New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

portal_session_cancel

Cancel a client's session on behalf of the client (client-initiated cancellation: cancelledBy=client). Allowed from scheduled/pending_confirmation/confirmed; rejects past sessions. Idempotent: a session already cancelled returns alreadyCancelled=true. Distinct from the admin cancellation with can...

SERVERServicialo SOURCE@servicialo/mcp-server
Critical RISK CLASS
Category Destructive
Parameters 42 required
Recommended Hiddensee the rule below
Registry record Grade F, identity unverified Pull the record →

This record as markdown: /tools/com-servicialo-mcp-server/portal-session-cancel.md

What portal_session_cancel does on Servicialo

AI agents call portal_session_cancel to permanently remove resources in Servicialo, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

ParameterTypeRequiredDescription
apiKey string
orgSlug string Yes
sessionId string Yes
cancellationReason string

Parameters from the server's own tool schema.

Why portal_session_cancel is rated Critical

Although framed as a client-portal action, this tool irreversibly cancels sessions — a state change that cannot be undone without re-scheduling and cannot be reversed by the tool itself. This fits Destructive (irreversible state removal) rather than Write (reversible modification).

From the tool's definition Tool description states it "Cancel[s] a client's session" and explicitly distinguishes this from admin cancellation by noting it is "client-initiated cancellation".

Risk signalsHandles credentials or secrets (apiKey) · Admin/system-level operation

Questions about portal_session_cancel

What does the portal_session_cancel tool do? +

Cancel a client's session on behalf of the client (client-initiated cancellation: cancelledBy=client). Allowed from scheduled/pending_confirmation/confirmed; rejects past sessions. Idempotent: a session already cancelled returns alreadyCancelled=true. Distinct from the admin cancellation with cancellation-policy charges — this is the client-portal cancel flow. The org API key owner is recorded as the actor acting on behalf of the client (ADR-004 §6). It is categorised as a Destructive tool in the Servicialo MCP Server, which means it can permanently delete or destroy data. Block by default and require explicit approval.

What parameters does portal_session_cancel accept? +

portal_session_cancel accepts 4 parameters: apiKey, orgSlug, sessionId, cancellationReason. Required: orgSlug, sessionId. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on portal_session_cancel? +

Register the Servicialo MCP server in PolicyLayer and add a rule for portal_session_cancel: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Servicialo. Nothing to install.

What risk level is portal_session_cancel? +

portal_session_cancel is a Destructive tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.

Can I rate-limit portal_session_cancel? +

Yes. Add a rate_limit block to the portal_session_cancel rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block portal_session_cancel completely? +

Set action: deny in the PolicyLayer policy for portal_session_cancel. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides portal_session_cancel? +

portal_session_cancel is provided by the Servicialo MCP server (@servicialo/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

More on Servicialo, and thousands of servers like it.

// THE MCP REGISTRY

PolicyLayer tracks 44,603 MCP servers and 515,000+ tools.

Every server has a live record: who publishes it, whether it answers without auth, its risk grade, every tool classified, the recommended policy. This page is one line of Servicialo's. Pull the full record:

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.