create_signup_request
Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agents create a request and hand the returned consentUrl to the ...
This record as markdown: /tools/doit/create-signup-request.md
What create_signup_request does on Doit
AI agents use create_signup_request to create or update resources in Doit, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Doit environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
email | string | Yes | Work email of the organization's admin. Free-mail and disposable addresses are rejected. |
source | object | — | Attribution. channel defaults to agent; console and web are the human channels. |
companyName | string | Yes | |
termsConsent | object | — | Terms of Service acceptance. Required for the console and web channels. |
turnstileToken | string | — | Cloudflare Turnstile response token. Required for the console and web channels. |
Idempotency-Key | string | Yes | |
customerContext | string | — | Scope the request to a specific customer by ID. Required for DoiT employees (whose token isn't tied to a single customer); omit for direct customer users. |
Parameters from the server's own tool schema.
Why create_signup_request is rated Medium
An AI agent can call create_signup_request faster than any human can review: one bad instruction and it creates or modifies resources in Doit by the hundred, each call as confident as the last.
Risk signalsHigh parameter count (15 properties) · Admin/system-level operation
Attacks that exploit this kind of access
The rule that runs create_signup_request safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Doit, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_signup_request, this is the rule to start with:
create_signup_request stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Doit, apply this rule, and every create_signup_request call is checked against it from then on.
Questions about create_signup_request
Start a Cloud Intelligence trial for an organization that is not yet a DoiT customer. These operations require no API key: they are rate limited, idempotent, and provision nothing until the organization's admin verifies the request. Agents create a request and hand the returned consentUrl to the admin; the admin verifies by entering the emailed code (or signing the request on the console), after which the tenant is provisioned and the request reports its customer id. Starts a Cloud Intelligence trial signup for the organization owning the email domain. Idempotent per Idempotency-Key: a retried create returns the same request. Nothing is provisioned until the admin verifies the request. Human channels (console, web) additionally require a Cloudflare Turnstile token and an accepted Terms of Service version; the emailed 6-digit verification code is then the consent act. Agents should present consentUrl to the organization's admin and poll getSignupRequest. It is categorised as a Write tool in the Doit MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
create_signup_request accepts 7 parameters: email, source, companyName, termsConsent, turnstileToken, Idempotency-Key, customerContext. Required: email, companyName, Idempotency-Key. The full parameter table on this page comes from the server's own tool schema.
Register the Doit MCP server in PolicyLayer and add a rule for create_signup_request: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Doit. Nothing to install.
create_signup_request is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_signup_request rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_signup_request. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_signup_request is provided by the Doit MCP server (@doitintl/doit-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Doit, and thousands of servers like it.
This server
Across the catalogue