SMAO API Documentation
Public APITools

Create a tool

POST
/tools

Creates a new webhook-type tool. tool_key must be unique within your organization; reuse returns 409. Auth secrets are stored AES-256-GCM encrypted and are never returned — submit them on create / PATCH to set or rotate. Integration-type tools must be created via the dashboard (OAuth flow) and cannot be created through the public API in v1.

Authorization

bearerAuth
AuthorizationBearer <token>

API key in the Authorization: Bearer <key> header. Keys are created in the SMAO dashboard (Settings → API Keys).

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/tools" \  -H "Content-Type: application/json" \  -d '{    "tool_key": "get_opening_hours",    "display_name": "Get Opening Hours",    "execution_type": "webhook",    "webhook": {      "url": "https://api.example.com/smao-tools"    }  }'
{  "data": {    "id": "string",    "tool_key": "string",    "display_name": "string",    "description": "string",    "parameters": {},    "execution_type": "webhook",    "source": "custom",    "webhook": {      "url": "http://example.com",      "method": "GET",      "headers": {},      "body_template": "string",      "timeout_ms": 500,      "retry_count": 0    },    "integration": null,    "auth": {      "type": "apiKey",      "header_name": "string",      "username": "string",      "has_secret": true    },    "created_at": "2019-08-24T14:15:22Z",    "updated_at": "2019-08-24T14:15:22Z"  }}