create_post_type_field
Add a custom field to a post type schema. The field key becomes the key in meta when creating/updating posts. Use fieldType="repeater" with fields=[...] for repeatable structured rows. Use this instead of storing structured data in excerpt.
This record as markdown: /tools/io-favcrm-favcrm/create-post-type-field.md
What create_post_type_field does on FavCRM
AI agents use create_post_type_field to create or update resources in FavCRM, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your FavCRM environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
key | string | — | snake_case key used in meta. Auto-derived from label if omitted. |
label | string | Yes | Human-readable field label, e.g. "Tagline" |
fields | array | — | Required for fieldType="repeater". Defines the child fields stored in each row object. |
options | object | — | For select/multiselect: { choices: [{ label, value }] }. For URL fields that should accept merchant uploads, use { uploadable: true } so the UI stores the uploa |
helpText | string | — | Optional hint shown in the UI |
required | boolean | — | Whether the field is required on post creation (default false) |
fieldType | string | Yes | Field type: text | textarea | richtext | number | boolean | date | datetime | select | multiselect | url | email | image | file | gallery | attachments | repeat |
sortOrder | number | — | Sort order (lower = earlier) |
postTypeId | string | Yes | Post type ID (from list_post_types) |
Parameters from the server's own tool schema.
Why create_post_type_field is rated Medium
This tool creates and modifies schema metadata in the CRM system. While it does not irreversibly delete data (not Destructive), it does structurally alter how data is stored and organized, making it a Write operation. Severity is medium because schema modifications can have cascading effects on existing posts and queries, but the changes are reversible by removing or modifying fields.
From the tool's definition Tool description states 'Add a custom field to a post type schema' — this creates or modifies the schema structure used by the CRM.
Risk signalsHigh parameter count (16 properties)
Attacks that exploit this kind of access
The rule that runs create_post_type_field safely
PolicyLayer is an MCP gateway: it sits between your AI agents and FavCRM, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_post_type_field, this is the rule to start with:
create_post_type_field stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect FavCRM, apply this rule, and every create_post_type_field call is checked against it from then on.
Questions about create_post_type_field
Add a custom field to a post type schema. The field key becomes the key in meta when creating/updating posts. Use fieldType="repeater" with fields=[...] for repeatable structured rows. Use this instead of storing structured data in excerpt. It is categorised as a Write tool in the FavCRM MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
create_post_type_field accepts 9 parameters: key, label, fields, options, helpText, required, fieldType, sortOrder, postTypeId. Required: label, fieldType, postTypeId. The full parameter table on this page comes from the server's own tool schema.
Register the FavCRM MCP server in PolicyLayer and add a rule for create_post_type_field: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches FavCRM. Nothing to install.
create_post_type_field is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_post_type_field rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_post_type_field. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_post_type_field is provided by the FavCRM MCP server (https://api.favcrm.io/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on FavCRM, and thousands of servers like it.
This server
Across the catalogue