async_run_inline
Manage Cloud Analytics reports and get reports data in JSON format. Submits an async report execution job using an inline configuration. Returns 202 immediately with a Location header pointing to the operation status endpoint. Requires the Idempotency-Key header to ensure at-most-once submission....
This record as markdown: /tools/doit/async-run-inline.md
What async_run_inline does on Doit
AI agents invoke async_run_inline to trigger actions in Doit. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
| Parameter | Type | Required | Description |
|---|---|---|---|
config | object | — | Report configuration. |
dryRun | boolean | — | |
Idempotency-Key | string | Yes | |
customerContext | string | — | Scope the request to a specific customer by ID. Required for DoiT employees (whose token isn't tied to a single customer); omit for direct customer users. |
Parameters from the server's own tool schema.
Why async_run_inline is rated High
async_run_inline triggers real processes with real consequences. An agent gone sideways doesn't fire it once. It starts dozens of builds, sends mass notifications, or burns through compute before anyone looks up.
Risk signalsHigh parameter count (95 properties)
Attacks that exploit this kind of access
The rule that runs async_run_inline safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Doit, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For async_run_inline, this is the rule to start with:
async_run_inline stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Doit, apply this rule, and every async_run_inline call is checked against it from then on.
Questions about async_run_inline
Manage Cloud Analytics reports and get reports data in JSON format. Submits an async report execution job using an inline configuration. Returns 202 immediately with a Location header pointing to the operation status endpoint. Requires the Idempotency-Key header to ensure at-most-once submission. Duplicate requests with the same config for the same customer return the existing in-flight operation. Use ?dryRun=true to validate the config without creating an operation. It is categorised as a Execute tool in the Doit MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
async_run_inline accepts 4 parameters: config, dryRun, Idempotency-Key, customerContext. Required: Idempotency-Key. The full parameter table on this page comes from the server's own tool schema.
Register the Doit MCP server in PolicyLayer and add a rule for async_run_inline: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Doit. Nothing to install.
async_run_inline is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the async_run_inline rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for async_run_inline. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
async_run_inline is provided by the Doit MCP server (@doitintl/doit-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Doit, and thousands of servers like it.
This server
Across the catalogue