MCP tools

share_app

Give people, teams or the whole company access to an app.

Same rules as the Share dialog: Owners and admins can always share; Editors only when the app lets Editors share.

Share the lead tracker with [email protected] and the sales team, view only.

Parameters

appstringrequired

App name, address name, URL or id.

withstring[]required

Who to add, 1 to 50 entries. Each can be:

  • an email address: [email protected]
  • a person's name: Priya Shah
  • a team (group) name: the sales team, Finance. Use list_teams to see the workspace's teams.
  • company (or "everyone", "the whole company") for everyone at the company. See The whole company.
  • an id: usr_… or grp_…
rolestringdefault: viewer

viewer can open the app. editor can also deploy and change it.

general_accessstring

restricted (only people added), org (everyone at the company) or link (anyone with the link). Owner only. See General access.

notifybooleandefault: true

Email the people added.

messagestring

A note for the invite email. Up to 1,000 characters.

descriptionstring

For company in a company workspace: the one-line description shown in the company directory. Up to 140 characters. Defaults to the first sentence of the app's own description.

teamstring

For company in a company workspace: the team the app is listed under in the company directory. Up to 40 characters. Defaults to the app's team.

How names are matched

Names and groups are looked up in your workspace. "the sales team" is tried as written, then as "sales team", then as "sales". If any entry matches nobody, or more than one person, nothing is shared. The tool returns the candidates so your AI tool can ask you which one you meant.

The whole company

In a company workspace, everyone at the company gets an app through the company directory. So company (or general_access: "org") submits the app to the directory, with description and team:

  • If the workspace has one team, the app is listed under it. If it has none, it is listed under team or the app's team, else General. If it has several and team does not name one, nothing is submitted and the tool asks which team (team_required).
  • Depending on the workspace's policy, the app is listed at once, or an admin approves it first and you get an email with the decision.
  • general_access: "restricted" on a listed app asks to take it out of the directory, the same as unlist_from_directory.

To pick the description and team yourself, or add a README, use submit_to_directory.

Result

app_idstring
The app's id.
addedobject[]
Each person or group added: type, id, name, role.
invited_emailsnumber
How many invite emails were sent.
skippedobject[]
Entries skipped because they already had access or were not allowed.
generalstring | null
The general access setting after the call, if it changed.
blocked_reasonstring
Why general access did not change, when people were still added.
directoryobject
When the call submitted or unlisted the app in the company directory: status and request_id (set when an admin has to approve).
Example
Shared Lead Tracker with Priya Shah (viewer), Sales (viewer). 1 invite email sent.

Errors

CodeWhen
ambiguousA name matched more than one person or group. Nothing was shared.
guests_not_allowedAn email outside the company, with guests turned off.
scan_failedorg access while the latest version has blocking issues.
team_requiredcompany in a workspace with several teams, and team names none of them. Nothing was submitted.
payment_requiredThe workspace's 7 free days are over. Sharing needs a plan.
policy_blockedlink access while public links are off.
forbiddenYou cannot share this app.