UTCP tools / jarvis.run.create
Auth
Header: Authorization: Bearer $JARVIS_BEARER_TOKEN
- Every call requires a Bearer token (JARVIS_BEARER_TOKEN). Missing/wrong → HTTP 403.
- Optional capability grants: JARVIS_UTCP_CAPABILITIES=policy:check,run:create (empty = full owner grant).
- Missing capability on invoke → HTTP 403 with reason "capability denied".
- Audit actor is a token fingerprint (tok_<prefix>_<sha256[0..4]>), never the raw secret.
- Loopback bind only in v0 (127.0.0.1).
This tool requires capability run:create.
If JARVIS_UTCP_CAPABILITIES is set, include that grant
or the provider returns 403.
curl
curl -sS \
-H "Authorization: Bearer $JARVIS_BEARER_TOKEN" \
-H "Content-Type: application/json" \
-d '{"tool":"jarvis.run.create","args":{"argv":["echo","hello"],"cwd":"/tmp"}}' \
http://127.0.0.1:7777/tools/invoke
Python
import json, os, urllib.request
url = "http://127.0.0.1:7777/tools/invoke"
token = os.environ["JARVIS_BEARER_TOKEN"]
payload = {
"tool": "jarvis.run.create",
"args": {
"argv": [
"echo",
"hello"
],
"cwd": "/tmp"
}
}
req = urllib.request.Request(
url,
data=json.dumps(payload).encode(),
headers={
"Authorization": f"Bearer {token}",
"Content-Type": "application/json",
},
method="POST",
)
with urllib.request.urlopen(req) as resp:
print(resp.read().decode())
Example args
{
"argv": [
"echo",
"hello"
],
"cwd": "/tmp"
}
input_schema
{
"type": "object",
"required": [
"argv"
],
"properties": {
"argv": {
"type": "array",
"items": {
"type": "string"
}
},
"cwd": {
"type": "string"
},
"timeout_ms": {
"type": "integer"
}
}
}
output_schema
{
"type": "object",
"required": [
"decision"
],
"properties": {
"decision": {
"type": "string"
},
"reason": {
"type": "string"
},
"matched_rule": {
"type": "string"
},
"run_id": {
"type": "integer"
},
"status": {
"type": "string"
},
"exit_code": {
"type": "integer"
}
}
}
← All UTCP tools