list_models and report their current availability. A 401 means the API key is missing, invalid or revoked; signing into the browser does not authenticate the MCP connection.
HTTP MCP is available only on deployments installed with the MCP extra. These tools use your account and can create paid jobs or change production model versions. Review the requested operation using your MCP client’s approval controls.
Local stdio option
For users with access to a workbench clone, install its MCP extra and run the included command:D1_API_KEY. The process speaks MCP over stdio; use it through the client rather than typing into it. No separately published MCP package is required.
Add the workflow skill
The repository containsskills/decisionone/SKILL.md. Copy its decisionone directory into .agents/skills/ for Codex, or .claude/skills/ for Claude Code; Cursor can use the supported skill directory for your setup. This is a repository-distributed skill, not a registry installation command.
Agents that read documentation can also start with the service’s llms.txt and OpenAPI. The skill explains how to write decisions, build datasets, inspect evaluations and promote or roll back a model.
Give the agent a concrete task
For example: “Inspect my labelled support dataset, tune theteam decision, and show me the verdict and changed wording before I apply it.” A completed tuning job is not necessarily an improvement. Use result.tuned only when result.verdict is improved.
For a fine-tune, ask the agent to inspect the held-out gate and candidate version. A successful training job does not by itself move the production pointer. Versions and promotion explains that boundary.
Claude Code tool-call hook
POST /v1/hooks/claude-code is a separate integration for PreToolUse payloads. It returns hookSpecificOutput with allow, ask or deny. Default mode=guard never grants permission; mode=auto can allow. If scoring fails after the authenticated request reaches the hook, the hook asks the person. Other hook events return an empty object.
This classifier is one input to tool permissions. Keep your application’s deterministic permission checks and scope restrictions. The tool-risk recipe explains the decision policy; the Integrations API reference describes the HTTP payload.