# adrata_api_request

Governed low-level Adrata API request. Read calls run directly except sensitive denied surfaces. Writes default to dry-run; a live write requires dryRun:false plus approved:true, a reason, and an idempotencyKey, and additionally requires the connection to hold the matching write:* scope (connect_workspace with writeAccess:true). Without that scope the API rejects the call with 403 insufficient_scope. Use only after a higher-level tool is not available.

Agent View of the PolicyLayer registry record for `adrata_api_request`. HTML page: https://policylayer.com/tools/adrata-starfield-mcp/adrata-api-request

## Facts

- Tool: `adrata_api_request`
- Server: Starfield (`@adrata/starfield-mcp`) — https://policylayer.com/tools/adrata-starfield-mcp.md
- Install: `npx -y @adrata/starfield-mcp`
- Homepage: https://www.npmjs.com/package/@adrata/starfield-mcp
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 9 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `body` | object | no |  |
| `path` | string | yes | Relative Adrata API path, e.g. /api/v1/opportunities/opp_123 |
| `dryRun` | boolean | no | Defaults to true for write methods. Set false to execute a live write; the connection must also hold the matching write:* scope. |
| `method` | string | no |  |
| `params` | object | no |  |
| `reason` | string | no | Required for a live write. Recorded as the audit reason (X-Adrata-Reason). |
| `approved` | boolean | no | Required (true) for a live write. Records that the caller confirmed the mutation; it does not by itself grant scope. |
| `idempotencyKey` | string | no | Required for a live write. Sent as Idempotency-Key so a retry cannot double-apply. |
| `realtimePublish` | object | no | Optional realtime event to publish after a successful live write. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "adrata_api_request",
    "arguments": {
      "path": "<path>"
    }
  }
}
```

## Why adrata_api_request is rated High

adrata_api_request triggers real processes with real consequences. An agent gone sideways doesn't fire it once. It starts dozens of builds, sends mass notifications, or burns through compute before anyone looks up.

Risk signals: Accepts file system path (path) · Accepts raw HTML/template content (body) · High parameter count (16 properties)

## Use case

AI agents invoke adrata_api_request to trigger actions in Starfield. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Starfield:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "adrata_api_request": {
      "limits": [
        {
          "counter": "adrata_api_request_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Starfield (232)

- `bulk_delete_buyer_groups` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/bulk-delete-buyer-groups.md
- `cancel_agent_task` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/cancel-agent-task.md
- `delete_action` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-action.md
- `delete_buyer_group` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-buyer-group.md
- `delete_company` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-company.md
- `delete_note` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-note.md
- `delete_opportunity` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-opportunity.md
- `delete_partner` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-partner.md
- `delete_person` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-person.md
- `delete_webhook` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/delete-webhook.md
- `flag_work_item` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/flag-work-item.md
- `forget` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/forget.md
- `paper_delete_document` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/paper-delete-document.md
- `paper_revoke_share` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/paper-revoke-share.md
- `remove_buyer_group_member` — Destructive — https://policylayer.com/tools/adrata-starfield-mcp/remove-buyer-group-member.md
- `adrata_ai_tool_execute` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/adrata-ai-tool-execute.md
- `attribute_partner_to_deal` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/attribute-partner-to-deal.md
- `build_pursuit_command_center` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/build-pursuit-command-center.md
- `draft_workflow` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/draft-workflow.md
- `dry_run_workflow` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/dry-run-workflow.md
- `record_partner_consumption` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/record-partner-consumption.md
- `replay_workflow_run` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/replay-workflow-run.md
- `request_deployment` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/request-deployment.md
- `request_provider_action_execution` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/request-provider-action-execution.md
- `request_workflow_deployment` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/request-workflow-deployment.md
- `warmup_email` — Execute — https://policylayer.com/tools/adrata-starfield-mcp/warmup-email.md
- `adrata_ai_tool_catalog` — Read — https://policylayer.com/tools/adrata-starfield-mcp/adrata-ai-tool-catalog.md
- `adrata_api_catalog` — Read — https://policylayer.com/tools/adrata-starfield-mcp/adrata-api-catalog.md
- `adrata_desktop_app_audit` — Read — https://policylayer.com/tools/adrata-starfield-mcp/adrata-desktop-app-audit.md
- `check_batch_import_status` — Read — https://policylayer.com/tools/adrata-starfield-mcp/check-batch-import-status.md
- …and 202 more: https://policylayer.com/tools/adrata-starfield-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=adrata-starfield-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/adrata-starfield-mcp
