# dephq_app_unpublish

Return an owned Dephq app to draft and remove it from public use.

Agent View of the PolicyLayer registry record for `dephq_app_unpublish`. HTML page: https://policylayer.com/tools/dephq-mcp/dephq-app-unpublish

## Facts

- Tool: `dephq_app_unpublish`
- Server: Dephq (`@dephq/mcp`) — https://policylayer.com/tools/dephq-mcp.md
- Install: `npx -y @dephq/mcp`
- Homepage: https://www.npmjs.com/package/@dephq/mcp
- Risk category: Destructive (Critical risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 1 (1 required)
- Recommended policy verdict: Hidden

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `app_id` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "dephq_app_unpublish",
    "arguments": {
      "app_id": "<app_id>"
    }
  }
}
```

## Why dephq_app_unpublish is rated Critical

Unpublishing an app removes it from public availability, which is an irreversible operational action in the sense that any users depending on the app lose access immediately. While technically the app could be re-published, the act of removing a live service from public use has high blast radius and is categorized as Destructive due to its irreversible impact on availability.

From the tool's own definition: "'remove it from public use' and 'Return an owned Dephq app to draft' — this action takes a live application offline, making it unavailable to users, which is not easily reversible in terms of service disruption."

## Use case

AI agents call dephq_app_unpublish to permanently remove resources in Dephq, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Dephq:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "dephq_app_unpublish"
  ]
}
```

## Other tools on Dephq (11)

- `dephq_app_check` — Execute — https://policylayer.com/tools/dephq-mcp/dephq-app-check.md
- `dephq_account` — Read — https://policylayer.com/tools/dephq-mcp/dephq-account.md
- `dephq_app_show` — Read — https://policylayer.com/tools/dephq-mcp/dephq-app-show.md
- `dephq_app_versions` — Read — https://policylayer.com/tools/dephq-mcp/dephq-app-versions.md
- `dephq_apps_list` — Read — https://policylayer.com/tools/dephq-mcp/dephq-apps-list.md
- `dephq_project_validate` — Read — https://policylayer.com/tools/dephq-mcp/dephq-project-validate.md
- `dephq_sync_status` — Read — https://policylayer.com/tools/dephq-mcp/dephq-sync-status.md
- `dephq_app_publish` — Write — https://policylayer.com/tools/dephq-mcp/dephq-app-publish.md
- `dephq_app_rollback` — Write — https://policylayer.com/tools/dephq-mcp/dephq-app-rollback.md
- `dephq_project_init` — Write — https://policylayer.com/tools/dephq-mcp/dephq-project-init.md
- `dephq_project_sync` — Write — https://policylayer.com/tools/dephq-mcp/dephq-project-sync.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dephq-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dephq-mcp
