Tool catalog
hpe-networking-mcp registers 6,732 backend tools when every generated surface and guarded write is enabled: 6,713 platform API tools across nine vendor surfaces (Aruba Central, GreenLake Platform, ClearPass, Juniper Mist, Apstra, ArubaOS 8, EdgeConnect, UXI, Axis Atmos Cloud) plus 8 credential-free design-core diagram tools and 5 credential-free interop-core tools that make no vendor API call at all, plus the always-loaded cross-platform site-health aggregator, the protocol-only Central Streaming collector, and the local GLP preflight and SKU-catalog helpers. Direct-all router mode adds nineteen router-native tools (present only in direct mode, not part of the backend registry itself) for 6,751 client-visible tools total. The recommended minimal router exposes only find_tool, invoke_read_tool, and invoke_tool, then searches the larger index on demand.
Every number in this section is derived, not hand-entered – see docs/project-facts.json’s tools and router_modes sections, regenerated by scripts/project_facts.py --write.
The nine committed generated manifests contain 6,145 operations (6,128 register as active generated tools; 17 are intentionally excluded — see below). Adding 584 curated platform tools yields the 6,713 platform API backend total. Capability totals across the platform API catalog are 3,161 read, 165 diagnostic, 2,545 write, and 842 destructive. See docs/capability-gap-matrix.md for the full, reproducible per-platform breakdown and the pinned benchmark comparison (intentionally excludes design-core/interop-core, which have no vendor API to benchmark against).
Generated manifests also drive parameter constraints. Compatible OpenAPI enums with up to 20 choices are published exactly; larger enums stay compact in tool schemas but are still enforced before dispatch with bounded errors. Contradictory vendor metadata is ignored in favor of the declared parameter type rather than breaking valid defaults.
Counts by backend
| Server | Read-only annotated | Registered total | Main coverage |
|---|---|---|---|
central-generated | 681 | 1,677 | New Central configuration APIs from merged official specifications |
central-config | 26 | 80 | SSIDs, VLANs, profiles, firmware, BGP, OSPF, VRF, HA, telemetry, application experience, checkpoint policy |
central-monitoring | 75 | 90 | Health, inventory, topology, BSSID mappings, applications, onboarding, AP tunnels, config health, notification rules, guarded Central GET, and reports |
central-nac | 15 | 38 | MAC registration, named MPSK, visitors, auth servers, auth server groups, AAA profiles and diagnostics |
central-ops | 2 | 41 | Troubleshooting, reboot, PoE/port bounce, cable tests, gateway iperf and ping sweep |
glp-core | 572 | 1,0131 | Current devices, grouping, subscriptions, auto-subscription settings, users, Audit Logs v2beta1, workspaces, reporting, service catalog, RBAC role-assignment/scope-group lifecycle, identity user lifecycle, events/webhooks/deliveries, locations/tags, SCIM users/groups/membership, region-aware Compute Ops Management/Storage Fleet/Block Storage/Virtualization/Backup & Recovery/Data Services reads plus guarded VM power and run-protection-job-now writes, and read-only cross-resource reconciliation (105 curated + 906 active generated; HPE_MCP_GLP_GENERATED_TOOLS=1 to expand) |
rag-core | 15 | 162 | Docs, exact API, AOS-CX release comparison, advisory/lifecycle lookup, and skills/runbooks |
catalog-core | 2 | 2 | Always-loaded local SQLite HPE Aruba/HPE Juniper SKU/model search and verified device comparison; no RAG or vendor API call |
clearpass-core | 285 | 845 | CPPM 6.12.7 APIs, Insight endpoint data, OnGuard activity, guarded writes |
mist-core | 547 | 1,080 | 1,050 official OpenAPI operations plus curated NAC, Marvis, inventory, Wired/WAN workflows, assurance snapshots, and bounded authenticated regional WebSocket diagnostic collection |
apstra-core | 86 | 155 | Official 6.1 SDK-derived blueprints, tasks, endpoint policies, object-policy workflows |
aos8-core | 132 | 311 | UIDARUBA/X-CSRF sessions, 258 generated config operations, normalized migration model and dependency planning, and six resumable migration-run tools |
edgeconnect-core | 687 | 1,270 | 1,216 generated operations plus fail-closed Swagger compatibility diagnostics and curated SD-WAN workflows |
uxi-core | 24 | 49 | Current 25-operation UXI API plus curated OAuth, inventory, groups, and assignments |
axis-core | 12 | 47 | Reviewed split create/update/delete Atmos operations from the deterministic SHA-pinned manifest generator |
| Platform API backend total | 3,161 | 6,713 | Vendor-facing tools only – see the note below |
site-health | 1 | 1 | Bounded cross-platform Central/Mist site-health aggregation with explicit availability states – aggregator, not a vendor API surface |
central-streaming | 1 | 1 | Protocol-only authenticated Central WebSocket event collection – no REST/OpenAPI operation backs it |
glp-core preflight | 1 | 1 | Local GreenLake credential/scope preflight – inspects local configuration, makes no vendor API call |
rag-core provenance | 1 | 1 | Local corpus provenance for the committed vendor/openapi corpus and the locally built prose index – reads manifests/index artifacts only, makes no vendor API call |
design-core | 8 | 8 | Diagram/network-design tools (drawio, Graphviz, next-ui exports) – credential-free, no vendor API call |
interop-core | 5 | 5 | Central <-> Mist WLAN/site concept translation and bounded trend normalization – credential-free, always loaded |
| Complete backend total | 3,177 | 6,732 | Platform API total plus the non-platform backends itemized in docs/project-facts.json |
design-core (opt-in via HPE_MCP_PRODUCTS=design) and interop-core (always loaded) generate no vendor API traffic, so they sit outside the platform-API benchmark comparison in docs/capability-gap-matrix.md – but they are real, registered, client-dispatchable backend tools, so they are still counted toward release validation’s tool-catalog floor (a conservative lower bound set at the platform-only total, checked against the complete 6,732-tool registered catalog) and are included in the complete backend total (6,732) reported everywhere else in this repository (docs/project-facts.json’s tools.registered_total, docs/release-indexes.md’s “Complete backend catalog”, and the router-modes table below).
“Read-only annotated” excludes diagnostic operations that remain visible in optional read-only mode. Registered totals include guarded writes; write gates, dry-run defaults, and confirmation still apply.
Generated manifest counts
| Platform | Operations |
|---|---|
| Aruba Central | 1,677 |
| GreenLake Platform | 921 |
| Juniper Mist | 1,050 |
| ClearPass | 816 |
| ArubaOS 8 | 258 |
| EdgeConnect | 1,216 |
| HPE Aruba UXI | 25 |
| Juniper Apstra | 135 |
| Axis Atmos Cloud | 47 |
| Total | 6,145 |
GLP registers 906 generated operations because 14 sunset device/subscription operations remain in the provenance manifest but are intentionally suppressed at runtime. ClearPass registers 815 generated operations because /oauth returns credentials and is excluded from model-visible tools. Apstra excludes its two login operations because session credentials are injected internally. 17 operations total are excluded this way, so 6,128 of the 6,145 manifest operations register as active generated tools.
Router modes
| Mode | Client-visible tools | Use |
|---|---|---|
minimal | 3 | Recommended low-token discovery and dispatch |
default | 35 | Router convenience wrappers (list_sites, ask_docs, search_hardware_catalog, compare_hardware, AOS8, ClearPass, Mist, and other common reads) |
direct + HPE_MCP_TOOLSETS=all | 6,751 | Full schema introspection and debugging |
The default count (35) is measured identically whether every toolset is loaded or only the documented recommended client profile (HPE_MCP_ROUTER_MODE=default, HPE_MCP_TOOLSETS=central,glp,rag) is – default mode’s wrapper set depends only on central-monitoring/rag-core being loaded, which both scenarios satisfy. docs/project-facts.json’s router_modes.tools.default_recommended_profile tracks this specific, documented-profile measurement separately from the “every toolset” scenario so the two are never assumed to match without being independently checked.
direct mode’s 6,751 = the complete 6,732 backend total + 19 router-native tools that have no backend-identity equivalent at all (find_tool, invoke_read_tool, invoke_tool, invoke_read_tool_batch, invoke_tools_batch, plan_tool_workflow, plan_reconciliation_schedule, evaluate_compliance_policy, mist_clients, mist_devices, mist_ports, mist_health, aos8_switches, aos8_ports, aos8_vlans, aos8_migration, clearpass_endpoint, clearpass_active_session, clearpass_sessions). The other 13 default-mode wrapper names (list_scopes, get_global_scope_id, list_sites, list_devices, find_device, find_client, get_site, list_clients, ask_docs, search_docs, list_skills, load_skill, lookup_api) intentionally reuse the name of a real backend tool, so they don’t add to the total in direct mode – the router’s compact forwarding signature simply wins over the backend’s registration for that name. See docs/project-facts.json’s router_modes section for the exact, regenerable derivation.
HPE_MCP_ROUTER_MODE=minimal
HPE_MCP_TOOLSETS=central,glp,rag
For full direct introspection:
HPE_MCP_ROUTER_MODE=direct
HPE_MCP_TOOLSETS=all
HPE_MCP_ACCESS_PROFILE=full-read-write
HPE_MCP_PRODUCT_ACCESS=read-write
HPE_MCP_CENTRAL_GENERATED_TOOLS=1
HPE_MCP_GLP_GENERATED_TOOLS=1
HPE_MCP_AOS8_GENERATED_TOOLS=1
HPE_MCP_EDGECONNECT_GENERATED_TOOLS=1
HPE_MCP_APSTRA_GENERATED_TOOLS=1
HPE_MCP_MIST_GENERATED_TOOLS=1
HPE_MCP_CLEARPASS_GENERATED_TOOLS=1
HPE_MCP_UXI_GENERATED_TOOLS=1
HPE_MCP_GLP_V2BETA1_WRITES=1
HPE_MCP_TOOLSETS=all alone loads every core, generated, always-on, and optional-product backend – do not also set HPE_MCP_PRODUCTS=all; HPE_MCP_PRODUCTS only accepts specific product names (clearpass,mist,apstra,aos8,edgeconnect,uxi,axis,design) or is omitted entirely, never the literal value all. Setting HPE_MCP_PRODUCTS=all raises InvalidRuntimeConfigError at startup.
Build and validate the catalog
uv run python scripts/ingest_tools.py
uv run python scripts/ingest_tools.py --complete-catalog
uv run python scripts/check_generated_tool_manifests.py
uv run python scripts/report_capability_gaps.py --check
Optional product writes are hidden and blocked under safe-read-only and under the default optional-product settings in custom. Generated writes remain platform-gated and preview-first. invoke_tool remains annotated destructive because it can dispatch any enabled write-capable backend.
-
docs/project-facts.jsonreportstools.by_server["glp-core"]as 1,015 – the 1,013 vendor-facing tools plus the localglp_preflightdiagnostic, which is listed separately below because it makes no vendor API call and is therefore excluded from the platform API total. ↩ -
docs/project-facts.jsonreportstools.by_server["rag-core"]as 16 – the 15 tools counted in the platform API total plus localcorpus_provenance, which is listed separately below because it reads only local artifacts and is excluded from the platform API total. ↩