> ## Documentation Index
> Fetch the complete documentation index at: https://developer.communicate.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a custom agent action

> Use an explicitly scoped user-bound account bearer credential or an application session. Scope grants are intersected with live membership, role, tenant isolation, agent access and plan limits; a credential does not grant an owner role. Invitation acceptance requires the verified recipient email.



## OpenAPI

````yaml https://app.communicate.so/api/v1/openapi/mintlify.json post /workspaces/{workspaceId}/agents/{agentId}/actions
openapi: 3.1.0
info:
  title: Communicate Public REST API
  version: 0.1.4
  summary: >-
    Scoped agent chat, account credential lifecycle and workspace bootstrap
    operations.
  description: >-
    Canonical external schema for implemented REST operations. Account
    credentials and application sessions authorize the documented account and
    workspace operations separately from workspace keys. Exchange a workspace
    API-key client ID and secret for a short-lived OAuth access token, or use
    the `ck_` key directly for backward compatibility. `requestId` is optional
    but, when supplied, becomes the idempotency key for retries of the same chat
    input.
servers:
  - url: https://app.communicate.so/api/v1
    description: Canonical external base URL served through the Next.js /api/v1 rewrite.
security:
  - oauth2: []
  - bearerAuth: []
paths:
  /workspaces/{workspaceId}/agents/{agentId}/actions:
    post:
      tags:
        - Agents
      summary: Create a custom agent action
      description: >-
        Use an explicitly scoped user-bound account bearer credential or an
        application session. Scope grants are intersected with live membership,
        role, tenant isolation, agent access and plan limits; a credential does
        not grant an owner role. Invitation acceptance requires the verified
        recipient email.
      operationId: createAction
      parameters:
        - name: workspaceId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
        - name: agentId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/createActionRequest'
      responses:
        '201':
          description: Create a custom agent action
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/createActionResponse'
        '400':
          description: Invalid request, timezone, resource association or confirmation.
        '401':
          description: >-
            Missing, invalid, expired or revoked account credential or
            application session.
        '402':
          description: Plan entitlement, capacity or credits do not allow this operation.
        '403':
          description: >-
            Required account scope, live verified identity, membership or role
            permission is missing.
        '404':
          description: Workspace or addressed resource is not visible to this member.
        '409':
          description: >-
            Support handle, source URL or pending transfer conflicts with this
            operation.
        '422':
          description: Website URL or extraction source is not supported.
        '429':
          description: Agent request or website crawl rate limit exceeded.
        '500':
          description: Unexpected server failure.
        '503':
          description: Authorization service temporarily unavailable.
      security:
        - accountBearer: []
        - accountSession: []
        - localAccountSession: []
components:
  schemas:
    createActionRequest:
      type: object
      properties:
        name:
          type: string
          pattern: ^[a-zA-Z0-9_]{1,64}$
        description:
          type: string
          minLength: 1
          maxLength: 1000
        method:
          default: GET
          type: string
          enum:
            - GET
            - POST
            - PUT
            - PATCH
            - DELETE
        urlTemplate:
          type: string
          format: uri
        headers:
          default: {}
          type: object
          propertyNames:
            type: string
          additionalProperties:
            type: string
        paramSchema:
          default: {}
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        bodyTemplate:
          default: null
          anyOf:
            - type: object
              propertyNames:
                type: string
              additionalProperties: {}
            - type: 'null'
      required:
        - name
        - description
        - urlTemplate
      additionalProperties: false
    createActionResponse:
      type: object
      properties:
        id:
          type: string
          minLength: 1
        workspaceId:
          type: string
          minLength: 1
        agentId:
          type: string
          minLength: 1
        name:
          type: string
        description:
          type: string
        method:
          type: string
          enum:
            - GET
            - POST
            - PUT
            - PATCH
            - DELETE
        urlTemplate:
          type: string
        paramSchema:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        bodyTemplate:
          anyOf:
            - type: object
              propertyNames:
                type: string
              additionalProperties: {}
            - type: 'null'
        headersConfigured:
          type: boolean
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
      required:
        - id
        - workspaceId
        - agentId
        - name
        - description
        - method
        - urlTemplate
        - paramSchema
        - bodyTemplate
        - headersConfigured
        - createdAt
      additionalProperties: false
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client-credentials tokens bounded by the source API key scope
        ceiling.
      flows:
        clientCredentials:
          tokenUrl: https://app.communicate.so/api/v1/oauth/token
          scopes:
            agents:read: List agents in the authenticated workspace.
            chat:write: Create chat turns with an agent in the authenticated workspace.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: Workspace API key token with the `ck_` prefix.
    accountBearer:
      type: http
      scheme: bearer
      bearerFormat: Account credential
      description: >-
        Opaque user-bound `ca_` account credential. Each request checks live
        account scopes, verified email, expiry, revocation and the issuer
        session. Not a workspace `ck_` key or OAuth access token.
    accountSession:
      type: apiKey
      in: cookie
      name: __Secure-better-auth.session_token
      description: >-
        Signed Better Auth session cookie for an HTTPS application origin.
        Credential management additionally requires verified email and fresh
        password proof on writes.
    localAccountSession:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: >-
        Signed session cookie used when the configured application auth origin
        is HTTP, such as local development.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.