<!-- Generated by scripts/generate-tool-contract.mjs. Do not edit by hand. -->

# MCP Tool Profiles

Contract version: `1`
MCP revision: `2026-07-28`
Approved modern cache hint: `ttlMs=30000`, `cacheScope=private`

| Profile | Total | `b2_*` | `s3_*` | `bz_*` | Hash prefix |
| --- | ---: | ---: | ---: | ---: | --- |
| `full` | 40 | 21 | 19 | 0 | `537cb0277be8` |
| `live-b2-contract` | 39 | 20 | 19 | 0 | `9449981e8ef1` |
| `phase1-default` | 37 | 18 | 19 | 0 | `de997e8002ad` |
| `read-only` | 20 | 11 | 9 | 0 | `9873510da79d` |

## `full`

Complete tool superset for contract review and regression detection across all backing categories; durable-secret producers are sink-backed when a secret sink is active and otherwise remain availability-annotated stubs.

Profile hash: `537cb0277be8d453239d7ca8462eedb5d24733da6ee804d1a22458250a2d129c`

### Capability Input

- Full-surface override (`null` capability input).

### Backing Categories

- Native B2 SDK: 17
- AWS S3 SDK: 19
- Neither SDK: 4

### `b2_*` Tools (21)

- `b2_authorize_account`
- `b2_create_bucket`
- `b2_create_group_member`
- `b2_create_key`
- `b2_delete_bucket`
- `b2_delete_key`
- `b2_egress_leaders`
- `b2_eject_group_member`
- `b2_get_bucket_notification_rules`
- `b2_largest_files`
- `b2_list_buckets`
- `b2_list_group_members`
- `b2_list_groups`
- `b2_list_keys`
- `b2_reserve_trial_create_account`
- `b2_set_bucket_notification_rules`
- `b2_unfinished_uploads`
- `b2_update_bucket`
- `b2_update_file_legal_hold`
- `b2_update_file_retention`
- `b2_usage_growth`

### `s3_*` Tools (19)

- `s3_abort_multipart_upload`
- `s3_complete_multipart_upload`
- `s3_copy_object`
- `s3_create_multipart_upload`
- `s3_delete_object`
- `s3_delete_objects`
- `s3_get_bucket_location`
- `s3_get_object`
- `s3_get_presigned_url`
- `s3_head_bucket`
- `s3_head_object`
- `s3_list_multipart_uploads`
- `s3_list_object_versions`
- `s3_list_objects_v2`
- `s3_list_parts`
- `s3_presign_upload_part`
- `s3_put_bucket_lifecycle`
- `s3_put_object`
- `s3_upload_part_copy`

## `live-b2-contract`

Protected live B2 contract profile: non-master application key with release-evidence capabilities, no key-management grants, and a distinct master key only for Partner/Groups API surface discovery.

Profile hash: `9449981e8ef194d9c1b4f2da77da00388e4f91c10609eed526655d6be446cacf`

### Capability Input

- `bypassGovernance`
- `deleteBuckets`
- `deleteFiles`
- `listBuckets`
- `listFiles`
- `listKeys`
- `readBucketEncryption`
- `readBucketRetentions`
- `readBuckets`
- `readFileLegalHolds`
- `readFileRetentions`
- `readFiles`
- `writeBucketEncryption`
- `writeBucketNotifications`
- `writeBucketRetentions`
- `writeBuckets`
- `writeFileLegalHolds`
- `writeFileRetentions`
- `writeFiles`

### Backing Categories

- Native B2 SDK: 16
- AWS S3 SDK: 19
- Neither SDK: 4

### `b2_*` Tools (20)

- `b2_authorize_account`
- `b2_create_bucket`
- `b2_create_group_member`
- `b2_create_key`
- `b2_delete_bucket`
- `b2_egress_leaders`
- `b2_eject_group_member`
- `b2_get_bucket_notification_rules`
- `b2_largest_files`
- `b2_list_buckets`
- `b2_list_group_members`
- `b2_list_groups`
- `b2_list_keys`
- `b2_reserve_trial_create_account`
- `b2_set_bucket_notification_rules`
- `b2_unfinished_uploads`
- `b2_update_bucket`
- `b2_update_file_legal_hold`
- `b2_update_file_retention`
- `b2_usage_growth`

### `s3_*` Tools (19)

- `s3_abort_multipart_upload`
- `s3_complete_multipart_upload`
- `s3_copy_object`
- `s3_create_multipart_upload`
- `s3_delete_object`
- `s3_delete_objects`
- `s3_get_bucket_location`
- `s3_get_object`
- `s3_get_presigned_url`
- `s3_head_bucket`
- `s3_head_object`
- `s3_list_multipart_uploads`
- `s3_list_object_versions`
- `s3_list_objects_v2`
- `s3_list_parts`
- `s3_presign_upload_part`
- `s3_put_bucket_lifecycle`
- `s3_put_object`
- `s3_upload_part_copy`

## `phase1-default`

Default customer-hosted Phase 1 profile: standard B2 application key, no distinct Partner/master credential, and durable-secret producers exposed as sink-backed tools on local stdio or unavailable stubs when the sink is off.

Profile hash: `de997e8002adb8c1c38147202b4a8f8507d98c37ca1870f928eef281b5523e1c`

### Capability Input

- `deleteBuckets`
- `deleteFiles`
- `deleteKeys`
- `listBuckets`
- `listFiles`
- `listKeys`
- `readBucketNotifications`
- `readFiles`
- `writeBucketNotifications`
- `writeBuckets`
- `writeFileLegalHolds`
- `writeFileRetentions`
- `writeFiles`

### Backing Categories

- Native B2 SDK: 14
- AWS S3 SDK: 19
- Neither SDK: 4

### `b2_*` Tools (18)

- `b2_authorize_account`
- `b2_create_bucket`
- `b2_create_group_member`
- `b2_create_key`
- `b2_delete_bucket`
- `b2_delete_key`
- `b2_egress_leaders`
- `b2_get_bucket_notification_rules`
- `b2_largest_files`
- `b2_list_buckets`
- `b2_list_keys`
- `b2_reserve_trial_create_account`
- `b2_set_bucket_notification_rules`
- `b2_unfinished_uploads`
- `b2_update_bucket`
- `b2_update_file_legal_hold`
- `b2_update_file_retention`
- `b2_usage_growth`

### `s3_*` Tools (19)

- `s3_abort_multipart_upload`
- `s3_complete_multipart_upload`
- `s3_copy_object`
- `s3_create_multipart_upload`
- `s3_delete_object`
- `s3_delete_objects`
- `s3_get_bucket_location`
- `s3_get_object`
- `s3_get_presigned_url`
- `s3_head_bucket`
- `s3_head_object`
- `s3_list_multipart_uploads`
- `s3_list_object_versions`
- `s3_list_objects_v2`
- `s3_list_parts`
- `s3_presign_upload_part`
- `s3_put_bucket_lifecycle`
- `s3_put_object`
- `s3_upload_part_copy`

## `read-only`

Deterministic read/list profile for safe production use and contract tests; write/delete/admin handlers are omitted while durable-secret producer names remain unavailable stubs unless a sink-backed admin profile is configured.

Profile hash: `9873510da79d6862df6aa9b9d0bb55d4646f09b6daf6d89646f197b3845411c0`

### Capability Input

- `listBuckets`
- `listFiles`
- `listKeys`
- `readBucketNotifications`
- `readFiles`

### Backing Categories

- Native B2 SDK: 7
- AWS S3 SDK: 9
- Neither SDK: 4

### `b2_*` Tools (11)

- `b2_authorize_account`
- `b2_create_group_member`
- `b2_create_key`
- `b2_egress_leaders`
- `b2_get_bucket_notification_rules`
- `b2_largest_files`
- `b2_list_buckets`
- `b2_list_keys`
- `b2_reserve_trial_create_account`
- `b2_unfinished_uploads`
- `b2_usage_growth`

### `s3_*` Tools (9)

- `s3_get_bucket_location`
- `s3_get_object`
- `s3_get_presigned_url`
- `s3_head_bucket`
- `s3_head_object`
- `s3_list_multipart_uploads`
- `s3_list_object_versions`
- `s3_list_objects_v2`
- `s3_list_parts`
