Skip to main content
Tools let an agent run commands, work with files, read the web, and coordinate with other agents. You don’t list built-in tools on an agent. A session receives them from its agent version, its environment, and the features the agent uses, and the set is fixed when the session starts.
Creating, changing, or deleting agents and their tool settings needs the organization developer or admin role. The organization user role can view them. See Organizations and roles. For the API, create a key on API keys and export it as RECURSION_API_KEY. Tool settings belong to an agent version, and every change is a new version, so read Update an agent first.

How a session gets its tools

  • The agent version decides web search, remote MCP servers, skills, the apps it’s granted through integrations, and multi-agent roles.
  • The environment decides the sandbox tools. computer needs an environment with computer use turned on. See Environments.
  • The model decides view_image, which is offered only to models that accept images.
A running session keeps its tool set. A new agent version, or a new tool on an MCP server, reaches only sessions that start afterward. web_search_enabled defaults to true. Set it to false to remove web_search. The agent can still read a known URL with web_fetch, except in sessions started by an automation or a Slack thread in an environment that limits internet access.
  1. In the sidebar, click Agents, then open the agent.
  2. On Configuration, find Tools.
  3. Clear Web search.
  4. Click Save new version.
A 201 response is the agent at its new version. Some fields are left out here.
A version is a full replacement, so resend mcp_servers, skills, vault defaults, and anything else you want to keep. In a multi-agent roster, a subagent can turn web search off but not on.

Withhold integration tools

disabled_integration_mcp_providers lists the native integration providers whose MCP tools an agent’s sessions do not receive, even when the agent has access to the connection. In the console, it’s the MCP tools checkbox on each native connection in the agent’s Integrations section. The jira entry in the example above withholds Jira’s MCP tools.
  • Supported values are confluence, github, jira, launchdarkly, and loom. An unknown value returns 400 invalid_request.
  • Omitting the field means an empty list.
  • github is accepted but ignored: a GitHub grant works only through GitHub’s MCP tools.
  • The field never affects servers you list in mcp_servers.
  • It doesn’t affect built-in integrations, whose tools are controlled by each app’s allow-list.

Read a session’s tool set

A session records the tool settings it started with in config. Read the session to see them.
  1. In the sidebar, click Sessions, then open the session.
  2. Each tool call in the transcript shows the tool’s name and input.
This session’s agent has web search turned off, so web_search is missing. config is left out when you request view=summary. config.available_builtin_tools lists which of web_search, web_fetch, write_artifact, read_artifact, get_events, and delegate_subagent the session may use. The session’s top-level sandbox_provider names the sandbox its environment used. Sandbox and feature tools follow the rules in Built-in tools.

Built-in tools

A session’s tools come in three groups. Tools from MCP servers are added next to these. Their names and schemas come from the server and are fixed when the session starts. Sandbox tools run inside the session’s sandbox and see its /workspace: run_command, write_file, read_file, share_file, write_artifact, read_artifact, release_compute, screenshot, computer, and handoff_to_user.
Under a restricted network policy, browser tools reach an external site only when the destination is allowed.
Tools that run outside the sandbox are not subject to the environment’s network policy: web_search, web_fetch, get_events, delegate_subagent, sleep, update_scratchpad, and view_image.
To protect restricted environments, a session started by an automation or a Slack thread doesn’t get web_fetch when its environment has a network policy that limits internet access.
Tools added by agent features appear when the agent uses skills, subagents, an advisor, teams, referenced sessions, or agent file history.
Apps granted through built-in integrations don’t add tools to this list. The agent calls an app’s tools with commands in the sandbox, and each call appears in the transcript as a run_command call with the app’s result. It can call only the tools on the app’s allow-list.

What can go wrong

The most common problems:
  • The agent never searches the web. web_search_enabled is false on the version the session used. Create a version with web_search_enabled: true, then start a new session.
  • No computer tool. The environment does not have computer use turned on, or the display did not start. Turn on computer use in the environment, then start a new session.
  • A tool change doesn’t reach a running session. The tool set is fixed when the session starts. Start a new session.
The full error catalog is on Errors.

Limits

See Limits for request and session limits.

Next steps

MCP servers

Add remote tools and keep their credentials in a vault.

Environments

Choose the compute, network policy, and computer use.

Deliverables and artifacts

Ask for deliverables and see how they’re kept.

Skills

Give the agent procedures it loads when they apply.