Trust Boundary
Public
discover public pages, read llms files, read OpenAPI, read well-known manifests, read RSS and sitemap files, run MCP initialize, run MCP ping, run MCP tools/list, run MCP resources/list, run MCP prompts/list, call public-safe read-only MCP tools
Protected
site registration, tool creation, tool publishing, tool deprecation, capability registry mutation, protected gateway proxying, sandbox execution, BrowserOps execution, eval execution, report generation, sync jobs, private traces, raw audit logs, trusted-domain mutation
Auth
PLATPHORM_API_KEY only for protected actions