ghl_get_custom_fields_by_object_key
Get all custom fields and folders for a specific object key (e.g., custom object or company).
This record as markdown: /tools/ghl/ghl-get-custom-fields-by-object-key.md
What ghl_get_custom_fields_by_object_key does on Ghl
AI agents call ghl_get_custom_fields_by_object_key to retrieve information from Ghl without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
objectKey | string | Yes | Object key to get fields for. Format: "custom_object.{objectKey}" for custom objects. Example: "custom_object.pet" |
locationId | string | — | GoHighLevel location ID (will use default if not provided) |
Parameters from the server's own tool schema.
Why ghl_get_custom_fields_by_object_key is rated Low
This tool retrieves configuration metadata (custom field definitions) without modifying, deleting, or executing anything. It is a safe read-only operation typical of MCP information gathering.
From the tool's definition Tool name and description indicate 'Get all custom fields' — a retrieval operation with no side effects. The verb 'get' and phrase 'for a specific object key' confirm this is a data query.
Attacks that exploit this kind of access
The rule that runs ghl_get_custom_fields_by_object_key safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Ghl, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For ghl_get_custom_fields_by_object_key, this is the rule to start with:
ghl_get_custom_fields_by_object_key is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Ghl, apply this rule, and every ghl_get_custom_fields_by_object_key call is checked against it from then on.
Questions about ghl_get_custom_fields_by_object_key
Get all custom fields and folders for a specific object key (e.g., custom object or company). It is categorised as a Read tool in the Ghl MCP Server, which means it retrieves data without modifying state.
ghl_get_custom_fields_by_object_key accepts 2 parameters: objectKey, locationId. Required: objectKey. The full parameter table on this page comes from the server's own tool schema.
Register the Ghl MCP server in PolicyLayer and add a rule for ghl_get_custom_fields_by_object_key: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Ghl. Nothing to install.
ghl_get_custom_fields_by_object_key is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the ghl_get_custom_fields_by_object_key rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for ghl_get_custom_fields_by_object_key. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
ghl_get_custom_fields_by_object_key is provided by the Ghl MCP server (ghl-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Ghl, and thousands of servers like it.
This server
Across the catalogue