list_entries
LIST the newest captured traffic entries as SLIM feed rows (id, ts, device, kind, request_id, host, path, method, status, contentType, url — NO bodies/headers) — the dashboard main live feed's MCP-parity read (#778). No search term needed (unlike search_entries' required q). FULL /feed filter set...
This record as markdown: /tools/dev-busymate-busymate-devtools/list-entries.md
What list_entries does on Busymate DevTools
AI agents call list_entries to retrieve information from Busymate DevTools without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
host | string | — | EXACT hostname filter (e.g. 'api.busymate.net'). Use host_contains for a substring. |
after | string | — | Only entries with ts >= this ISO date/datetime. |
limit | number | — | Max rows (default 30, cap 100). |
order | string | — | Sort direction (default 'newest'). |
before | string | — | Only entries with ts < this ISO date/datetime. |
method | string | — | HTTP method filter, case-insensitive exact (e.g. GET, POST). |
status | string | — | Response status filter: an exact code ('404') or a class ('2xx'|'4xx'|'5xx'). |
since_id | number | — | Only entries with id > this — the live-tail append cursor (pass the max id you already rendered). |
deviceName | string | — | Scope to one device by display name. |
device_uuid | string | — | Scope to one device by uuid. |
owner_email | string | — | OPERATOR cross-user scope (devices:view required, re-verified): another user's account email (exact, case-insensitive) — the feed covers THAT user's devices. |
host_contains | string | — | Substring hostname filter, case-insensitive (e.g. 'doordash' matches every *.doordash.com host). |
Parameters from the server's own tool schema.
Why list_entries is rated Low
Even though list_entries only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.
Risk signalsAccepts URL/endpoint input (host) · High parameter count (13 properties)
Attacks that exploit this kind of access
The rule that runs list_entries safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Busymate DevTools, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For list_entries, this is the rule to start with:
list_entries is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Busymate DevTools, apply this rule, and every list_entries call is checked against it from then on.
Questions about list_entries
LIST the newest captured traffic entries as SLIM feed rows (id, ts, device, kind, request_id, host, path, method, status, contentType, url — NO bodies/headers) — the dashboard main live feed's MCP-parity read (#778). No search term needed (unlike search_entries' required q). FULL /feed filter set (#819): scope to ONE device (device_uuid/deviceName), an EXACT host or a host_contains substring, an HTTP method, a status (exact code or a class '2xx'/'4xx'/'5xx'), and/or an absolute ts range; since_id returns ONLY rows newer than an id you already hold (the live-tail append cursor — poll cheaply for what's new); order newest (default) or oldest; limit default 30, capped 100. Owner-scoped like the dashboard: your own devices' traffic by default. OPERATORS (devices:view, re-verified in-handler fail-closed) may scope the feed to ANOTHER user's account via owner_email (exact) or owner_user_id — that user's devices only. For full bodies/headers use inspect_requests; for substring search use search_entries. Returns { ok, count, entries:[…] }. It is categorised as a Read tool in the Busymate DevTools MCP Server, which means it retrieves data without modifying state.
list_entries accepts 12 parameters: host, after, limit, order, before, method, status, since_id, deviceName, device_uuid, owner_email, host_contains. The full parameter table on this page comes from the server's own tool schema.
Register the Busymate DevTools MCP server in PolicyLayer and add a rule for list_entries: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Busymate DevTools. Nothing to install.
list_entries is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the list_entries rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for list_entries. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
list_entries is provided by the Busymate DevTools MCP server (https://mcp.busymate.dev). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Busymate DevTools, and thousands of servers like it.
This server
Across the catalogue