К содержанию
TelegaFirst

Для AI-агентов: markdown этой страницы — /docs/mcp-site.mdиндекс документации — /llms.txt

MCP: site

Обновлено

Определения инструментов. Обновляйте tools/list после изменения прав. required_scopes: ALL.

secret_delete

Delete a stored secret by name. REQUIRES THE OWNER'S CONFIRMATION — same two-call handshake as `secret_put`: once without `action_id` to ask, then again with the returned `action_id` once they confirm. Anything still configured to use that name stops working at once, and the value cannot be recovered — the name simply becomes free again.

Scopes (ALL): ["site:write"]. Risk: "destructive".

Вход, результат и права

secret_list

List the NAMES of the secrets stored for the business's hosted site, with when each was stored and last rotated. Values are never returned — there is no parameter that changes that. Use it to check whether a name exists before wiring a form handler or relay to it. 0-cost read.

Scopes (ALL): ["site:read"]. Risk: "read".

Вход, результат и права

secret_put

Store a NEW secret for the business's hosted site (an API token its pages or form handlers call out with). REQUIRES THE OWNER'S CONFIRMATION: call it once without `action_id` and you get back `pending_approval` with an `action_id` — the owner is asked in Telegram to confirm storing a secret under this name. Once they confirm, call again with the SAME `action_id` and the same value, and it is stored. Nothing is kept between the two calls. The value is encrypted at rest and is NEVER returned by any tool — not by this one, not by `secret_list`. A name that already holds a live secret is a conflict: use `secret_rotate` to change a value, or `secret_delete` first to re-use the name.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

secret_rotate

Replace the value stored under an existing secret name. REQUIRES THE OWNER'S CONFIRMATION — same two-call handshake as `secret_put`: once without `action_id` to ask, then again with the returned `action_id` and the value once they confirm. The name does not change (it cannot — it is bound into the encryption of the value). Everything already wired to this name picks up the new value on its next use, so rotate only when the old credential is being retired.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_checkout_key

Get the PUBLIC key the business's checkout page uses to start an order from its own website. Paste the returned key into the page — it is designed to sit in page source where every visitor can read it, and it can do exactly one thing: start a checkout for a form the business configured. It can read nothing. Calling this again REPLACES the key: the previous one keeps working for 24 hours so an already-published page does not break before you redeploy it. The key is shown ONCE — it cannot be retrieved later, only replaced. Which website addresses may use it is set per form (`allowed_origins`), not here.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_execute_delete

Delete the deployed site identified by a matching prepared scenario. Call this tool only after final human confirmation of the prepared scenario.

Scopes (ALL): ["site:write"]. Risk: "destructive".

Вход, результат и права

site_fetch_file

Read one UTF-8 file from a deployed site bundle. Use `site_get_manifest` first to discover its exact path and checksum. This returns page/source text for editing; platform access-policy configuration is intentionally not readable through this tool. After editing, publish the complete bundle through `site_request_upload` and `site_publish`: Delta Sync uploads only the changed file.

Scopes (ALL): ["site:read"]. Risk: "read".

Вход, результат и права

site_form_declare

Declare a form and its submit URL BEFORE BUILDING THE PAGES: it returns `clientSlug` and `code`, the pages POST to `https://fn.telegafirst.ru/f/\{clientSlug\}/\{code\}\` (`fn.telegafirst.com` when `zone` is `com`). Pass the returned `seqNum` to UPDATE it (`clientSlug` + `code` stay, live pages keep working); omit it for a NEW form at a NEW address. It configures the ENVELOPE (delivery, origins, captcha), NOT fields: draw any inputs in your HTML; answers are stored as submitted. `destinations` items: `{"kind":"telegram","topicId":<topic id>}`, `{"kind":"webhook","url":"https://…"}`, or `{"kind":"external_api","url":"https://…","method":"POST","headerName":"X-Api-Key","secretName":"<name from secret_put>"}` (secret NAME, never value). `allowedOrigins` must list the site's own addresses (`https://acme.ru\`), or no submission is accepted. Stop accepting with `enabled: false`; there is no delete (answers keep their config). `afterSubmit` = what the visitor sees after sending: `{"mode":"auto"}` shows your `title`/`text` (or zone defaults) with a way back to the chat, `{"mode":"redirect","redirectUrl":"https://…"}` redirects to a URL on the site's own hosts or `allowedOrigins`; `description` and `submitLabel` dress the hosted page. `variants` run after a submission: each names a funnel step by `stepSeqNum` plus a condition — `when` for `funnelMode: "deterministic"` (first match by `sort` wins) or `hint` (plain language) for `funnelMode: "ai_agent"`; exactly one per entry. `defaultStepSeqNum` if none matches. `managerFollowUp: true` adds an AI Manager answer after the step. `callOperatorOnSubmit: true` (or an entry's `callsOperator: true`) calls a live operator. ⚠️ Not a patch: an optional omitted on re-declaration (`variants`, `afterSubmit`…) RESETS — always send the complete declaration. Optional `submissionSchema`, e.g. `[{"name":"phone","type":"tel","required":true}]`, validates: a non-matching submission is refused naming the field; names must match your HTML inputs.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_get_analytics

Read the daily analytics rollup for this business's own hosted site. It returns total page views, tab sessions (the historical `views_unique` / `unique` names do NOT mean unique visitors), bot-link clicks, pages, referrer hostnames, UTM labels and click actions. It reads durable daily rollups, not the live event buffer, and costs no tokens. Omit `days` for the latest 7 days; requests above 30 days are bounded to 30. Optionally pass `page_path` to report one published page. There is intentionally no `host` argument: this call is scoped to the authenticated tenant's own site.

Scopes (ALL): ["site:read"]. Risk: "read".

Вход, результат и права

site_get_manifest

Read the deployed site bundle manifest for one connected domain. It returns every path with its MD5 checksum and byte size, plus `manifestDigest`. To edit one page, read this first, then use `site_fetch_file` for that page; when you publish, still declare and stage the COMPLETE bundle. The existing checksum Delta Sync writes only files whose bytes changed, so unchanged pages are not re-uploaded. 0-cost read.

Scopes (ALL): ["site:read"]. Risk: "read".

Вход, результат и права

site_page_preview

Open a private preview of a tenant page. Returns a short-lived opaque URL on an isolated origin, using stored content without publishing it.

Scopes (ALL): ["site:write"]. Risk: "read".

Вход, результат и права

site_pages_set_visibility

Show or hide existing site pages by their tenant page numbers. Root and system pages are protected. Returns one result per selected page. Hidden desire survives redeployment and tariff restore; showing does not override tariff or moderation.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_prepare_delete

Prepare deletion of the deployed site at one connected domain. The preparation freezes the current manifest checksum for human review and does not delete anything. Show the returned scenario to a human, then call `site_execute_delete` only if they give final confirmation.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_publish

Step 2 of publishing the site: take the files uploaded under `uploadId` and make them live on the connected domain. Only files that actually differ from what is deployed are written; files the new bundle no longer contains are removed; `index.html` is written LAST so visitors never see a half-swapped site. If the bundle contains `tgf-gate.json`, the access rules in it are applied to the site's gated pages. Returns which paths were written, which were removed and which were already identical. The uploaded files are consumed — to publish again, request fresh upload URLs. It also returns `attributionSnippet`: a one-line `<script>` tag. Paste it into every page of the site that links to the business's bot. Without it, a visitor who taps such a link on this site arrives anonymous and the business cannot tell which page or campaign brought them — the links keep working either way, so nothing looks broken. If the pages you just published do not carry it yet, add it and publish again.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права

site_request_upload

Step 1 of publishing the business's static site to its connected custom domain: declare EVERY file of the bundle (path, byte size, content type) and get back one upload URL per file plus an `uploadId`. Upload each file with an HTTP PUT to its URL — the byte length must match what you declared, or the upload is rejected. Declare the WHOLE site, not just what changed: the platform works out which files actually differ from what is deployed and only writes those. Then call `site_publish` with the same `host` and the `uploadId`. The domain must already be connected to this account (`domain_add_request` → `domain_verify`), and the bundle must fit the plan's size limit — both are checked here, before any URL is issued. Before you build the pages: every page that carries a link to the business's bot should also carry the platform's small attribution script, or the business cannot tell which page or campaign produced a customer. `site_publish` returns the exact `<script>` line to paste — put it in the page template now and you will not need a second deploy to add it.

Scopes (ALL): ["site:write"]. Risk: "write".

Вход, результат и права