Do not assume repeated calls are safe merely because the client offers Retry. Inspect the result or existing request before repeating work that changes state. For 429 responses, honor Retry-After rather than retrying immediately.
Why is this tool missing or returning an error?
Confirm the workspace, resource IDs, and permission scopes. Read the returned error before changing the request. See connection, authentication and troubleshooting for sign-in, scope, resource access, and rate-limit errors.
source_write_policy_bind
Bind an approved workspace-wide write policy version to a data endpoint, or pass null to clear it. Project-bound policies are rejected.
source_write_grant_save
Create or replace the write grant of one API key or member on a data endpoint. API keys need the data:write scope, and data:delete to delete rows.