> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnia-voice.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register or update a tool

> Declare a tool an agentic run may call. Endpoints are https-only; credentials go in authHeader and are encrypted at rest, never returned. Registering an existing name updates it. Requires an owner/admin key.



## OpenAPI

````yaml /openapi.json post /v1/env/tools
openapi: 3.1.0
info:
  title: Omnia Management API
  description: >-
    The management API behind the improvement loop: capture and setup, request
    logs and datasets, grades (labels), judges (criteria), evals and deploy
    gates, fine-tuning and reinforcement learning, dedicated GPU endpoints, and
    model aliases and versions. Authenticated with a workspace API key
    (sk_sovereign_...). The inference API (chat, embeddings, rerank, responses)
    is OpenAI-compatible and documented separately.


    Responses are snake_case, list endpoints on the loop products use the
    {"object": "list", "data": [...]} envelope, and refusals use the same nested
    error shape the gateway emits: {"error": {"message", "type", "code"}}.
    Request bodies on the loop products (logs, labels, criteria, evals,
    datasets, aliases) are snake_case; the training and infrastructure products
    (fine-tuning, GRPO, environment tools, dedicated, model-version adoption)
    validate camelCase bodies, and each schema below says which it is. Endpoints
    that spend money require a key minted by a workspace owner or admin and
    return 403 otherwise.
  version: 1.0.0
servers:
  - url: https://gateway.omnia-voice.com
    description: Production
  - url: https://platform.omnia-voice.com/api
    description: Production (legacy alias — same API, older base URL)
security:
  - bearerAuth: []
paths:
  /v1/env/tools:
    post:
      tags:
        - Reinforcement learning
      summary: Register or update a tool
      description: >-
        Declare a tool an agentic run may call. Endpoints are https-only;
        credentials go in authHeader and are encrypted at rest, never returned.
        Registering an existing name updates it. Requires an owner/admin key.
      operationId: registerEnvTool
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegisterEnvTool'
      responses:
        '201':
          description: The registration (credential redacted).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnvTool'
        '400':
          description: Missing name/endpointUrl, or a non-https endpoint.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  schemas:
    RegisterEnvTool:
      type: object
      description: >-
        This body is camelCase (endpointUrl, authHeader), unlike the snake_case
        loop endpoints. Registering the same name again updates the tool.
      required:
        - name
        - endpointUrl
      properties:
        name:
          type: string
        endpointUrl:
          type: string
          description: https-only.
        authHeader:
          type: string
          description: >-
            Full header value ("Bearer xyz"). Stored encrypted; never returned
            by any read.
        readOnly:
          type: boolean
        maxCallsPerEpisode:
          type: integer
    EnvTool:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        endpoint_url:
          type: string
        auth_prefix:
          type:
            - string
            - 'null'
          description: >-
            A redacted prefix of the stored credential (e.g. "Bearer sk-ab…"),
            never the credential itself.
        read_only:
          type: boolean
          description: >-
            Read-only tools are callable during training without
            allowSideEffects.
        max_calls_per_episode:
          type: integer
        enabled:
          type: boolean
        created_at:
          type: string
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            message:
              type: string
            type:
              type: string
              description: >-
                invalid_request_error, insufficient_quota, rate_limit_error, or
                api_error.
            code:
              type: string
              description: >-
                Machine-stable cause, e.g. invalid_api_key, not_found,
                insufficient_permissions, precondition_failed.
          required:
            - message
            - type
            - code
      description: >-
        Every refusal — gateway and management API alike — uses this one
        envelope.
  responses:
    Unauthorized:
      description: Missing, malformed, or revoked API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              message: Invalid API key
              type: invalid_request_error
              code: invalid_api_key
    Forbidden:
      description: The key lacks the required owner/admin permission.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your workspace API key, e.g. `sk_sovereign_...`, sent as `Authorization:
        Bearer <key>`.

````