Actions
Web searchtavily.searchrisk: read
Searches the web with Tavily and returns titles, URLs and snippets.
- Query *
query - What to search the web for.
- Max results
maxResults - How many results to return. 1 to 20. Default
5. - Topic
topicone of general, news, finance - news = recent articles with a publish date. Blank = general web.
- Time range
timeRangeone of day, week, month, year - Only results from the last day, week, month or year. Blank = any time.
- Depth
searchDepthone of basic, advanced - advanced = more relevant snippets, 2 credits instead of 1. Blank = basic.
- Only these sites
includeDomains - Restrict results to these domains, one per row. Blank = the whole web.
Crawls a website with Tavily and returns each page's text, or just its URLs in map mode.
- Start URL *
url - Root of the site to crawl.
- Mode
modeone of crawl, map - crawl = pages with their text; map = only the list of URLs found (cheaper: 1 credit per 10 pages). Default
"crawl". - Instructions
instructions - Optional: which pages matter, in plain words. Doubles the mapping cost.
- Max depth
maxDepth - How many links deep from the start URL. 1 to 5. Default
1. - Links per page
maxBreadth - How many links to follow from each page. 1 to 500. Default
20. - Max pages
limit - Stop after this many pages. 1 to 500; every page costs credits. Default
50. - Only paths
selectPaths - Regex patterns; only matching paths are crawled.
- Skip paths
excludePaths - Regex patterns for paths to skip.
- Leave the site
allowExternal - Follow links to other domains. Off keeps the crawl on the start URL's site. Default
false. - Format
formatone of markdown, text - crawl only: markdown or plain text. Default
"markdown". - Max characters per page
maxChars - Each page's text is cut here so a big site cannot flood the next step. 500 to 200,000. Default
20000.
Runs a Tavily research task and returns a cited report (content plus sources).
- Question *
input - What to research, in plain words.
- Model
modelone of mini, pro, auto - mini = 4 to 110 credits; pro = 15 to 250 credits, deeper; auto lets Tavily pick. Default
"mini". - Request id
requestId - Set to check on an earlier research task instead of starting a new one.
- Wait (s)
waitSec - How long to poll for the finished report. 0 returns the request id at once. Max 600. Default
180.
Lists the tools an external MCP server offers, with their input schemas.
- Server URL *
url - The MCP server's Streamable HTTP endpoint. Set by you, never by the model.
- Authentication
authTypeone of none, basic, bearer, header, query, oauth2 - none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default
"none". - Secret
authSecret - Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
- Username
authUser - Basic auth user name. Empty = the secret is user:password.
- Key name
authName - Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
- OAuth2 connection
authConnection - Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.
Calls one tool on an external MCP server, from the list of tools you allowed.
- Server URL *
url - The MCP server's Streamable HTTP endpoint. Set by you, never by the model.
- Authentication
authTypeone of none, basic, bearer, header, query, oauth2 - none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default
"none". - Secret
authSecret - Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
- Username
authUser - Basic auth user name. Empty = the secret is user:password.
- Key name
authName - Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
- OAuth2 connection
authConnection - Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.
- Allowed tools *
allowedTools - Exact tool names this node may call, one per row. Anything else is refused. Use mcp.tools to see what the server offers.
- Trusted tools
trustedTools - Subset of the allowed tools you have checked yourself and consider ordinary (a search, a lookup). They drop from “always asks a person” to your normal guardrail for messages. Leave empty if in doubt.
- Tool *
tool - Which of the allowed tools to call.
- Arguments
args - The tool's arguments as JSON, matching the schema mcp.tools reported.
Open a GitHub issuegithub.issuerisk: external-commswrites to an external system
Creates an issue in a GitHub repository.
- Repository *
repo - owner/name of the repository. Your github credential needs write access.
- Title *
title - Issue title. Expressions allowed.
- Description
body - Issue body, Markdown.
Finds Jira issues with a JQL query.
- JQL *
jql - Jira Query Language filter.
- Max results
maxResults - How many issues to return. 1 to 500. Default
20.
HTTP GEThttp.getrisk: read
Fetches a URL from an allowlisted host and returns JSON or text.
- URL *
url - Address to fetch. Its host must be in the allowlist.
- Headers
headers - Extra request headers, e.g. {"authorization": "Bearer {{secret.github}}"}. A saved secret goes only to its allowed hosts and never shows in the run.
- Allowed hosts
allowlist - Hosts this node may reach, one per row. Empty = the node refuses.
- Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - Authentication
authTypeone of none, basic, bearer, header, query, oauth2 - none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default
"none". - Secret
authSecret - Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
- Username
authUser - Basic auth user name. Empty = the secret is user:password.
- Key name
authName - Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
- OAuth2 connection
authConnection - Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.
HTTP POSThttp.postrisk: writewrites to an external system
Sends a POST, PUT, PATCH or DELETE request to an allowlisted host.
- URL *
url - Address to send to. Its host must be in the allowlist.
- Method
methodone of POST, PUT, PATCH, DELETE - HTTP verb. Use HTTP GET for reads. Default
"POST". - Body
body - Request body. Text is sent as-is; a JSON object is encoded.
- Content type
contentType - Value of the content-type header. Default
"application/json". - Headers
headers - Extra request headers, e.g. {"authorization": "Bearer {{secret.github}}"}. A saved secret goes only to its allowed hosts and never shows in the run.
- Allowed hosts
allowlist - Hosts this node may reach, one per row. Empty = the node refuses.
- Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - Authentication
authTypeone of none, basic, bearer, header, query, oauth2 - none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default
"none". - Secret
authSecret - Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
- Username
authUser - Basic auth user name. Empty = the secret is user:password.
- Key name
authName - Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
- OAuth2 connection
authConnection - Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.
Runs another agent inline and returns its result.
- Agent *
agentSlug - Slug of the agent to run. It runs inline and is billed to this run.
- Workflow
workflow - Name of one of the agent's workflows to run. Blank = its primary workflow.
- Input
input - Run input handed to the called agent's trigger, as key/value pairs.
- Timeout (ms)
timeoutMs - Give up after this long. 1,000 to 7,200,000 (2 h): cover the callee's longest code session. Default
60000.
Builds a string from a template filled with upstream values.
- Template *
template - Text with {0} for the first input, {1.title} for a path into the second, {name} for {0.name}.
Compares values and routes to the true or false branch.
- Left value *
left - Usually an expression, e.g. {{fetch.items.length}}.
- Operator
opone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex - How the two values are compared. Default
"truthy". - Right value
right - Ignored by is truthy / falsy / empty / not empty / exists.
- Compare as
typeone of auto, string, number, boolean, date - auto reads numbers as numbers, else text. Pick number, date, boolean or string to force one. Default
"auto". - Conditions
conditions - Several conditions, as JSON [{left, op, right, type}]. When set, the single condition above is ignored.
- Combine
combineone of and, or - and = all conditions must hold, or = any one is enough. Default
"and".
Routes to the branch whose case matches a value, else default.
- Value to route on *
value - Usually an expression; its value picks the branch.
- Cases
cases - Each case becomes a branch, plus default when nothing matches.
- Case sensitive
caseSensitive - Treat Urgent and urgent as different cases. Default
false.
Runs one node (or agent) once per item of an array.
- Node per item *
node - Node type to run once for every item.
- Agent per item
agentSlug - Run this agent's whole graph per item instead of a single node.
- Workflow per item
workflow - Agent-per-item mode: name of the agent's workflow to run. Blank = its primary workflow.
- Timeout per item (ms)
timeoutMs - Agent-per-item mode only. 1,000 to 300,000. Default
60000. - Child config *
config - Config for the per-item node. Use {{item}}, {{item.title}} and {{index}}.
- Max items
maxItems - Hard cap, 1 to 100. Every item can be a paid call. Default
25. - Items field
itemsField - Path to the array inside the input. Blank = the input itself.
Keeps only the array items that match a condition.
- Item field
field - Path inside each item to test. Blank = the item itself.
- Operator
opone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex - How the field is compared to the value. Default
"truthy". - Compare to
value - Right-hand value. Ignored by is truthy / falsy / empty / not empty.
- Max kept
max - Keep at most this many matching items. 1 to 500. Default
100. - Items field
itemsField - Path to the array inside the input. Blank = the input itself.
Mergemergerisk: destructive
Waits for every input and combines them: append, by position, by matching field, or pick one.
- Mode
modeone of append, position, field, choose - append: all items one after another. position: item 1 with item 1, 2 with 2. field: items whose field values match. choose: one input as it is, once all have finished. Default
"append". - Items field
itemsField - Path to the list inside each input. Blank = the input itself.
- Match field (input 1)
field - Mode field: path inside each input-1 item to match on.
- Match field (other inputs)
field2 - Mode field: path inside the other inputs' items. Blank = same as input 1.
- Keep
joinone of inner, left, outer - Mode field. inner: only matches. left: every input-1 item, enriched when it matches. outer: every item of both sides. Default
"inner". - Keep unpaired items
includeUnpaired - Mode position: when inputs differ in length, keep the extra items instead of dropping them. Default
false. - Input to pass on
input - Mode choose: 1 = the first connected input, 2 = the second. 0 = whichever input ran first. Default
1.
Pauses for a fixed delay, then passes its input on.
- Delay (ms)
ms - How long to pause before passing the input on. 0 to 30,000. Default
1000.
Post to Slackslack.postrisk: external-commswrites to an external system
Posts a message to a Slack channel.
- Webhook URL
webhookUrl - Slack incoming-webhook URL. Wins over the bot token when set.
- Channel
channel - #channel or a channel id. Needed when posting with the bot token.
- Message *
text - What to post. Slack mrkdwn works.
Append to Notionnotion.appendrisk: writewrites to an external system
Appends a paragraph to a Notion page or adds a database row.
- Page or database id *
parentId - The 32-character id from the Notion URL. Share the page with your integration first.
- Target
targetone of page, database - page appends a paragraph; database creates a row. Default
"page". - Title property
titleProperty - Name of the title column. Database target only. Default
"Name". - Text *
text - Paragraph text, or the new row's title.
Appends one row to a Google Sheet.
- Spreadsheet id *
spreadsheetId - The long id in the sheet URL, between /d/ and /edit.
- Range
range - Sheet and start cell in A1 notation; the row is appended below existing data. Default
"Sheet1!A1". - Row values *
values - One cell per row here, left to right. Parsed as if typed into the sheet.
Send an emailemail.sendrisk: external-commswrites to an external system
Sends a plain-text email through Resend.
- From *
from - Sender address. Its domain must be verified with your email provider.
- To *
to - One address, or several separated by commas.
- Subject *
subject - Subject line. Expressions allowed.
- Body *
text - Plain-text message body.
- API URL
apiUrl - A Resend-compatible endpoint. The key comes from your resend credential. Default
"https://api.resend.com/emails". - Allowed hosts
allowlist - Hosts the API key may be sent to. Empty = the node refuses to send. Default
["api.resend.com"].
Builds a new object by picking fields out of the input.
- Fields *
fields - JSON object mapping output keys to {path} of the input, e.g. {"title": "{items.0.title}"}. A bare {path} keeps the raw value.
Open a pull requestgithub.pr.createrisk: writewrites to an external system
Opens a pull request, as a draft by default.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Title *
title - Pull request title. Expressions allowed.
- Description
body - Pull request body, Markdown.
- Head branch *
head - The branch with the changes. owner:branch for a fork.
- Base branch
base - The branch to merge into. Default
"main". - Draft
draft - Open as a draft. Heavy CI often waits for ready-for-review. Default
true.
Mark pull request readygithub.pr.readyrisk: writewrites to an external system
Takes a draft pull request out of draft so it can be reviewed and merged.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Pull request *
number - Pull request number. Expressions allowed.
Reads a pull request: state, draft, mergeable, review decision and head commit.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Pull request *
number - Pull request number. Expressions allowed.
Request a reviewgithub.pr.review.requestrisk: writewrites to an external system
Asks people or teams to review a pull request.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Pull request *
number - Pull request number. Expressions allowed.
- Reviewers *
reviewers - GitHub logins to ask for a review.
- Teams
teams - Team slugs to ask for a review.
CI statusgithub.checksrisk: read
Combines check runs (or Actions runs) and commit statuses for a commit into green, red or pending, with failing names.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Commit or branch *
ref - Commit SHA (best: a pull request's head SHA), branch or tag.
Preview URLgithub.previewrisk: read
Finds the preview deployment of a commit or branch (Vercel, Netlify, any GitHub deployment) and its URL.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Commit or branch *
ref - The pushed branch or its head SHA.
- Environment
environment - Deployment environment name, e.g. Preview. Blank = the newest non-production deployment.
Merge a pull requestgithub.pr.mergerisk: deploywrites to an external system
Merges a pull request (squash by default), guarded by the expected head commit, one merge per repository at a time.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Pull request *
number - Pull request number. Expressions allowed.
- Expected head SHA
sha - Merge only if the head is still this commit, the one that was reviewed and tested. Blank = no guard.
- Merge method
methodone of squash, merge, rebase - Must be allowed in the repository's settings. Default
"squash". - Commit title
commitTitle - Title of the merge commit. Blank = GitHub's default.
- Delete branch
deleteBranch - Delete the head branch after a successful merge (same-repository branches only). Default
false.
Delete a branchgithub.branch.deleterisk: destructivewrites to an external system
Deletes a branch from a GitHub repository. The default branch is refused by GitHub.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- Branch *
branch - Name of the branch to delete, without refs/heads/.
Reads a text file from a GitHub repository at a branch or commit.
- Repository *
repo - owner/name of the repository. Uses your github credential.
- File path *
path - Path of the file inside the repository.
- Branch or commit
ref - Read the file at this branch, tag or SHA. Blank = default branch.
Reads a Jira issue: fields, description text, acceptance criteria, epic, links and recent comments.
- Issue key *
issueKey - The Jira issue. Expressions allowed.
Move a Jira issuejira.transitionrisk: writewrites to an external system
Moves a Jira issue to a status by name, using whichever workflow transition leads there.
- Issue key *
issueKey - The Jira issue. Expressions allowed.
- Target status *
status - Status name to move the issue to, as shown on the board. Case does not matter.
Add a Jira labeljira.label.addrisk: writewrites to an external system
Adds a label to a Jira issue, keeping its other labels.
- Issue key *
issueKey - The Jira issue. Expressions allowed.
- Label *
label - One label. Jira labels cannot contain spaces.
Remove a Jira labeljira.label.removerisk: writewrites to an external system
Removes a label from a Jira issue, keeping its other labels.
- Issue key *
issueKey - The Jira issue. Expressions allowed.
- Label *
label - One label. Jira labels cannot contain spaces.
Assign a Jira issuejira.assignrisk: writewrites to an external system
Sets or clears the assignee of a Jira issue by Atlassian account ID.
- Issue key *
issueKey - The Jira issue. Expressions allowed.
- Account ID
accountId - Atlassian account ID of the new assignee. Blank = unassign.
Create a Jira issuejira.issue.createrisk: external-commswrites to an external system
Creates a Jira issue and returns its key and link.
- Project key *
project - The Jira project the issue is created in.
- Issue type
issueType - Task, Bug, Story, ... as named in the project. Default
"Task". - Summary *
summary - One-line title of the issue.
- Description
description - Plain text. Blank lines start paragraphs, lines starting with "- " become bullets.
- Labels
labels - Comma-separated, or a JSON array. Spaces inside a label become dashes.
- Priority
priority - Priority name. Blank = the project default.
- Assignee
assignee - Email or Atlassian account ID. Blank = unassigned.
- Parent / epic
parent - Issue key of the parent or epic. Blank = none.
Code sessioncode.sessionrisk: readwrites to an external system
Runs a Claude Code session in a git worktree on your local runner, pushes the branch and returns it.
- Repository *
repo - Absolute path of a git repo on the runner machine, or an https/ssh git URL to clone.
- Base branch
baseBranch - The session branches off this. Never written to. Default
"main". - Branch name
branchName - New branch for the session. {slug} = first words of the prompt, {rand} = random, {date} = YYYYMMDD. Default
"code/{slug}-{rand}". - Task *
prompt - What the session should do, in plain words.
- Role
systemPrompt - Appended to Claude Code's system prompt, e.g. the role and its rules.
- Profile
profileone of readonly, edit - readonly = look, never change files; edit = may edit and commit on its own branch. Default
"readonly". - Max turns
maxTurns - Hard cap on agent turns. 1 to 200. Default
30. - Timeout (s)
timeoutSec - The session is killed after this long. 30 to 14,400. Default
1800. - House rules
houseRulesPaths - Repo-relative files or folders of .md rules handed to the session, one per row.
- Push branch
push - After an edit session with commits, the runner pushes the branch to origin (its own git credentials; the session never pushes). CODE_SESSION_PUSH=0 on the runner turns it off everywhere. Default
true. - Push required
pushRequired - A failed or skipped (capped) push fails the node instead of returning pushError. Default
false.
Pauses the run until you approve or reject it in Messages.
- Title *
title - What is being approved, in one line.
- Checklist
checklist - Markdown list. Every item must be ticked before Approve is possible. Expressions allowed.
- Details
details - Markdown shown under the checklist: audit findings, a diff summary, a link.
- Approvers
approversone of owner - Who can decide. For now the person whose run it is. Default
"owner". - On reject
onRejectone of fail, branch - fail stops the run; branch routes to the rejected edge instead. Default
"fail". - No dashes
noDashes - Replace em dashes and spaced en dashes with a comma, as output.card does. Ranges like 2019-2020 stay.
- Timeout (hours)
timeoutHours - How long the run waits for a person. Default 168 (7 days), max 720. Default
168.
Pauses the run to ask you a question in Messages; your answer is the output.
- Question *
question - One question, answerable in a word if you can.
- Context
context - Markdown under the question: what you would do and why.
- Answer options
answerOptions - One per line; shown as buttons. A typed answer is still possible.
- Ask
escalateToone of owner - Who gets the question. For now the person whose run it is. Default
"owner". - Human only
humanOnly - A product decision: refuse answers from API tokens and MCP (an orchestrating AI). Default
false. - Default answer
fallback - Used when nobody answers in time. Empty = the run fails.
- Timeout (hours)
timeoutHours - How long the run waits for a person. Default 168 (7 days), max 720. Default
168.
Starts (or reuses) this run's browser session and outputs {sessionId}.
- New session
newSession - Open an additional browser instead of this run's shared one. Default
false. - Persistent profile
profile - Blank = a fresh browser that forgets everything at the end of the run. A name (lowercase letters, digits and dashes) opens a Chromium profile that survives runs, so a site login done once is still there next time. One run at a time per profile.
- Record the screen
video - Film this browser as a webm. The Close browser node saves it as a run file; without that node the recording is thrown away. Default
false. - Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit".
Go to URLbrowser.gotorisk: read
Navigates the browser to a URL and returns where it landed.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- URL *
url - http(s) address to open. Private and local addresses are refused.
Clickbrowser.clickrisk: writewrites to an external system
Clicks an element found by a stable locator (role, label, text, css…).
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default
{"by":"css","value":""}. - Button
buttonone of left, right - Mouse button. Default
"left". - Double click
double - Click twice. Default
false. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000. - If blocked
onBlockedone of fail, branch, handoff - Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default
"fail".
Fill fieldbrowser.fillrisk: writewrites to an external system
Types a value or a saved secret into an input; secrets are masked everywhere.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default
{"by":"css","value":""}. - Value
value - Text to type. Leave blank when using a saved secret.
- Saved secret
secret - Name of a secret saved in Settings (secret:<name>). Filled at run time, never shown or logged.
- Press Enter
submit - Press Enter after filling. Default
false. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000. - If blocked
onBlockedone of fail, branch, handoff - Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default
"fail".
Select optionbrowser.selectrisk: writewrites to an external system
Chooses an option in a <select> by value or label.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default
{"by":"css","value":""}. - Option *
value - Option value or visible label.
- Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000.
Check boxbrowser.checkrisk: writewrites to an external system
Ticks or unticks a checkbox or radio button.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default
{"by":"css","value":""}. - Checked
checked - On = tick the box, off = untick it. Default
true. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000.
Press keybrowser.pressrisk: external-commswrites to an external system
Presses a key, in an element or wherever the focus is.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Key
key - Playwright key name: Enter, Tab, Escape, ArrowDown, Control+A… Default
"Enter". - Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default
{"by":"css","value":""}. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000.
Hoverbrowser.hoverrisk: read
Moves the mouse over an element, e.g. to open a menu.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default
{"by":"css","value":""}. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000.
Scrollbrowser.scrollrisk: read
Scrolls an element into view, or the page by some pixels.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default
{"by":"css","value":""}. - Pixels
dy - Without an element: scroll by this much, positive = down. Default
600.
Wait forbrowser.waitrisk: read
Waits for an element, a URL, some text, network idle or a fixed time.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Wait until
untilone of visible, hidden, url, text, network_idle, ms - visible / hidden = the element; url = the address contains the text; text = the page shows it; network_idle; ms = a fixed pause. Default
"visible". - Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default
{"by":"css","value":""}. - Text or URL part
text - For url and text.
- Pause (ms)
ms - For ms. 0 to 30,000. Default
1000. - Timeout (ms)
timeoutMs - How long to wait for the element. 100 to 60,000. Default
10000. - If blocked
onBlockedone of fail, branch, handoff - Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default
"fail".
Assert pagebrowser.assertrisk: read
Checks the page and routes to the pass or fail branch.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Check
checkone of text_contains, text_equals, visible, hidden, exists, value_equals, count_equals, url_contains, title_contains - What must be true. url_contains and title_contains need no element. Default
"text_contains". - Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default
{"by":"css","value":""}. - Expected
expected - Text, value or count to compare with.
- Retry for (ms)
timeoutMs - Keep checking this long before reporting fail. 0 to 60,000. Default
5000.
Screenshotbrowser.screenshotrisk: read
Captures the page or one element as run evidence (PNG).
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Full page
fullPage - The whole scrollable page instead of the visible part. Default
false. - Element
locator - Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default
{"by":"css","value":""}.
Compact accessibility tree with [ref_N] ids, for an AI agent to decide what to click.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Interactive only
interactiveOnly - Only links, buttons and inputs: far shorter. Default
true. - Max characters
maxChars - Cut the snapshot here. 500 to 20,000. Default
6000.
Save cookiesbrowser.cookies.saverisk: read
Stores the browser's cookies encrypted under a name, so a login survives runs.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Name *
name - Your name for this saved login, e.g. the site. Stored encrypted as cookies:<name>.
Load cookiesbrowser.cookies.loadrisk: read
Restores cookies saved by browser.cookies.save into the browser.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Name *
name - Your name for this saved login, e.g. the site. Stored encrypted as cookies:<name>.
Pauses the run so you can act in the live browser (captcha, login, 2FA), then continues.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- What to do *
instructions - Shown to you next to the live browser.
- Success element
locator - Optional: after Done, this element must be visible (e.g. the account menu). Either this or the success URL is enough. Default
{"by":"css","value":""}. - Success URL contains
successUrl - Optional: after Done, the page URL must contain one of these (comma separated). Counts as success on its own.
- Save cookies as
saveCookiesAs - Optional: store the cookies under this name the moment you press Done, before anything is checked, so a login is never lost.
- Timeout (min)
timeoutMinutes - How long the run waits for you. Default 1440 (24 h), up to 10080 (7 days). Default
1440. - On give up
onGiveUpone of fail, branch - fail stops the run; branch routes to gave_up (Done = branch done). Default
"fail".
Closes a browser session and saves its screen recording, if it made one.
- Session
session - Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
- Recording file name
videoName - Name of the saved webm, without extension. Only used when the session was opened with Record the screen. Default
"recording".
Fetches a page and returns clean text, title, meta, links, images and selector fields.
- URL *
url - Page to scrape. Private and internal addresses are refused.
- Render JavaScript
render - Load the page in a real browser (browser service) instead of a plain HTTP request. Default
false. - Wait for
waitFor - Render only: networkidle, ms:1500, or text:Some visible text. Default
"networkidle". - Main content only
mainContent - Readability-style article text instead of the whole page's text. Default
true. - Links
includeLinks - Return the page's links (absolute, deduplicated, up to 500). Default
true. - Images
includeImages - Return image URLs and alt text (up to 200). Default
true. - Fields
fields - field -> CSS or XPath selector, or {selector, attr, all}. attr: text (default), html or an attribute; href/src come back absolute.
- Item selector
itemSelector - With fields: one item per match, fields relative to it (items[]). Blank = one object (data).
- Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - User agent
userAgent - Sent as User-Agent. Blank = alleex-scraper/1.0.
- Timeout (ms)
timeoutMs - Per request. 1,000 to 120,000. Default
20000. - Max bytes
maxBytes - Stop reading a response after this many bytes. Up to 10 MB. Default
2097152. - Respect robots.txt
respectRobots - Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default
true. - Delay per domain (ms)
delayMs - Minimum gap between two requests to the same host. Default
1000.
Pages through a listing and extracts items with a field schema, deduplicated.
- First page *
url - Listing page to start from.
- Item selector *
itemSelector - CSS or XPath matching one element per item.
- Fields
fields - field -> CSS or XPath selector, or {selector, attr, all}. attr: text (default), html or an attribute; href/src come back absolute.
- Next link
nextSelector - CSS or XPath of the next-page link. Or use a page URL template.
- Page URL template
pageUrlTemplate - Instead of a next link: a URL with {page}, counted up from the start number.
- Start page number
pageStart - First {page} value for the template. Default
1. - Max pages
maxPages - Stop after this many pages. 1 to 100. Default
5. - Dedupe by field
dedupeBy - Items with the same value of this field are kept once. Blank = identical items.
- Render JavaScript
render - Load the page in a real browser (browser service) instead of a plain HTTP request. Default
false. - Wait for
waitFor - Render only: networkidle, ms:1500, or text:Some visible text. Default
"networkidle". - Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - User agent
userAgent - Sent as User-Agent. Blank = alleex-scraper/1.0.
- Timeout (ms)
timeoutMs - Per request. 1,000 to 120,000. Default
20000. - Max bytes
maxBytes - Stop reading a response after this many bytes. Up to 10 MB. Default
2097152. - Respect robots.txt
respectRobots - Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default
true. - Delay per domain (ms)
delayMs - Minimum gap between two requests to the same host. Default
1000.
Lists a site's URLs from robots.txt and sitemap.xml, with include and exclude filters.
- Site or sitemap URL *
url - A sitemap.xml, or any page of the site (its robots.txt Sitemap lines are used, else /sitemap.xml).
- Include
include - Keep URLs containing one of these (* is a wildcard). Empty = all.
- Exclude
exclude - Drop URLs containing one of these (* is a wildcard).
- Max URLs
limit - Stop after this many URLs. 1 to 5,000. Default
500. - Max sitemaps
maxSitemaps - Sitemap files to read, index files included. 1 to 50. Default
10. - Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - User agent
userAgent - Sent as User-Agent. Blank = alleex-scraper/1.0.
- Timeout (ms)
timeoutMs - Per request. 1,000 to 120,000. Default
20000. - Max bytes
maxBytes - Stop reading a response after this many bytes. Up to 10 MB. Default
2097152. - Respect robots.txt
respectRobots - Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default
true. - Delay per domain (ms)
delayMs - Minimum gap between two requests to the same host. Default
250.
Crawl sitescrape.crawlrisk: read
Bounded same-host crawl, two at a time and polite, returning a summary per page.
- Start URL *
url - Crawl starts here and stays on this host.
- Max pages
maxPages - Requests to make at most. 1 to 200. Default
20. - Max depth
maxDepth - Link hops from the start page. 0 = only the start page. Default
2. - Include
include - Only follow URLs containing one of these (* is a wildcard). Empty = all.
- Exclude
exclude - Never follow URLs containing one of these (* is a wildcard).
- Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - User agent
userAgent - Sent as User-Agent. Blank = alleex-scraper/1.0.
- Timeout (ms)
timeoutMs - Per request. 1,000 to 120,000. Default
20000. - Max bytes
maxBytes - Stop reading a response after this many bytes. Up to 10 MB. Default
2097152. - Respect robots.txt
respectRobots - Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default
true. - Delay per domain (ms)
delayMs - Minimum gap between two requests to the same host. Default
1000.
Pauses the run without a worker until a time, a polled condition or a webhook call.
- Wait for
modeone of time, poll, webhook - time: a moment or duration. poll: re-check a read-only node until a condition holds. webhook: a POST to a one-time resume URL. Default
"time". - Duration (seconds)
seconds - Time mode: how long to wait when no timestamp is set. Up to 30 days. Default
60. - Until (timestamp)
until - Time mode: ISO timestamp to resume at. Overrides the duration. Expressions allowed.
- Check node
nodeone of http.get, rss.fetch, github.checks, github.preview, github.pr.get, github.pr.comments, github.file.get, jira.issue.get, jira.search - Poll mode: the read-only node run on every check. Default
"http.get". - Check config *
config - Poll mode: config for the check node, as for that node. Expressions allowed.
- Result field
field - Poll mode: path in the check result to test. Blank = the whole result.
- Operator
opone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex - Poll mode: how the field is compared to the value. Default
"truthy". - Compare to
value - Poll mode: right-hand value. Ignored by is truthy / falsy / empty / not empty.
- Check every (seconds)
intervalSec - Poll mode: pause between checks. 30 seconds to 1 day. Default
300. - Timeout (hours)
timeoutHours - Poll and webhook: give up after this long. Default 24, max 720 (30 days). Default
24. - On timeout
onTimeoutone of fail, branch - fail stops the run; branch routes to the timeout edge (done otherwise). Default
"fail".
Repeats an agent or workflow until its output meets a condition, with a hard cap.
- Body agent
agentSlug - Agent whose graph runs once per iteration. Billed to this run.
- Body workflow
workflowId - Or: id of another workflow of this same agent to run per iteration.
- Input per iteration
input - Trigger input of each iteration. {{iteration}} is 1, 2, …; {{previous}} is the last iteration's output (null at first).
- Until: output field
field - Path in the iteration output to test. Blank = the whole output.
- Until: operator
opone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex - Stop looping when the field compared to the value is true. Default
"truthy". - Until: compare to
value - Right-hand value. Ignored by is truthy / falsy / empty / not empty.
- Max iterations
maxIterations - Hard cap, 1 to 20. Every iteration can be paid calls. Default
3. - When exhausted
onExhaustedone of fail, branch - fail stops the run; branch routes to the exhausted edge (done otherwise) to escalate. Default
"fail". - Timeout per iteration (ms)
timeoutMs - 1,000 to 7,200,000 (2 h): cover every agent.call the body makes. Default
60000.
Drops items this agent already saw in an earlier successful run.
- Key field
key - Path inside each item that identifies it, e.g. link. Blank = the whole item.
- Scope
scope - Separate seen sets per agent, e.g. news or jobs. Letters, digits, _ . : - Default
"default". - Forget after (days)
ttlDays - An item counts as new again after this many days. 0 = never forget, max 365. Default
30. - Max new items
max - Pass on at most this many unseen items. 1 to 500. Default
100. - Items field
itemsField - Path to the array inside the input, e.g. results. Blank = the input itself.
Remembers these items so a later run's Only-new-items drops them. Passes everything through.
- Key field
key - Path inside each item that identifies it, e.g. link. Blank = the whole item.
- Scope
scope - Separate seen sets per agent, e.g. news or jobs. Letters, digits, _ . : - Default
"default". - Forget after (days)
ttlDays - An item counts as new again after this many days. 0 = never forget, max 365. Default
30.
Forget seen itemsseen.clearwrites to an external system
Empties this agent's seen set so every item counts as new again.
- Scope
scope - Which seen set to forget. Blank = every scope of this agent. Default
"default".
Add to knowledgeknowledge.addrisk: writewrites to an external system
Stores text in a knowledge base so later runs and agents can retrieve it.
- Knowledge base *
kb - Which base to use, by id or by its slug. Set by the author, never by the model.
- Text
text - What to store. {0} is the first input, {0.summary} a path into it; {{node}} expressions work too. Default
"{0}". - Title
title - Shown in citations. Blank = the run id.
- Replaces source
ref - A stable id for where the text came from (e.g. a file path). Set = an earlier source with the same id is replaced, so a re-sync updates instead of duplicating. Blank = always add.
- Metadata
metadata - Stored on every chunk, so a later search can filter on it.
AWS readcloud.aws.readrisk: read
Reads EC2 instances, S3 buckets, RDS databases, Cost Explorer costs or CloudWatch alarms. Read-only.
- What to read
whatone of instances, buckets, databases, costs, alerts, describe - instances = EC2, buckets = S3, databases = RDS, costs = Cost Explorer for the period, alerts = CloudWatch alarms in ALARM, describe = the one pinned instance. Default
"instances". - Region *
region - AWS region these calls go to, e.g. eu-central-1. Fixed by the author.
- Instance id
instanceId - Only for describe: the one EC2 instance this node may look at.
- Costs from
start - YYYY-MM-DD, inclusive. Blank = the first of this month.
- Costs to
end - YYYY-MM-DD, exclusive. Blank = tomorrow.
AWS changecloud.aws.writerisk: infrawrites to an external system
Starts, stops, restarts, scales, snapshots or tags one pinned AWS resource. Put an Approval before it.
- Action
actionone of start, stop, restart, scale, snapshot, tag - start/stop/restart the pinned EC2 instance, scale the pinned Auto Scaling group, snapshot the pinned volume, or tag the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default
"start". - Region *
region - AWS region these calls go to, e.g. eu-central-1. Fixed by the author.
- Instance id
instanceId - The one EC2 instance this node may start, stop, restart or tag.
- Auto Scaling group
groupName - The one Auto Scaling group this node may resize.
- Volume id
volumeId - The one EBS volume this node may snapshot.
- Desired capacity
capacity - For scale: how many instances the Auto Scaling group should run. Default
1. - Tag key
tagKey - For tag: the tag name to set.
- Tag value
tagValue - For tag: the tag value to set.
Reads Compute Engine instances, Cloud Storage buckets, Cloud SQL, billing costs or Cloud Logging errors. Read-only.
- What to read
whatone of instances, buckets, databases, costs, alerts, describe - instances = Compute Engine, buckets = Cloud Storage, databases = Cloud SQL, costs = the BigQuery billing export for the period, alerts = Cloud Logging entries at ERROR or worse, describe = the one pinned instance. Default
"instances". - Project id *
project - The GCP project these calls go to. Fixed by the author.
- Zone
zone - Zone of the pinned instance or disk, e.g. europe-west4-a.
- Instance name
instanceName - Only for describe: the one instance this node may look at.
- Billing export table
billingTable - Only for costs: project.dataset.table of the Cloud Billing BigQuery export.
- Costs from
start - YYYY-MM-DD, inclusive. Blank = the first of this month.
- Costs to
end - YYYY-MM-DD, exclusive. Blank = tomorrow.
Google Cloud changecloud.gcp.writerisk: infrawrites to an external system
Starts, stops, restarts, resizes, snapshots or labels one pinned Google Cloud resource. Put an Approval before it.
- Action
actionone of start, stop, restart, scale, snapshot, tag - start/stop/restart (reset) the pinned instance, resize the pinned managed instance group, snapshot the pinned disk, or set a label on the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default
"start". - Project id *
project - The GCP project these calls go to. Fixed by the author.
- Zone
zone - Zone of the pinned instance or disk, e.g. europe-west4-a.
- Instance name
instanceName - The one instance this node may start, stop, restart or label.
- Instance group manager
groupName - The one managed instance group this node may resize.
- Disk name
diskName - The one persistent disk this node may snapshot.
- Group size
size - For scale: how many instances the managed group should run. Default
1. - Label key
labelKey - For tag: the label name to set (lowercase).
- Label value
labelValue - For tag: the label value to set (lowercase).
Azure readcloud.azure.readrisk: read
Reads Azure virtual machines, storage accounts, SQL servers, Cost Management costs or open alerts. Read-only.
- What to read
whatone of instances, buckets, databases, costs, alerts, describe - instances = virtual machines, buckets = storage accounts, databases = SQL servers, costs = Cost Management for the period, alerts = Alerts Management alerts, describe = the one pinned resource id. Default
"instances". - Subscription id *
subscriptionId - The Azure subscription these calls go to. Fixed by the author.
- Resource id
resourceId - Only for describe: the one ARM resource id this node may look at.
- Costs from
start - YYYY-MM-DD, inclusive. Blank = the first of this month.
- Costs to
end - YYYY-MM-DD, exclusive. Blank = tomorrow.
Azure changecloud.azure.writerisk: infrawrites to an external system
Starts, stops, restarts, scales, snapshots or tags one pinned Azure resource. Put an Approval before it.
- Action
actionone of start, stop, restart, scale, snapshot, tag - start/stop (deallocate)/restart the pinned VM, set the pinned scale set's capacity, snapshot the pinned disk, or merge a tag onto the pinned resource. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default
"start". - Subscription id *
subscriptionId - The Azure subscription these calls go to. Fixed by the author.
- Resource group
resourceGroup - Resource group of the pinned resources.
- Virtual machine
vmName - The one VM this node may start, stop or restart.
- Scale set
scaleSetName - The one virtual machine scale set this node may resize.
- Managed disk
diskName - The one managed disk this node may snapshot.
- Location
location - Azure region the snapshot is created in, e.g. westeurope.
- Resource id
resourceId - The one ARM resource id this node may tag.
- Capacity
capacity - For scale: how many instances the scale set should run. Default
1. - Tag key
tagKey - For tag: the tag name to set.
- Tag value
tagValue - For tag: the tag value to set.
Reads OCI compute instances, Object Storage buckets, DB systems, Usage API costs or Monitoring alarms. Read-only.
- What to read
whatone of instances, buckets, databases, costs, alerts, describe - instances = Compute, buckets = Object Storage, databases = DB systems, costs = the Usage API for the period, alerts = Monitoring alarms, describe = the one pinned instance. Default
"instances". - Region *
region - OCI region these calls go to, e.g. eu-frankfurt-1. Fixed by the author.
- Compartment OCID *
compartmentId - The compartment these calls are scoped to.
- Object Storage namespace
namespace - Only for buckets: the tenancy's Object Storage namespace.
- Instance OCID
instanceId - Only for describe: the one instance this node may look at.
- Costs from
start - YYYY-MM-DD, inclusive. Blank = the first of this month.
- Costs to
end - YYYY-MM-DD, exclusive. Blank = tomorrow.
Oracle Cloud changecloud.oci.writerisk: infrawrites to an external system
Starts, stops, restarts, resizes, backs up or tags one pinned Oracle Cloud resource. Put an Approval before it.
- Action
actionone of start, stop, restart, scale, snapshot, tag - start/stop/restart (soft reset) the pinned instance, resize the pinned instance pool, back up the pinned boot volume, or set a freeform tag on the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default
"start". - Region *
region - OCI region these calls go to, e.g. eu-frankfurt-1. Fixed by the author.
- Instance OCID
instanceId - The one instance this node may start, stop, restart or tag.
- Instance pool OCID
instancePoolId - The one instance pool this node may resize.
- Boot volume OCID
bootVolumeId - The one boot volume this node may back up.
- Pool size
size - For scale: how many instances the pool should run. Default
1. - Tag key
tagKey - For tag: the freeform tag name to set.
- Tag value
tagValue - For tag: the freeform tag value to set.
Reads Nebius AI Cloud instances, disks, Kubernetes clusters, buckets or quotas in one pinned project. Read-only.
- What to read
whatone of instances, disks, clusters, buckets, quotas, describe - instances = Compute VMs, disks = Compute disks, clusters = Managed Kubernetes, buckets = Object Storage, quotas = quota allowances and usage, describe = the one pinned instance. Default
"instances". - Project id *
projectId - The Nebius project these calls are scoped to. Fixed by the author.
- Instance id
instanceId - Only for describe: the one instance this node may look at.
Nebius Cloud changecloud.nebius.writerisk: infrawrites to an external system
Starts or stops one pinned Nebius AI Cloud instance. Put an Approval before it.
- Action
actionone of start, stop - Start or stop the pinned instance. Nothing else. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default
"start". - Instance id *
instanceId - The one instance this node may start or stop.
Lists the Nebius Token Factory models with context length and prices (Nebius's own plus alleex's price table).
- Filter
search - Only models whose id contains this text. Blank = all.
Token Factory file uploadnebius.tf.file.uploadrisk: writewrites to an external system
Uploads a JSONL file to Nebius Token Factory for a batch or fine-tuning job and returns its file id.
- Purpose
purposeone of batch, fine-tune - batch = input for a batch job; fine-tune = training or validation data. Default
"batch". - File name
filename - Name shown in Token Factory. Default
"input.jsonl". - JSONL content *
content - One JSON object per line. Up to 20 MB.
Token Factory batch jobnebius.tf.batch.createrisk: moneywrites to an external system
Starts a Nebius Token Factory batch job over an uploaded JSONL file (OpenAI batch shape; unverified against current docs).
- Input file id *
inputFileId - A file uploaded with purpose batch.
- Endpoint
endpointone of /v1/chat/completions, /v1/completions, /v1/embeddings - The API every line of the file is sent to. Default
"/v1/chat/completions". - Completion window
completionWindow - How long Nebius may take, e.g. 24h. Batch runs at a lower price than live calls. Default
"24h". - Description
description - Stored as metadata.description on the job.
Token Factory fine-tunenebius.tf.finetune.createrisk: moneywrites to an external system
Starts a Nebius Token Factory fine-tuning job on a pinned model and training file.
- Base model *
model - The model to fine-tune. Fixed by the author.
- Training file id *
trainingFile - A file uploaded with purpose fine-tune. Fixed by the author.
- Validation file id
validationFile - Optional held-out file. Fixed by the author.
- Name suffix
suffix - Appended to the fine-tuned model's name. Max 64 characters.
- Epochs
nEpochs - Passes over the training data. 1 to 20 (Nebius default 3). Default
3. - Learning rate
learningRate - Nebius default 1e-5. Default
0.00001. - Batch size
batchSize - Nebius default 8. Default
8. - LoRA
lora - Train a LoRA adapter instead of all weights (cheaper). Default
false. - LoRA rank
loraR - Only with LoRA. Nebius default 8. Default
8. - Seed
seed - Fixes the run for reproducibility. Default
42.
Reads the status (and optionally the results) of a Nebius Token Factory batch, fine-tuning job or Data Lab operation.
- Kind
kindone of batch, fine_tune, operation - batch = /v1/batches, fine_tune = /v1/fine_tuning/jobs, operation = a Data Lab operation (/v1/operations). Default
"batch". - Job id
id - Blank = the most recent jobs of that kind (not for operation).
- Fetch results
results - batch: download the output file once completed. operation: the first 100 result rows. Capped at 128 KB. Default
false.
Finds messages in Gmail with a search query and returns their headers.
- Search query
q - Gmail search syntax, exactly as in the Gmail search box. Empty = the newest messages.
- How many
maxResults - Newest matches to return, 1 to 50. Each one costs a second lookup for its headers. Default
10.
Reads one Gmail message and returns its headers and plain-text body.
- Message id *
messageId - The Gmail message id, as returned by Search Gmail or the Gmail trigger.
Send a Gmail messagegmail.sendrisk: external-commswrites to an external system
Sends a plain-text email from your Gmail account.
- To *
to - One address, or several separated by commas.
- Subject *
subject - Subject line. Expressions allowed.
- Body *
text - Plain-text message body.
- Cc
cc - Copy recipients, separated by commas.
- Bcc
bcc - Blind-copy recipients, separated by commas.
- From
from - Sender address. Must be your Gmail address or one of its verified aliases; blank = the account itself.
- Thread id
threadId - Put the mail in this existing thread. Reply threading also needs the In-Reply-To field below.
- In reply to
inReplyTo - Message-Id header of the mail being answered. Gmail needs this, not just the thread id, to thread a reply.
Save a Gmail draftgmail.draftrisk: writewrites to an external system
Saves a plain-text email as a Gmail draft instead of sending it.
- To *
to - One address, or several separated by commas.
- Subject *
subject - Subject line. Expressions allowed.
- Body *
text - Plain-text message body.
- Cc
cc - Copy recipients, separated by commas.
- Bcc
bcc - Blind-copy recipients, separated by commas.
- From
from - Sender address. Must be your Gmail address or one of its verified aliases; blank = the account itself.
- Thread id
threadId - Put the mail in this existing thread. Reply threading also needs the In-Reply-To field below.
- In reply to
inReplyTo - Message-Id header of the mail being answered. Gmail needs this, not just the thread id, to thread a reply.
Relabel a Gmail messagegmail.labelrisk: writewrites to an external system
Adds and removes Gmail labels on one message, so it can be archived or marked read.
- Message id *
messageId - The Gmail message to relabel, as returned by Search Gmail or the Gmail trigger.
- Labels to add
addLabelIds - Label ids to add. System labels use their own names.
- Labels to remove
removeLabelIds - Label ids to remove. Removing UNREAD marks the message read; removing INBOX archives it.
Lists a Nextcloud folder with size, modified time and type, optionally up to 3 levels deep.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- Folder
path - Folder to list, inside the restricted folder. Blank = its top.
- Depth
depth - 1 = this folder only, up to 3 levels of subfolders. Default
1. - Show
onlyone of all, files, folders, text - all, files, folders, or text = only files whose text nextcloud.download can read (txt, md, csv, json…). Default
"all".
Nextcloud: photos to knowledgenextcloud.photosrisk: destructivewrites to an external system
Reads new photos in a Nextcloud folder with a vision model (the images are sent to that model's vendor) and returns the technical ones as one document.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- Photo folder
path - The folder the phone syncs into, inside the restricted folder. Android's Nextcloud app uses InstantUpload, iOS often Photos. Default
"InstantUpload". - Depth
depth - 1 = this folder only, up to 3 levels of subfolders (phones file by month). Default
2. - Vision model
model - vendor:model that SEES the photos. Blank = the cheapest vision model you have a key for. The default agent model has no eyes.
- Max images per run
maxImages - Stop after this many new photos. The rest follow on the next run. Default
100. - Skip files over (MB)
maxMb - Photos larger than this are left for a later look and counted as skipped. Default
8. - Seen set
scope - Name of this agent's memory of photos it already read. Changing it re-reads everything. Default
"photos". - Sort photos
sortone of off, copy, move - off = only classify. copy/move = also file each photo under Technik, Wissen or Privat. Junk is left alone and nothing is ever deleted. Default
"off". - Sort folder
sortInto - Where the Technik / Wissen / Privat subfolders are created, inside the restricted folder. Default
"Sortiert". - Create the sort folders
createFolders - Create Sort folder and its Technik / Wissen / Privat subfolders when they are missing. They are the agent's own output folders and always inside the restricted folder. The photo folder itself is only read, never created. Default
true.
Fetches one Nextcloud file into the run as an artifact, with its text when it is a text file.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- File *
path - The file to fetch, inside the restricted folder.
- Size limit (MB)
maxMb - Refuse larger files. Up to 10 MB (the run-artifact limit). Default
10. - Attach to the run
save - Store the file as a run artifact you can open from the run. Default
true. - Text characters
maxTextChars - For text files (txt, md, csv, json…): include up to this many characters as `text`. 0 = none. Default
20000.
Nextcloud: upload filenextcloud.uploadrisk: destructivewrites to an external system
Stores text, JSON or a run artifact (like a chat upload) as a file in Nextcloud, creating folders as needed.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- Save as *
path - Target file path inside the restricted folder. Ending in / = that folder, keeping the source file's name.
- Content
content - Text to store; an object or list is stored as JSON. Ignored when an artifact is given.
- Artifact
artifactId - Store this run artifact (e.g. a file uploaded in chat: {{trigger.files.0.artifactId}}) instead of Content.
- If the file exists
conflictone of rename, overwrite, fail - rename = save as “name (2).ext”, overwrite = replace it, fail = stop with an error. Default
"rename". - Create folders
createFolders - Create missing folders on the way. Default
true.
Finds Nextcloud files by name (WebDAV SEARCH) or by content (Full text search app), newest first.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- Search for *
query - Part of the file name (name), or words inside files (content, needs Nextcloud's Full text search app).
- Match
modeone of name, content - name = file and folder names; content = full-text search (not available with Restrict to folder). Default
"name". - Max results
limit - 1 to 100. Default
20.
Nextcloud: public linknextcloud.sharerisk: destructivewrites to an external system
Creates a read-only public link to a Nextcloud file or folder, with an expiry date and optional password.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- File or folder *
path - What to share, inside the restricted folder.
- Expires after (days)
expireDays - The link stops working after this many days. 1 to 90. Default
7. - Password
password - Optional. Anyone opening the link must type it. Your server's password policy applies.
Nextcloud: move or renamenextcloud.moverisk: destructivewrites to an external system
Moves or renames a Nextcloud file or folder, creating target folders as needed.
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- File or folder *
path - What to move, inside the restricted folder.
- New path *
newPath - Where it goes. Ending in / = into that folder, keeping the name. Also renames.
- Overwrite
overwrite - Replace whatever is at the target. Off = stop if it exists. Default
false. - Create folders
createFolders - Create missing target folders on the way. Default
true.
Nextcloud: deletenextcloud.deleterisk: destructivewrites to an external system
Deletes a Nextcloud file or folder (to the trash bin when the server keeps one).
- Restrict to folder
root - Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
- File or folder *
path - What to delete, inside the restricted folder. Goes to the Nextcloud trash bin when it is enabled.
Searches Slack messages with a user token.
- Query *
query - Slack search terms. Supports Slack's own modifiers.
- Scope
scope - Search modifiers pinned by the author, prepended to the query. Keeps the search inside chosen channels or people.
- Results
count - How many matches to return. 1 to 100. Default
20. - Sort
sortone of score, timestamp - score = most relevant first, timestamp = newest first. Default
"score". - Cursor
cursor - Page to fetch, from a previous run's nextCursor. Empty = the first page.
Reads recent messages from a Slack channel.
- Channel
channel - Channel id to read. Your bot must be a member of it.
- Messages
limit - How many messages to return, newest first. 1 to 999. Default
50. - Since
oldest - Only messages after this Slack timestamp. Empty = no lower bound.
- Cursor
cursor - Page to fetch, from a previous run's nextCursor. Empty = the first page.
Reads the last hours of every Slack channel the bot is in, flagging mentions of the bot and of you.
- Hours back
hours - How far back to read, 1 to 168 hours. Default
24. - Channel types
types - Comma-separated: public_channel, private_channel. Private ones also need the groups:read and groups:history scopes. Default
"public_channel". - Your Slack user id
you - Messages that mention this user are flagged mentionsYou. Blank = none.
- Messages per channel
perChannel - Newest messages read per channel, 1 to 200. Default
100. - Max channels
maxChannels - Channels read at most, 1 to 100. Default
30.
Reply in a Slack threadslack.replyrisk: external-commswrites to an external system
Replies to a Slack message inside its thread.
- Channel
channel - Channel id the thread lives in.
- Thread *
threadTs - Timestamp of the PARENT message to reply under, never a reply's own timestamp.
- Message *
text - What to reply. Slack mrkdwn works.
- Also show in channel
broadcast - Show the reply in the channel as well as in the thread. Default
false.
Send a Slack DMslack.dmrisk: external-commswrites to an external system
Sends a direct message to one Slack user.
- User *
user - Slack user id to message directly. Not a display name.
- Message *
text - What to send. Slack mrkdwn works.
Send a WhatsApp messagewhatsapp.sendrisk: external-commswrites to an external system
Sends a WhatsApp text or approved template through the Cloud API.
- To *
to - Recipient phone number in E.164 form, no plus sign needed.
- Message kind
kindone of text, template - Free text only works inside the 24-hour customer service window; outside it, WhatsApp requires an approved template. Default
"text". - Message
text - What to send when the kind is text. Expressions allowed.
- Template name
templateName - An approved template on your WhatsApp Business account. Used when the kind is template.
- Template language
languageCode - Language code the template was approved in. Default
"en_US". - Template variables
templateParams - Values for the template body placeholders, in order.
Send WhatsApp mediawhatsapp.mediarisk: external-commswrites to an external system
Sends an image, video, audio or document over WhatsApp, or resolves a media id to a URL.
- Action
actionone of send, url - send = deliver media to a recipient. url = turn a media id from an inbound message into a download URL. Default
"send". - To
to - Recipient phone number in E.164 form. Only used by the send action.
- Media type
mediaTypeone of image, video, audio, document, sticker - Which WhatsApp media message to send. Default
"image". - Media URL
link - Public https URL of the file. Either this or a media id.
- Media id
mediaId - An id already on WhatsApp's servers, e.g. from an inbound message. Wins over the URL.
- Caption
caption - Text shown under the image, video or document. Expressions allowed.
- File name
filename - Document file name shown to the recipient.
Checks the WhatsApp (Web) link of the picked Browser session and asks you to scan the QR code when it is not linked.
No settings.
WhatsApp (Web): sendwhatsapp.web.sendrisk: external-commswrites to an external system
Sends a WhatsApp text from your own number through WhatsApp Web, to a phone number or a chat name.
- To *
to - A phone number with country code (+43 660 1234567) or the exact chat name as WhatsApp shows it.
- Message *
text - What to send. Expressions allowed. Secrets are masked before it leaves.
- Allow new numbers
allowNewChats - Off: only numbers you already have a chat with. On: also a first message to a new number, at most 5 a day. Default
false. - Max per minute
perMinute - Sends per minute on this connection, across all runs. Default 5, up to 20. Default
5.
Reads your unread WhatsApp chats, or the recent messages of one chat, through WhatsApp Web (untrusted text).
- Read
modeone of chat, unread - unread = the chats with unread messages (does not open them); chat = the recent messages of one chat (marks it read). Default
"unread". - Chat
chat - For chat: a phone number with country code, or the exact chat name.
- Max messages
limit - For chat: the newest this many text messages. 1 to 100. Default
20.
Phone callphone.callrisk: external-commswrites to an external system
Places an outbound Twilio call with a scripted greeting, or hangs one up.
- Action
actionone of start, end - start = place an outbound call. end = hang up a call that is already in progress. Default
"start". - To
to - Number to call, E.164.
- From
from - Your Twilio number or a verified caller id, E.164.
- Call SID
callSid - Which call to hang up. Only used by the end action.
- Spoken text
say - What the call says first. Expressions allowed.
- Gather URL
actionUrl - Your trigger.phone webhook URL. Set it to listen for the caller's answer after the greeting; leave empty to just speak and hang up.
- Status callback URL
statusCallbackUrl - Where Twilio posts ringing/answered/completed updates.
- Raw TwiML
twiml - Hand-written TwiML. Wins over the spoken text and gather settings.
SSH commandssh.execrisk: writewrites to an external system
Runs one command on a saved SSH host; changes wait for your approval, output is redacted and audited.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Command *
command - One bash command line. Read-only commands run; changes need your approval (or an exact pre-approval); destructive ones only on hosts in full mode.
- Reason
why - Shown to you in the approval: why this command.
- Pre-approved commands
preapproved - Exact operate-level commands that run without asking, one per row, byte for byte. Never covers destructive commands. Leave empty to approve every change.
- Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30. - Max output (KB)
maxOutputKb - Output beyond this is cut off, per stream. 1 to 1024. Default
64. - Approval timeout (hours)
approvalHours - How long a change waits for your approval in Messages before the run fails. Max 168. Default
24.
Read-only snapshot of a host: OS, load, RAM, swap, disks, processes, ports, docker, failed units, updates, logins, certs.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default
false. - Disk alert (%)
diskPct - Alert when a mount is fuller than this. Default
85. - RAM alert (%)
memPct - Alert when used memory (total minus available) is above this. Default
90. - Swap alert (%)
swapPct - Alert when swap use is above this. Default
80. - Load alert (per CPU)
loadPerCpu - Alert when the 15-minute load divided by CPUs is above this. Default
2. - Certificate alert (days)
certDays - Alert when a certbot certificate expires within this many days. Default
14. - Timeout (s)
timeoutSec - The whole snapshot is stopped after this long. 5 to 120. Default
45.
SSH logsssh.logsrisk: read
Tails the systemd journal or a docker container's logs on a saved SSH host, with filters. Read-only, redacted.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default
false. - Source
sourceone of journal, docker - journal = systemd journal (journalctl), docker = a container's logs. Default
"journal". - Unit
unit - journal: a systemd unit, e.g. nginx. Blank = the whole journal.
- Container
container - docker: the container name.
- Lines
lines - Newest N lines. 1 to 2000. Default
200. - Since
since - e.g. "1 hour ago", "today", "2026-09-19 08:00". Blank = no limit.
- Filter
grep - Only lines containing this text (case-insensitive, not a regex).
- Priority
priorityone of , emerg, alert, crit, err, warning, notice, info, debug - journal: this level and worse. Blank = all.
- Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30.
Reads a size-capped file from a saved SSH host. Secret files and keys are refused; output is redacted.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default
false. - Path *
path - Absolute path of the file. Secret files (.env, keys, /etc/shadow…) are refused by the policy.
- Max size (KB)
maxKb - Read at most this much. 1 to 1024. Default
64. - From the end
fromEnd - Read the last bytes instead of the first (log files). Default
false. - Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30.
SSH servicessh.servicerisk: writewrites to an external system
Status, restart, start or stop of a systemd unit or docker container on a saved SSH host; changes need approval.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default
false. - Pre-approved commands
preapproved - Exact operate-level commands that run without asking, one per row, byte for byte. Never covers destructive commands. Leave empty to approve every change.
- Kind
kindone of systemd, docker - systemd unit or docker container. Default
"systemd". - Name *
name - Unit or container name, e.g. nextcloud.
- Action
actionone of status, restart, start, stop - status is read-only and runs at once; restart/start/stop wait for your approval. Default
"status". - Reason
why - Shown to you in the approval.
- Timeout (s)
timeoutSec - 5 to 600. Restarts can take a while. Default
120. - Approval timeout (hours)
approvalHours - How long a change waits for your approval in Messages before the run fails. Max 168. Default
24.
WireGuard serverwireguard.server.setuprisk: destructivewrites to an external system
Installs and starts a WireGuard server on a saved SSH host and prints its public key and endpoint. Re-running changes nothing.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Interface
iface - The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default
"wg0". - Tunnel subnet
subnet - The private range inside the tunnel. The server takes the first address (.1), peers get the next free ones. Default
"10.9.0.0/24". - UDP port
port - The port the server listens on. It must be open in the cloud firewall too. Default
51820. - MTU
mtu - 1420 fits inside a 1500-byte link. Lower it (1280) if large packets stall. Default
1420. - Forward and NAT
nat - Turn on IP forwarding and masquerade peer traffic out of the server's main interface, so peers reach the internet and the server's LAN. Default
true. - Outgoing interface
natInterface - The network card to masquerade out of. Blank = the one the default route uses.
- Endpoint
endpoint - The public host or IP clients dial. Blank = the saved SSH host's address.
- Timeout (s)
timeoutSec - Installing the package can take a minute. 10 to 600. Default
180. - Approval timeout (hours)
approvalHours - How long the script waits for your approval in Messages. Default
24.
WireGuard add peerwireguard.peer.addrisk: destructivewrites to an external system
Adds a device to a WireGuard server, gives it the next free address and returns a ready client config. A peer key is full access.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - WireGuard needs root. Off only when the SSH user is root itself. Default
true. - Interface
iface - The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default
"wg0". - Peer name *
name - A short name for this device, e.g. laptop or alleex-worker. It labels the [Peer] block and must be unique.
- Peer public key
publicKey - Blank = alleex generates the keypair and hands you the client config once. Fill it in when the device already has a key and its private key should never leave it.
- Address
address - Blank = the next free address in the server's subnet.
- Client routes
clientAllowedIps - What the client sends through the tunnel. Blank = the tunnel subnet only (split tunnel). 0.0.0.0/0 routes everything.
- Client DNS
dns - DNS server for the client while the tunnel is up. Blank = leave the client's own.
- Keepalive (s)
keepalive - Keeps the tunnel open behind NAT. 0 = off. Default
25. - Endpoint
endpoint - The public host or IP the client dials. Blank = the saved SSH host's address.
- Where the client config goes
deliverone of return, vault - vault (default) = saved as a secret in Settings → Secrets, and the run only names it. return = in this run's result, once, for you to copy (whoever can see the run sees it, private key included). Default
"vault". - Secret name
secretName - vault only: the name to save it under. Blank = wg-<interface>-<peer>.
- Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30. - Approval timeout (hours)
approvalHours - How long the change waits for your approval in Messages. Default
24.
WireGuard remove peerwireguard.peer.removerisk: destructivewrites to an external system
Removes a device from a WireGuard server: its [Peer] block goes out of the config and out of the live interface.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - WireGuard needs root. Off only when the SSH user is root itself. Default
true. - Interface
iface - The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default
"wg0". - Peer name *
name - The name the peer was added under.
- Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30. - Approval timeout (hours)
approvalHours - How long the change waits for your approval in Messages. Default
24.
WireGuard statuswireguard.statusrisk: destructive
Read-only: which peers a WireGuard server has, when each last shook hands and how much it transferred.
- Host *
host - Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
- Use sudo -n
sudo - WireGuard needs root. Off only when the SSH user is root itself. Default
true. - Interface
iface - The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default
"wg0". - Stale after (min)
staleMinutes - A peer whose last handshake is older than this counts as not connected. Default
10. - Timeout (s)
timeoutSec - The command (connection included) is stopped after this long. 1 to 600. Default
30.
Lists the ElevenLabs voices your key can use, with ids and preview links.
- Search
search - Filter by name, description, labels or category. Empty = all.
- How many
pageSize - 1 to 100. Default
30.
Fetches one ElevenLabs voice-agent call: transcript, summary and collected data.
- Conversation id *
conversationId - The ElevenLabs conversation id, e.g. from the post-call trigger.
Codecoderisk: destructive
Runs your JavaScript or Python on the items, in an isolated sandbox.
- Language
languageone of javascript, python, bash - JavaScript (Node 24) or Python 3 with numpy, pandas, python-dateutil, requests. Bash only on the local runner. Default
"javascript". - Mode
modeone of all, each - all = run once for all items (items). each = run once per item (item / $json / _json); the results form an array. Default
"all". - Code
code - Return a JSON value. console.log / print go to the run log. {{ }} is not filled in here: read inputs through items and $("nodeId"). Default
"// items: every input item. Return any JSON value.\nconsole.log(`got ${items.length} items`);\nreturn items.map((item) => ({ ...item, seen: true }));\n". - Allow network
network - Off = no network at all. On = http(s) to public hosts only, through the platform's egress guard (no private ranges, no cloud metadata). Default
false. - Credentials
credentials - Saved credential names, e.g. github, or a vault secret as {{secret.NAME}}. Each is env SECRET_<NAME> for this execution only and is masked in logs. Only used when you run your own agent, and never with network on.
- Timeout (s)
timeoutSec - Wall clock per execution, 1 to 60. Default
10. - Memory (MB)
memoryMb - 64 to 1024. Default
256.
Stripe: readstripe.queryrisk: destructive
Reads your own Stripe account: balance, charges, customers, subscriptions, invoices, refunds, disputes, payouts, products, prices.
- What to read
resourceone of balance, balance_transactions, charges, payment_intents, customers, subscriptions, invoices, refunds, disputes, payouts, products, prices - balance, balance_transactions, charges, payment_intents, customers, subscriptions, invoices, refunds, disputes, payouts, products or prices. Default
"charges". - Id
id - Read this one object (ch_…, cus_…, in_…) instead of a list. Ignored for balance.
- Created since
since - YYYY-MM-DD, ISO time, or relative like 7d / 24h. Blank = no lower bound.
- Created until
until - YYYY-MM-DD (that whole day included) or ISO time. Blank = now.
- Customer id
customer - Only this customer (charges, payment intents, subscriptions, invoices).
- Email
email - Customers only: exact email match (case-sensitive at Stripe).
- Status
status - subscriptions: active, past_due, canceled, all… invoices: draft, open, paid, uncollectible, void. payouts: pending, paid, failed, canceled, in_transit.
- Charge / payment intent
charge - Refunds and disputes only: those of this ch_… or pi_…. Prices: this prod_….
- Max items
limit - How many to read at most; pages are fetched until this. Hard cap 1000. Default
50.
Stripe: reportstripe.reportrisk: destructive
Computes revenue, MRR/ARR, new vs churned subscriptions, failed payments, open disputes and upcoming payouts from your Stripe account.
- Period (days)
days - The report covers the last N days up to now. 1 = the last 24 hours. Default
1. - Sections
sections - Which figures to compute: revenue, products, mrr, subscriptions, failed, disputes, payouts. Default
["revenue","products","mrr","subscriptions","failed","disputes","payouts"]. - Max items per read
limit - Cap for each underlying list (charges, subscriptions…). Hard cap 1000. Default
500.
Stripe: customerstripe.customerrisk: destructivewrites to an external system
Finds, creates or updates a customer in your Stripe account, or adds a note to one.
- Action
actionone of find, create, update, note - find by id or email, create one, update its fields, or add a note (stored in metadata). Default
"find". - Customer id
customerId - cus_… for find, update and note.
- Email
email - find: exact email. create/update: the new email.
- Name
name - create/update: the customer's name. Blank = unchanged.
- Phone
phone - create/update: phone number. Blank = unchanged.
- Description
description - create/update: internal description. Blank = unchanged.
- Metadata
metadata - create/update: key/value pairs to set (Stripe limits: 50 keys, 500-char values).
- Note
note - note: text stored as metadata note_<timestamp> (max 500 characters).
Stripe: invoicestripe.invoicerisk: destructivewrites to an external system
Creates a draft invoice, adds items, finalizes, sends or voids it, within a pinned maximum and currency list.
- Action
actionone of create_draft, add_item, finalize, send, void - create_draft for a customer, add_item to a draft, finalize it, send it by email (Stripe emails the customer; not in test mode), or void an open invoice. Default
"create_draft". - Customer id
customerId - create_draft: the cus_… to bill.
- Invoice id
invoiceId - add_item, finalize, send, void: the in_….
- Item amount (minor units)
amount - add_item: amount in the smallest currency unit (1500 = 15.00). Ignored when a price is given. Default
0. - Item currency
currency - add_item: lowercase ISO code, e.g. eur.
- Item price
price - add_item: a price_… from the pinned allowed prices instead of an amount.
- Quantity
quantity - add_item with a price: how many. Default
1. - Description
description - create_draft: the invoice memo. add_item: the line's text.
- Days until due
daysUntilDue - create_draft: payment term for an emailed invoice. Default
14. - Collection
collectionone of send_invoice, charge_automatically - send_invoice = the customer pays from an emailed link. charge_automatically = Stripe charges the saved card on finalize. Pinned by the author. Default
"send_invoice". - Max amount (minor units)
maxAmount - Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default
0. - Allowed currencies *
currencies - Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
- Allowed prices
allowedPrices - Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.
Stripe: refundstripe.refundrisk: destructivewrites to an external system
Refunds a charge after a person approves it, never above the pinned maximum or outside the pinned currencies.
- Charge or payment *
charge - The ch_… or pi_… to refund.
- Amount (minor units) *
amount - How much to refund, in the smallest currency unit (1250 = 12.50 EUR). Required: there is no implicit full refund. Default
1. - Reason
reasonone of requested_by_customer, duplicate, fraudulent - Stripe's refund reason. fraudulent also adds the card and email to your Radar block lists. Default
"requested_by_customer". - Note
note - Why, for the approver and the refund's metadata (max 500 characters).
- Max refund (minor units)
maxAmount - Pinned ceiling per refund. 0 = no refund is possible. The model cannot change it. Default
0. - Allowed currencies
currencies - Pinned lowercase ISO codes a refund may be in. Empty = none. The model cannot change it.
- Approval timeout (hours)
timeoutHours - How long the approval waits. No answer = no refund. Default
168.
Stripe: subscriptionstripe.subscriptionrisk: destructivewrites to an external system
Cancels a subscription at period end, undoes that, or moves it to a pinned price, within a pinned maximum.
- Action
actionone of cancel_at_period_end, resume, change_price - cancel_at_period_end schedules the end, resume undoes a scheduled cancellation, change_price swaps the single item to a pinned price. Default
"cancel_at_period_end". - Subscription id *
subscriptionId - The sub_… to change.
- New price
price - change_price: a price_… from the pinned allowed prices.
- Proration
prorationone of create_prorations, none, always_invoice - change_price: Stripe's proration_behavior. always_invoice charges the difference now. Pinned by the author. Default
"create_prorations". - Max amount (minor units)
maxAmount - Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default
0. - Allowed currencies *
currencies - Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
- Allowed prices
allowedPrices - Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.
Stripe: payment linkstripe.payment_linkrisk: destructivewrites to an external system
Creates a Stripe payment link for one pinned price and quantity, within a pinned maximum.
- Price *
price - A price_… from the pinned allowed prices.
- Quantity
quantity - How many of that price the link sells. Default
1. - Max amount (minor units)
maxAmount - Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default
0. - Allowed currencies *
currencies - Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
- Allowed prices
allowedPrices - Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.
Polar: readpolar.queryrisk: destructive
Reads orders, subscriptions, customers, products, refunds or checkouts from your Polar organisation. Never writes.
- What to read
resourceone of orders, subscriptions, customers, products, refunds, checkouts - orders, subscriptions, customers, products, refunds or checkouts. Default
"orders". - Id
id - Read this one object (a UUID) instead of a list. Not available for refunds or checkouts.
- Created since
since - YYYY-MM-DD, ISO time, or relative like 7d / 24h. Blank = no lower bound.
- Created until
until - YYYY-MM-DD (that whole day included) or ISO time. Blank = now.
- Customer id
customerId - Only this customer (orders, subscriptions, refunds).
- Product id
productId - Only this product (orders, subscriptions).
- Order id
orderId - Refunds only: those of this order.
- Status
status - Subscriptions only: active, trialing, past_due, canceled, unpaid, incomplete, paused.
- Email or search
email - Customers only: matches email or name.
- Max items
limit - How many to read at most; pages are fetched until this. Hard cap 1000. Default
50.
Polar: reportpolar.reportrisk: destructive
Revenue, MRR/ARR, new vs churned subscriptions, top products and past-due subscriptions from your Polar organisation. Reads only.
- Period (days)
days - The report covers the last N days up to now. 1 = the last 24 hours. Default
1. - Sections
sections - Which figures to compute: revenue, subscriptions, products, pastdue. Default
["revenue","subscriptions","products","pastdue"]. - Max items per read
limit - Cap for each underlying list (orders, subscriptions). Hard cap 1000. Default
500.
Polar: refundpolar.refundrisk: destructivewrites to an external system
Refunds a Polar order after a person approves it, never above the pinned maximum or outside the pinned currencies.
- Order *
order - The Polar order id (a UUID) to refund.
- Amount (minor units) *
amount - How much to refund, in the smallest currency unit (1250 = 12.50 EUR). Required: there is no implicit full refund. Default
1. - Reason
reasonone of customer_request, duplicate, fraudulent, service_disruption, satisfaction_guarantee, other - Polar's refund reason. Default
"customer_request". - Revoke benefits
revokeBenefits - Also take back what the order granted (a subscription's access, a licence key). Off = the customer keeps it. Default
false. - Note
note - Why, for the approver and the refund's comment (max 500 characters).
- Max refund (minor units)
maxAmount - Pinned ceiling per refund. 0 = no refund is possible. The model cannot change it. Default
0. - Allowed currencies
currencies - Pinned lowercase ISO codes a refund may be in. Empty = none. The model cannot change it.
- Approval timeout (hours)
timeoutHours - How long the approval waits. No answer = no refund. Default
168.
Sort itemssortrisk: destructive
Sorts array items by one or more fields, ascending or descending.
- Sort by *
by - One field per row, first wins. Add " desc" for descending, e.g. "price desc". Blank row = the item itself.
- Items field
itemsField - Path to the array inside the input. Blank = the input itself.
Keeps only the first or last N items of a list.
- How many
count - Keep this many items. 0 to 10,000. Default
10. - Keep
keepone of first, last - first = from the start of the list, last = from the end. Default
"first". - Items field
itemsField - Path to the array inside the input. Blank = the input itself.
Aggregateaggregaterisk: destructive
Groups items and computes count, sum, average, min, max or lists.
- Group by
groupBy - Field whose value forms the groups. Blank = one result over all items.
- Aggregations
aggregations - JSON [{field, op, as}]. op: count, sum, avg, min, max, concat (joined text), list (all values), unique (distinct values). Default
[{"field":"","op":"count","as":"count"}]. - Concat separator
separator - Placed between values by concat. Default
", ". - Items field
itemsField - Path to the array inside the input. Blank = the input itself.
Date & Timedate.timerisk: destructive
Parses, formats, shifts and compares dates, in any time zone.
- Operation
operationone of format, parse, add, subtract, diff, timezone - format = text in a pattern, parse = ISO instant, add/subtract = shift by an amount, diff = time between two dates, timezone = wall time in another zone. Default
"format". - Date
value - ISO 8601, epoch seconds/ms, or text matching the input format. Blank = now.
- Input format
inputFormat - Pattern of the date text, e.g. dd.MM.yyyy HH:mm. Blank = ISO or epoch.
- Time zone
timezone - IANA zone for reading wall times and for the output, e.g. Europe/Vienna. Default
"UTC". - Output format
format - format: yyyy yy MMM MM M dd d EEE HH H hh h mm ss SSS a XXX, 'literal text', or iso. Default
"yyyy-MM-dd HH:mm". - Amount
amount - add/subtract: how many units. Default
1. - Unit
unitone of milliseconds, seconds, minutes, hours, days, weeks, months, years - add/subtract/diff: milliseconds up to years. Days, months and years follow the calendar in the time zone. Default
"days". - Second date
value2 - diff: the later date; the result is second minus first. Blank = now.
XMLxmlrisk: destructive
Converts XML text to JSON, or JSON to XML text.
- Operation
operationone of toJson, toXml - toJson = XML text to an object, toXml = an object to XML text. Default
"toJson". - Data
data - XML text (toJson) or an object (toXml). Blank = this node's input.
- Root element
rootName - toXml: wraps the data unless it is an object with exactly one key. Default
"root". - Pretty print
pretty - toXml: indent nested elements. Default
true.
CSVcsvrisk: destructive
Parses CSV text into items or turns items into CSV text.
- Operation
operationone of parse, stringify - parse = CSV text to items, stringify = items to CSV text. Default
"parse". - Data
data - CSV text (parse) or a list of items (stringify). Blank = this node's input.
- Delimiter
delimiter - Separator between fields: , or ; or a tab (\t). Default
",". - Header row
header - parse: the first row names the fields. stringify: write a header row. Default
true. - Max rows
maxRows - parse stops after this many rows. 1 to 100,000. Default
10000.
Runs a GA4 report (metrics by dimensions over a date range) via the Data API or the logged-in browser.
- GA4 property id *
propertyId - The number from GA4 Admin -> Property details.
- Start date
startDate - YYYY-MM-DD, today, yesterday or NdaysAgo. Default
"28daysAgo". - End date
endDate - YYYY-MM-DD, today, yesterday or NdaysAgo. Default
"yesterday". - Metrics
metrics - GA4 Data API metric names, comma separated. Default
"activeUsers, sessions, engagementRate". - Dimensions
dimensions - GA4 dimension names, comma separated. Blank = one totals row.
- Sort by
orderBy - A metric to sort by, descending. Blank = the first metric.
- Row limit
limit - Rows to return, 1 to 50,000 (fetched in pages of 10,000). Default
100.
Clicks, impressions, CTR and position by query, page, country or device from Google Search Console.
- Property *
site - The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
- Start date
startDate - YYYY-MM-DD, today, yesterday or NdaysAgo. Default
"28daysAgo". - End date
endDate - YYYY-MM-DD, today, yesterday or NdaysAgo. Default
"yesterday". - Dimensions
dimensions - Comma separated: query, page, country, device, date, searchAppearance. Blank = totals only. Default
"query". - Search type
typeone of web, image, video, news, discover, googleNews - Which Google surface. Default web. Default
"web". - Row limit
rowLimit - Rows to return, 1 to 100,000 (fetched in pages of 25,000). Default
1000.
Lists the property's sitemaps with their status and errors, or submits a sitemap.
- Property *
site - The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
- Action
actionone of list, submit - list = status of every submitted sitemap; submit = (re)submit the sitemap URL below. Default
"list". - Sitemap URL
sitemapUrl - For submit: the full sitemap URL on the property.
Asks Google whether pages are indexed, their canonical, last crawl and rich-result issues.
- Property *
site - The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
- URLs *
urls - Up to 20 page URLs of the property, comma or newline separated (Google allows 2,000 inspections a day).
Core Web Vitals (lab and real-user field data), Lighthouse scores and top speed fixes for public pages.
- URLs *
urls - Up to 10 public page URLs, comma or newline separated. Each takes 10 to 30 seconds.
- Device
strategyone of mobile, desktop - mobile (what Google ranks on) or desktop. Default
"mobile". - API key
apiKey - Optional, for a higher quota: {{secret.NAME}} of a saved secret whose allowed hosts include www.googleapis.com.
SEO auditseo.auditrisk: destructive
Crawls a site (robots.txt, sitemap) and checks titles, descriptions, canonicals, noindex, JSON-LD, h1, thin, duplicate and broken pages.
- Site URL *
url - The site's home page. robots.txt and the sitemap are read from its origin.
- Max pages
maxPages - Pages to audit (sitemap order), 1 to 200. Default
30. - Check links
checkLinks - Fetch internal links the audit did not visit and report broken ones. Default
true. - Max link checks
maxLinkChecks - Extra requests for link checking, 0 to 500. Default
100. - Proxy
proxy - inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default
"inherit". - User agent
userAgent - Sent as User-Agent. Blank = alleex-scraper/1.0.
- Timeout (ms)
timeoutMs - Per request. 1,000 to 120,000. Default
20000. - Max bytes
maxBytes - Stop reading a response after this many bytes. Up to 10 MB. Default
2097152. - Respect robots.txt
respectRobots - Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default
true. - Delay per domain (ms)
delayMs - Minimum gap between two requests to the same host. Default
250.
Read Redditreddit.searchrisk: destructive
Searches Reddit, lists a subreddit or reads a post's comments (untrusted content).
- Read
modeone of search, subreddit, comments - search = posts matching the query, subreddit = a subreddit's listing, comments = the comments of one post. Default
"search". - Query
query - Search terms (search mode). Reddit syntax works: quotes, OR, author:, subreddit:.
- Subreddit
subreddit - Name without r/. Blank in search mode = all of Reddit.
- Post
postId - Comments mode: the post id (abc123), its t3_ name or its URL.
- Sort
sortone of new, hot, top, rising, relevance, comments - new, hot, top, rising (subreddit), relevance, comments (search). Default
"new". - Time window
timeone of hour, day, week, month, year, all - For top and search: how far back. Default
"day". - Results
limit - How many items to return. 1 to 100. Default
25. - Via
viaone of auto, api, browser - auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default
"auto".
Post to Redditreddit.postrisk: destructivewrites to an external system
Submits one Reddit post or comment, after approval by default.
- Kind
kindone of post, comment - post = a new post in a subreddit, comment = a reply to a post or comment. Default
"post". - Subreddit
subreddit - Where to post, without r/. Read its rules first: many ban self-promotion.
- Title
title - Post title, up to 300 characters.
- Text *
text - Post body or comment, markdown.
- Link
url - Makes a link post instead of a text post.
- Reply to
parentId - Comment kind: the t3_ (post) or t1_ (comment) name to answer.
- Via
viaone of auto, api, browser - auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default
"auto".
Search YouTubeyoutube.searchrisk: destructive
Searches YouTube videos or channels with the Data API (100 quota units per call).
- Query *
query - What to search for on YouTube.
- Find
typeone of video, channel - Videos or channels. Default
"video". - Order
orderone of date, relevance, viewCount - date = newest first, relevance, viewCount = most viewed. Default
"date". - Within (days)
withinDays - Only items published in the last N days. 0 = any time. Default
7. - Results
limit - How many items to return. 1 to 50. Default
10.
YouTube statsyoutube.statsrisk: destructive
Reads a YouTube channel's totals and recent uploads, or the stats of given videos.
- Channel or videos *
target - A channel (@handle, UC… id or channel URL), or video ids / URLs separated by commas.
- Recent uploads
recent - For a channel: also the stats of its last N uploads. 0 = channel totals only. Default
10.
Read Xx.searchrisk: destructive
Searches recent X posts or reads one account's timeline (untrusted content).
- Read
modeone of search, user - search = recent posts matching the query, user = one account's latest posts. Default
"search". - Query
query - Search mode: X search syntax (quotes, OR, -is:retweet, from:).
- Account
user - User mode: the handle, with or without @.
- Results
limit - How many items to return. 1 to 100. Default
20. - Via
viaone of auto, api, browser - auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default
"auto".
Post to Xx.postrisk: destructivewrites to an external system
Posts or replies on X from your signed-in browser, after approval by default.
- Post *
text - What to post, up to 280 characters.
- Reply to
replyTo - A post id or URL to reply to. Blank = a new post.
Post to Facebookfacebook.postrisk: destructivewrites to an external system
Posts one update to your Facebook Page (API) or profile (browser), after approval by default.
- Post as
targetone of page, profile - page = your Facebook Page via the Graph API, profile = your personal profile in your signed-in browser. Default
"page". - Message *
message - What to post.
- Link
link - Optional URL to attach (Page posts).
Post to Instagraminstagram.postrisk: destructivewrites to an external system
Publishes one image post to your Instagram business account, after approval by default.
- Image URL *
imageUrl - A public https JPEG that Meta downloads. Instagram posts need an image.
- Caption *
caption - Post caption, hashtags included. Up to 2,200 characters.
Reads your Page posts, insights, Instagram media and comments, or any social profile (untrusted content).
- Read
sourceone of facebook.posts, facebook.insights, instagram.media, instagram.comments, profile - Your Page's posts or insights, your Instagram media or one post's comments (Graph API), or any profile page on Facebook, Instagram, X, Reddit or YouTube (signed-in browser). Default
"facebook.posts". - Instagram media
mediaId - instagram.comments: the media id.
- Profile URL
url - profile: the page to read.
- Metrics
metrics - facebook.insights: comma-separated Page metrics (daily). Default
"page_impressions_unique,page_post_engagements". - Results
limit - How many items to return. 1 to 100. Default
20.
Sync proxiesproxy.syncrisk: destructivewrites to an external system
Refreshes the workspace's Webshare proxy list and reports how many exits it has.
No settings.
Check proxiesproxy.healthrisk: destructivewrites to an external system
Tests the workspace's proxies through an IP echo and reports which exits are dead.
- How many to check
limit - Proxies to test this run, oldest check first. 1 to 100. A big pool is swept over several runs. Default
25. - Rows to report
report - How many of the worst proxies to list in the output. Default
10.