getDocument
Read a document's content with line numbers. content.text lines are formatted NNNNN<TAB>content (cat -n style); the number+tab prefix is DISPLAY ONLY — never part of the document — so when building editDocument anchor patches, copy only the text AFTER the tab. Reads paginate by lines (offset/limi...
This record as markdown: /tools/io-stablebaseline-sb/getdocument.md
What getDocument does on Stable Baseline
AI agents call getDocument to retrieve information from Stable Baseline without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
limit | number | — | Max lines to return. Default: 200. |
fields | array | — | Field projection. Valid fields: id, title, friendlyId, friendlyIdNumber, projectId, folderId, createdAt, updatedAt, versionTimestamp. |
offset | number | — | Lines to skip from start. Default: 0. |
documentId | string | Yes | The document ID to read. |
contentFields | array | — | Content field projection. Valid fields: offset, limit, totalLines, nextOffset, metadata, text. |
includeDiagramDsl | boolean | — | If true, inline each diagram's full DSL (as diagramCode) and its versionTimestamp into the DIAGRAM_OMITTED markers, so you can inspect and then edit a diagram ( |
Parameters from the server's own tool schema.
Why getDocument is rated Low
This tool retrieves and queries document data with no side effects. The mention of versionTimestamp is a concurrency control mechanism used by mutating tools downstream, not evidence of mutation by getDocument itself. The tool fits the Read category definition: 'retrieves or queries data; no side effects.'
From the tool's definition Tool name is 'getDocument' and description states 'Read a document's content with line numbers' — core functionality is retrieval without modification.
Risk signalsBulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs getDocument safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Stable Baseline, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For getDocument, this is the rule to start with:
getDocument is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Stable Baseline, apply this rule, and every getDocument call is checked against it from then on.
Questions about getDocument
Read a document's content with line numbers. content.text lines are formatted NNNNN<TAB>content (cat -n style); the number+tab prefix is DISPLAY ONLY — never part of the document — so when building editDocument anchor patches, copy only the text AFTER the tab. Reads paginate by lines (offset/limit, default 200): use content.totalLines and content.nextOffset to page. document.versionTimestamp is the optimistic-lock token that every mutating document tool accepts (as versionTimestamp; the older documentVersionTimestamp name also works) — and every mutating tool returns a fresh token, so you rarely need to re-read just to keep editing. Diagrams/images appear as OMITTED markers with metadata (type, diagramId, renderStatus, nlDescription) — use getDiagramInDocument(diagramId) for full DSL code, or pass includeDiagramDsl:true to inline each diagram's DSL and versionTimestamp directly into its DIAGRAM_OMITTED marker (saves a getDiagramInDocument call when you intend to read or edit diagrams). It is categorised as a Read tool in the Stable Baseline MCP Server, which means it retrieves data without modifying state.
getDocument accepts 6 parameters: limit, fields, offset, documentId, contentFields, includeDiagramDsl. Required: documentId. The full parameter table on this page comes from the server's own tool schema.
Register the Stable Baseline MCP server in PolicyLayer and add a rule for getDocument: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Stable Baseline. Nothing to install.
getDocument is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the getDocument rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for getDocument. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
getDocument is provided by the Stable Baseline MCP server (https://api.stablebaseline.io/functions/v1/cloud-serve/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Stable Baseline, and thousands of servers like it.
This server
Across the catalogue