← All action domains

Cloud

15 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Cloud activity

cloud.activityreadadmin only

Read the latest fifty cloud submission receipts for this account. Includes accepted, rejected and uncertain outcomes; excludes deployment specifications, credentials and job payloads.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.activity \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool cloud_activity at https://app.chirply.io/api/mcp, same bearer token, same input.

Cloud launch catalog

cloud.catalogreadadmin only

List supported customer-owned infrastructure services, deployment examples and provider documentation. Read-only; does not connect accounts or provision resources.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.catalog \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool cloud_catalog at https://app.chirply.io/api/mcp, same bearer token, same input.

Connect cloud provider

cloud.connectwriteconfirmadmin only

Verify and encrypt this account’s own cloud credentials. Replaces this provider’s previous connection and changes where future operations run. Verification launches no infrastructure; subsequent launches are billed by the provider.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
provider"aws" | "google-cloud" | "digitalocean" | "runner"requiredConnected cloud provider; runner is your customer-hosted execution server.
credentialsmap of string → stringrequiredAWS: accessKeyId, secretAccessKey, region, optional sessionToken. Google: serviceAccount JSON string. DigitalOcean: token (omit to use an existing OAuth connection), optional spacesAccessKeyId and spacesSecretAccessKey supplied together. Runner: HTTPS origin url and token.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.connect \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "aws",
    "credentials": {}
  }'
Test with your API key

Over MCP the same operation is the tool cloud_connect at https://app.chirply.io/api/mcp, same bearer token, same input.

Cloud connections

cloud.connectionsreadadmin only

List this account’s saved cloud connections and last verified status. Returns no credentials and makes no provider changes.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.connections \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool cloud_connections at https://app.chirply.io/api/mcp, same bearer token, same input.

Launch cloud resource

cloud.create_resourcewriteconfirmadmin only

Launches real infrastructure using the connected provider’s deployment specification. The provider bills the customer directly for compute, storage and traffic. Records an idempotent submission receipt; accepted means submitted, not ready. Inspect resources before retrying an uncertain operation.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
service"aws-functions" | "aws-stacks" | "google-services" | "google-functions" | "google-compute" | "google-databases" | … 9 morerequiredService key from cloud.catalog.
resourcestringoptionalProvider resource ID or name from a list operation. Required to inspect, update or delete.
locationstringoptionalProvider region or zone; use the same location as the existing resource.
requestKeystring (uuid)requiredUnique request ID. Reuse exactly this ID after an uncertain response; never generate a new ID to retry blindly.
specmap of string → objectoptionalDeployment JSON; required for create/update and ignored for delete.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.create_resource \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "service": "aws-functions",
    "requestKey": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_create_resource at https://app.chirply.io/api/mcp, same bearer token, same input.

Delete cloud resource

cloud.delete_resourcewriteconfirmadmin only

Permanently deletes a provider resource and may destroy its stored data. The provider bills the customer directly for compute, storage and traffic. Records an idempotent submission receipt; accepted means submitted, not ready. Inspect resources before retrying an uncertain operation.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
service"aws-functions" | "aws-stacks" | "google-services" | "google-functions" | "google-compute" | "google-databases" | … 9 morerequiredService key from cloud.catalog.
resourcestringoptionalProvider resource ID or name from a list operation. Required to inspect, update or delete.
locationstringoptionalProvider region or zone; use the same location as the existing resource.
requestKeystring (uuid)requiredUnique request ID. Reuse exactly this ID after an uncertain response; never generate a new ID to retry blindly.
specmap of string → objectoptionalDeployment JSON; required for create/update and ignored for delete.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.delete_resource \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "service": "aws-functions",
    "requestKey": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_delete_resource at https://app.chirply.io/api/mcp, same bearer token, same input.

Disconnect cloud provider

cloud.disconnectwriteconfirmadmin only

Remove this account’s encrypted cloud connection. Existing resources and running jobs remain on the provider and continue billing; future Chirply operations require reconnecting.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
provider"aws" | "google-cloud" | "digitalocean" | "runner"requiredConnected cloud provider; runner is your customer-hosted execution server.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.disconnect \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "aws"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_disconnect at https://app.chirply.io/api/mcp, same bearer token, same input.

Inspect my infrastructure job

cloud.get_jobreadadmin only

Read a job’s current state and result directly from your connected execution server. The payload, queue and result are stored on that server. Does not start or retry work.

Parameters

FieldTypeRequiredDescription
jobIdstring (uuid)requiredJob ID from cloud.submit_job; identical to its requestKey.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.get_job \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "jobId": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_get_job at https://app.chirply.io/api/mcp, same bearer token, same input.

Inspect cloud resource

cloud.get_resourcereadadmin only

Read live resource state from the connected cloud provider. Use after a launch to distinguish provider acceptance from readiness. Secret configuration is redacted; no resources are changed.

Parameters

FieldTypeRequiredDescription
service"aws-functions" | "aws-stacks" | "google-services" | "google-functions" | "google-compute" | "google-databases" | … 9 morerequiredService key from cloud.catalog.
resourcestringrequiredProvider resource ID or name to inspect.
locationstringoptionalProvider region or zone; use the same location as the existing resource.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.get_resource \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "service": "aws-functions",
    "resource": "example"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_get_resource at https://app.chirply.io/api/mcp, same bearer token, same input.

Invoke Lambda function

cloud.invoke_lambdawriteconfirmadmin only

Run a Lambda function directly on your connected AWS infrastructure. The function can cause external effects and AWS bills its execution. The request is not automatically retried; inspect uncertain outcomes before invoking again.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
functionNamestringrequiredExisting Lambda function name in your connected AWS account.
regionstringrequiredAWS region containing the function.
payloadmap of string → objectrequiredJSON event passed to the existing Lambda function.
requestKeystring (uuid)requiredUnique request ID. Reuse exactly this ID after an uncertain response; never generate a new ID to retry blindly.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.invoke_lambda \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "functionName": "Example",
    "region": "example",
    "payload": {},
    "requestKey": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_invoke_lambda at https://app.chirply.io/api/mcp, same bearer token, same input.

Cloud launch options

cloud.launch_optionsreadadmin only

Read live deployment choices from your cloud provider. DigitalOcean returns sizes with prices, regions, images, SSH keys and Kubernetes versions; AWS returns subnet, security group and key-pair IDs; Google returns available project zones. Permission failures are reported per option group. No resources are launched.

Parameters

FieldTypeRequiredDescription
provider"aws" | "google-cloud" | "digitalocean" | "runner"requiredConnected cloud provider; runner is your customer-hosted execution server.
locationstringoptionalAWS region for network and key-pair choices. Defaults to the connection region.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.launch_options \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "aws"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_launch_options at https://app.chirply.io/api/mcp, same bearer token, same input.

List cloud resources

cloud.list_resourcesreadadmin only

Read one page of resources from the connected provider in the requested region. Returns provider pagination metadata; secret configuration is redacted. Does not launch or change resources.

Parameters

FieldTypeRequiredDescription
service"aws-functions" | "aws-stacks" | "google-services" | "google-functions" | "google-compute" | "google-databases" | … 9 morerequiredService key from cloud.catalog.
resourcestringoptionalProvider resource ID or name from a list operation. Required to inspect, update or delete.
locationstringoptionalProvider region or zone; use the same location as the existing resource.
cursorstringoptionalProvider next-page token, or DigitalOcean page number. Omit for the first page.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.list_resources \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "service": "aws-functions"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_list_resources at https://app.chirply.io/api/mcp, same bearer token, same input.

Run on my infrastructure

cloud.submit_jobwriteconfirmadmin only

Submit an agent or registered HTTP job directly to your connected execution server. Its own durable queue, compute and disk hold the work and result; it never enters Chirply’s shared job queue. Uses your server’s configured AI/tool credentials and can spend provider money or cause external effects. Core Chirply application data remains in Chirply.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
requestKeystring (uuid)requiredUnique request ID. Reuse exactly this ID after an uncertain response; never generate a new ID to retry blindly.
kind"agent" | "http"requiredagent runs a model/tool loop on your server; http calls a server-configured named endpoint.
payloadmap of string → objectrequiredagent: {task: string}. http: {endpoint: server-configured name, body: object}. Stored and processed on your execution server.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.submit_job \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "requestKey": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11",
    "kind": "agent",
    "payload": {}
  }'
Test with your API key

Over MCP the same operation is the tool cloud_submit_job at https://app.chirply.io/api/mcp, same bearer token, same input.

Test cloud connection

cloud.test_connectionwriteadmin only

Verify stored cloud credentials with a metadata request and persist the result. Does not launch infrastructure or execute an agent job; individual resource permissions can still differ.

Parameters

FieldTypeRequiredDescription
provider"aws" | "google-cloud" | "digitalocean" | "runner"requiredConnected cloud provider; runner is your customer-hosted execution server.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.test_connection \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "aws"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_test_connection at https://app.chirply.io/api/mcp, same bearer token, same input.

Update cloud resource

cloud.update_resourcewriteconfirmadmin only

Changes a running provider resource; updates may replace resources, interrupt service or change billing. The provider bills the customer directly for compute, storage and traffic. Records an idempotent submission receipt; accepted means submitted, not ready. Inspect resources before retrying an uncertain operation.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
service"aws-functions" | "aws-stacks" | "google-services" | "google-functions" | "google-compute" | "google-databases" | … 9 morerequiredService key from cloud.catalog.
resourcestringoptionalProvider resource ID or name from a list operation. Required to inspect, update or delete.
locationstringoptionalProvider region or zone; use the same location as the existing resource.
requestKeystring (uuid)requiredUnique request ID. Reuse exactly this ID after an uncertain response; never generate a new ID to retry blindly.
specmap of string → objectoptionalDeployment JSON; required for create/update and ignored for delete.

Example

curl -X POST https://app.chirply.io/api/v1/actions/cloud.update_resource \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "service": "aws-functions",
    "requestKey": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool cloud_update_resource at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=cloud — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.