The stability-guaranteed subset of the xlsx-for-ai HTTP API. Each path is a stateless base64-in / base64-out tool. Request schemas are generated from the live server routes; a breaking change to any schema below requires an anchored SPM sign-off (see the change-review gate, scripts/public-contract-gate.mts). Auth: Authorization: Bearer <xfa_… key from POST /api/v1/clients>. Free tier: a monthly allowance of files you can process, no card required.
Every call is authenticated with a bearer API key. There is no signup form: call
POST /api/v1/clients with no authentication to mint an anonymous
client_id / api_key pair, then send that key back as an
Authorization: Bearer <api_key> header on every tool call below.
curl -sX POST https://api.xlsx-for-ai.dev/api/v1/clients \
-H 'content-type: application/json' \
-d '{"client_version":"1.0.0","platform":"cli"}'The response is a JSON object shaped { "client_id": "...", "api_key": "xfa_..." }. Store the api_key — it is not shown again.
Then call any documented tool with that key:
curl -sX POST https://api.xlsx-for-ai.dev/api/v1/tools/csv_check \
-H 'content-type: application/json' \
-H 'Authorization: Bearer <api_key>' \
-d '{}'Free tier: a monthly allowance of files you can process, no card required.
csv_checkxlsx_aggregatexlsx_chartsxlsx_checkxlsx_commentsxlsx_conditional_formatsxlsx_convertxlsx_data_cleanxlsx_data_validationsxlsx_describexlsx_diffxlsx_doctorxlsx_evalxlsx_external_linksxlsx_filterxlsx_form_controlsxlsx_formulasxlsx_healer_curexlsx_healer_diagnosexlsx_healer_intentxlsx_healer_simulatexlsx_hyperlinksxlsx_imagesxlsx_list_sheetsxlsx_macrosxlsx_merged_cellsxlsx_named_rangesxlsx_pii_cleanxlsx_pii_scanxlsx_pivotxlsx_pivot_tablesxlsx_post_slackxlsx_post_teamsxlsx_print_settingsxlsx_propertiesxlsx_protectionxlsx_readxlsx_read_handlexlsx_receiptxlsx_redactxlsx_schemaxlsx_session_set_validationsxlsx_slicers_timelinesxlsx_sortxlsx_stampxlsx_stylesxlsx_tablesxlsx_topologyxlsx_validatexlsx_value_countsxlsx_vault_curexlsx_vault_scanxlsx_verify_receiptxlsx_verify_stampxlsx_workbook_viewsxlsx_writecsv_checkPOST /api/v1/tools/csv_check — Verify CSV structure and injection safety before it is imported anywhere else.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_aggregatePOST /api/v1/tools/xlsx_aggregate — Group-and-aggregate (sum/mean/min/max/count/count_distinct) on a spreadsheet — reshape rows into per-group summaries.
Auth: Authorization: Bearer <api_key> (required)
aggs array required as string optionalcolumn string requiredfunc string required file_b64 string requiredgroup_by array required options object optionalheader_row integer optional limit integer optional sheet string optionalsort string optional {
"properties": {
"aggs": {
"items": {
"properties": {
"as": {
"type": "string"
},
"column": {
"type": "string"
},
"func": {
"enum": [
"sum",
"mean",
"min",
"max",
"count",
"count_distinct"
],
"type": "string"
}
},
"required": [
"column",
"func"
],
"type": "object"
},
"maxItems": 16,
"minItems": 1,
"type": "array"
},
"file_b64": {
"type": "string"
},
"group_by": {
"items": {
"type": "string"
},
"maxItems": 6,
"minItems": 1,
"type": "array"
},
"options": {
"properties": {
"header_row": {
"minimum": 0,
"type": "integer"
},
"limit": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
},
"sort": {
"enum": [
"asc",
"desc",
"none"
],
"type": "string"
}
},
"type": "object"
}
},
"required": [
"aggs",
"file_b64",
"group_by"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_chartsPOST /api/v1/tools/xlsx_charts — List every chart in a workbook — type, title, axis titles, and the cell ranges each series pulls from.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 500,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_checkPOST /api/v1/tools/xlsx_check — Verify a workbook with an independent engine — cross-checks the primary parser against a second renderer.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_commentsPOST /api/v1/tools/xlsx_comments — List every cell comment — legacy notes and modern threaded comments — with author, text, and reply thread.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 5000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_conditional_formatsPOST /api/v1/tools/xlsx_conditional_formats — List every conditional formatting rule (color scales, data bars, icon sets, formula-based highlights, …) with range, type, and priority.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 5000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_convertPOST /api/v1/tools/xlsx_convert — Convert a spreadsheet between formats — reads xlsx, xls, xlsb, ods/fods, csv/tsv, dbf, sylk, dif and prn (25+ inputs), plus a file exported or downloaded from Google Sheets; emits xlsx, csv, tsv, json, md, or html. Often the only way to get a legacy .xls or .dbf into an agent that can't upload one directly. Deterministic and structural, no LLM mapping; exact formula/structure preservation holds on the own-engine path only, so check served_engine in the response (and decline_reason if it reads "incumbent") — a compatibility-engine fallback may not preserve charts, pivots, or other advanced features.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalflatten string optional JSON input only: how to flatten a nested array into columns — "dot" (default) stringifies it into one cell, "index" gives one column per array position, "explode" repeats the record across one output row per element.
sheet string optionalRender only this sheet (text outputs only).
sheets string optional to string required Target format. Binary formats return bytes in _meta.file_b64; text formats render in body.
{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"flatten": {
"description": "JSON input only: how to flatten a nested array into columns — \"dot\" (default) stringifies it into one cell, \"index\" gives one column per array position, \"explode\" repeats the record across one output row per element.",
"enum": [
"dot",
"index",
"explode"
],
"type": "string"
},
"sheet": {
"description": "Render only this sheet (text outputs only).",
"type": "string"
},
"sheets": {
"enum": [
"all",
"first"
],
"type": "string"
}
},
"type": "object"
},
"to": {
"description": "Target format. Binary formats return bytes in _meta.file_b64; text formats render in body.",
"enum": [
"csv",
"tsv",
"txt",
"html",
"md",
"json",
"dif",
"sylk",
"eth",
"prn",
"rtf",
"xlsx",
"xlsb",
"xlsm",
"xls",
"ods",
"fods",
"dbf"
],
"type": "string"
}
},
"required": [
"file_b64",
"to"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_data_cleanPOST /api/v1/tools/xlsx_data_clean — Scan for the common data-grime issues (NA variants, merged-cell residue, type-coercion mistakes, stray header/footer rows, mojibake, duplicate headers) and either flag or fix them.
Auth: Authorization: Bearer <api_key> (required)
accept_findings array optional detectors array optional file_b64 string requiredmode string optional options object optional auto_accept_above number optional column_roles object optional date_ratio_threshold number optional dedup_compare_columns array optional dedup_ignore_case boolean optionalheader_scan_depth integer optional identity_uniqueness_threshold number optional impute_fixed_value number optionalimpute_strategy string optional na_canonical string optionalnumeric_ratio_threshold number optional trailing_threshold integer optional overrides array optional action string required detector string requiredparams object optionalscope object required {
"additionalProperties": false,
"properties": {
"column_letter": {
"type": "string"
},
"region": {
"additionalProperties": false,
"properties": {
"bottom_right": {
"type": "string"
},
"top_left": {
"type": "string"
}
},
"required": [
"bottom_right",
"top_left"
],
"type": "object"
},
"sheet": {
"type": "string"
}
},
"required": [
"sheet"
],
"type": "object"
}reject_findings array optional sheets array optional {
"properties": {
"accept_findings": {
"items": {
"type": "string"
},
"type": "array"
},
"detectors": {
"items": {
"type": "string"
},
"type": "array"
},
"file_b64": {
"type": "string"
},
"mode": {
"enum": [
"diagnose",
"execute"
],
"type": "string"
},
"options": {
"additionalProperties": false,
"properties": {
"auto_accept_above": {
"maximum": 1,
"minimum": 0,
"type": "number"
},
"column_roles": {
"additionalProperties": {
"enum": [
"numeric_measurement",
"categorical",
"identity_pii",
"date",
"free_text"
],
"type": "string"
},
"type": "object"
},
"date_ratio_threshold": {
"maximum": 1,
"minimum": 0,
"type": "number"
},
"dedup_compare_columns": {
"items": {
"type": "string"
},
"type": "array"
},
"dedup_ignore_case": {
"type": "boolean"
},
"header_scan_depth": {
"maximum": 50,
"minimum": 2,
"type": "integer"
},
"identity_uniqueness_threshold": {
"maximum": 1,
"minimum": 0,
"type": "number"
},
"impute_fixed_value": {
"type": "number"
},
"impute_strategy": {
"enum": [
"mean",
"median",
"mode",
"fixed"
],
"type": "string"
},
"na_canonical": {
"type": "string"
},
"numeric_ratio_threshold": {
"maximum": 1,
"minimum": 0,
"type": "number"
},
"trailing_threshold": {
"maximum": 100,
"minimum": 1,
"type": "integer"
}
},
"type": "object"
},
"overrides": {
"items": {
"additionalProperties": false,
"properties": {
"action": {
"enum": [
"skip",
"flag_only",
"force",
"accept"
],
"type": "string"
},
"detector": {
"type": "string"
},
"params": {
"type": "object"
},
"scope": {
"additionalProperties": false,
"properties": {
"column_letter": {
"type": "string"
},
"region": {
"additionalProperties": false,
"properties": {
"bottom_right": {
"type": "string"
},
"top_left": {
"type": "string"
}
},
"required": [
"bottom_right",
"top_left"
],
"type": "object"
},
"sheet": {
"type": "string"
}
},
"required": [
"sheet"
],
"type": "object"
}
},
"required": [
"action",
"detector",
"scope"
],
"type": "object"
},
"type": "array"
},
"reject_findings": {
"items": {
"type": "string"
},
"type": "array"
},
"sheets": {
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_data_validationsPOST /api/v1/tools/xlsx_data_validations — List every cell-level data validation rule (dropdowns, numeric/date bounds, text-length caps, custom formulas) Excel enforces on entry.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_describePOST /api/v1/tools/xlsx_describe — Pandas-style summary statistics per column: count, nulls, unique, min/max/mean/std for numerics.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalheader_row integer optional max_rows integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"header_row": {
"minimum": 0,
"type": "integer"
},
"max_rows": {
"maximum": 100000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_diffPOST /api/v1/tools/xlsx_diff — Compute a deterministic semantic diff between two workbooks — cell-level deltas, formula changes, added/removed rows.
Auth: Authorization: Bearer <api_key> (required)
file_a_b64 string requiredfile_b_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_a_b64": {
"type": "string"
},
"file_b_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_a_b64",
"file_b_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_doctorPOST /api/v1/tools/xlsx_doctor — One-call workbook health report: macros, external refs, hidden sheets, missing metadata, oversized images, ranked HIGH/MEDIUM/LOW findings.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_evalPOST /api/v1/tools/xlsx_eval — Evaluate Excel formulas against a workbook via a formula engine — pass ad-hoc formulas or re-evaluate specific cell refs, never trusting a stale cached value.
Auth: Authorization: Bearer <api_key> (required)
cells array optional file_b64 string requiredformulas array optional options object optionalsheet string optional{
"properties": {
"cells": {
"items": {
"maxLength": 64,
"minLength": 1,
"type": "string"
},
"maxItems": 100,
"type": "array"
},
"file_b64": {
"type": "string"
},
"formulas": {
"items": {
"maxLength": 4096,
"minLength": 1,
"type": "string"
},
"maxItems": 100,
"type": "array"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_external_linksPOST /api/v1/tools/xlsx_external_links — List every external workbook reference this file depends on, classified (http / network share / absolute / relative) with cached-value counts.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_filterPOST /api/v1/tools/xlsx_filter — Row filter with AND-combined predicates (eq/ne/gt/gte/lt/lte/contains/in/is_null/not_null) on real, formula-evaluated cell values.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalheader_row integer optional limit integer optional sheet string optionalpredicates array required column string requiredop string required value any optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"header_row": {
"minimum": 0,
"type": "integer"
},
"limit": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
},
"predicates": {
"items": {
"properties": {
"column": {
"type": "string"
},
"op": {
"enum": [
"eq",
"ne",
"gt",
"gte",
"lt",
"lte",
"contains",
"not_contains",
"in",
"not_in",
"is_null",
"not_null"
],
"type": "string"
},
"value": {}
},
"required": [
"column",
"op"
],
"type": "object"
},
"maxItems": 16,
"minItems": 1,
"type": "array"
}
},
"required": [
"file_b64",
"predicates"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_form_controlsPOST /api/v1/tools/xlsx_form_controls — List every form control (checkbox, button, dropdown, list box, option button, scroll bar, spinner, …) with its linked cell and current value.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_formulasPOST /api/v1/tools/xlsx_formulas — Extract every formula in a workbook — cell coordinate, formula text, cached result — for auditing or bulk transformation.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalinclude_results boolean optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"include_results": {
"type": "boolean"
},
"limit": {
"maximum": 5000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_healer_curePOST /api/v1/tools/xlsx_healer_cure — Apply one specific repair to a diagnosed workbook. For broken external references: rewrite ref paths, freeze / redirect / localize a deleted source, strip embedded credentials, or collapse multi-hop chains. For Google-Sheets-to-Excel export damage: flag each dead Sheets-only formula with an in-cell note so the loss is visible (it does NOT recompute the function — a Sheets-only function has no Excel equivalent to compute), trim an oversized used-range, and compact repeated formulas into Excel shared-formula form.
Auth: Authorization: Bearer <api_key> (required)
cure_params object optionalfile_b64 string requiredintent string optionalmode string optional operation string required{
"additionalProperties": false,
"properties": {
"cure_params": {
"type": "object"
},
"file_b64": {
"type": "string"
},
"intent": {
"type": "string"
},
"mode": {
"enum": [
"as_copy",
"in_place"
],
"type": "string"
},
"operation": {
"type": "string"
}
},
"required": [
"file_b64",
"operation"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_healer_diagnosePOST /api/v1/tools/xlsx_healer_diagnose — Produce a structured report of repairable damage in a workbook, keyed to the cure operations. Two families: (1) broken or at-risk external references — moved, deleted, or permission-denied sources and #REF! chains; (2) Google-Sheets-to-Excel export damage — Sheets-only functions such as QUERY, ARRAYFORMULA, IMPORTRANGE, or GOOGLEFINANCE that Excel cannot evaluate and that arrive as dead formula text or a #NAME? error (surfaced as an unverified value to double-check), an oversized used-range, and repeated formulas left un-compacted. Every finding is reported, not altered in place.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"additionalProperties": false,
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_healer_intentPOST /api/v1/tools/xlsx_healer_intent — Goal-driven healing: declare an intent (make-it-work / make-standalone / migrate) and let the healer plan + apply the operation sequence.
Auth: Authorization: Bearer <api_key> (required)
confirm boolean optionalfile_b64 string requiredintent string requiredintent_params object optional from string optionalto string optionalmode string optional operation string optional{
"additionalProperties": false,
"properties": {
"confirm": {
"type": "boolean"
},
"file_b64": {
"type": "string"
},
"intent": {
"type": "string"
},
"intent_params": {
"additionalProperties": false,
"properties": {
"from": {
"type": "string"
},
"to": {
"type": "string"
}
},
"type": "object"
},
"mode": {
"enum": [
"as_copy",
"in_place"
],
"type": "string"
},
"operation": {
"type": "string"
}
},
"required": [
"file_b64",
"intent"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_healer_simulatePOST /api/v1/tools/xlsx_healer_simulate — Simulate recipient-side accessibility of a workbook's external references — read-only, no output workbook.
Auth: Authorization: Bearer <api_key> (required)
accessible_paths array required file_b64 string required{
"additionalProperties": false,
"properties": {
"accessible_paths": {
"items": {
"type": "string"
},
"maxItems": 1000,
"type": "array"
},
"file_b64": {
"type": "string"
}
},
"required": [
"accessible_paths",
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_hyperlinksPOST /api/v1/tools/xlsx_hyperlinks — List every hyperlink with its anchor cell, target, display text, tooltip, and a kind classifier (external / internal / mailto).
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 5000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_imagesPOST /api/v1/tools/xlsx_images — List every embedded image with format, size, sheet attribution, and the cell range it floats over.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_list_sheetsPOST /api/v1/tools/xlsx_list_sheets — List every sheet in a spreadsheet with its name, dimensions, and visibility.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_macrosPOST /api/v1/tools/xlsx_macros — Inspect an xlsm/xlsb workbook for VBA macro presence, module size, and likely module names, with a short safety note.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_merged_cellsPOST /api/v1/tools/xlsx_merged_cells — List every merged-cell region with its master value, range, and a layout-kind heuristic (header / horizontal / vertical / block).
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"limit": {
"maximum": 5000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_named_rangesPOST /api/v1/tools/xlsx_named_ranges — List every defined name (named range) in a workbook — name, scope, kind, and reference.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_pii_cleanPOST /api/v1/tools/xlsx_pii_clean — Redact personal or sensitive data from a spreadsheet.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required mode string optional selection object optional all boolean optionalfinding_ids array optional type_keys array optional simulate boolean optional{
"additionalProperties": false,
"properties": {
"file_b64": {
"maxLength": 279685803,
"type": "string"
},
"mode": {
"enum": [
"as_copy",
"in_place"
],
"type": "string"
},
"selection": {
"additionalProperties": false,
"properties": {
"all": {
"type": "boolean"
},
"finding_ids": {
"items": {
"pattern": "^[0-9a-f]{64}$",
"type": "string"
},
"maxItems": 10000,
"type": "array"
},
"type_keys": {
"items": {
"maxLength": 64,
"type": "string"
},
"maxItems": 64,
"type": "array"
}
},
"type": "object"
},
"simulate": {
"type": "boolean"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_pii_scanPOST /api/v1/tools/xlsx_pii_scan — Scan a spreadsheet for personal or sensitive data.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required {
"additionalProperties": false,
"properties": {
"file_b64": {
"maxLength": 279685803,
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_pivotPOST /api/v1/tools/xlsx_pivot — Pivot-table reshape — reshape a flat table into a 2D matrix of index × columns with an aggregated value per cell.
Auth: Authorization: Bearer <api_key> (required)
agg string optional columns array optional file_b64 string requiredindex array required options object optionalfill_value any optionalheader_row integer optional sheet string optionalvalues array required {
"properties": {
"agg": {
"enum": [
"sum",
"mean",
"min",
"max",
"count",
"count_distinct"
],
"type": "string"
},
"columns": {
"items": {
"type": "string"
},
"maxItems": 4,
"type": "array"
},
"file_b64": {
"type": "string"
},
"index": {
"items": {
"type": "string"
},
"maxItems": 4,
"minItems": 1,
"type": "array"
},
"options": {
"properties": {
"fill_value": {},
"header_row": {
"minimum": 0,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
},
"values": {
"items": {
"type": "string"
},
"maxItems": 8,
"minItems": 1,
"type": "array"
}
},
"required": [
"file_b64",
"index",
"values"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_pivot_tablesPOST /api/v1/tools/xlsx_pivot_tables — List every pre-existing pivot table an Excel user already built — source range, row/column/page fields, and each data field's aggregation.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_post_slackPOST /api/v1/tools/xlsx_post_slack — Post a spreadsheet to a Slack channel as a file attachment, with an optional accompanying message.
Auth: Authorization: Bearer <api_key> (required)
channel string required file_b64 string optionalfilename string optional message string optional slack_token string required workbook_handle string optional {
"properties": {
"channel": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"file_b64": {
"type": "string"
},
"filename": {
"maxLength": 128,
"type": "string"
},
"message": {
"maxLength": 4000,
"type": "string"
},
"slack_token": {
"maxLength": 256,
"minLength": 10,
"type": "string"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"channel",
"slack_token"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_post_teamsPOST /api/v1/tools/xlsx_post_teams — Post a spreadsheet to a Microsoft Teams channel as a file attachment, with an optional accompanying message.
Auth: Authorization: Bearer <api_key> (required)
channel_id string required file_b64 string optionalfilename string optional graph_token string required message string optional team_id string required workbook_handle string optional {
"properties": {
"channel_id": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"file_b64": {
"type": "string"
},
"filename": {
"maxLength": 128,
"type": "string"
},
"graph_token": {
"maxLength": 8192,
"minLength": 100,
"type": "string"
},
"message": {
"maxLength": 4000,
"type": "string"
},
"team_id": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"channel_id",
"graph_token",
"team_id"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_print_settingsPOST /api/v1/tools/xlsx_print_settings — Surface exactly what Excel would print for each sheet — print area, orientation, paper size, margins, headers/footers, page breaks.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_propertiesPOST /api/v1/tools/xlsx_properties — Surface a workbook's identity card — creator, timestamps, title/subject/company, and every custom Info > Properties entry.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_protectionPOST /api/v1/tools/xlsx_protection — Surface every protection setting — workbook lock, per-sheet protection, per-action allow/block list, and which cells stay editable.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_readPOST /api/v1/tools/xlsx_read — Read a spreadsheet as text (markdown, JSON, or SQL) — from an uploaded .xlsx/.xls/.csv file, or from a live Google Sheet read by ID; for a Google Sheet pass source:"gsheets", spreadsheet_id, and a readonly access_token (connects directly, no upload).
Auth: Authorization: Bearer <api_key> (required)
access_token string optionalevaluate boolean optionalfile_b64 string optionaloptions object optionalformat string optionalmaxRows integer optional sheet string optionalsource string optional spreadsheet_id string optional{
"properties": {
"access_token": {
"type": "string"
},
"evaluate": {
"type": "boolean"
},
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"format": {
"type": "string"
},
"maxRows": {
"maximum": 100000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
},
"source": {
"enum": [
"gsheets"
],
"type": "string"
},
"spreadsheet_id": {
"type": "string"
}
},
"required": [],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_read_handlePOST /api/v1/tools/xlsx_read_handle — [Stateful · session/handle-based] Read a workbook already uploaded via the chunked cache flow, by its server-side handle — skips re-sending the bytes.
Auth: Authorization: Bearer <api_key> (required)
options object optionalformat string optional sheet string optionalworkbook_handle string required {
"properties": {
"options": {
"properties": {
"format": {
"enum": [
"md",
"json"
],
"type": "string"
},
"sheet": {
"type": "string"
}
},
"type": "object"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"pattern": "^[^\\u0000-\\u001f\\u007f\\s:*?\\[\\]]+$",
"type": "string"
}
},
"required": [
"workbook_handle"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_receiptPOST /api/v1/tools/xlsx_receipt — Attach a cryptographic AI-generation receipt to a workbook — who/what/when generated it, against which inputs.
Auth: Authorization: Bearer <api_key> (required)
agent object requireddisplay_name string optional identity_url string optional name string required covers_sheets array optional description string optional file_b64 string optionalinputs object optionalcustom object optionalmcp_tools_called array optional prompt_hash string optional source_file_hashes array optional {
"properties": {
"name": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"sha256": {
"pattern": "^[a-f0-9]{64}$",
"type": "string"
}
},
"required": [
"name",
"sha256"
],
"type": "object"
}workbook_handle string optional {
"properties": {
"agent": {
"properties": {
"display_name": {
"maxLength": 256,
"type": "string"
},
"identity_url": {
"maxLength": 512,
"type": "string"
},
"name": {
"maxLength": 128,
"minLength": 1,
"pattern": "^[a-z0-9][a-z0-9\\-_/.:]{0,127}$",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"covers_sheets": {
"items": {
"maxLength": 128,
"type": "string"
},
"maxItems": 100,
"type": "array"
},
"description": {
"maxLength": 256,
"type": "string"
},
"file_b64": {
"type": "string"
},
"inputs": {
"properties": {
"custom": {
"type": "object"
},
"mcp_tools_called": {
"items": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"maxItems": 100,
"type": "array"
},
"prompt_hash": {
"pattern": "^[a-f0-9]{64}$",
"type": "string"
},
"source_file_hashes": {
"items": {
"properties": {
"name": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"sha256": {
"pattern": "^[a-f0-9]{64}$",
"type": "string"
}
},
"required": [
"name",
"sha256"
],
"type": "object"
},
"maxItems": 200,
"type": "array"
}
},
"type": "object"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"agent"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_redactPOST /api/v1/tools/xlsx_redact — Redact PII and sensitive values from a spreadsheet before sharing or archiving, preserving formulas/comments/styles by default.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalmode string optional strip_comments boolean optionalstrip_formulas boolean optionalstrip_macros boolean optionalstrip_metadata boolean optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"mode": {
"enum": [
"pii",
"scaffold",
"none"
],
"type": "string"
},
"strip_comments": {
"type": "boolean"
},
"strip_formulas": {
"type": "boolean"
},
"strip_macros": {
"type": "boolean"
},
"strip_metadata": {
"type": "boolean"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_schemaPOST /api/v1/tools/xlsx_schema — Infer per-column types from the first rows of a sheet, with sample values and confidence.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalrange string optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"range": {
"type": "string"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_session_set_validationsPOST /api/v1/tools/xlsx_session_set_validations — [Stateful · session/handle-based] Configure per-session data-validation rules the server applies to subsequent calls in the same session.
Auth: Authorization: Bearer <api_key> (required)
session_id string required validations array required ref string requiredsheet string requiredtype string required{
"properties": {
"session_id": {
"maxLength": 128,
"minLength": 16,
"type": "string"
},
"validations": {
"items": {
"additionalProperties": true,
"properties": {
"ref": {
"type": "string"
},
"sheet": {
"type": "string"
},
"type": {
"type": "string"
}
},
"required": [
"ref",
"sheet",
"type"
],
"type": "object"
},
"maxItems": 5000,
"minItems": 1,
"type": "array"
}
},
"required": [
"session_id",
"validations"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_slicers_timelinesPOST /api/v1/tools/xlsx_slicers_timelines — List every slicer and timeline (interactive filter controls) in a workbook with their source bindings.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_sortPOST /api/v1/tools/xlsx_sort — Multi-column sort with per-column direction — stable, type-aware, nulls last.
Auth: Authorization: Bearer <api_key> (required)
by array required column string requireddirection string optional file_b64 string requiredoptions object optionalheader_row integer optional limit integer optional sheet string optional{
"properties": {
"by": {
"items": {
"properties": {
"column": {
"type": "string"
},
"direction": {
"enum": [
"asc",
"desc"
],
"type": "string"
}
},
"required": [
"column"
],
"type": "object"
},
"maxItems": 8,
"minItems": 1,
"type": "array"
},
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"header_row": {
"minimum": 0,
"type": "integer"
},
"limit": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"by",
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_stampPOST /api/v1/tools/xlsx_stamp — Sign a workbook with a cryptographic integrity-verification stamp — which checks it passed, when, tamper-evident.
Auth: Authorization: Bearer <api_key> (required)
checks array required detail string optional id string required name string required status string required exclude_sheets array optional file_b64 string optionalgenerated_by object optionalnpm string optional supervisor string optional workbook_handle string optional {
"properties": {
"checks": {
"items": {
"properties": {
"detail": {
"maxLength": 1024,
"type": "string"
},
"id": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"name": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"status": {
"enum": [
"passed",
"failed",
"skipped"
],
"type": "string"
}
},
"required": [
"id",
"name",
"status"
],
"type": "object"
},
"maxItems": 200,
"minItems": 0,
"type": "array"
},
"exclude_sheets": {
"items": {
"maxLength": 128,
"type": "string"
},
"maxItems": 100,
"type": "array"
},
"file_b64": {
"type": "string"
},
"generated_by": {
"properties": {
"npm": {
"maxLength": 128,
"type": "string"
},
"supervisor": {
"maxLength": 128,
"type": "string"
}
},
"type": "object"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"checks"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_stylesPOST /api/v1/tools/xlsx_styles — Surface cell formatting (number formats, fonts, fills, alignment) — what a cell LOOKS like, not just its raw value.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionaldetailed boolean optionallimit integer optional sheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"detailed": {
"type": "boolean"
},
"limit": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_tablesPOST /api/v1/tools/xlsx_tables — List every Excel ListObject ("Format as Table") in a workbook — name, sheet, range, header/totals flags, columns.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalinclude_columns boolean optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"include_columns": {
"type": "boolean"
},
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_topologyPOST /api/v1/tools/xlsx_topology — One-call workbook orientation — sheets, formulas, named ranges, tables, validations, hyperlinks, merges, and feature flags in one shot.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_validatePOST /api/v1/tools/xlsx_validate — Cross-engine consistency check — parse the same workbook with two independent renderers and report cell-level divergences.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required{
"properties": {
"file_b64": {
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_value_countsPOST /api/v1/tools/xlsx_value_counts — Per-column value counts — each unique value, sorted by frequency, with percentage.
Auth: Authorization: Bearer <api_key> (required)
column string requiredfile_b64 string requiredoptions object optionalheader_row integer optional include_nulls boolean optionalsheet string optionaltop_n integer optional {
"properties": {
"column": {
"type": "string"
},
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"header_row": {
"minimum": 0,
"type": "integer"
},
"include_nulls": {
"type": "boolean"
},
"sheet": {
"type": "string"
},
"top_n": {
"maximum": 1000,
"minimum": 1,
"type": "integer"
}
},
"type": "object"
}
},
"required": [
"column",
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_vault_curePOST /api/v1/tools/xlsx_vault_cure — Clean hidden or risky content out of a spreadsheet.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required mode string optional selection object optional finding_actions object optional finding_ids array optional risk_tiers array optional simulate boolean optional{
"additionalProperties": false,
"properties": {
"file_b64": {
"maxLength": 279685803,
"type": "string"
},
"mode": {
"enum": [
"as_copy",
"in_place"
],
"type": "string"
},
"selection": {
"additionalProperties": false,
"properties": {
"finding_actions": {
"additionalProperties": {
"properties": {
"sub_action": {
"type": "string"
}
},
"required": [
"sub_action"
],
"type": "object"
},
"type": "object"
},
"finding_ids": {
"items": {
"type": "string"
},
"type": "array"
},
"risk_tiers": {
"items": {
"enum": [
"high",
"medium",
"low"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"simulate": {
"type": "boolean"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_vault_scanPOST /api/v1/tools/xlsx_vault_scan — Scan a spreadsheet for hidden or risky content (macros, external links, embedded objects).
Auth: Authorization: Bearer <api_key> (required)
file_b64 string required {
"additionalProperties": false,
"properties": {
"file_b64": {
"maxLength": 279685803,
"type": "string"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_verify_receiptPOST /api/v1/tools/xlsx_verify_receipt — Verify a workbook's embedded AI-generation receipt — signature validity, content-hash match, and the full declared claims.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string optionalworkbook_handle string optional {
"properties": {
"file_b64": {
"type": "string"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_verify_stampPOST /api/v1/tools/xlsx_verify_stamp — Verify a workbook's embedded integrity stamp — signature validity, content-hash match, and the recorded check results.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string optionalworkbook_handle string optional {
"properties": {
"file_b64": {
"type": "string"
},
"workbook_handle": {
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_workbook_viewsPOST /api/v1/tools/xlsx_workbook_views — Surface the UI state of a workbook — per-sheet visibility/zoom/frozen-panes/tab color, and which sheet is active on open.
Auth: Authorization: Bearer <api_key> (required)
file_b64 string requiredoptions object optionalsheet string optional{
"properties": {
"file_b64": {
"type": "string"
},
"options": {
"properties": {
"sheet": {
"type": "string"
}
},
"type": "object"
}
},
"required": [
"file_b64"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.xlsx_writePOST /api/v1/tools/xlsx_write — Create or update a spreadsheet from a structured spec ({sheets: [{name, cells: [{address, value | formula}]}]}) — server-validated before writing.
Auth: Authorization: Bearer <api_key> (required)
base_file_b64 string optionalcache_handle string optional spec object required{
"properties": {
"base_file_b64": {
"type": "string"
},
"cache_handle": {
"maxLength": 128,
"minLength": 1,
"pattern": "^[^\\u0000-\\u001f\\u007f\\s:*?\\[\\]]+$",
"type": "string"
},
"spec": {
"type": "object"
}
},
"required": [
"spec"
],
"type": "object"
}200 — Tool result (base64-in / base64-out; stateless).400 — Bad request. `error.code` is one of: `bad_request` (malformed or oversized JSON body, invalid base64, or a missing/invalid field), `hardening_rejected` (the upload failed an ingest safety guard — e.g. an encrypted workbook, a non-OOXML zip, a truncated file, or a legacy .xls on a route that does not accept it), `unparseable_input` (no readable CSV header row), or `malformed_csv` (a structurally broken CSV — an unclosed or mid-field quote). A sheet- or column-not-found request also carries `available_sheets` / `available_columns`.401 — Missing or invalid API key. `error.code`: `unauthorized`.402 — Payment required. `error.code`: `tier_upgrade_required`. A forward-compatible response for a capability gated to a paid subscription; it is driven by the account/consent surface (POST /api/v1/consent), not by the stateless tool inputs. No action is needed for standard tool calls on the free tier.413 — Payload too large. `error.code`: `file_too_large` (the input exceeds the per-format upload ceiling, or expands past the content-processing ceiling once parsed) or `write_output_too_large` (the requested output would exceed the format write cap). These are capacity ceilings — identical for every caller, never a paywall lever.429 — Free-tier file allowance reached for the current period. `error.code`: `rate_limit_exceeded`.500 — Internal server error — an unexpected fault on our side. `error.code`: `internal_error`.503 — Service temporarily unavailable — retryable; a `Retry-After` header is sent when known. `error.code` is one of: `service_unavailable` (a backing service is down, or parse capacity is momentarily saturated), `rate_limit_backend_unavailable`, or `cache_backend_unavailable`.