Tool classification (Meta Muse)
Meta's connector guidelines require every tool to be classified as Read, Write or Sensitive Write, and sensitive writes to prompt the user on every use. The classification is machine-readable in two places:
- OpenAPI: each operation carries
x-tool-class: read | write | sensitive-write. - MCP:
annotations.readOnlyHint/destructiveHint.
| Class | Operations | Why |
|---|---|---|
| Read | searchCatalog, getProduct, getVariant, getVariantAvailability, listCollections, getCollection, listTags, listCountries, autocompleteAddress, validateAddress, getMe, getQuote, listCheckouts, getCheckout, getCheckoutTimeline, streamCheckoutEvents, listOrders, getOrder, getOrderTimeline, listOrderSupportRequests, listSupportRequests |
Retrieve information; change nothing |
| Write | createQuote, updateMe, addAddress, deleteAddress, sendReceipt, sendCheckoutReceipt, createSupportRequest |
Create or modify data without financial consequence (a support request asks operators to act; it does not move money by itself) |
| Sensitive Write | createCheckout, cancelCheckout, cancelOrder |
Start a purchase (payment link), abandon it, or trigger a refund |
Notes for reviewers:
createCheckoutdoes not charge. It creates one hosted Stripe session for the whole cart that the user completes themselves. It is still classified sensitive because it starts a purchase.- No tool can read or store card data. Stripe hosts the payment page; the platform receives only a payment intent id.
- Users can limit a grant to read-only at consent time; all write tools then fail with
insufficient_scope. - All writes are idempotent (quote per call, checkout per cart via
idempotencyKey, one Snappy order per checkout item). - SMS requires recorded consent; STOP is honoured platform-wide.
Snappy Agents · agents.snappy.com · support@snappy.com