> ## Documentation Index
> Fetch the complete documentation index at: https://docs.famulor.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a tool

> Revision-protected partial update. `type` is immutable. Sending `•••` for a secret keeps the stored value. A provided `config` replaces the stored configuration: send back every header from the read response (masked values as `•••`); omitted headers are removed. A stale revision returns `409 revision_conflict`. **Required scope:** `assistants:write`.



## OpenAPI

````yaml /api-reference/openapi.json patch /tools/{id}
openapi: 3.1.0
info:
  title: Famulor API
  version: 1.0.0
  description: >-
    REST API for Famulor. Authenticate with an API key (`fam_...`, created under
    **Settings → API Keys**) or an OAuth 2.0 access token (`fam_at_...`) as a
    Bearer token.


    Every response uses a consistent envelope: `{ "data": ... , "meta": { ... }
    }` on success and `{ "error": { "code", "message" } }` on failure. List
    endpoints paginate with `?limit=` (default 50, max 200) and `?offset=`;
    `meta.pagination.total` carries the total match count.


    REST operations require API Access through the workspace plan or a recurring
    add-on. Without it, regular operations return `403 api_access_required`. The
    invoice-payment and billing-portal operations remain available with a valid
    `billing:write` credential after a failed plan payment so an authorized
    owner, admin, or billing member can recover billing.


    The same customer-facing capabilities are available as MCP tools at
    `https://app.famulor.io/mcp` (Model Context Protocol, streamable HTTP) using
    the same credentials, scopes, and workspace access. MCP availability is
    controlled separately by Connect AI / MCP, not by API Access.
servers:
  - url: https://app.famulor.io/api/v1
    description: Hosted platform.
  - url: https://{domain}/api/v1
    description: White-label tenant domain — same paths, tenant branding.
    variables:
      domain:
        default: app.famulor.io
        description: Your white-label tenant domain.
security:
  - bearerAuth: []
tags:
  - name: Account
    description: Self-inspection of the calling credential.
  - name: Migrations
    description: Preview and import data from supported legacy platforms.
  - name: Assistants
    description: Create and manage voice assistants.
  - name: Tools
    description: >-
      Reusable tools (HTTP APIs and external MCP servers) assistants can call
      mid-conversation.
  - name: Voices
    description: Browse the text-to-speech voice library.
  - name: Calls
    description: Start outbound calls and read call history, transcripts and recordings.
  - name: History
    description: Unified conversation history across calls, messaging and assistant emails.
  - name: Campaigns
    description: Outbound calling campaigns with a compliant power dialer.
  - name: Leads
    description: Manage Audience contacts across campaigns, channels and Call QA metrics.
  - name: Segments
    description: >-
      Saved, dynamic lead filters — reusable audience definitions used for
      Audience search and campaign lead assignment.
  - name: Suppression
    description: Cross-channel marketing opt-outs and active workspace suppression records.
  - name: Callbacks
    description: >-
      Scheduled callbacks booked by the Schedule callback tool across voice,
      chat, and email.
  - name: Phone Numbers
    description: Marketplace numbers and customer-provided numbers.
  - name: Famulor Loop
    description: >-
      Personal business-phone access, directory, presence, devices, and Loop
      call recents.
  - name: SIP Trunks
    description: Bring your own SIP provider and numbers.
  - name: Carrier Connections
    description: Connect a supported carrier account and import its existing phone numbers.
  - name: Knowledge Bases
    description: RAG knowledge bases and documents for assistants.
  - name: Settings
    description: Workspace-level settings such as caller-memory defaults.
  - name: Billing
    description: Balance and transaction ledger of the API key's workspace.
  - name: Automations
    description: >-
      Native workspace automations — list, create, update, trigger. Requires
      Automations in the workspace plan.
  - name: Milian Missions
    description: Recurring jobs that Milian runs unattended on schedule.
  - name: Integrations
    description: >-
      Calendar integrations (Cal.com, Calendly, Acuity Scheduling, Google
      Calendar, Outlook, native booking engine). Assign them to assistants to
      provide availability and booking tools, plus provider-supported
      appointment lookup, cancellation, and rescheduling.
  - name: Bookings
    description: >-
      Native booking engine — event types with weekly availability, public
      booking pages at /book/{workspace}/{slug}, and the bookings they produce.
  - name: Dashboards
    description: >-
      Custom analytics dashboards, reusable widgets, and tenant-scoped
      performance analytics. Requires Custom dashboards in the workspace plan.
  - name: Catalog
    description: >-
      Read-only platform catalogs — available models, supported assistant
      languages, and prompt templates.
  - name: Simulations
    description: Assistant simulation tests (plan-gated).
  - name: Versions
    description: Assistant configuration version history.
  - name: Caller IDs
    description: Outbound caller ID verification.
  - name: Widgets
    description: Web widget connectors.
  - name: Messaging
    description: >-
      Telegram, Slack, and Messenger text bots linked to assistants (Chat SDK).
      Includes conversation delay, inactivity end, and conversation-ended
      webhooks.
  - name: QA
    description: Cohort AI Quality Assurance runs over call transcripts.
  - name: White Label
    description: >-
      Manage white-label customer accounts, defaults, credit transfers and
      customer plan offers. Each endpoint documents its required scope and
      workspace eligibility.
  - name: API Keys
    description: >-
      Self-service API keys for the calling workspace or a same-brand workspace
      where the credential's user is owner/admin. A key can only mint further
      keys with a scope subset of its own.
  - name: Workspaces
    description: >-
      List visible workspaces, create an additional workspace for the key owner,
      and mint a dedicated credential for a selected owner/admin workspace.
  - name: SMS
    description: Outbound SMS from workspace phone numbers.
  - name: Milian
    description: >-
      Ask Milian, the AI co-worker in your workspace, and start voice sessions
      with it.
  - name: Translation
    description: >-
      Live translation sessions that interpret a conversation between two
      languages.
paths:
  /tools/{id}:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
        description: Tool ID.
    patch:
      tags:
        - Tools
      summary: Update a tool
      description: >-
        Revision-protected partial update. `type` is immutable. Sending `•••`
        for a secret keeps the stored value. A provided `config` replaces the
        stored configuration: send back every header from the read response
        (masked values as `•••`); omitted headers are removed. A stale revision
        returns `409 revision_conflict`. **Required scope:** `assistants:write`.
      operationId: updateTool
      requestBody:
        required: true
        content:
          application/json:
            schema:
              allOf:
                - $ref: '#/components/schemas/UserToolInput'
                - type: object
                  required:
                    - expected_revision
            example:
              description: Look up an order by its number.
              is_active: false
              expected_revision: 4
      responses:
        '200':
          description: The updated tool (secret values masked).
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                properties:
                  data:
                    $ref: '#/components/schemas/UserTool'
              example:
                data:
                  id: f1b2c3d4-0000-4000-8000-000000000010
                  name: check_order_status
                  description: Look up the status of a customer order by order number.
                  type: api
                  config:
                    method: GET
                    url: https://api.example.com/orders/status
                    headers:
                      Authorization: •••
                    parameters:
                      - name: order_number
                        type: string
                        description: The order number
                        required: true
                        source: llm
                        location: query
                    static_values: {}
                    response_mapping: {}
                    timeout_ms: 10000
                    async: false
                    filler_phrase: One moment, I am checking that for you.
                  is_active: true
                  created_at: '2026-07-01T09:00:00Z'
                  updated_at: '2026-07-01T09:00:00Z'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '503':
          $ref: '#/components/responses/RequestProtectionUnavailable'
components:
  schemas:
    UserToolInput:
      type: object
      description: >-
        Create/update payload for a reusable tool. On update, `type` is
        immutable and sending `•••` for a secret config value keeps the stored
        value unchanged.
      properties:
        name:
          type: string
          pattern: ^[a-zA-Z][a-zA-Z0-9_-]{0,63}$
          description: Tool name — becomes the LLM function name.
        description:
          type: string
          maxLength: 1000
          description: What the tool does — shown to the LLM as the function description.
        type:
          type: string
          enum:
            - api
            - mcp
            - builtin
          description: >-
            `api` = HTTP API tool, `mcp` = external MCP server, `builtin` =
            built-in capability (call transfer & co.). Immutable after creation.
        config:
          type: object
          description: >-
            Type-specific configuration. `api`: `{ method, url, headers,
            parameters[], static_values, response_mapping, timeout_ms, async,
            filler_phrase, speak_after }`. `speak_after` (default true): when
            false, the tool completes silently without an LLM spoken reply.
            `mcp`: `{ url, auth_type, auth_header_name, auth_value_encrypted,
            allowed_tools[], tool_options: { [toolName]: { cancellable,
            on_duplicate, report_progress } }, timeout_ms }`; `on_duplicate` is
            allow, reject, replace, or confirm, and replace requires
            cancellation. `builtin`: exactly one built-in tool item `{ type:
            call_transfer|warm_call_transfer|end_call|…|collect_payment_card|set_variable,
            description?, stripe_connection_id? for collect_payment_card,
            allowed_keys? for set_variable, ... }` — same shape as one element
            of an assistant's `builtin_tools` array; secrets are masked as `•••`
            in responses. For warm_call_transfer, optional post_answer_dtmf
            accepts up to 32 characters (0-9*#A-D and w, case-insensitive); each
            w is a fixed half-second pause after answer and before the briefing.
            Omit or clear it for a direct destination. See BuiltinTool for field
            constraints. Saved caller-facing announcements, filler phrases and
            end-call farewells remain editable. With secondary languages
            configured on the assistant, they guide generated wording in the
            current supported conversation language without fixed saved audio.
            Otherwise their existing delivery behavior is preserved. An empty
            End call farewell adds no speech.
        is_active:
          type: boolean
          description: Whether the tool is active (default `true`).
        expected_revision:
          type: integer
          minimum: 1
          description: Required for PATCH to prevent lost concurrent updates.
    UserTool:
      type: object
      description: >-
        A reusable tool of the account. Secret values inside `config` (auth
        values, header values) are always masked as `•••`.
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
          description: >-
            Tool name — doubles as the LLM function name (letters, digits, `_`,
            `-`).
        description:
          type: string
          description: Human/LLM-readable description of what the tool does.
        type:
          type: string
          enum:
            - mcp
            - api
            - builtin
          description: >-
            `api` = HTTP API tool, `mcp` = external MCP server, `builtin` =
            built-in capability (call transfer, warm call transfer, end call,
            DTMF, keypad collection, Cal.com scheduling, assistant transfer).
        config:
          type: object
          description: >-
            Type-specific configuration (URL, method, parameters, auth). Secret
            values are masked.
        is_active:
          type: boolean
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ErrorEnvelope:
      type: object
      description: Error envelope returned by every /api/v1 endpoint on failure.
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              enum:
                - unauthorized
                - forbidden
                - api_access_required
                - not_found
                - invalid_request
                - rate_limited
                - conflict
                - telephony_configuration_error
                - telephony_unavailable
                - destination_forbidden
                - internal_error
                - service_unavailable
              description: >-
                Stable, machine-readable error code. `service_unavailable` is
                returned by POST /bookings and GET
                /booking-event-types/{id}/slots specifically when the
                availability engine could not be reached (see
                AvailabilityOrProtectionUnavailable).
            message:
              type: string
              description: Human-readable description of the error.
  responses:
    Unauthorized:
      description: Missing, invalid, expired or revoked API key / access token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: unauthorized
              message: Invalid API key.
    Forbidden:
      description: >-
        The credential lacks the required scope or role, or the workspace does
        not have the required capability.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          examples:
            scopeDenied:
              summary: Required scope is missing
              value:
                error:
                  code: forbidden
                  message: >-
                    This API key is missing the required scope
                    "assistants:write".
            apiAccessRequired:
              summary: API Access is not available
              value:
                error:
                  code: api_access_required
                  message: >-
                    API Access is not available for this workspace. Review
                    Settings → Plan.
    NotFound:
      description: Resource not found (or it belongs to another workspace).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: not_found
              message: Assistant not found
    Conflict:
      description: The resource is in a conflicting state.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: conflict
              message: Campaign is not running.
    RateLimited:
      description: Too many requests. Retry after the indicated delay.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 1
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: rate_limited
              message: Too many requests. Retry after the indicated delay.
    RequestProtectionUnavailable:
      description: Request protection is temporarily unavailable.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 1
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
          example:
            error:
              code: internal_error
              message: Request protection is temporarily unavailable.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: >-
        API key (`fam_...`, created under **Settings → API Keys**) or an OAuth
        2.0 access token (`fam_at_...`). REST operations also require API Access
        for the credential's workspace. Keys can be restricted to scopes such as
        `assistants:read`, `calls:write`, `campaigns:write`, `automations:read`,
        `dashboards:read`, `dashboards:write`, `leads:write`, `segments:write`,
        `loop:read`, `loop:write`, `phone_numbers:write`, `sip_trunks:write`,
        `knowledge:write`, `voices:read`, `billing:read`, `billing:write`,
        `settings:write`, `platform:read`, `platform:write`; a `*:write` scope
        implies the matching `*:read`. Automation and dashboard endpoints also
        accept the legacy `calls:*` scope. Keys without scope restrictions have
        full access within the workspace's available capabilities.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.