Cookies on alleex

We use strictly necessary cookies to keep you signed in and remember your display settings. With your permission we also use analytics cookies to see which pages are used. Nothing optional loads until you choose. Details in the Privacy Policy.

alleex
FeedExplore
FeedExplore
Terms · Privacy · Imprint · DPA · · © 2026 alleex

Node reference

Every node you can place in an agent graph. Text fields accept expressions such as {{nodeId.items[0].title}}, filled in from earlier nodes before the node runs. Fields marked * are required.

Browser flows: every browser.* node in a run shares one browser, closed when the run ends. Find elements by role, label or text before CSS. Passwords go in Settings as a saved secret and into browser.fill by name, never in the graph. browser.assert takes branch pass or fail; with “If blocked: branch”, click, fill and wait take ok or blocked. The AI Agent node can use the same nodes as tools (add browser.snapshot). Example: docs/examples/browser-login-flow.json.

Waits and loops: wait.until parks the run without holding a worker, until a time, until a polled read-only node (HTTP GET, GitHub checks, a PR, Jira) meets a condition, or until someone POSTs to its one-time resume URL (shown on the waiting run). Default timeout 24 hours, at most 30 days; then it fails or takes branch timeout. loop runs another agent or workflow again and again until its output meets a condition, at most 20 times; {{iteration}} and {{previous}} fill its input. When it runs out it fails or takes branch exhausted. A loop body cannot pause (no approval, question or wait inside it). A sub-agent run with agent.call can pause: the calling run waits with it and continues when it does. Runs with these nodes save progress after every step: if the worker restarts, the run continues from the step it was on, up to 3 times. That step runs again, so a write step there can happen twice.

Safety: every step has a risk level (none, read, write, external-comms, money, destructive, deploy, infra), shown next to each node below; some depend on the settings, e.g. an HTTP DELETE is destructive. Before a step runs, alleex checks it against your guardrails, whatever the graph says: by default sending messages asks you first, and money, deletes, deploys and infrastructure changes always wait for your approval in Messages. Approvals are yours alone, never an API token, the copilot or the agent itself, and never on the channel the run is acting on. You can let messages to known targets run (slack:#alerts), block levels outright, or make one agent stricter in Settings → Guardrails, where every guarded step is also logged. An Approval node placed right before a guarded step covers it, so you are asked once.

Manual triggerScheduleWebhookWeb searchRead web pagesCrawl a siteDeep researchMCP: list toolsMCP: call a toolOpen a GitHub issueJev decisionLLMAI AgentFeed cardJira search (JQL)Comment on a Jira issueHTTP GETHTTP POSTRespond to WebhookCall an agentRSS / Atom feedText templateIfSwitchMap over itemsFilter itemsMergeWaitPost to SlackAppend to NotionAppend row to Google SheetSend an emailReshape JSONJira issueOpen a pull requestMark pull request readyGet a pull requestPull request commentsRequest a reviewCI statusPreview URLMerge a pull requestDelete a branchRead a repository fileGet a Jira issueMove a Jira issueAdd a Jira labelRemove a Jira labelAssign a Jira issueCreate a Jira issueCode sessionApprovalAskOpen browserGo to URLClickFill fieldSelect optionCheck boxPress keyHoverScrollWait forAssert pageExtract dataScreenshotPage snapshotSave cookiesLoad cookiesHand over to meClose browserScrape pageScrape listSitemap URLsCrawl siteAI extractWait untilLoop untilSave fileCompose videoRender documentConvert documentExtract textEvidence ledgerOnly new itemsMark items seenForget seen itemsSearch knowledgeAdd to knowledgeAnswer from knowledgeAWS readAWS changeGoogle Cloud readGoogle Cloud changeAzure readAzure changeOracle Cloud readOracle Cloud changeNebius Cloud readNebius Cloud changeToken Factory modelsToken Factory file uploadToken Factory batch jobToken Factory fine-tuneToken Factory job statusNebius batchSearch GmailRead a Gmail messageSend a Gmail messageSave a Gmail draftRelabel a Gmail messageGmail messageNextcloud: list folderNextcloud: photos to knowledgeNextcloud: download fileNextcloud: upload fileNextcloud: search filesNextcloud: public linkNextcloud: move or renameNextcloud: deleteNextcloud new fileSearch SlackRead a Slack channelRead recent Slack activityReply in a Slack threadSend a Slack DMSlack eventSend a WhatsApp messageSend WhatsApp mediaWhatsApp messageWhatsApp (Web): linkWhatsApp (Web): sendWhatsApp (Web): readPhone callPhone callSSH commandSSH machine factsSSH logsSSH read fileSSH serviceWireGuard serverWireGuard add peerWireGuard remove peerWireGuard statusElevenLabs speechElevenLabs transcribeElevenLabs voicesElevenLabs call transcriptElevenLabs call endedCodeStripe: readStripe: reportStripe: customerStripe: invoiceStripe: refundStripe: subscriptionStripe: payment linkStripe eventPolar: readPolar: reportPolar: refundPolar eventSort itemsLimit itemsAggregateDate & TimeXMLCSVGoogle Analytics reportSearch Console performanceSearch Console sitemapsSearch Console URL inspectionPageSpeed InsightsSEO auditRead RedditPost to RedditSearch YouTubeYouTube statsYouTube commentsComment on YouTubeRead XPost to XPost to FacebookPost to InstagramRead Facebook / InstagramSync proxiesCheck proxies

Triggers

Manual triggertrigger.manual

Starts the agent when you press Run; the run input is its output.

No settings.

Scheduletrigger.cron

Starts the agent on a cron schedule, e.g. every weekday at 09:00.

Schedule (cron)expr
Five fields: minute hour day-of-month month weekday. 0 9 * * * = every day at 09:00. Default "0 9 * * *".
Timezonetimezone
IANA zone the schedule is read in. Blank = server time.

Webhooktrigger.webhook

Starts the agent when its secret URL receives a POST; the JSON body is the input.

Respondrespondone of immediately, respondNode
immediately: answer 202 with the run id at once. respondNode: wait for a Respond to Webhook node and send its status, headers and body. Default "immediately".
Response timeout (seconds)timeoutSec
respondNode only: how long the caller is held. After that (or if the run ends without responding) it gets the immediate 202 answer. Default 30.

Jira issuetrigger.jira

Starts the agent once for every new Jira issue matching a JQL query; the issue is the input.

JQL *jql
Issues to start on. Checked about every 30 seconds with your Jira credentials; each matching issue starts one run, once.

Gmail messagetrigger.gmail

Starts the agent once for every new Gmail message matching a search query; the message is the input.

Search query *q
Gmail search syntax. Checked about every 30 seconds; each new matching message starts one run, once.

Nextcloud new filetrigger.nextcloudrisk: destructive

Starts the agent once for every new file in a Nextcloud folder; the file's path, size and type are the input.

Folderfolder
Nextcloud folder to watch (its direct files, not subfolders). Checked about every 30 seconds; each new file starts one run, once. Default "Inbox".

Slack eventtrigger.slack

Starts the agent when Slack sends a subscribed event; the event is the input. Its Request URL is on the agent page under Webhooks once the agent is saved.

Event typeseventTypes
Only these Slack event types start a run. Empty = every event your app subscribes to.

WhatsApp messagetrigger.whatsapp

Starts the agent when a WhatsApp Cloud API webhook arrives; the message is the input. Its Callback URL is on the agent page under Webhooks once the agent is saved.

Verify token *verifyToken
The same string you type into Meta's webhook setup form. It only guards the one-time GET handshake, and it is stored in the graph, so keep it low-value and never reuse a real secret.
Eventsevents
Which webhook events start a run. Empty = all of them. Default ["message"].

Phone calltrigger.phone

Starts the agent when Twilio posts an inbound call or the caller's speech. Its webhook URL is on the agent page under Webhooks once the agent is saved.

Spoken replyreply
Plain text spoken back to the caller immediately, before the graph runs. Static: the model cannot write this line live.
Eventsevents
Which Twilio callbacks start a run: a new inbound call, a caller's speech or digits, or a call status update. Empty = all of them.

ElevenLabs call endedtrigger.elevenlabs

Starts the agent when an ElevenLabs voice call ends, with its transcript and analysis.

Eventsevents
Which ElevenLabs webhooks start a run: a finished call's transcript and analysis, or an outbound call that never connected. Empty = both.
ElevenLabs agent idsagentIds
Only calls handled by these ElevenLabs agents. Empty = every agent in the workspace.

Stripe eventtrigger.striperisk: destructive

Starts the agent when your Stripe webhook endpoint delivers a signed event; the event is the input.

Event typeseventTypes
Only these Stripe event types start a run; a trailing * matches a prefix (invoice.*). Empty = every event the endpoint sends.

Polar eventtrigger.polarrisk: destructive

Starts the agent when your Polar webhook endpoint delivers a signed event; the event is the input.

Event typeseventTypes
Only these Polar event types start a run; a trailing * matches a prefix (subscription.*). Empty = every event the endpoint sends.

Actions

Web searchtavily.searchrisk: read

Searches the web with Tavily and returns titles, URLs and snippets.

Query *query
What to search the web for.
Max resultsmaxResults
How many results to return. 1 to 20. Default 5.
Topictopicone of general, news, finance
news = recent articles with a publish date. Blank = general web.
Time rangetimeRangeone of day, week, month, year
Only results from the last day, week, month or year. Blank = any time.
DepthsearchDepthone of basic, advanced
advanced = more relevant snippets, 2 credits instead of 1. Blank = basic.
Only these sitesincludeDomains
Restrict results to these domains, one per row. Blank = the whole web.

Read web pagestavily.extractrisk: read

Reads up to 20 web pages with Tavily Extract and returns their text as markdown.

URLs *urls
Pages to read, one per row. 1 to 20.
Focusquery
Optional: rerank the extracted text towards this question.
Depthdepthone of basic, advanced
basic = 1 credit per 5 pages; advanced also reads tables and embedded content, 2 credits per 5 pages. Default "basic".
Formatformatone of markdown, text
markdown or plain text. Default "markdown".
Max characters per pagemaxChars
Each page's text is cut here so a big site cannot flood the next step. 500 to 200,000. Default 20000.

Crawl a sitetavily.crawlrisk: read

Crawls a website with Tavily and returns each page's text, or just its URLs in map mode.

Start URL *url
Root of the site to crawl.
Modemodeone of crawl, map
crawl = pages with their text; map = only the list of URLs found (cheaper: 1 credit per 10 pages). Default "crawl".
Instructionsinstructions
Optional: which pages matter, in plain words. Doubles the mapping cost.
Max depthmaxDepth
How many links deep from the start URL. 1 to 5. Default 1.
Links per pagemaxBreadth
How many links to follow from each page. 1 to 500. Default 20.
Max pageslimit
Stop after this many pages. 1 to 500; every page costs credits. Default 50.
Only pathsselectPaths
Regex patterns; only matching paths are crawled.
Skip pathsexcludePaths
Regex patterns for paths to skip.
Leave the siteallowExternal
Follow links to other domains. Off keeps the crawl on the start URL's site. Default false.
Formatformatone of markdown, text
crawl only: markdown or plain text. Default "markdown".
Max characters per pagemaxChars
Each page's text is cut here so a big site cannot flood the next step. 500 to 200,000. Default 20000.

Deep researchtavily.researchrisk: read

Runs a Tavily research task and returns a cited report (content plus sources).

Question *input
What to research, in plain words.
Modelmodelone of mini, pro, auto
mini = 4 to 110 credits; pro = 15 to 250 credits, deeper; auto lets Tavily pick. Default "mini".
Request idrequestId
Set to check on an earlier research task instead of starting a new one.
Wait (s)waitSec
How long to poll for the finished report. 0 returns the request id at once. Max 600. Default 180.

MCP: list toolsmcp.toolsrisk: read

Lists the tools an external MCP server offers, with their input schemas.

Server URL *url
The MCP server's Streamable HTTP endpoint. Set by you, never by the model.
AuthenticationauthTypeone of none, basic, bearer, header, query, oauth2
none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default "none".
SecretauthSecret
Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
UsernameauthUser
Basic auth user name. Empty = the secret is user:password.
Key nameauthName
Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
OAuth2 connectionauthConnection
Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.

MCP: call a toolmcp.callrisk: destructive

Calls one tool on an external MCP server, from the list of tools you allowed.

Server URL *url
The MCP server's Streamable HTTP endpoint. Set by you, never by the model.
AuthenticationauthTypeone of none, basic, bearer, header, query, oauth2
none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default "none".
SecretauthSecret
Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
UsernameauthUser
Basic auth user name. Empty = the secret is user:password.
Key nameauthName
Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
OAuth2 connectionauthConnection
Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.
Allowed tools *allowedTools
Exact tool names this node may call, one per row. Anything else is refused. Use mcp.tools to see what the server offers.
Trusted toolstrustedTools
Subset of the allowed tools you have checked yourself and consider ordinary (a search, a lookup). They drop from “always asks a person” to your normal guardrail for messages. Leave empty if in doubt.
Tool *tool
Which of the allowed tools to call.
Argumentsargs
The tool's arguments as JSON, matching the schema mcp.tools reported.

Open a GitHub issuegithub.issuerisk: external-commswrites to an external system

Creates an issue in a GitHub repository.

Repository *repo
owner/name of the repository. Your github credential needs write access.
Title *title
Issue title. Expressions allowed.
Descriptionbody
Issue body, Markdown.

Jira search (JQL)jira.searchrisk: read

Finds Jira issues with a JQL query.

JQL *jql
Jira Query Language filter.
Max resultsmaxResults
How many issues to return. 1 to 500. Default 20.

Comment on a Jira issuejira.commentrisk: external-commswrites to an external system

Adds a comment to a Jira issue.

Issue key *issueKey
The issue to comment on.
Comment *body
Comment text. Blank lines start new paragraphs.

HTTP GEThttp.getrisk: read

Fetches a URL from an allowlisted host and returns JSON or text.

URL *url
Address to fetch. Its host must be in the allowlist.
Headersheaders
Extra request headers, e.g. {"authorization": "Bearer {{secret.github}}"}. A saved secret goes only to its allowed hosts and never shows in the run.
Allowed hostsallowlist
Hosts this node may reach, one per row. Empty = the node refuses.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
AuthenticationauthTypeone of none, basic, bearer, header, query, oauth2
none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default "none".
SecretauthSecret
Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
UsernameauthUser
Basic auth user name. Empty = the secret is user:password.
Key nameauthName
Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
OAuth2 connectionauthConnection
Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.

HTTP POSThttp.postrisk: writewrites to an external system

Sends a POST, PUT, PATCH or DELETE request to an allowlisted host.

URL *url
Address to send to. Its host must be in the allowlist.
Methodmethodone of POST, PUT, PATCH, DELETE
HTTP verb. Use HTTP GET for reads. Default "POST".
Bodybody
Request body. Text is sent as-is; a JSON object is encoded.
Content typecontentType
Value of the content-type header. Default "application/json".
Headersheaders
Extra request headers, e.g. {"authorization": "Bearer {{secret.github}}"}. A saved secret goes only to its allowed hosts and never shows in the run.
Allowed hostsallowlist
Hosts this node may reach, one per row. Empty = the node refuses.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
AuthenticationauthTypeone of none, basic, bearer, header, query, oauth2
none, basic, bearer, header (API key header), query (API key parameter) or oauth2 (a connection's token). The value comes from a saved secret or a connection, never from the graph. Default "none".
SecretauthSecret
Name of a saved secret (Settings → Secrets) for basic/bearer/header/query. Basic: the password, or user:password when no username is set. Goes only to the secret's allowed hosts.
UsernameauthUser
Basic auth user name. Empty = the secret is user:password.
Key nameauthName
Header name (default x-api-key) or query parameter (default api_key) for the API key presets.
OAuth2 connectionauthConnection
Integration whose connection token is sent as a bearer token: github, gmail, notion, slack. The account is picked under Connection.

Call an agentagent.call

Runs another agent inline and returns its result.

Agent *agentSlug
Slug of the agent to run. It runs inline and is billed to this run.
Workflowworkflow
Name of one of the agent's workflows to run. Blank = its primary workflow.
Inputinput
Run input handed to the called agent's trigger, as key/value pairs.
Timeout (ms)timeoutMs
Give up after this long. 1,000 to 7,200,000 (2 h): cover the callee's longest code session. Default 60000.

RSS / Atom feedrss.fetchrisk: read

Reads the newest items from an RSS or Atom feed.

Feed URL *url
An RSS or Atom feed address.
Max itemslimit
Newest items to keep. 1 to 100. Default 10.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".

Text templatetext.template

Builds a string from a template filled with upstream values.

Template *template
Text with {0} for the first input, {1.title} for a path into the second, {name} for {0.name}.

Ifif

Compares values and routes to the true or false branch.

Left value *left
Usually an expression, e.g. {{fetch.items.length}}.
Operatoropone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex
How the two values are compared. Default "truthy".
Right valueright
Ignored by is truthy / falsy / empty / not empty / exists.
Compare astypeone of auto, string, number, boolean, date
auto reads numbers as numbers, else text. Pick number, date, boolean or string to force one. Default "auto".
Conditionsconditions
Several conditions, as JSON [{left, op, right, type}]. When set, the single condition above is ignored.
Combinecombineone of and, or
and = all conditions must hold, or = any one is enough. Default "and".

Switchswitch

Routes to the branch whose case matches a value, else default.

Value to route on *value
Usually an expression; its value picks the branch.
Casescases
Each case becomes a branch, plus default when nothing matches.
Case sensitivecaseSensitive
Treat Urgent and urgent as different cases. Default false.

Map over itemsmap

Runs one node (or agent) once per item of an array.

Node per item *node
Node type to run once for every item.
Agent per itemagentSlug
Run this agent's whole graph per item instead of a single node.
Workflow per itemworkflow
Agent-per-item mode: name of the agent's workflow to run. Blank = its primary workflow.
Timeout per item (ms)timeoutMs
Agent-per-item mode only. 1,000 to 300,000. Default 60000.
Child config *config
Config for the per-item node. Use {{item}}, {{item.title}} and {{index}}.
Max itemsmaxItems
Hard cap, 1 to 100. Every item can be a paid call. Default 25.
Items fielditemsField
Path to the array inside the input. Blank = the input itself.

Filter itemsfilter

Keeps only the array items that match a condition.

Item fieldfield
Path inside each item to test. Blank = the item itself.
Operatoropone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex
How the field is compared to the value. Default "truthy".
Compare tovalue
Right-hand value. Ignored by is truthy / falsy / empty / not empty.
Max keptmax
Keep at most this many matching items. 1 to 500. Default 100.
Items fielditemsField
Path to the array inside the input. Blank = the input itself.

Mergemergerisk: destructive

Waits for every input and combines them: append, by position, by matching field, or pick one.

Modemodeone of append, position, field, choose
append: all items one after another. position: item 1 with item 1, 2 with 2. field: items whose field values match. choose: one input as it is, once all have finished. Default "append".
Items fielditemsField
Path to the list inside each input. Blank = the input itself.
Match field (input 1)field
Mode field: path inside each input-1 item to match on.
Match field (other inputs)field2
Mode field: path inside the other inputs' items. Blank = same as input 1.
Keepjoinone of inner, left, outer
Mode field. inner: only matches. left: every input-1 item, enriched when it matches. outer: every item of both sides. Default "inner".
Keep unpaired itemsincludeUnpaired
Mode position: when inputs differ in length, keep the extra items instead of dropping them. Default false.
Input to pass oninput
Mode choose: 1 = the first connected input, 2 = the second. 0 = whichever input ran first. Default 1.

Waitwait

Pauses for a fixed delay, then passes its input on.

Delay (ms)ms
How long to pause before passing the input on. 0 to 30,000. Default 1000.

Post to Slackslack.postrisk: external-commswrites to an external system

Posts a message to a Slack channel.

Webhook URLwebhookUrl
Slack incoming-webhook URL. Wins over the bot token when set.
Channelchannel
#channel or a channel id. Needed when posting with the bot token.
Message *text
What to post. Slack mrkdwn works.

Append to Notionnotion.appendrisk: writewrites to an external system

Appends a paragraph to a Notion page or adds a database row.

Page or database id *parentId
The 32-character id from the Notion URL. Share the page with your integration first.
Targettargetone of page, database
page appends a paragraph; database creates a row. Default "page".
Title propertytitleProperty
Name of the title column. Database target only. Default "Name".
Text *text
Paragraph text, or the new row's title.

Append row to Google Sheetsheets.appendrisk: writewrites to an external system

Appends one row to a Google Sheet.

Spreadsheet id *spreadsheetId
The long id in the sheet URL, between /d/ and /edit.
Rangerange
Sheet and start cell in A1 notation; the row is appended below existing data. Default "Sheet1!A1".
Row values *values
One cell per row here, left to right. Parsed as if typed into the sheet.

Send an emailemail.sendrisk: external-commswrites to an external system

Sends a plain-text email through Resend.

From *from
Sender address. Its domain must be verified with your email provider.
To *to
One address, or several separated by commas.
Subject *subject
Subject line. Expressions allowed.
Body *text
Plain-text message body.
API URLapiUrl
A Resend-compatible endpoint. The key comes from your resend credential. Default "https://api.resend.com/emails".
Allowed hostsallowlist
Hosts the API key may be sent to. Empty = the node refuses to send. Default ["api.resend.com"].

Reshape JSONjson.transform

Builds a new object by picking fields out of the input.

Fields *fields
JSON object mapping output keys to {path} of the input, e.g. {"title": "{items.0.title}"}. A bare {path} keeps the raw value.

Open a pull requestgithub.pr.createrisk: writewrites to an external system

Opens a pull request, as a draft by default.

Repository *repo
owner/name of the repository. Uses your github credential.
Title *title
Pull request title. Expressions allowed.
Descriptionbody
Pull request body, Markdown.
Head branch *head
The branch with the changes. owner:branch for a fork.
Base branchbase
The branch to merge into. Default "main".
Draftdraft
Open as a draft. Heavy CI often waits for ready-for-review. Default true.

Mark pull request readygithub.pr.readyrisk: writewrites to an external system

Takes a draft pull request out of draft so it can be reviewed and merged.

Repository *repo
owner/name of the repository. Uses your github credential.
Pull request *number
Pull request number. Expressions allowed.

Get a pull requestgithub.pr.getrisk: read

Reads a pull request: state, draft, mergeable, review decision and head commit.

Repository *repo
owner/name of the repository. Uses your github credential.
Pull request *number
Pull request number. Expressions allowed.

Pull request commentsgithub.pr.commentsrisk: read

Collects conversation comments, inline review comments and review verdicts on a pull request.

Repository *repo
owner/name of the repository. Uses your github credential.
Pull request *number
Pull request number. Expressions allowed.
Sincesince
Only comments at or after this ISO timestamp. Blank = all.
Only fromauthors
Keep only comments by these logins, e.g. a review bot. Empty = everyone.
IgnoreexcludeAuthors
Drop comments by these logins, e.g. your own agent.

Request a reviewgithub.pr.review.requestrisk: writewrites to an external system

Asks people or teams to review a pull request.

Repository *repo
owner/name of the repository. Uses your github credential.
Pull request *number
Pull request number. Expressions allowed.
Reviewers *reviewers
GitHub logins to ask for a review.
Teamsteams
Team slugs to ask for a review.

CI statusgithub.checksrisk: read

Combines check runs (or Actions runs) and commit statuses for a commit into green, red or pending, with failing names.

Repository *repo
owner/name of the repository. Uses your github credential.
Commit or branch *ref
Commit SHA (best: a pull request's head SHA), branch or tag.

Preview URLgithub.previewrisk: read

Finds the preview deployment of a commit or branch (Vercel, Netlify, any GitHub deployment) and its URL.

Repository *repo
owner/name of the repository. Uses your github credential.
Commit or branch *ref
The pushed branch or its head SHA.
Environmentenvironment
Deployment environment name, e.g. Preview. Blank = the newest non-production deployment.

Merge a pull requestgithub.pr.mergerisk: deploywrites to an external system

Merges a pull request (squash by default), guarded by the expected head commit, one merge per repository at a time.

Repository *repo
owner/name of the repository. Uses your github credential.
Pull request *number
Pull request number. Expressions allowed.
Expected head SHAsha
Merge only if the head is still this commit, the one that was reviewed and tested. Blank = no guard.
Merge methodmethodone of squash, merge, rebase
Must be allowed in the repository's settings. Default "squash".
Commit titlecommitTitle
Title of the merge commit. Blank = GitHub's default.
Delete branchdeleteBranch
Delete the head branch after a successful merge (same-repository branches only). Default false.

Delete a branchgithub.branch.deleterisk: destructivewrites to an external system

Deletes a branch from a GitHub repository. The default branch is refused by GitHub.

Repository *repo
owner/name of the repository. Uses your github credential.
Branch *branch
Name of the branch to delete, without refs/heads/.

Read a repository filegithub.file.getrisk: read

Reads a text file from a GitHub repository at a branch or commit.

Repository *repo
owner/name of the repository. Uses your github credential.
File path *path
Path of the file inside the repository.
Branch or commitref
Read the file at this branch, tag or SHA. Blank = default branch.

Get a Jira issuejira.issue.getrisk: read

Reads a Jira issue: fields, description text, acceptance criteria, epic, links and recent comments.

Issue key *issueKey
The Jira issue. Expressions allowed.

Move a Jira issuejira.transitionrisk: writewrites to an external system

Moves a Jira issue to a status by name, using whichever workflow transition leads there.

Issue key *issueKey
The Jira issue. Expressions allowed.
Target status *status
Status name to move the issue to, as shown on the board. Case does not matter.

Add a Jira labeljira.label.addrisk: writewrites to an external system

Adds a label to a Jira issue, keeping its other labels.

Issue key *issueKey
The Jira issue. Expressions allowed.
Label *label
One label. Jira labels cannot contain spaces.

Remove a Jira labeljira.label.removerisk: writewrites to an external system

Removes a label from a Jira issue, keeping its other labels.

Issue key *issueKey
The Jira issue. Expressions allowed.
Label *label
One label. Jira labels cannot contain spaces.

Assign a Jira issuejira.assignrisk: writewrites to an external system

Sets or clears the assignee of a Jira issue by Atlassian account ID.

Issue key *issueKey
The Jira issue. Expressions allowed.
Account IDaccountId
Atlassian account ID of the new assignee. Blank = unassign.

Create a Jira issuejira.issue.createrisk: external-commswrites to an external system

Creates a Jira issue and returns its key and link.

Project key *project
The Jira project the issue is created in.
Issue typeissueType
Task, Bug, Story, ... as named in the project. Default "Task".
Summary *summary
One-line title of the issue.
Descriptiondescription
Plain text. Blank lines start paragraphs, lines starting with "- " become bullets.
Labelslabels
Comma-separated, or a JSON array. Spaces inside a label become dashes.
Prioritypriority
Priority name. Blank = the project default.
Assigneeassignee
Email or Atlassian account ID. Blank = unassigned.
Parent / epicparent
Issue key of the parent or epic. Blank = none.

Code sessioncode.sessionrisk: readwrites to an external system

Runs a Claude Code session in a git worktree on your local runner, pushes the branch and returns it.

Repository *repo
Absolute path of a git repo on the runner machine, or an https/ssh git URL to clone.
Base branchbaseBranch
The session branches off this. Never written to. Default "main".
Branch namebranchName
New branch for the session. {slug} = first words of the prompt, {rand} = random, {date} = YYYYMMDD. Default "code/{slug}-{rand}".
Task *prompt
What the session should do, in plain words.
RolesystemPrompt
Appended to Claude Code's system prompt, e.g. the role and its rules.
Profileprofileone of readonly, edit
readonly = look, never change files; edit = may edit and commit on its own branch. Default "readonly".
Max turnsmaxTurns
Hard cap on agent turns. 1 to 200. Default 30.
Timeout (s)timeoutSec
The session is killed after this long. 30 to 14,400. Default 1800.
House ruleshouseRulesPaths
Repo-relative files or folders of .md rules handed to the session, one per row.
Push branchpush
After an edit session with commits, the runner pushes the branch to origin (its own git credentials; the session never pushes). CODE_SESSION_PUSH=0 on the runner turns it off everywhere. Default true.
Push requiredpushRequired
A failed or skipped (capped) push fails the node instead of returning pushError. Default false.

Approvalapproval

Pauses the run until you approve or reject it in Messages.

Title *title
What is being approved, in one line.
Checklistchecklist
Markdown list. Every item must be ticked before Approve is possible. Expressions allowed.
Detailsdetails
Markdown shown under the checklist: audit findings, a diff summary, a link.
Approversapproversone of owner
Who can decide. For now the person whose run it is. Default "owner".
On rejectonRejectone of fail, branch
fail stops the run; branch routes to the rejected edge instead. Default "fail".
No dashesnoDashes
Replace em dashes and spaced en dashes with a comma, as output.card does. Ranges like 2019-2020 stay.
Timeout (hours)timeoutHours
How long the run waits for a person. Default 168 (7 days), max 720. Default 168.

Askask

Pauses the run to ask you a question in Messages; your answer is the output.

Question *question
One question, answerable in a word if you can.
Contextcontext
Markdown under the question: what you would do and why.
Answer optionsanswerOptions
One per line; shown as buttons. A typed answer is still possible.
AskescalateToone of owner
Who gets the question. For now the person whose run it is. Default "owner".
Human onlyhumanOnly
A product decision: refuse answers from API tokens and MCP (an orchestrating AI). Default false.
Default answerfallback
Used when nobody answers in time. Empty = the run fails.
Timeout (hours)timeoutHours
How long the run waits for a person. Default 168 (7 days), max 720. Default 168.

Open browserbrowser.openrisk: read

Starts (or reuses) this run's browser session and outputs {sessionId}.

New sessionnewSession
Open an additional browser instead of this run's shared one. Default false.
Persistent profileprofile
Blank = a fresh browser that forgets everything at the end of the run. A name (lowercase letters, digits and dashes) opens a Chromium profile that survives runs, so a site login done once is still there next time. One run at a time per profile.
Record the screenvideo
Film this browser as a webm. The Close browser node saves it as a run file; without that node the recording is thrown away. Default false.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".

Go to URLbrowser.gotorisk: read

Navigates the browser to a URL and returns where it landed.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
URL *url
http(s) address to open. Private and local addresses are refused.

Clickbrowser.clickrisk: writewrites to an external system

Clicks an element found by a stable locator (role, label, text, css…).

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default {"by":"css","value":""}.
Buttonbuttonone of left, right
Mouse button. Default "left".
Double clickdouble
Click twice. Default false.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.
If blockedonBlockedone of fail, branch, handoff
Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default "fail".

Fill fieldbrowser.fillrisk: writewrites to an external system

Types a value or a saved secret into an input; secrets are masked everywhere.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default {"by":"css","value":""}.
Valuevalue
Text to type. Leave blank when using a saved secret.
Saved secretsecret
Name of a secret saved in Settings (secret:<name>). Filled at run time, never shown or logged.
Press Entersubmit
Press Enter after filling. Default false.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.
If blockedonBlockedone of fail, branch, handoff
Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default "fail".

Select optionbrowser.selectrisk: writewrites to an external system

Chooses an option in a <select> by value or label.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default {"by":"css","value":""}.
Option *value
Option value or visible label.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.

Check boxbrowser.checkrisk: writewrites to an external system

Ticks or unticks a checkbox or radio button.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default {"by":"css","value":""}.
Checkedchecked
On = tick the box, off = untick it. Default true.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.

Press keybrowser.pressrisk: external-commswrites to an external system

Presses a key, in an element or wherever the focus is.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Keykey
Playwright key name: Enter, Tab, Escape, ArrowDown, Control+A… Default "Enter".
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.

Hoverbrowser.hoverrisk: read

Moves the mouse over an element, e.g. to open a menu.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Default {"by":"css","value":""}.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.

Scrollbrowser.scrollrisk: read

Scrolls an element into view, or the page by some pixels.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.
Pixelsdy
Without an element: scroll by this much, positive = down. Default 600.

Wait forbrowser.waitrisk: read

Waits for an element, a URL, some text, network idle or a fixed time.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Wait untiluntilone of visible, hidden, url, text, network_idle, ms
visible / hidden = the element; url = the address contains the text; text = the page shows it; network_idle; ms = a fixed pause. Default "visible".
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.
Text or URL parttext
For url and text.
Pause (ms)ms
For ms. 0 to 30,000. Default 1000.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.
If blockedonBlockedone of fail, branch, handoff
Element missing, timeout or captcha: fail the run, take branch blocked (success = branch ok), or hand over to a human (the run pauses until they press Done in Messages, up to 24 h) and retry once. Default "fail".

Assert pagebrowser.assertrisk: read

Checks the page and routes to the pass or fail branch.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Checkcheckone of text_contains, text_equals, visible, hidden, exists, value_equals, count_equals, url_contains, title_contains
What must be true. url_contains and title_contains need no element. Default "text_contains".
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.
Expectedexpected
Text, value or count to compare with.
Retry for (ms)timeoutMs
Keep checking this long before reporting fail. 0 to 60,000. Default 5000.

Extract databrowser.extractrisk: read

Reads text, attributes, lists, tables or links from the page (untrusted page data).

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Extractmodeone of text, attribute, all, table, links
text of one element, an attribute, all matches → items[], a table → rows[], or links. Default "text".
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.
Attributeattribute
For attribute, e.g. href.
Max itemsmaxItems
Cap for all, table and links. 1 to 1,000. Default 200.
Timeout (ms)timeoutMs
How long to wait for the element. 100 to 60,000. Default 10000.

Screenshotbrowser.screenshotrisk: read

Captures the page or one element as run evidence (PNG).

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Full pagefullPage
The whole scrollable page instead of the visible part. Default false.
Elementlocator
Which element: find by role, label, text, placeholder, css, testid or xpath, plus match # and iframe. Optional here. Default {"by":"css","value":""}.

Page snapshotbrowser.snapshotrisk: read

Compact accessibility tree with [ref_N] ids, for an AI agent to decide what to click.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Interactive onlyinteractiveOnly
Only links, buttons and inputs: far shorter. Default true.
Max charactersmaxChars
Cut the snapshot here. 500 to 20,000. Default 6000.

Save cookiesbrowser.cookies.saverisk: read

Stores the browser's cookies encrypted under a name, so a login survives runs.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Name *name
Your name for this saved login, e.g. the site. Stored encrypted as cookies:<name>.

Load cookiesbrowser.cookies.loadrisk: read

Restores cookies saved by browser.cookies.save into the browser.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Name *name
Your name for this saved login, e.g. the site. Stored encrypted as cookies:<name>.

Hand over to mebrowser.handoff

Pauses the run so you can act in the live browser (captcha, login, 2FA), then continues.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
What to do *instructions
Shown to you next to the live browser.
Success elementlocator
Optional: after Done, this element must be visible (e.g. the account menu). Either this or the success URL is enough. Default {"by":"css","value":""}.
Success URL containssuccessUrl
Optional: after Done, the page URL must contain one of these (comma separated). Counts as success on its own.
Save cookies assaveCookiesAs
Optional: store the cookies under this name the moment you press Done, before anything is checked, so a login is never lost.
Timeout (min)timeoutMinutes
How long the run waits for you. Default 1440 (24 h), up to 10080 (7 days). Default 1440.
On give uponGiveUpone of fail, branch
fail stops the run; branch routes to gave_up (Done = branch done). Default "fail".

Close browserbrowser.closerisk: read

Closes a browser session and saves its screen recording, if it made one.

Sessionsession
Blank = this run's browser. Or {{open.sessionId}} from a browser.open node.
Recording file namevideoName
Name of the saved webm, without extension. Only used when the session was opened with Record the screen. Default "recording".

Scrape pagescrape.pagerisk: read

Fetches a page and returns clean text, title, meta, links, images and selector fields.

URL *url
Page to scrape. Private and internal addresses are refused.
Render JavaScriptrender
Load the page in a real browser (browser service) instead of a plain HTTP request. Default false.
Wait forwaitFor
Render only: networkidle, ms:1500, or text:Some visible text. Default "networkidle".
Main content onlymainContent
Readability-style article text instead of the whole page's text. Default true.
LinksincludeLinks
Return the page's links (absolute, deduplicated, up to 500). Default true.
ImagesincludeImages
Return image URLs and alt text (up to 200). Default true.
Fieldsfields
field -> CSS or XPath selector, or {selector, attr, all}. attr: text (default), html or an attribute; href/src come back absolute.
Item selectoritemSelector
With fields: one item per match, fields relative to it (items[]). Blank = one object (data).
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 1000.

Scrape listscrape.listrisk: read

Pages through a listing and extracts items with a field schema, deduplicated.

First page *url
Listing page to start from.
Item selector *itemSelector
CSS or XPath matching one element per item.
Fieldsfields
field -> CSS or XPath selector, or {selector, attr, all}. attr: text (default), html or an attribute; href/src come back absolute.
Next linknextSelector
CSS or XPath of the next-page link. Or use a page URL template.
Page URL templatepageUrlTemplate
Instead of a next link: a URL with {page}, counted up from the start number.
Start page numberpageStart
First {page} value for the template. Default 1.
Max pagesmaxPages
Stop after this many pages. 1 to 100. Default 5.
Dedupe by fielddedupeBy
Items with the same value of this field are kept once. Blank = identical items.
Render JavaScriptrender
Load the page in a real browser (browser service) instead of a plain HTTP request. Default false.
Wait forwaitFor
Render only: networkidle, ms:1500, or text:Some visible text. Default "networkidle".
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 1000.

Sitemap URLsscrape.sitemaprisk: read

Lists a site's URLs from robots.txt and sitemap.xml, with include and exclude filters.

Site or sitemap URL *url
A sitemap.xml, or any page of the site (its robots.txt Sitemap lines are used, else /sitemap.xml).
Includeinclude
Keep URLs containing one of these (* is a wildcard). Empty = all.
Excludeexclude
Drop URLs containing one of these (* is a wildcard).
Max URLslimit
Stop after this many URLs. 1 to 5,000. Default 500.
Max sitemapsmaxSitemaps
Sitemap files to read, index files included. 1 to 50. Default 10.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 250.

Crawl sitescrape.crawlrisk: read

Bounded same-host crawl, two at a time and polite, returning a summary per page.

Start URL *url
Crawl starts here and stays on this host.
Max pagesmaxPages
Requests to make at most. 1 to 200. Default 20.
Max depthmaxDepth
Link hops from the start page. 0 = only the start page. Default 2.
Includeinclude
Only follow URLs containing one of these (* is a wildcard). Empty = all.
Excludeexclude
Never follow URLs containing one of these (* is a wildcard).
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 1000.

Wait untilwait.until

Pauses the run without a worker until a time, a polled condition or a webhook call.

Wait formodeone of time, poll, webhook
time: a moment or duration. poll: re-check a read-only node until a condition holds. webhook: a POST to a one-time resume URL. Default "time".
Duration (seconds)seconds
Time mode: how long to wait when no timestamp is set. Up to 30 days. Default 60.
Until (timestamp)until
Time mode: ISO timestamp to resume at. Overrides the duration. Expressions allowed.
Check nodenodeone of http.get, rss.fetch, github.checks, github.preview, github.pr.get, github.pr.comments, github.file.get, jira.issue.get, jira.search
Poll mode: the read-only node run on every check. Default "http.get".
Check config *config
Poll mode: config for the check node, as for that node. Expressions allowed.
Result fieldfield
Poll mode: path in the check result to test. Blank = the whole result.
Operatoropone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex
Poll mode: how the field is compared to the value. Default "truthy".
Compare tovalue
Poll mode: right-hand value. Ignored by is truthy / falsy / empty / not empty.
Check every (seconds)intervalSec
Poll mode: pause between checks. 30 seconds to 1 day. Default 300.
Timeout (hours)timeoutHours
Poll and webhook: give up after this long. Default 24, max 720 (30 days). Default 24.
On timeoutonTimeoutone of fail, branch
fail stops the run; branch routes to the timeout edge (done otherwise). Default "fail".

Loop untilloop

Repeats an agent or workflow until its output meets a condition, with a hard cap.

Body agentagentSlug
Agent whose graph runs once per iteration. Billed to this run.
Body workflowworkflowId
Or: id of another workflow of this same agent to run per iteration.
Input per iterationinput
Trigger input of each iteration. {{iteration}} is 1, 2, …; {{previous}} is the last iteration's output (null at first).
Until: output fieldfield
Path in the iteration output to test. Blank = the whole output.
Until: operatoropone of eq, ne, contains, not_contains, startsWith, endsWith, gt, gte, lt, lte, truthy, falsy, empty, not_empty, exists, not_exists, regex, not_regex
Stop looping when the field compared to the value is true. Default "truthy".
Until: compare tovalue
Right-hand value. Ignored by is truthy / falsy / empty / not empty.
Max iterationsmaxIterations
Hard cap, 1 to 20. Every iteration can be paid calls. Default 3.
When exhaustedonExhaustedone of fail, branch
fail stops the run; branch routes to the exhausted edge (done otherwise) to escalate. Default "fail".
Timeout per iteration (ms)timeoutMs
1,000 to 7,200,000 (2 h): cover every agent.call the body makes. Default 60000.

Extract textdoc.extractrisk: read

Pulls the text out of a PDF, Word, OpenDocument, e-book or HTML file as Markdown.

Inputinput
A file from this run ({{render.files[0]}} or an artifact id), a data: URL, or text. Default "{0}".
Input formatinputFormatone of auto, markdown, html, latex, docx, odt, epub, pdf
auto = from the file name or type. Default "auto".
Max charactersmaxChars
Longer text is cut here (a knowledge source takes up to 5MB). Default 200000.

Only new itemsseen.filter

Drops items this agent already saw in an earlier successful run.

Key fieldkey
Path inside each item that identifies it, e.g. link. Blank = the whole item.
Scopescope
Separate seen sets per agent, e.g. news or jobs. Letters, digits, _ . : - Default "default".
Forget after (days)ttlDays
An item counts as new again after this many days. 0 = never forget, max 365. Default 30.
Max new itemsmax
Pass on at most this many unseen items. 1 to 500. Default 100.
Items fielditemsField
Path to the array inside the input, e.g. results. Blank = the input itself.

Mark items seenseen.mark

Remembers these items so a later run's Only-new-items drops them. Passes everything through.

Key fieldkey
Path inside each item that identifies it, e.g. link. Blank = the whole item.
Scopescope
Separate seen sets per agent, e.g. news or jobs. Letters, digits, _ . : - Default "default".
Forget after (days)ttlDays
An item counts as new again after this many days. 0 = never forget, max 365. Default 30.

Forget seen itemsseen.clearwrites to an external system

Empties this agent's seen set so every item counts as new again.

Scopescope
Which seen set to forget. Blank = every scope of this agent. Default "default".

Add to knowledgeknowledge.addrisk: writewrites to an external system

Stores text in a knowledge base so later runs and agents can retrieve it.

Knowledge base *kb
Which base to use, by id or by its slug. Set by the author, never by the model.
Texttext
What to store. {0} is the first input, {0.summary} a path into it; {{node}} expressions work too. Default "{0}".
Titletitle
Shown in citations. Blank = the run id.
Replaces sourceref
A stable id for where the text came from (e.g. a file path). Set = an earlier source with the same id is replaced, so a re-sync updates instead of duplicating. Blank = always add.
Metadatametadata
Stored on every chunk, so a later search can filter on it.

AWS readcloud.aws.readrisk: read

Reads EC2 instances, S3 buckets, RDS databases, Cost Explorer costs or CloudWatch alarms. Read-only.

What to readwhatone of instances, buckets, databases, costs, alerts, describe
instances = EC2, buckets = S3, databases = RDS, costs = Cost Explorer for the period, alerts = CloudWatch alarms in ALARM, describe = the one pinned instance. Default "instances".
Region *region
AWS region these calls go to, e.g. eu-central-1. Fixed by the author.
Instance idinstanceId
Only for describe: the one EC2 instance this node may look at.
Costs fromstart
YYYY-MM-DD, inclusive. Blank = the first of this month.
Costs toend
YYYY-MM-DD, exclusive. Blank = tomorrow.

AWS changecloud.aws.writerisk: infrawrites to an external system

Starts, stops, restarts, scales, snapshots or tags one pinned AWS resource. Put an Approval before it.

Actionactionone of start, stop, restart, scale, snapshot, tag
start/stop/restart the pinned EC2 instance, scale the pinned Auto Scaling group, snapshot the pinned volume, or tag the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default "start".
Region *region
AWS region these calls go to, e.g. eu-central-1. Fixed by the author.
Instance idinstanceId
The one EC2 instance this node may start, stop, restart or tag.
Auto Scaling groupgroupName
The one Auto Scaling group this node may resize.
Volume idvolumeId
The one EBS volume this node may snapshot.
Desired capacitycapacity
For scale: how many instances the Auto Scaling group should run. Default 1.
Tag keytagKey
For tag: the tag name to set.
Tag valuetagValue
For tag: the tag value to set.

Google Cloud readcloud.gcp.readrisk: read

Reads Compute Engine instances, Cloud Storage buckets, Cloud SQL, billing costs or Cloud Logging errors. Read-only.

What to readwhatone of instances, buckets, databases, costs, alerts, describe
instances = Compute Engine, buckets = Cloud Storage, databases = Cloud SQL, costs = the BigQuery billing export for the period, alerts = Cloud Logging entries at ERROR or worse, describe = the one pinned instance. Default "instances".
Project id *project
The GCP project these calls go to. Fixed by the author.
Zonezone
Zone of the pinned instance or disk, e.g. europe-west4-a.
Instance nameinstanceName
Only for describe: the one instance this node may look at.
Billing export tablebillingTable
Only for costs: project.dataset.table of the Cloud Billing BigQuery export.
Costs fromstart
YYYY-MM-DD, inclusive. Blank = the first of this month.
Costs toend
YYYY-MM-DD, exclusive. Blank = tomorrow.

Google Cloud changecloud.gcp.writerisk: infrawrites to an external system

Starts, stops, restarts, resizes, snapshots or labels one pinned Google Cloud resource. Put an Approval before it.

Actionactionone of start, stop, restart, scale, snapshot, tag
start/stop/restart (reset) the pinned instance, resize the pinned managed instance group, snapshot the pinned disk, or set a label on the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default "start".
Project id *project
The GCP project these calls go to. Fixed by the author.
Zonezone
Zone of the pinned instance or disk, e.g. europe-west4-a.
Instance nameinstanceName
The one instance this node may start, stop, restart or label.
Instance group managergroupName
The one managed instance group this node may resize.
Disk namediskName
The one persistent disk this node may snapshot.
Group sizesize
For scale: how many instances the managed group should run. Default 1.
Label keylabelKey
For tag: the label name to set (lowercase).
Label valuelabelValue
For tag: the label value to set (lowercase).

Azure readcloud.azure.readrisk: read

Reads Azure virtual machines, storage accounts, SQL servers, Cost Management costs or open alerts. Read-only.

What to readwhatone of instances, buckets, databases, costs, alerts, describe
instances = virtual machines, buckets = storage accounts, databases = SQL servers, costs = Cost Management for the period, alerts = Alerts Management alerts, describe = the one pinned resource id. Default "instances".
Subscription id *subscriptionId
The Azure subscription these calls go to. Fixed by the author.
Resource idresourceId
Only for describe: the one ARM resource id this node may look at.
Costs fromstart
YYYY-MM-DD, inclusive. Blank = the first of this month.
Costs toend
YYYY-MM-DD, exclusive. Blank = tomorrow.

Azure changecloud.azure.writerisk: infrawrites to an external system

Starts, stops, restarts, scales, snapshots or tags one pinned Azure resource. Put an Approval before it.

Actionactionone of start, stop, restart, scale, snapshot, tag
start/stop (deallocate)/restart the pinned VM, set the pinned scale set's capacity, snapshot the pinned disk, or merge a tag onto the pinned resource. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default "start".
Subscription id *subscriptionId
The Azure subscription these calls go to. Fixed by the author.
Resource groupresourceGroup
Resource group of the pinned resources.
Virtual machinevmName
The one VM this node may start, stop or restart.
Scale setscaleSetName
The one virtual machine scale set this node may resize.
Managed diskdiskName
The one managed disk this node may snapshot.
Locationlocation
Azure region the snapshot is created in, e.g. westeurope.
Resource idresourceId
The one ARM resource id this node may tag.
Capacitycapacity
For scale: how many instances the scale set should run. Default 1.
Tag keytagKey
For tag: the tag name to set.
Tag valuetagValue
For tag: the tag value to set.

Oracle Cloud readcloud.oci.readrisk: read

Reads OCI compute instances, Object Storage buckets, DB systems, Usage API costs or Monitoring alarms. Read-only.

What to readwhatone of instances, buckets, databases, costs, alerts, describe
instances = Compute, buckets = Object Storage, databases = DB systems, costs = the Usage API for the period, alerts = Monitoring alarms, describe = the one pinned instance. Default "instances".
Region *region
OCI region these calls go to, e.g. eu-frankfurt-1. Fixed by the author.
Compartment OCID *compartmentId
The compartment these calls are scoped to.
Object Storage namespacenamespace
Only for buckets: the tenancy's Object Storage namespace.
Instance OCIDinstanceId
Only for describe: the one instance this node may look at.
Costs fromstart
YYYY-MM-DD, inclusive. Blank = the first of this month.
Costs toend
YYYY-MM-DD, exclusive. Blank = tomorrow.

Oracle Cloud changecloud.oci.writerisk: infrawrites to an external system

Starts, stops, restarts, resizes, backs up or tags one pinned Oracle Cloud resource. Put an Approval before it.

Actionactionone of start, stop, restart, scale, snapshot, tag
start/stop/restart (soft reset) the pinned instance, resize the pinned instance pool, back up the pinned boot volume, or set a freeform tag on the pinned instance. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default "start".
Region *region
OCI region these calls go to, e.g. eu-frankfurt-1. Fixed by the author.
Instance OCIDinstanceId
The one instance this node may start, stop, restart or tag.
Instance pool OCIDinstancePoolId
The one instance pool this node may resize.
Boot volume OCIDbootVolumeId
The one boot volume this node may back up.
Pool sizesize
For scale: how many instances the pool should run. Default 1.
Tag keytagKey
For tag: the freeform tag name to set.
Tag valuetagValue
For tag: the freeform tag value to set.

Nebius Cloud readcloud.nebius.readrisk: read

Reads Nebius AI Cloud instances, disks, Kubernetes clusters, buckets or quotas in one pinned project. Read-only.

What to readwhatone of instances, disks, clusters, buckets, quotas, describe
instances = Compute VMs, disks = Compute disks, clusters = Managed Kubernetes, buckets = Object Storage, quotas = quota allowances and usage, describe = the one pinned instance. Default "instances".
Project id *projectId
The Nebius project these calls are scoped to. Fixed by the author.
Instance idinstanceId
Only for describe: the one instance this node may look at.

Nebius Cloud changecloud.nebius.writerisk: infrawrites to an external system

Starts or stops one pinned Nebius AI Cloud instance. Put an Approval before it.

Actionactionone of start, stop
Start or stop the pinned instance. Nothing else. Key, credential, IAM user and policy operations are out of scope: this node cannot perform them. Default "start".
Instance id *instanceId
The one instance this node may start or stop.

Token Factory modelsnebius.tf.modelsrisk: read

Lists the Nebius Token Factory models with context length and prices (Nebius's own plus alleex's price table).

Filtersearch
Only models whose id contains this text. Blank = all.

Token Factory file uploadnebius.tf.file.uploadrisk: writewrites to an external system

Uploads a JSONL file to Nebius Token Factory for a batch or fine-tuning job and returns its file id.

Purposepurposeone of batch, fine-tune
batch = input for a batch job; fine-tune = training or validation data. Default "batch".
File namefilename
Name shown in Token Factory. Default "input.jsonl".
JSONL content *content
One JSON object per line. Up to 20 MB.

Token Factory batch jobnebius.tf.batch.createrisk: moneywrites to an external system

Starts a Nebius Token Factory batch job over an uploaded JSONL file (OpenAI batch shape; unverified against current docs).

Input file id *inputFileId
A file uploaded with purpose batch.
Endpointendpointone of /v1/chat/completions, /v1/completions, /v1/embeddings
The API every line of the file is sent to. Default "/v1/chat/completions".
Completion windowcompletionWindow
How long Nebius may take, e.g. 24h. Batch runs at a lower price than live calls. Default "24h".
Descriptiondescription
Stored as metadata.description on the job.

Token Factory fine-tunenebius.tf.finetune.createrisk: moneywrites to an external system

Starts a Nebius Token Factory fine-tuning job on a pinned model and training file.

Base model *model
The model to fine-tune. Fixed by the author.
Training file id *trainingFile
A file uploaded with purpose fine-tune. Fixed by the author.
Validation file idvalidationFile
Optional held-out file. Fixed by the author.
Name suffixsuffix
Appended to the fine-tuned model's name. Max 64 characters.
EpochsnEpochs
Passes over the training data. 1 to 20 (Nebius default 3). Default 3.
Learning ratelearningRate
Nebius default 1e-5. Default 0.00001.
Batch sizebatchSize
Nebius default 8. Default 8.
LoRAlora
Train a LoRA adapter instead of all weights (cheaper). Default false.
LoRA rankloraR
Only with LoRA. Nebius default 8. Default 8.
Seedseed
Fixes the run for reproducibility. Default 42.

Token Factory job statusnebius.tf.jobrisk: read

Reads the status (and optionally the results) of a Nebius Token Factory batch, fine-tuning job or Data Lab operation.

Kindkindone of batch, fine_tune, operation
batch = /v1/batches, fine_tune = /v1/fine_tuning/jobs, operation = a Data Lab operation (/v1/operations). Default "batch".
Job idid
Blank = the most recent jobs of that kind (not for operation).
Fetch resultsresults
batch: download the output file once completed. operation: the first 100 result rows. Capped at 128 KB. Default false.

Search Gmailgmail.searchrisk: read

Finds messages in Gmail with a search query and returns their headers.

Search queryq
Gmail search syntax, exactly as in the Gmail search box. Empty = the newest messages.
How manymaxResults
Newest matches to return, 1 to 50. Each one costs a second lookup for its headers. Default 10.

Read a Gmail messagegmail.getrisk: read

Reads one Gmail message and returns its headers and plain-text body.

Message id *messageId
The Gmail message id, as returned by Search Gmail or the Gmail trigger.

Send a Gmail messagegmail.sendrisk: external-commswrites to an external system

Sends a plain-text email from your Gmail account.

To *to
One address, or several separated by commas.
Subject *subject
Subject line. Expressions allowed.
Body *text
Plain-text message body.
Cccc
Copy recipients, separated by commas.
Bccbcc
Blind-copy recipients, separated by commas.
Fromfrom
Sender address. Must be your Gmail address or one of its verified aliases; blank = the account itself.
Thread idthreadId
Put the mail in this existing thread. Reply threading also needs the In-Reply-To field below.
In reply toinReplyTo
Message-Id header of the mail being answered. Gmail needs this, not just the thread id, to thread a reply.

Save a Gmail draftgmail.draftrisk: writewrites to an external system

Saves a plain-text email as a Gmail draft instead of sending it.

To *to
One address, or several separated by commas.
Subject *subject
Subject line. Expressions allowed.
Body *text
Plain-text message body.
Cccc
Copy recipients, separated by commas.
Bccbcc
Blind-copy recipients, separated by commas.
Fromfrom
Sender address. Must be your Gmail address or one of its verified aliases; blank = the account itself.
Thread idthreadId
Put the mail in this existing thread. Reply threading also needs the In-Reply-To field below.
In reply toinReplyTo
Message-Id header of the mail being answered. Gmail needs this, not just the thread id, to thread a reply.

Relabel a Gmail messagegmail.labelrisk: writewrites to an external system

Adds and removes Gmail labels on one message, so it can be archived or marked read.

Message id *messageId
The Gmail message to relabel, as returned by Search Gmail or the Gmail trigger.
Labels to addaddLabelIds
Label ids to add. System labels use their own names.
Labels to removeremoveLabelIds
Label ids to remove. Removing UNREAD marks the message read; removing INBOX archives it.

Nextcloud: list foldernextcloud.listrisk: destructive

Lists a Nextcloud folder with size, modified time and type, optionally up to 3 levels deep.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
Folderpath
Folder to list, inside the restricted folder. Blank = its top.
Depthdepth
1 = this folder only, up to 3 levels of subfolders. Default 1.
Showonlyone of all, files, folders, text
all, files, folders, or text = only files whose text nextcloud.download can read (txt, md, csv, json…). Default "all".

Nextcloud: photos to knowledgenextcloud.photosrisk: destructivewrites to an external system

Reads new photos in a Nextcloud folder with a vision model (the images are sent to that model's vendor) and returns the technical ones as one document.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
Photo folderpath
The folder the phone syncs into, inside the restricted folder. Android's Nextcloud app uses InstantUpload, iOS often Photos. Default "InstantUpload".
Depthdepth
1 = this folder only, up to 3 levels of subfolders (phones file by month). Default 2.
Vision modelmodel
vendor:model that SEES the photos. Blank = the cheapest vision model you have a key for. The default agent model has no eyes.
Max images per runmaxImages
Stop after this many new photos. The rest follow on the next run. Default 100.
Skip files over (MB)maxMb
Photos larger than this are left for a later look and counted as skipped. Default 8.
Seen setscope
Name of this agent's memory of photos it already read. Changing it re-reads everything. Default "photos".
Sort photossortone of off, copy, move
off = only classify. copy/move = also file each photo under Technik, Wissen or Privat. Junk is left alone and nothing is ever deleted. Default "off".
Sort foldersortInto
Where the Technik / Wissen / Privat subfolders are created, inside the restricted folder. Default "Sortiert".
Create the sort folderscreateFolders
Create Sort folder and its Technik / Wissen / Privat subfolders when they are missing. They are the agent's own output folders and always inside the restricted folder. The photo folder itself is only read, never created. Default true.

Nextcloud: download filenextcloud.downloadrisk: destructive

Fetches one Nextcloud file into the run as an artifact, with its text when it is a text file.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
File *path
The file to fetch, inside the restricted folder.
Size limit (MB)maxMb
Refuse larger files. Up to 10 MB (the run-artifact limit). Default 10.
Attach to the runsave
Store the file as a run artifact you can open from the run. Default true.
Text charactersmaxTextChars
For text files (txt, md, csv, json…): include up to this many characters as `text`. 0 = none. Default 20000.

Nextcloud: upload filenextcloud.uploadrisk: destructivewrites to an external system

Stores text, JSON or a run artifact (like a chat upload) as a file in Nextcloud, creating folders as needed.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
Save as *path
Target file path inside the restricted folder. Ending in / = that folder, keeping the source file's name.
Contentcontent
Text to store; an object or list is stored as JSON. Ignored when an artifact is given.
ArtifactartifactId
Store this run artifact (e.g. a file uploaded in chat: {{trigger.files.0.artifactId}}) instead of Content.
If the file existsconflictone of rename, overwrite, fail
rename = save as “name (2).ext”, overwrite = replace it, fail = stop with an error. Default "rename".
Create folderscreateFolders
Create missing folders on the way. Default true.

Nextcloud: search filesnextcloud.searchrisk: destructive

Finds Nextcloud files by name (WebDAV SEARCH) or by content (Full text search app), newest first.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
Search for *query
Part of the file name (name), or words inside files (content, needs Nextcloud's Full text search app).
Matchmodeone of name, content
name = file and folder names; content = full-text search (not available with Restrict to folder). Default "name".
Max resultslimit
1 to 100. Default 20.

Nextcloud: public linknextcloud.sharerisk: destructivewrites to an external system

Creates a read-only public link to a Nextcloud file or folder, with an expiry date and optional password.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
File or folder *path
What to share, inside the restricted folder.
Expires after (days)expireDays
The link stops working after this many days. 1 to 90. Default 7.
Passwordpassword
Optional. Anyone opening the link must type it. Your server's password policy applies.

Nextcloud: move or renamenextcloud.moverisk: destructivewrites to an external system

Moves or renames a Nextcloud file or folder, creating target folders as needed.

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
File or folder *path
What to move, inside the restricted folder.
New path *newPath
Where it goes. Ending in / = into that folder, keeping the name. Also renames.
Overwriteoverwrite
Replace whatever is at the target. Off = stop if it exists. Default false.
Create folderscreateFolders
Create missing target folders on the way. Default true.

Nextcloud: deletenextcloud.deleterisk: destructivewrites to an external system

Deletes a Nextcloud file or folder (to the trash bin when the server keeps one).

Restrict to folderroot
Every path is inside this folder and cannot leave it. Blank = the whole Nextcloud. Pin it when the node is an agent tool.
File or folder *path
What to delete, inside the restricted folder. Goes to the Nextcloud trash bin when it is enabled.

Search Slackslack.searchrisk: read

Searches Slack messages with a user token.

Query *query
Slack search terms. Supports Slack's own modifiers.
Scopescope
Search modifiers pinned by the author, prepended to the query. Keeps the search inside chosen channels or people.
Resultscount
How many matches to return. 1 to 100. Default 20.
Sortsortone of score, timestamp
score = most relevant first, timestamp = newest first. Default "score".
Cursorcursor
Page to fetch, from a previous run's nextCursor. Empty = the first page.

Read a Slack channelslack.historyrisk: read

Reads recent messages from a Slack channel.

Channelchannel
Channel id to read. Your bot must be a member of it.
Messageslimit
How many messages to return, newest first. 1 to 999. Default 50.
Sinceoldest
Only messages after this Slack timestamp. Empty = no lower bound.
Cursorcursor
Page to fetch, from a previous run's nextCursor. Empty = the first page.

Read recent Slack activityslack.recentrisk: read

Reads the last hours of every Slack channel the bot is in, flagging mentions of the bot and of you.

Hours backhours
How far back to read, 1 to 168 hours. Default 24.
Channel typestypes
Comma-separated: public_channel, private_channel. Private ones also need the groups:read and groups:history scopes. Default "public_channel".
Your Slack user idyou
Messages that mention this user are flagged mentionsYou. Blank = none.
Messages per channelperChannel
Newest messages read per channel, 1 to 200. Default 100.
Max channelsmaxChannels
Channels read at most, 1 to 100. Default 30.

Reply in a Slack threadslack.replyrisk: external-commswrites to an external system

Replies to a Slack message inside its thread.

Channelchannel
Channel id the thread lives in.
Thread *threadTs
Timestamp of the PARENT message to reply under, never a reply's own timestamp.
Message *text
What to reply. Slack mrkdwn works.
Also show in channelbroadcast
Show the reply in the channel as well as in the thread. Default false.

Send a Slack DMslack.dmrisk: external-commswrites to an external system

Sends a direct message to one Slack user.

User *user
Slack user id to message directly. Not a display name.
Message *text
What to send. Slack mrkdwn works.

Send a WhatsApp messagewhatsapp.sendrisk: external-commswrites to an external system

Sends a WhatsApp text or approved template through the Cloud API.

To *to
Recipient phone number in E.164 form, no plus sign needed.
Message kindkindone of text, template
Free text only works inside the 24-hour customer service window; outside it, WhatsApp requires an approved template. Default "text".
Messagetext
What to send when the kind is text. Expressions allowed.
Template nametemplateName
An approved template on your WhatsApp Business account. Used when the kind is template.
Template languagelanguageCode
Language code the template was approved in. Default "en_US".
Template variablestemplateParams
Values for the template body placeholders, in order.

Send WhatsApp mediawhatsapp.mediarisk: external-commswrites to an external system

Sends an image, video, audio or document over WhatsApp, or resolves a media id to a URL.

Actionactionone of send, url
send = deliver media to a recipient. url = turn a media id from an inbound message into a download URL. Default "send".
Toto
Recipient phone number in E.164 form. Only used by the send action.
Media typemediaTypeone of image, video, audio, document, sticker
Which WhatsApp media message to send. Default "image".
Media URLlink
Public https URL of the file. Either this or a media id.
Media idmediaId
An id already on WhatsApp's servers, e.g. from an inbound message. Wins over the URL.
Captioncaption
Text shown under the image, video or document. Expressions allowed.
File namefilename
Document file name shown to the recipient.

WhatsApp (Web): linkwhatsapp.web.linkrisk: read

Checks the WhatsApp (Web) link of the picked Browser session and asks you to scan the QR code when it is not linked.

No settings.

WhatsApp (Web): sendwhatsapp.web.sendrisk: external-commswrites to an external system

Sends a WhatsApp text from your own number through WhatsApp Web, to a phone number or a chat name.

To *to
A phone number with country code (+43 660 1234567) or the exact chat name as WhatsApp shows it.
Message *text
What to send. Expressions allowed. Secrets are masked before it leaves.
Allow new numbersallowNewChats
Off: only numbers you already have a chat with. On: also a first message to a new number, at most 5 a day. Default false.
Max per minuteperMinute
Sends per minute on this connection, across all runs. Default 5, up to 20. Default 5.

WhatsApp (Web): readwhatsapp.web.readrisk: read

Reads your unread WhatsApp chats, or the recent messages of one chat, through WhatsApp Web (untrusted text).

Readmodeone of chat, unread
unread = the chats with unread messages (does not open them); chat = the recent messages of one chat (marks it read). Default "unread".
Chatchat
For chat: a phone number with country code, or the exact chat name.
Max messageslimit
For chat: the newest this many text messages. 1 to 100. Default 20.

Phone callphone.callrisk: external-commswrites to an external system

Places an outbound Twilio call with a scripted greeting, or hangs one up.

Actionactionone of start, end
start = place an outbound call. end = hang up a call that is already in progress. Default "start".
Toto
Number to call, E.164.
Fromfrom
Your Twilio number or a verified caller id, E.164.
Call SIDcallSid
Which call to hang up. Only used by the end action.
Spoken textsay
What the call says first. Expressions allowed.
Gather URLactionUrl
Your trigger.phone webhook URL. Set it to listen for the caller's answer after the greeting; leave empty to just speak and hang up.
Status callback URLstatusCallbackUrl
Where Twilio posts ringing/answered/completed updates.
Raw TwiMLtwiml
Hand-written TwiML. Wins over the spoken text and gather settings.

SSH commandssh.execrisk: writewrites to an external system

Runs one command on a saved SSH host; changes wait for your approval, output is redacted and audited.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Command *command
One bash command line. Read-only commands run; changes need your approval (or an exact pre-approval); destructive ones only on hosts in full mode.
Reasonwhy
Shown to you in the approval: why this command.
Pre-approved commandspreapproved
Exact operate-level commands that run without asking, one per row, byte for byte. Never covers destructive commands. Leave empty to approve every change.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.
Max output (KB)maxOutputKb
Output beyond this is cut off, per stream. 1 to 1024. Default 64.
Approval timeout (hours)approvalHours
How long a change waits for your approval in Messages before the run fails. Max 168. Default 24.

SSH machine factsssh.factsrisk: read

Read-only snapshot of a host: OS, load, RAM, swap, disks, processes, ports, docker, failed units, updates, logins, certs.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default false.
Disk alert (%)diskPct
Alert when a mount is fuller than this. Default 85.
RAM alert (%)memPct
Alert when used memory (total minus available) is above this. Default 90.
Swap alert (%)swapPct
Alert when swap use is above this. Default 80.
Load alert (per CPU)loadPerCpu
Alert when the 15-minute load divided by CPUs is above this. Default 2.
Certificate alert (days)certDays
Alert when a certbot certificate expires within this many days. Default 14.
Timeout (s)timeoutSec
The whole snapshot is stopped after this long. 5 to 120. Default 45.

SSH logsssh.logsrisk: read

Tails the systemd journal or a docker container's logs on a saved SSH host, with filters. Read-only, redacted.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default false.
Sourcesourceone of journal, docker
journal = systemd journal (journalctl), docker = a container's logs. Default "journal".
Unitunit
journal: a systemd unit, e.g. nginx. Blank = the whole journal.
Containercontainer
docker: the container name.
Lineslines
Newest N lines. 1 to 2000. Default 200.
Sincesince
e.g. "1 hour ago", "today", "2026-09-19 08:00". Blank = no limit.
Filtergrep
Only lines containing this text (case-insensitive, not a regex).
Prioritypriorityone of , emerg, alert, crit, err, warning, notice, info, debug
journal: this level and worse. Blank = all.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.

SSH read filessh.file.readrisk: read

Reads a size-capped file from a saved SSH host. Secret files and keys are refused; output is redacted.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default false.
Path *path
Absolute path of the file. Secret files (.env, keys, /etc/shadow…) are refused by the policy.
Max size (KB)maxKb
Read at most this much. 1 to 1024. Default 64.
From the endfromEnd
Read the last bytes instead of the first (log files). Default false.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.

SSH servicessh.servicerisk: writewrites to an external system

Status, restart, start or stop of a systemd unit or docker container on a saved SSH host; changes need approval.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
Prefix privileged commands with sudo -n (no password prompt). Only the exact commands in the host's sudoers file will work. Default false.
Pre-approved commandspreapproved
Exact operate-level commands that run without asking, one per row, byte for byte. Never covers destructive commands. Leave empty to approve every change.
Kindkindone of systemd, docker
systemd unit or docker container. Default "systemd".
Name *name
Unit or container name, e.g. nextcloud.
Actionactionone of status, restart, start, stop
status is read-only and runs at once; restart/start/stop wait for your approval. Default "status".
Reasonwhy
Shown to you in the approval.
Timeout (s)timeoutSec
5 to 600. Restarts can take a while. Default 120.
Approval timeout (hours)approvalHours
How long a change waits for your approval in Messages before the run fails. Max 168. Default 24.

WireGuard serverwireguard.server.setuprisk: destructivewrites to an external system

Installs and starts a WireGuard server on a saved SSH host and prints its public key and endpoint. Re-running changes nothing.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Interfaceiface
The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default "wg0".
Tunnel subnetsubnet
The private range inside the tunnel. The server takes the first address (.1), peers get the next free ones. Default "10.9.0.0/24".
UDP portport
The port the server listens on. It must be open in the cloud firewall too. Default 51820.
MTUmtu
1420 fits inside a 1500-byte link. Lower it (1280) if large packets stall. Default 1420.
Forward and NATnat
Turn on IP forwarding and masquerade peer traffic out of the server's main interface, so peers reach the internet and the server's LAN. Default true.
Outgoing interfacenatInterface
The network card to masquerade out of. Blank = the one the default route uses.
Endpointendpoint
The public host or IP clients dial. Blank = the saved SSH host's address.
Timeout (s)timeoutSec
Installing the package can take a minute. 10 to 600. Default 180.
Approval timeout (hours)approvalHours
How long the script waits for your approval in Messages. Default 24.

WireGuard add peerwireguard.peer.addrisk: destructivewrites to an external system

Adds a device to a WireGuard server, gives it the next free address and returns a ready client config. A peer key is full access.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
WireGuard needs root. Off only when the SSH user is root itself. Default true.
Interfaceiface
The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default "wg0".
Peer name *name
A short name for this device, e.g. laptop or alleex-worker. It labels the [Peer] block and must be unique.
Peer public keypublicKey
Blank = alleex generates the keypair and hands you the client config once. Fill it in when the device already has a key and its private key should never leave it.
Addressaddress
Blank = the next free address in the server's subnet.
Client routesclientAllowedIps
What the client sends through the tunnel. Blank = the tunnel subnet only (split tunnel). 0.0.0.0/0 routes everything.
Client DNSdns
DNS server for the client while the tunnel is up. Blank = leave the client's own.
Keepalive (s)keepalive
Keeps the tunnel open behind NAT. 0 = off. Default 25.
Endpointendpoint
The public host or IP the client dials. Blank = the saved SSH host's address.
Where the client config goesdeliverone of return, vault
vault (default) = saved as a secret in Settings → Secrets, and the run only names it. return = in this run's result, once, for you to copy (whoever can see the run sees it, private key included). Default "vault".
Secret namesecretName
vault only: the name to save it under. Blank = wg-<interface>-<peer>.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.
Approval timeout (hours)approvalHours
How long the change waits for your approval in Messages. Default 24.

WireGuard remove peerwireguard.peer.removerisk: destructivewrites to an external system

Removes a device from a WireGuard server: its [Peer] block goes out of the config and out of the live interface.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
WireGuard needs root. Off only when the SSH user is root itself. Default true.
Interfaceiface
The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default "wg0".
Peer name *name
The name the peer was added under.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.
Approval timeout (hours)approvalHours
How long the change waits for your approval in Messages. Default 24.

WireGuard statuswireguard.statusrisk: destructive

Read-only: which peers a WireGuard server has, when each last shook hands and how much it transferred.

Host *host
Name of a saved SSH host (Settings → Model providers → SSH hosts), e.g. alleex. Fixed by the author; a model can never pick the machine.
Use sudo -nsudo
WireGuard needs root. Off only when the SSH user is root itself. Default true.
Interfaceiface
The WireGuard interface, e.g. wg0. Its config lives in /etc/wireguard/<interface>.conf. Default "wg0".
Stale after (min)staleMinutes
A peer whose last handshake is older than this counts as not connected. Default 10.
Timeout (s)timeoutSec
The command (connection included) is stopped after this long. 1 to 600. Default 30.

ElevenLabs voiceselevenlabs.voicesrisk: read

Lists the ElevenLabs voices your key can use, with ids and preview links.

Searchsearch
Filter by name, description, labels or category. Empty = all.
How manypageSize
1 to 100. Default 30.

ElevenLabs call transcriptelevenlabs.conversation.getrisk: read

Fetches one ElevenLabs voice-agent call: transcript, summary and collected data.

Conversation id *conversationId
The ElevenLabs conversation id, e.g. from the post-call trigger.

Codecoderisk: destructive

Runs your JavaScript or Python on the items, in an isolated sandbox.

Languagelanguageone of javascript, python, bash
JavaScript (Node 24) or Python 3 with numpy, pandas, python-dateutil, requests. Bash only on the local runner. Default "javascript".
Modemodeone of all, each
all = run once for all items (items). each = run once per item (item / $json / _json); the results form an array. Default "all".
Codecode
Return a JSON value. console.log / print go to the run log. {{ }} is not filled in here: read inputs through items and $("nodeId"). Default "// items: every input item. Return any JSON value.\nconsole.log(`got ${items.length} items`);\nreturn items.map((item) => ({ ...item, seen: true }));\n".
Allow networknetwork
Off = no network at all. On = http(s) to public hosts only, through the platform's egress guard (no private ranges, no cloud metadata). Default false.
Credentialscredentials
Saved credential names, e.g. github, or a vault secret as {{secret.NAME}}. Each is env SECRET_<NAME> for this execution only and is masked in logs. Only used when you run your own agent, and never with network on.
Timeout (s)timeoutSec
Wall clock per execution, 1 to 60. Default 10.
Memory (MB)memoryMb
64 to 1024. Default 256.

Stripe: readstripe.queryrisk: destructive

Reads your own Stripe account: balance, charges, customers, subscriptions, invoices, refunds, disputes, payouts, products, prices.

What to readresourceone of balance, balance_transactions, charges, payment_intents, customers, subscriptions, invoices, refunds, disputes, payouts, products, prices
balance, balance_transactions, charges, payment_intents, customers, subscriptions, invoices, refunds, disputes, payouts, products or prices. Default "charges".
Idid
Read this one object (ch_…, cus_…, in_…) instead of a list. Ignored for balance.
Created sincesince
YYYY-MM-DD, ISO time, or relative like 7d / 24h. Blank = no lower bound.
Created untiluntil
YYYY-MM-DD (that whole day included) or ISO time. Blank = now.
Customer idcustomer
Only this customer (charges, payment intents, subscriptions, invoices).
Emailemail
Customers only: exact email match (case-sensitive at Stripe).
Statusstatus
subscriptions: active, past_due, canceled, all… invoices: draft, open, paid, uncollectible, void. payouts: pending, paid, failed, canceled, in_transit.
Charge / payment intentcharge
Refunds and disputes only: those of this ch_… or pi_…. Prices: this prod_….
Max itemslimit
How many to read at most; pages are fetched until this. Hard cap 1000. Default 50.

Stripe: reportstripe.reportrisk: destructive

Computes revenue, MRR/ARR, new vs churned subscriptions, failed payments, open disputes and upcoming payouts from your Stripe account.

Period (days)days
The report covers the last N days up to now. 1 = the last 24 hours. Default 1.
Sectionssections
Which figures to compute: revenue, products, mrr, subscriptions, failed, disputes, payouts. Default ["revenue","products","mrr","subscriptions","failed","disputes","payouts"].
Max items per readlimit
Cap for each underlying list (charges, subscriptions…). Hard cap 1000. Default 500.

Stripe: customerstripe.customerrisk: destructivewrites to an external system

Finds, creates or updates a customer in your Stripe account, or adds a note to one.

Actionactionone of find, create, update, note
find by id or email, create one, update its fields, or add a note (stored in metadata). Default "find".
Customer idcustomerId
cus_… for find, update and note.
Emailemail
find: exact email. create/update: the new email.
Namename
create/update: the customer's name. Blank = unchanged.
Phonephone
create/update: phone number. Blank = unchanged.
Descriptiondescription
create/update: internal description. Blank = unchanged.
Metadatametadata
create/update: key/value pairs to set (Stripe limits: 50 keys, 500-char values).
Notenote
note: text stored as metadata note_<timestamp> (max 500 characters).

Stripe: invoicestripe.invoicerisk: destructivewrites to an external system

Creates a draft invoice, adds items, finalizes, sends or voids it, within a pinned maximum and currency list.

Actionactionone of create_draft, add_item, finalize, send, void
create_draft for a customer, add_item to a draft, finalize it, send it by email (Stripe emails the customer; not in test mode), or void an open invoice. Default "create_draft".
Customer idcustomerId
create_draft: the cus_… to bill.
Invoice idinvoiceId
add_item, finalize, send, void: the in_….
Item amount (minor units)amount
add_item: amount in the smallest currency unit (1500 = 15.00). Ignored when a price is given. Default 0.
Item currencycurrency
add_item: lowercase ISO code, e.g. eur.
Item priceprice
add_item: a price_… from the pinned allowed prices instead of an amount.
Quantityquantity
add_item with a price: how many. Default 1.
Descriptiondescription
create_draft: the invoice memo. add_item: the line's text.
Days until duedaysUntilDue
create_draft: payment term for an emailed invoice. Default 14.
Collectioncollectionone of send_invoice, charge_automatically
send_invoice = the customer pays from an emailed link. charge_automatically = Stripe charges the saved card on finalize. Pinned by the author. Default "send_invoice".
Max amount (minor units)maxAmount
Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default 0.
Allowed currencies *currencies
Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
Allowed pricesallowedPrices
Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.

Stripe: refundstripe.refundrisk: destructivewrites to an external system

Refunds a charge after a person approves it, never above the pinned maximum or outside the pinned currencies.

Charge or payment *charge
The ch_… or pi_… to refund.
Amount (minor units) *amount
How much to refund, in the smallest currency unit (1250 = 12.50 EUR). Required: there is no implicit full refund. Default 1.
Reasonreasonone of requested_by_customer, duplicate, fraudulent
Stripe's refund reason. fraudulent also adds the card and email to your Radar block lists. Default "requested_by_customer".
Notenote
Why, for the approver and the refund's metadata (max 500 characters).
Max refund (minor units)maxAmount
Pinned ceiling per refund. 0 = no refund is possible. The model cannot change it. Default 0.
Allowed currenciescurrencies
Pinned lowercase ISO codes a refund may be in. Empty = none. The model cannot change it.
Approval timeout (hours)timeoutHours
How long the approval waits. No answer = no refund. Default 168.

Stripe: subscriptionstripe.subscriptionrisk: destructivewrites to an external system

Cancels a subscription at period end, undoes that, or moves it to a pinned price, within a pinned maximum.

Actionactionone of cancel_at_period_end, resume, change_price
cancel_at_period_end schedules the end, resume undoes a scheduled cancellation, change_price swaps the single item to a pinned price. Default "cancel_at_period_end".
Subscription id *subscriptionId
The sub_… to change.
New priceprice
change_price: a price_… from the pinned allowed prices.
Prorationprorationone of create_prorations, none, always_invoice
change_price: Stripe's proration_behavior. always_invoice charges the difference now. Pinned by the author. Default "create_prorations".
Max amount (minor units)maxAmount
Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default 0.
Allowed currencies *currencies
Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
Allowed pricesallowedPrices
Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.

Stripe: payment linkstripe.payment_linkrisk: destructivewrites to an external system

Creates a Stripe payment link for one pinned price and quantity, within a pinned maximum.

Price *price
A price_… from the pinned allowed prices.
Quantityquantity
How many of that price the link sells. Default 1.
Max amount (minor units)maxAmount
Pinned ceiling per action in the currency's smallest unit (1000 = 10.00 EUR). 0 = nothing may be charged. The model cannot change it. Default 0.
Allowed currencies *currencies
Pinned, lowercase ISO codes (eur, usd). Anything else is refused. The model cannot change it.
Allowed pricesallowedPrices
Pinned price ids (price_…) this node may use. Empty = none. The model cannot change it.

Polar: readpolar.queryrisk: destructive

Reads orders, subscriptions, customers, products, refunds or checkouts from your Polar organisation. Never writes.

What to readresourceone of orders, subscriptions, customers, products, refunds, checkouts
orders, subscriptions, customers, products, refunds or checkouts. Default "orders".
Idid
Read this one object (a UUID) instead of a list. Not available for refunds or checkouts.
Created sincesince
YYYY-MM-DD, ISO time, or relative like 7d / 24h. Blank = no lower bound.
Created untiluntil
YYYY-MM-DD (that whole day included) or ISO time. Blank = now.
Customer idcustomerId
Only this customer (orders, subscriptions, refunds).
Product idproductId
Only this product (orders, subscriptions).
Order idorderId
Refunds only: those of this order.
Statusstatus
Subscriptions only: active, trialing, past_due, canceled, unpaid, incomplete, paused.
Email or searchemail
Customers only: matches email or name.
Max itemslimit
How many to read at most; pages are fetched until this. Hard cap 1000. Default 50.

Polar: reportpolar.reportrisk: destructive

Revenue, MRR/ARR, new vs churned subscriptions, top products and past-due subscriptions from your Polar organisation. Reads only.

Period (days)days
The report covers the last N days up to now. 1 = the last 24 hours. Default 1.
Sectionssections
Which figures to compute: revenue, subscriptions, products, pastdue. Default ["revenue","subscriptions","products","pastdue"].
Max items per readlimit
Cap for each underlying list (orders, subscriptions). Hard cap 1000. Default 500.

Polar: refundpolar.refundrisk: destructivewrites to an external system

Refunds a Polar order after a person approves it, never above the pinned maximum or outside the pinned currencies.

Order *order
The Polar order id (a UUID) to refund.
Amount (minor units) *amount
How much to refund, in the smallest currency unit (1250 = 12.50 EUR). Required: there is no implicit full refund. Default 1.
Reasonreasonone of customer_request, duplicate, fraudulent, service_disruption, satisfaction_guarantee, other
Polar's refund reason. Default "customer_request".
Revoke benefitsrevokeBenefits
Also take back what the order granted (a subscription's access, a licence key). Off = the customer keeps it. Default false.
Notenote
Why, for the approver and the refund's comment (max 500 characters).
Max refund (minor units)maxAmount
Pinned ceiling per refund. 0 = no refund is possible. The model cannot change it. Default 0.
Allowed currenciescurrencies
Pinned lowercase ISO codes a refund may be in. Empty = none. The model cannot change it.
Approval timeout (hours)timeoutHours
How long the approval waits. No answer = no refund. Default 168.

Sort itemssortrisk: destructive

Sorts array items by one or more fields, ascending or descending.

Sort by *by
One field per row, first wins. Add " desc" for descending, e.g. "price desc". Blank row = the item itself.
Items fielditemsField
Path to the array inside the input. Blank = the input itself.

Limit itemslimitrisk: destructive

Keeps only the first or last N items of a list.

How manycount
Keep this many items. 0 to 10,000. Default 10.
Keepkeepone of first, last
first = from the start of the list, last = from the end. Default "first".
Items fielditemsField
Path to the array inside the input. Blank = the input itself.

Aggregateaggregaterisk: destructive

Groups items and computes count, sum, average, min, max or lists.

Group bygroupBy
Field whose value forms the groups. Blank = one result over all items.
Aggregationsaggregations
JSON [{field, op, as}]. op: count, sum, avg, min, max, concat (joined text), list (all values), unique (distinct values). Default [{"field":"","op":"count","as":"count"}].
Concat separatorseparator
Placed between values by concat. Default ", ".
Items fielditemsField
Path to the array inside the input. Blank = the input itself.

Date & Timedate.timerisk: destructive

Parses, formats, shifts and compares dates, in any time zone.

Operationoperationone of format, parse, add, subtract, diff, timezone
format = text in a pattern, parse = ISO instant, add/subtract = shift by an amount, diff = time between two dates, timezone = wall time in another zone. Default "format".
Datevalue
ISO 8601, epoch seconds/ms, or text matching the input format. Blank = now.
Input formatinputFormat
Pattern of the date text, e.g. dd.MM.yyyy HH:mm. Blank = ISO or epoch.
Time zonetimezone
IANA zone for reading wall times and for the output, e.g. Europe/Vienna. Default "UTC".
Output formatformat
format: yyyy yy MMM MM M dd d EEE HH H hh h mm ss SSS a XXX, 'literal text', or iso. Default "yyyy-MM-dd HH:mm".
Amountamount
add/subtract: how many units. Default 1.
Unitunitone of milliseconds, seconds, minutes, hours, days, weeks, months, years
add/subtract/diff: milliseconds up to years. Days, months and years follow the calendar in the time zone. Default "days".
Second datevalue2
diff: the later date; the result is second minus first. Blank = now.

XMLxmlrisk: destructive

Converts XML text to JSON, or JSON to XML text.

Operationoperationone of toJson, toXml
toJson = XML text to an object, toXml = an object to XML text. Default "toJson".
Datadata
XML text (toJson) or an object (toXml). Blank = this node's input.
Root elementrootName
toXml: wraps the data unless it is an object with exactly one key. Default "root".
Pretty printpretty
toXml: indent nested elements. Default true.

CSVcsvrisk: destructive

Parses CSV text into items or turns items into CSV text.

Operationoperationone of parse, stringify
parse = CSV text to items, stringify = items to CSV text. Default "parse".
Datadata
CSV text (parse) or a list of items (stringify). Blank = this node's input.
Delimiterdelimiter
Separator between fields: , or ; or a tab (\t). Default ",".
Header rowheader
parse: the first row names the fields. stringify: write a header row. Default true.
Max rowsmaxRows
parse stops after this many rows. 1 to 100,000. Default 10000.

Google Analytics reportgoogle.analytics.reportrisk: destructive

Runs a GA4 report (metrics by dimensions over a date range) via the Data API or the logged-in browser.

GA4 property id *propertyId
The number from GA4 Admin -> Property details.
Start datestartDate
YYYY-MM-DD, today, yesterday or NdaysAgo. Default "28daysAgo".
End dateendDate
YYYY-MM-DD, today, yesterday or NdaysAgo. Default "yesterday".
Metricsmetrics
GA4 Data API metric names, comma separated. Default "activeUsers, sessions, engagementRate".
Dimensionsdimensions
GA4 dimension names, comma separated. Blank = one totals row.
Sort byorderBy
A metric to sort by, descending. Blank = the first metric.
Row limitlimit
Rows to return, 1 to 50,000 (fetched in pages of 10,000). Default 100.

Search Console performancegoogle.searchconsole.queryrisk: destructive

Clicks, impressions, CTR and position by query, page, country or device from Google Search Console.

Property *site
The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
Start datestartDate
YYYY-MM-DD, today, yesterday or NdaysAgo. Default "28daysAgo".
End dateendDate
YYYY-MM-DD, today, yesterday or NdaysAgo. Default "yesterday".
Dimensionsdimensions
Comma separated: query, page, country, device, date, searchAppearance. Blank = totals only. Default "query".
Search typetypeone of web, image, video, news, discover, googleNews
Which Google surface. Default web. Default "web".
Row limitrowLimit
Rows to return, 1 to 100,000 (fetched in pages of 25,000). Default 1000.

Search Console sitemapsgoogle.searchconsole.sitemapsrisk: destructive

Lists the property's sitemaps with their status and errors, or submits a sitemap.

Property *site
The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
Actionactionone of list, submit
list = status of every submitted sitemap; submit = (re)submit the sitemap URL below. Default "list".
Sitemap URLsitemapUrl
For submit: the full sitemap URL on the property.

Search Console URL inspectiongoogle.searchconsole.inspectrisk: destructive

Asks Google whether pages are indexed, their canonical, last crawl and rich-result issues.

Property *site
The Search Console property: "sc-domain:example.com" or a URL prefix like "https://example.com/".
URLs *urls
Up to 20 page URLs of the property, comma or newline separated (Google allows 2,000 inspections a day).

PageSpeed Insightsgoogle.pagespeedrisk: destructive

Core Web Vitals (lab and real-user field data), Lighthouse scores and top speed fixes for public pages.

URLs *urls
Up to 10 public page URLs, comma or newline separated. Each takes 10 to 30 seconds.
Devicestrategyone of mobile, desktop
mobile (what Google ranks on) or desktop. Default "mobile".
API keyapiKey
Optional, for a higher quota: {{secret.NAME}} of a saved secret whose allowed hosts include www.googleapis.com.

SEO auditseo.auditrisk: destructive

Crawls a site (robots.txt, sitemap) and checks titles, descriptions, canonicals, noindex, JSON-LD, h1, thin, duplicate and broken pages.

Site URL *url
The site's home page. robots.txt and the sitemap are read from its origin.
Max pagesmaxPages
Pages to audit (sitemap order), 1 to 200. Default 30.
Check linkscheckLinks
Fetch internal links the audit did not visit and report broken ones. Default true.
Max link checksmaxLinkChecks
Extra requests for link checking, 0 to 500. Default 100.
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 250.

Read Redditreddit.searchrisk: destructive

Searches Reddit, lists a subreddit or reads a post's comments (untrusted content).

Readmodeone of search, subreddit, comments
search = posts matching the query, subreddit = a subreddit's listing, comments = the comments of one post. Default "search".
Queryquery
Search terms (search mode). Reddit syntax works: quotes, OR, author:, subreddit:.
Subredditsubreddit
Name without r/. Blank in search mode = all of Reddit.
PostpostId
Comments mode: the post id (abc123), its t3_ name or its URL.
Sortsortone of new, hot, top, rising, relevance, comments
new, hot, top, rising (subreddit), relevance, comments (search). Default "new".
Time windowtimeone of hour, day, week, month, year, all
For top and search: how far back. Default "day".
Resultslimit
How many items to return. 1 to 100. Default 25.
Viaviaone of auto, api, browser
auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default "auto".

Post to Redditreddit.postrisk: destructivewrites to an external system

Submits one Reddit post or comment, after approval by default.

Kindkindone of post, comment
post = a new post in a subreddit, comment = a reply to a post or comment. Default "post".
Subredditsubreddit
Where to post, without r/. Read its rules first: many ban self-promotion.
Titletitle
Post title, up to 300 characters.
Text *text
Post body or comment, markdown.
Linkurl
Makes a link post instead of a text post.
Reply toparentId
Comment kind: the t3_ (post) or t1_ (comment) name to answer.
Viaviaone of auto, api, browser
auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default "auto".

Search YouTubeyoutube.searchrisk: destructive

Searches YouTube videos or channels with the Data API (100 quota units per call).

Query *query
What to search for on YouTube.
Findtypeone of video, channel
Videos or channels. Default "video".
Orderorderone of date, relevance, viewCount
date = newest first, relevance, viewCount = most viewed. Default "date".
Within (days)withinDays
Only items published in the last N days. 0 = any time. Default 7.
Resultslimit
How many items to return. 1 to 50. Default 10.

YouTube statsyoutube.statsrisk: destructive

Reads a YouTube channel's totals and recent uploads, or the stats of given videos.

Channel or videos *target
A channel (@handle, UC… id or channel URL), or video ids / URLs separated by commas.
Recent uploadsrecent
For a channel: also the stats of its last N uploads. 0 = channel totals only. Default 10.

YouTube commentsyoutube.commentsrisk: destructive

Reads the top-level comments of one YouTube video (untrusted content).

Video *video
Video id or URL.
Orderorderone of time, relevance
time = newest first, or relevance. Default "time".
Containingsearch
Only comments containing these words.
Resultslimit
How many items to return. 1 to 100. Default 20.

Comment on YouTubeyoutube.commentrisk: destructivewrites to an external system

Posts one comment or reply on a YouTube video, after approval by default.

Video *video
Video id or URL to comment on.
Reply toparentId
A comment id to reply to instead (API only). Blank = a new top-level comment.
Comment *text
What to post. Plain text.
Viaviaone of auto, api, browser
auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default "auto".

Read Xx.searchrisk: destructive

Searches recent X posts or reads one account's timeline (untrusted content).

Readmodeone of search, user
search = recent posts matching the query, user = one account's latest posts. Default "search".
Queryquery
Search mode: X search syntax (quotes, OR, -is:retweet, from:).
Accountuser
User mode: the handle, with or without @.
Resultslimit
How many items to return. 1 to 100. Default 20.
Viaviaone of auto, api, browser
auto = the official API when its key is saved, else your signed-in browser session. api or browser forces one. Default "auto".

Post to Xx.postrisk: destructivewrites to an external system

Posts or replies on X from your signed-in browser, after approval by default.

Post *text
What to post, up to 280 characters.
Reply toreplyTo
A post id or URL to reply to. Blank = a new post.

Post to Facebookfacebook.postrisk: destructivewrites to an external system

Posts one update to your Facebook Page (API) or profile (browser), after approval by default.

Post astargetone of page, profile
page = your Facebook Page via the Graph API, profile = your personal profile in your signed-in browser. Default "page".
Message *message
What to post.
Linklink
Optional URL to attach (Page posts).

Post to Instagraminstagram.postrisk: destructivewrites to an external system

Publishes one image post to your Instagram business account, after approval by default.

Image URL *imageUrl
A public https JPEG that Meta downloads. Instagram posts need an image.
Caption *caption
Post caption, hashtags included. Up to 2,200 characters.

Read Facebook / Instagramsocial.readrisk: destructive

Reads your Page posts, insights, Instagram media and comments, or any social profile (untrusted content).

Readsourceone of facebook.posts, facebook.insights, instagram.media, instagram.comments, profile
Your Page's posts or insights, your Instagram media or one post's comments (Graph API), or any profile page on Facebook, Instagram, X, Reddit or YouTube (signed-in browser). Default "facebook.posts".
Instagram mediamediaId
instagram.comments: the media id.
Profile URLurl
profile: the page to read.
Metricsmetrics
facebook.insights: comma-separated Page metrics (daily). Default "page_impressions_unique,page_post_engagements".
Resultslimit
How many items to return. 1 to 100. Default 20.

Sync proxiesproxy.syncrisk: destructivewrites to an external system

Refreshes the workspace's Webshare proxy list and reports how many exits it has.

No settings.

Check proxiesproxy.healthrisk: destructivewrites to an external system

Tests the workspace's proxies through an IP echo and reports which exits are dead.

How many to checklimit
Proxies to test this run, oldest check first. 1 to 100. A big pool is swept over several runs. Default 25.
Rows to reportreport
How many of the worst proxies to list in the output. Default 10.

AI

Jev decisionjev.deciderisk: destructive

Asks Jev (TypeSafe) typed yes/no, choice and score questions about some text and returns calibrated probabilities plus a top-level `confidence` (the lowest of the answers), so an `if` on {{node.confidence}} < 0.8 can route the unsure cases on to a full LLM node.

Modelmodelone of jev-latest, jev-preview, jev-1.13.0
jev-latest is the stable alias; jev-1.13.0 pins the version. Default "jev-latest".
State *state
The context to judge, usually an expression, e.g. {{trigger.body.text}}.
Questions *questions
One row per decision. Every row needs an id, a type and a question.
API keyapiKey
Blank = the saved TypeSafe connection (Settings → Connections → TypeSafe (Jev), where Test checks it). Or a vault reference, {{secret.NAME}}, whose allowed hosts include api.typesafe.ai.

LLMllm

Sends one prompt to a language model and returns text or JSON.

Prompt *prompt
What to ask the model. Reference other nodes with {{nodeId.path}}.
Modelmodel
vendor:model. Blank uses the tier below.
Model tiertierone of cheap, standard, deep
Which model runs this step when no model is pinned: cheap (classification, extraction, short summaries), standard (drafting, answering), deep (planning, code).
Output schemaschema
JSON Schema for a structured answer. The answer is validated; one retry with the errors, then the step fails. Blank = plain text.

AI Agentagent

A model that calls the tools you list, in a loop, until the task is done.

Modelmodel
Which model runs the loop, as vendor:model. Blank uses the tier below.
Model tiertierone of cheap, standard, deep
Which Nemotron runs the loop when no model is pinned: cheap, standard (the default for a loop) or deep for planning and code.
System promptsystemPrompt
Standing instructions: role, tone, rules. Sent before every turn.
Task *prompt
What the agent should do this run. Expressions like {{trigger.topic}} are filled in first.
Toolstools
Node types the agent may call, one per row (e.g. tavily.search, http.get, agent.call:<slug>). Nothing else is exposed.
Pinned tool settingstoolConfig
JSON keyed by tool name. These values override whatever the model sends, e.g. {"http.get": {"allowlist": ["example.com"]}}.
Max stepsmaxSteps
Model turns (tool calls plus the answer) before it must stop. 1 to 10. Default 5.
Memory (runs)memory
Include this node's answers from the last N successful runs. 0 = no memory, max 20. Default 0.
Output schemaschema
JSON Schema the final answer must match. It is validated; one retry with the errors, then the step fails. Blank = plain text.

AI extractscrape.ai_extractrisk: read

Reads a page or text and has a model fill a JSON schema from it.

URLurl
Page to read. Blank = use the Content field instead.
Contentcontent
Text to extract from when no URL is set, e.g. {{scrape.content}}.
What to extract *instructions
Plain-language instructions for the model.
Output schema *schema
JSON Schema the answer must match.
Modelmodel
vendor:model. Blank uses the server default.
Max charactersmaxChars
Page text sent to the model is cut to this length. Default 20000.
Render JavaScriptrender
Load the page in a real browser (browser service) instead of a plain HTTP request. Default false.
Wait forwaitFor
Render only: networkidle, ms:1500, or text:Some visible text. Default "networkidle".
Proxyproxy
inherit (agent default), none, rotate, sticky, country:DE, rotate:US, sticky:FR or fixed:<proxy id> from Settings → Proxies. Default "inherit".
User agentuserAgent
Sent as User-Agent. Blank = alleex-scraper/1.0.
Timeout (ms)timeoutMs
Per request. 1,000 to 120,000. Default 20000.
Max bytesmaxBytes
Stop reading a response after this many bytes. Up to 10 MB. Default 2097152.
Respect robots.txtrespectRobots
Skip URLs the site's robots.txt disallows, and honour its Crawl-delay. Default true.
Delay per domain (ms)delayMs
Minimum gap between two requests to the same host. Default 1000.

Search knowledgeknowledge.searchrisk: read

Finds the passages of a knowledge base that best match a query, with scores.

Knowledge base *kb
Which base to use, by id or by its slug. Set by the author, never by the model.
Query *query
What to look for. The text is embedded and matched against the stored chunks.
Resultsk
How many chunks to return, best first. 1 to 50. Default 5.
Minimum scoreminScore
Drop chunks below this cosine similarity (0 to 1). 0 keeps everything. Default 0.
Only these sourcessources
Source ids to search. Empty = the whole base.
Metadata filtermetadata
Only chunks whose metadata contains these key/value pairs.

Answer from knowledgeknowledge.answerrisk: read

Searches a knowledge base and answers the question with citations back to the sources.

Knowledge base *kb
Which base to use, by id or by its slug. Set by the author, never by the model.
Question *question
What to answer from the knowledge base.
Passagesk
How many chunks to put in front of the model. 1 to 20. Default 6.
Minimum scoreminScore
Drop chunks below this cosine similarity (0 to 1). 0 keeps everything. Default 0.
Modelmodel
vendor:model for the answer. Blank uses the server default.
Extra instructionssystemPrompt
Added to the answering instructions: tone, length, house rules.

Nebius batchnebius.batchrisk: destructivewrites to an external system

Runs one prompt over every item as a Nebius Token Factory batch job and parks the run until the results are in.

Prompt per item *prompt
Sent once per item. Use {{item}}, {{item.title}} and {{index}}.
System promptsystemPrompt
Standing instructions sent with every line.
Modelmodel
vendor:model on Nebius. Blank uses the cheap tier (Nemotron Nano).
Items fielditemsField
Path to the array inside the input. Blank = the input itself.
Max itemsmaxItems
Hard cap, 1 to 5000. Every item is a paid line. Default 500.
Max output tokens per itemmaxOutputTokens
Budget for one line's answer. Every Nemotron 3 spends this on thinking before it writes, so a short budget returns nothing at all: 4096 is the default, and short answers still only bill what they use. Default 4096.
Completion windowcompletionWindow
How long Nebius may take, e.g. 24h. The batch price is the reason to allow a long one. Default "24h".
Check every (seconds)pollSec
How often the parked run asks Nebius whether the job is done. 30 seconds to 1 day. Default 300.
Give up after (hours)timeoutHours
The run fails if the job has not finished by then. Default 24, max 720. Default 24.

ElevenLabs speechelevenlabs.ttsrisk: write

Turns text into speech with an ElevenLabs voice and saves the audio as a run file.

Text *text
What to say. Expressions allowed. Max 5000 characters.
Voice id *voiceId
An ElevenLabs voice id (see the ElevenLabs voices node).
Modelmodel
eleven_multilingual_v2 (quality), eleven_flash_v2_5 (fast, cheap), eleven_turbo_v2_5 or eleven_v3. Default "eleven_multilingual_v2".
Audio formatformatone of mp3_44100_128, mp3_22050_32, pcm_16000, pcm_24000, ulaw_8000
codec_samplerate_bitrate. ulaw_8000 is what phone lines use. Default "mp3_44100_128".
Languagelanguage
Optional ISO 639-1 code to force a language, e.g. de. Empty = detect from the text.
File namefileName
Name of the saved audio file, without extension. Default "speech".

ElevenLabs transcribeelevenlabs.sttrisk: read

Transcribes an audio file with ElevenLabs Scribe: text, language and word timestamps.

Audio *audio
A run file (its artifact id or /api/artifacts/<id> url) or a public https URL ElevenLabs downloads itself.
Modelmodelone of scribe_v1, scribe_v2
ElevenLabs Scribe model. Default "scribe_v1".
Languagelanguage
ISO 639-1/3 code if known. Empty = detect.
Speakersdiarize
Label which speaker said each word. Default false.
Audio eventsaudioEvents
Include sounds like (laughter) in the transcript. Default false.

Output

Feed cardoutput.card

Posts the result to the feed as a card, with links and media found upstream.

Card titletitle
Headline in the feed. Blank = taken from the upstream result.
No dashesnoDashes
Replace em dashes and spaced en dashes in the title and text with a comma. Ranges like 2019–2020 stay.

Respond to Webhookwebhook.respondrisk: destructive

Sets the HTTP response a waiting webhook caller gets: status, headers, JSON or text body.

Status codestatus
HTTP status sent to the caller, 200 to 599. Default 200.
Headersheaders
Response headers. Set-Cookie, Location and security headers are not allowed.
Bodybody
Text is sent as-is (text/plain); a JSON object is encoded (application/json).

Save fileartifact.save

Saves text, JSON or bytes as a file in the run's evidence.

File namename
Shown in the evidence list and used for downloads. Default "output.txt".
Valuevalue
What to save. {0} is the first input, {0.body} a path into it; {{node}} expressions work too. Default "{0}".
Formatformatone of auto, text, json, base64
auto: objects become JSON, data: URLs become bytes, anything else text. base64: decode the value into bytes. Default "auto".
Content typemime
Optional. Empty = from the format and file extension.
Attach to postattachone of auto, yes, no
Show the file on the run's feed post. auto: yes for images and documents (PDF, Markdown, HTML, office files), no for data and logs. Default "auto".

Compose videovideo.composerisk: write

Joins a recorded video and an optional narration track into one playable file.

Video *video
A run file: its artifact id or /api/artifacts/<id> url, e.g. from a Close browser node that recorded.
Narrationaudio
Optional run file with the audio track, e.g. from an ElevenLabs speech node. Empty = no sound.
Formatformatone of mp4, webm
mp4 re-encodes to h264 and plays everywhere, and costs minutes of CPU. webm keeps the original frames and only adds the sound, in seconds. Default "mp4".
Quality (mp4)crf
18 is sharp and large, 40 is soft and small. Raise it when the file lands over the 10MB run file cap. Default 26.
File namename
Name of the saved video, without extension. Default "video".

Render documentdoc.renderrisk: write

Turns Markdown, HTML or LaTeX into PDF, Word, OpenDocument, HTML, LaTeX, slides or e-book files.

Sourcesource
The document text. {0} is the first input, {0.text} a path into it; {{node}} expressions work too. Default "{0}".
Source formatsourceFormatone of markdown, html, latex
markdown (what LLMs write best), html, or latex (checked, run sandboxed). Default "markdown".
Formatsformats
Comma-separated: md, html, pdf, docx, odt, tex, pptx, epub, or all. Each becomes a file in the run. Default "pdf".
Titletitle
Document title. Blank = the document's only top-level heading.
Subtitlesubtitle
Shown under the title.
Authorauthor
One or more, separated by ;.
Datedate
Printed as given, e.g. 19 September 2026.
Templatetemplate
default (title block), report (title page, contents, numbered sections) or letter (sender, date, subject line). Default "default".
PDF enginepdfEngineone of latex, html
latex: typeset with TeX (best for print, math). html: print the styled HTML page. Default "latex".
Contentstocone of auto, yes, no
Table of contents. auto = only for the report template. Default "auto".
Brandbrand
Put the alleex mark in the header (PDF, HTML). Default false.
Paperpaperone of a4, letter
PDF page size. Default "a4".
File namefileName
Without extension. Blank = from the title.

Convert documentdoc.convertrisk: write

Converts a document file into other formats, e.g. DOCX to PDF or Markdown to Word.

Inputinput
A file from this run ({{render.files[0]}} or an artifact id), a data: URL, or text. Default "{0}".
Input formatinputFormatone of auto, markdown, html, latex, docx, odt, epub, pdf
auto = from the file name or type. Default "auto".
Formatsformats
Comma-separated: md, html, pdf, docx, odt, tex, pptx, epub, or all. Each becomes a file in the run. Default "pdf".
Titletitle
Document title. Blank = the document's only top-level heading.
Subtitlesubtitle
Shown under the title.
Authorauthor
One or more, separated by ;.
Datedate
Printed as given, e.g. 19 September 2026.
Templatetemplate
default (title block), report (title page, contents, numbered sections) or letter (sender, date, subject line). Default "default".
PDF enginepdfEngineone of latex, html
latex: typeset with TeX (best for print, math). html: print the styled HTML page. Default "latex".
Contentstocone of auto, yes, no
Table of contents. auto = only for the report template. Default "auto".
Brandbrand
Put the alleex mark in the header (PDF, HTML). Default false.
Paperpaperone of a4, letter
PDF page size. Default "a4".
File namefileName
Without extension. Blank = from the title.

Evidence ledgerevidence.ledger

Maps acceptance criteria to pass/fail/missing with artifact evidence and stores the ledger.

Acceptance criteriacriteria
One per line, optionally with an id: "AC-1: Login works". Empty = take them from the verdicts.
Verdictsverdicts
The tester's verdicts: [{id, status, evidence:[artifactIds], note}] or {criteria:[...]}, as a value or JSON text. {0} = first input. Default "{0}".
Pass needs evidencerequireEvidence
A pass without at least one artifact of this run counts as missing. Default true.
File namename
Name of the stored ledger JSON. Default "evidence-ledger.json".

Models

The model field of LLM and AI Agent is vendor:model, for example anthropic:claude-sonnet-5. Blank uses the server default on Nebius. Each vendor uses your own key from Settings first and the platform key only as a fallback. The picker lists a vendor's live models once a key is available; any id can be typed by hand. Local vendors run only on the local runner. Prices are per 1M tokens, checked 2026-09-15; unknown models are costed at $3/$15.

VendorNameKey and settings
nebiusNebius Token FactoryAPI key
openrouterOpenRouterAPI key
openaiOpenAIAPI key
anthropicAnthropicAPI key
googleGoogle GeminiAPI key
vertexGoogle Vertex AIService-account JSON key, or a Vertex express-mode API key, project id, location
azureAzure OpenAIAzure OpenAI resource key, resource name
bedrockAmazon BedrockBedrock API key, or ACCESS_KEY_ID:SECRET_ACCESS_KEY, region
mistralMistralAPI key
groqGroqAPI key
xaixAI (Grok)API key
deepseekDeepSeekAPI key
cerebrasCerebrasAPI key
togetherTogether AIAPI key
fireworksFireworksAPI key
deepinfraDeepInfraAPI key
perplexityPerplexityAPI key
cohereCohereAPI key
huggingfaceHugging FaceAPI key
sambanovaSambaNovaAPI key
novitaNovita AIAPI key
hyperbolicHyperbolicAPI key
moonshotMoonshot (Kimi)API key
zhipuZhipu / Z.ai (GLM)API key
qwenQwen (Alibaba DashScope)API key
cliLocal CLI (your subscription)API key
ollamaOllama (local)API key
lmstudioLM Studio (local)API key
vllmvLLM (local)API key
openai_compatibleOpenAI-compatible (custom URL)The endpoint's API key, base url