Refresh agent snapshot
Re-probe the agent and update its registry health (online, tools_count, response_time_ms), capability snapshot (inferred type, discovered tools), and compliance verdict (storyboard pass/fail counts). Use after fixing your agent so the registry shows fresh data without waiting for the periodic heartbeat (~1h).
Compliance re-run: when the caller owns the agent or is an AAO admin and the capability probe succeeds, the full storyboard suite can run for several minutes on capability-rich agents with a fresh test session, and agent_storyboard_status is updated. Owner-triggered runs use triggered_by: 'owner_test'; admin-triggered support runs use triggered_by: 'manual'. Badge fan-out reissues verification badges off the new run. If the compliance call fails (timeout, OAuth wall, internal error), the capability/health portion still returns successfully — compliance.ran is false with an error string.
Auth: owner of the agent, AAO admin, or static ADMIN_API_KEY.
Rate limits: 60 seconds per agent URL, 30 requests per user per hour.
Authorizations
Bearer token in the Authorization header. Two token types are accepted:
- Organization API key (
sk_...) issued via the dashboard. Org-scoped, long-lived, for server-to-server use. - User JWT obtained via the OAuth 2.1 authorization code flow with PKCE. User-scoped, short-lived. Discover the authorization server at
/.well-known/oauth-authorization-serverand the protected-resource metadata at/.well-known/oauth-protected-resource/api.
Path Parameters
URL-encoded agent URL
"https%3A%2F%2Fvastlint.org%2Fmcp"
Response
Snapshot refreshed
Type inferred from discovered tools (sales, creative, signals, governance, etc.) or 'unknown'
True when registry type was upgraded from unknown to inferred_type
Compliance re-run summary. The capability/health portion of the response is independent of this block — a failed compliance run still returns the rest of the snapshot.