> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Adopt a reviewed A2A source revision

> Adopt one A2A ToolSource revision only when its complete ordered ES256 keyset and card URL exactly match the host's current configured ProviderPackage. The required Idempotency-Key and request compare-and-swap the ToolSource and name the exact version of every non-revoked dependent Connection; each dependent package binding must advance monotonically, declare its predecessor compatible, preserve or raise its visible review tier, and continue to contain that Connection's scopes, Principal-qualified custody binding, and egress. Discovery verifies the candidate card before publication, existing Tool enablement remains stable by name, and an exact retry resumes any already-migrated Connection without trusting a card-named key.

Checkfu support posture: alpha; hosted. Required evidence journey: capability-catalog. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json post /v1/tool-sources/{id}/source-revisions
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: sandboxProfiles
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: sessionHandoffs
  - name: sessionCapsules
  - name: sessionTrajectories
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/tool-sources/{id}/source-revisions:
    post:
      tags:
        - toolSources
      summary: Adopt a reviewed A2A source revision
      description: >-
        Adopt one A2A ToolSource revision only when its complete ordered ES256
        keyset and card URL exactly match the host's current configured
        ProviderPackage. The required Idempotency-Key and request
        compare-and-swap the ToolSource and name the exact version of every
        non-revoked dependent Connection; each dependent package binding must
        advance monotonically, declare its predecessor compatible, preserve or
        raise its visible review tier, and continue to contain that Connection's
        scopes, Principal-qualified custody binding, and egress. Discovery
        verifies the candidate card before publication, existing Tool enablement
        remains stable by name, and an exact retry resumes any already-migrated
        Connection without trusting a card-named key.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        capability-catalog. Deployment-specific readiness and the latest proven
        release are available from GET /v1/support/capabilities.
      operationId: toolSources.reviseToolSource
      parameters:
        - name: id
          in: path
          schema:
            $ref: '#/components/schemas/ToolSourceId'
          required: true
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
        - name: idempotency-key
          in: header
          schema:
            type: string
            allOf:
              - maxLength: 255
              - minLength: 1
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                expected_version:
                  type: integer
                  allOf:
                    - exclusiveMinimum: 0
                source:
                  $ref: '#/components/schemas/Objects_80'
                provider_package:
                  type: object
                  properties:
                    name:
                      type: string
                      allOf:
                        - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
                    version:
                      type: integer
                      allOf:
                        - exclusiveMinimum: 0
                    digest:
                      type: string
                      allOf:
                        - pattern: ^sha256:[0-9a-f]{64}$
                  required:
                    - name
                    - version
                    - digest
                  additionalProperties: false
                connections:
                  $ref: '#/components/schemas/ToolSourceConnectionRevisions'
              required:
                - expected_version
                - source
                - provider_package
                - connections
              additionalProperties: false
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  tool_source:
                    $ref: '#/components/schemas/Objects_81'
                  provider_package:
                    type: object
                    properties:
                      name:
                        type: string
                        allOf:
                          - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
                      version:
                        type: integer
                        allOf:
                          - exclusiveMinimum: 0
                      digest:
                        type: string
                        allOf:
                          - pattern: ^sha256:[0-9a-f]{64}$
                      review:
                        $ref: '#/components/schemas/Union_144'
                    required:
                      - name
                      - version
                      - digest
                      - review
                    additionalProperties: false
                  connection_count:
                    type: integer
                    allOf:
                      - minimum: 0
                        maximum: 10000
                required:
                  - tool_source
                  - provider_package
                  - connection_count
                additionalProperties: false
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - validation.malformed
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#validation-malformed
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    required:
                      - type
                      - message
                      - more
                    additionalProperties: false
                additionalProperties: false
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '409':
          description: >-
            The request conflicts with the resource's current state. | An
            idempotent mutation conflicts with a completed or in-progress
            request for the same key.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ValidationConflictError'
                  - $ref: '#/components/schemas/IdempotencyConflictError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    ToolSourceId:
      type: string
      allOf:
        - pattern: ^ts_[0-9a-f]{32}$
    Objects_80:
      type: object
      properties:
        kind:
          type: string
          enum:
            - a2a
        card_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        verification_keys:
          $ref: '#/components/schemas/A2aEs256PublicJwkSet'
      required:
        - kind
        - card_url
        - verification_keys
      additionalProperties: false
    ToolSourceConnectionRevisions:
      type: array
      items:
        type: object
        properties:
          connection_id:
            $ref: '#/components/schemas/ConnectionId'
          expected_version:
            type: integer
            allOf:
              - exclusiveMinimum: 0
        required:
          - connection_id
          - expected_version
        additionalProperties: false
      allOf:
        - maxItems: 10000
    Objects_81:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/ToolSourceId'
        workspace_id:
          $ref: '#/components/schemas/WorkspaceId'
        name:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        provider:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        description:
          anyOf:
            - type: string
              allOf:
                - maxLength: 16384
            - type: 'null'
        source:
          $ref: '#/components/schemas/Union_142'
        status:
          $ref: '#/components/schemas/Union_143'
        default_enabled:
          type: boolean
        default_permission:
          type: string
          enum:
            - always_ask
            - always_allow
        tool_count:
          type: integer
          allOf:
            - minimum: 0
        last_sync_at:
          anyOf:
            - type: string
            - type: 'null'
        last_sync_error_code:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 8192
            - type: 'null'
        version:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        created_at:
          type: string
        updated_at:
          type: string
      required:
        - id
        - workspace_id
        - name
        - provider
        - description
        - source
        - status
        - default_enabled
        - default_permission
        - tool_count
        - last_sync_at
        - last_sync_error_code
        - version
        - created_at
        - updated_at
      additionalProperties: false
    Union_144:
      type: string
      enum:
        - curated
        - structural
        - unreviewed
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    ValidationConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.conflict
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The request conflicts with the resource's current state.
    IdempotencyConflictError:
      anyOf:
        - $ref: '#/components/schemas/ValidationIdempotencyConflictError'
        - $ref: '#/components/schemas/ValidationIdempotencyInProgressError'
      description: >-
        An idempotent mutation conflicts with a completed or in-progress request
        for the same key.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    PublicHttpsUrl:
      type: string
      allOf:
        - pattern: ^https:\/\/[^\s]+$
        - maxLength: 2048
    A2aEs256PublicJwkSet:
      type: array
      items:
        type: object
        properties:
          kty:
            type: string
            enum:
              - EC
          crv:
            type: string
            enum:
              - P-256
          x:
            type: string
            allOf:
              - minLength: 43
              - maxLength: 43
              - pattern: ^[A-Za-z0-9_-]+$
          'y':
            type: string
            allOf:
              - minLength: 43
              - maxLength: 43
              - pattern: ^[A-Za-z0-9_-]+$
          kid:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 1024
          alg:
            type: string
            enum:
              - ES256
        required:
          - kty
          - crv
          - x
          - 'y'
          - kid
          - alg
        additionalProperties: false
      allOf:
        - minItems: 1
        - maxItems: 16
    ConnectionId:
      type: string
      allOf:
        - pattern: ^conn_[0-9a-f]{32}$
    Union_142:
      anyOf:
        - type: object
          properties:
            kind:
              type: string
              enum:
                - mcp
            url:
              $ref: '#/components/schemas/PublicHttpsUrl'
            authenticated:
              type: boolean
          required:
            - kind
            - url
          additionalProperties: false
        - type: object
          properties:
            kind:
              type: string
              enum:
                - openapi
            document_url:
              $ref: '#/components/schemas/PublicHttpsUrl'
            base_url:
              $ref: '#/components/schemas/CredentialFreeHttpsUrl'
          required:
            - kind
            - document_url
            - base_url
          additionalProperties: false
        - type: object
          properties:
            kind:
              type: string
              enum:
                - api
            base_url:
              $ref: '#/components/schemas/CredentialFreeHttpsUrl'
            tools:
              type: array
              items:
                $ref: '#/components/schemas/Objects_76'
              allOf:
                - maxItems: 1000
          required:
            - kind
            - base_url
            - tools
          additionalProperties: false
        - $ref: '#/components/schemas/Objects_80'
        - type: object
          properties:
            kind:
              type: string
              enum:
                - connector
            source_digest:
              type: string
              allOf:
                - pattern: ^sha256:[0-9a-f]{64}$
            tools:
              type: array
              items:
                $ref: '#/components/schemas/Objects_76'
              allOf:
                - maxItems: 1000
          required:
            - kind
            - source_digest
            - tools
          additionalProperties: false
    Union_143:
      type: string
      enum:
        - pending
        - healthy
        - sync_failed
    ValidationIdempotencyConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_conflict
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The Idempotency-Key is already bound to a different request.
    ValidationIdempotencyInProgressError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_in_progress
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-in-progress
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An identical idempotent request is still in progress and may be retried
        later.
    CredentialFreeHttpsUrl:
      type: string
      allOf:
        - pattern: ^https:\/\/[^\s]+$
        - maxLength: 2048
    Objects_76:
      type: object
      properties:
        name:
          type: string
          allOf:
            - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
        description:
          type: string
          allOf:
            - maxLength: 16384
        input_schema:
          $ref: '#/components/schemas/JsonValue'
        output_schema:
          $ref: '#/components/schemas/JsonValue'
        safety_hints:
          $ref: '#/components/schemas/Objects_77'
        http:
          type: object
          properties:
            method:
              $ref: '#/components/schemas/HttpMethod'
            path_template:
              type: string
              allOf:
                - minLength: 1
                - maxLength: 8192
                - pattern: ^\/[^\r\n?#]*$
            arguments:
              $ref: '#/components/schemas/Objects_78'
          required:
            - method
            - path_template
            - arguments
          additionalProperties: false
        a2a:
          $ref: '#/components/schemas/Objects_79'
        integration:
          type: object
          properties:
            digest:
              type: string
              allOf:
                - pattern: ^sha256:[0-9a-f]{64}$
          required:
            - digest
          additionalProperties: false
      required:
        - name
      additionalProperties: false
    JsonValue:
      description: >-
        A value in the JSON data model: null, boolean, finite number, string,
        array, or object.
    Objects_77:
      type: object
      properties:
        read_only:
          type: boolean
        destructive:
          type: boolean
        requires_approval:
          type: boolean
      required:
        - read_only
        - destructive
        - requires_approval
      additionalProperties: false
    HttpMethod:
      type: string
      enum:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
        - HEAD
        - OPTIONS
    Objects_78:
      type: object
      properties:
        path:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                type: string
                allOf:
                  - minLength: 1
                  - maxLength: 128
                  - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
        query:
          type: object
          additionalProperties:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 128
              - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
          allOf:
            - propertyNames:
                $ref: '#/components/schemas/ToolHttpQueryName'
        body:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 128
                - pattern: ^[A-Za-z_][A-Za-z0-9_.-]*$
            - type: 'null'
      required:
        - path
        - query
        - body
      additionalProperties: false
    Objects_79:
      type: object
      properties:
        kind:
          type: string
          enum:
            - a2a
        card_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        endpoint_url:
          $ref: '#/components/schemas/PublicHttpsUrl'
        tenant:
          anyOf:
            - type: string
              allOf:
                - minLength: 1
                - maxLength: 1024
            - type: 'null'
        skill_id:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 1024
        card_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        endpoint_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        verification_keyset_fingerprint:
          type: string
          allOf:
            - pattern: ^sha256:[0-9a-f]{64}$
        streaming:
          type: boolean
        push_notifications:
          type: boolean
        authentication:
          anyOf:
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - bearer
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - oauth2
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
                flow:
                  type: string
                  enum:
                    - authorization_code
                scopes:
                  $ref: '#/components/schemas/ConnectionScopes'
              required:
                - kind
                - scheme_name
                - flow
                - scopes
              additionalProperties: false
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - mtls
                scheme_name:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 1024
              required:
                - kind
                - scheme_name
              additionalProperties: false
      required:
        - kind
        - card_url
        - endpoint_url
        - tenant
        - skill_id
        - card_fingerprint
        - endpoint_fingerprint
        - verification_keyset_fingerprint
      additionalProperties: false
    ConnectionScopes:
      type: array
      items:
        $ref: '#/components/schemas/ConnectionScope'
      allOf:
        - maxItems: 256
    ConnectionScope:
      type: string
      allOf:
        - minLength: 1
        - maxLength: 512
        - pattern: ^[^\s,]+$
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````