Skip to content

REST tools from OpenAPI

Operations of any REST API with an OpenAPI 3 document can be shared as tool.rest capabilities, one per operation, with the operation’s input schema. The provider’s node calls the API with credentials named from the provider’s secrets (a bearer token, an API key, HTTP basic, or OAuth from the document’s security scheme):

Terminal window
bnw rest import ./openapi.yaml # prints its hash, servers, auth schemes, operations
bnw rest share <SPEC_HASH> listPets getPet --server https://api.example.com/v1 \
--auth api-key --api-key-name X-API-Key --secret-env PETS_API_KEY --allow-remote-execution

The server is fixed when sharing, and only public addresses are reached unless allowed. Operations that change data need --allow-side-effects. Each operation is pinned, so a changed document pauses it until it is shared again. REST.md covers inputs and outputs, authentication, and the safety rules.