# Kiteworks MCP Available Tools — Complete Tool Reference

> Complete reference for all 51 tools the Kiteworks MCP Server exposes to AI assistants — file, folder, member, search, mail, form, user, and administration operations.

Kiteworks MCP

# Available Kiteworks MCP Tools

The Kiteworks MCP Server exposes **51 tools** to connected AI assistants, grouped into 9 families. This is the complete list. Every tool runs under the signed-in user’s own Kiteworks permissions and is written to the same tamper-evident audit trail, so an agent can never reach data the person driving it could not reach themselves.

[Join the Innovators in AI program — Full MCP access included for all members

Unlimited agent workflows, policy controls, and audit telemetry at no additional cost for the first 6 months. Kiteworks admins can activate it through the admin console.

Learn more](mcp-innovators-ai.html)

| I want to… | Tool family |
|---|---|
| Read or write file data | [File Operations](#file-operations) |
| Browse, create, or reorganize folders | [Folder Operations](#folder-operations) |
| See or change who can access a file or folder | [Folder & File Members](#members) |
| Find something by name or by file content | [Search Operations](#search-operations) |
| Read the mailbox, or send secure mail | [Mail](#mail) |
| Build a Kiteworks Form | [Forms](#forms) |
| Look up a user, or check who I am signed in as | [User Operations](#user-operations) |
| Check risk policy before moving data | [Risk Policies](#risk-policies) |
| Manage users, mailboxes, profiles, or audit logs | [Administration](#administration) |

> **Deployment mode affects availability.** Only the two path-based file tools — `download_file_to_path` and `upload_file_from_path` — are restricted to Local STDIO mode, because they read and write your local filesystem. Every other tool on this page works in all modes. See [Installation & Setup](mcp-installation-setup.html) for the differences between modes.

> **These tools ask before they act.** `delete_file`, `delete_folder`, `delete_mailbox`, `send_email`, and every `manage_members` action require explicit confirmation before they run. `delete_mailbox` cannot be undone.

## File Operations

Reading and writing file data. The split that matters here is **path-based** versus **content-based**: path-based tools touch your local disk and therefore need Local STDIO mode, while content-based tools move data through the conversation and work everywhere.

### Path-Based — STDIO Mode Only

| Tool | What it does |
|---|---|
| `download_file_to_path` | Download a file from Kiteworks to the local filesystem by file ID. |
| `upload_file_from_path` | Upload a file from the local filesystem to a Kiteworks folder. |

### Content-Based — All Modes

| Tool | What it does |
|---|---|
| `read_file_contents` | Read text file contents into conversation context as UTF-8. Not for local download. |
| `create_file_from_content` | Create a file in Kiteworks from content in conversation context. Not for local upload. |

### Metadata — All Modes

| Tool | What it does |
|---|---|
| `get_file_metadata` | Retrieve file metadata by ID. |
| `rename_file` | Rename a file by ID. |
| `move_file` | Move one or more files to a different folder. |
| `copy_file` | Copy one or more files into a folder, leaving the originals in place. |
| `delete_file` | Delete one or more files. Requires confirmation. |

## Folder Operations

Browsing, creating, and reorganizing the folder tree, plus requesting files from people outside it.

| Tool | What it does |
|---|---|
| `get_top_folders` | Fetch top-level folders with optional filtering. |
| `get_folder_children` | Fetch folder contents by parent ID with filtering. |
| `create_folder` | Create a new folder with specified options. |
| `rename_folder` | Rename a folder by ID. |
| `move_folder` | Move a folder to a different parent folder. |
| `delete_folder` | Delete one or more folders and their contents. Requires confirmation. |
| `request_file_to_folder` | Request files from recipients into a Kiteworks folder via an email invitation with an upload link. |

## Folder & File Members

Reading and changing who has access to a folder or file, and with what role.

| Tool | What it does |
|---|---|
| `list_members` | List the members of a Kiteworks folder or file, including their role and how access was granted. Set `target_type` to `folder` or `file`. |
| `manage_members` | Add, update, or remove members of a folder or file, chosen by `action`. Folders take exactly one target ID; `add` on files supports sharing multiple files with the same members in one call. Every action requires confirmation. Omitting the member on `remove` (files only) removes every member at once. |

## Search Operations

Locating folders and files. Only `search_files` can match on file content as well as name.

| Tool | What it does |
|---|---|
| `search` | Search folders and/or files by name. |
| `search_folders` | Search folders only by name. |
| `search_files` | Search files only by name or content. |

## Mail

Reading the mailbox and sending secure Kiteworks messages. Sending is deliberately a two-step flow — `compose_email` drafts and validates, `send_email` sends exactly what was validated.

| Tool | What it does |
|---|---|
| `list_mail` | List Kiteworks mail messages with optional filters (bucket, status, read state, sender, shared mailbox) and pagination. |
| `get_mail` | Retrieve a single mail message by ID, including subject, body, status, AV/DLP scan status, recipients, and attachments. |
| `get_mail_counters` | Retrieve mailbox counters — draft, inbox, inbox unread, outgoing and its sub-counts, and trash. |
| `compose_email` | Compose, edit, and check a secure Kiteworks message. Writes it to a server-side draft and validates it against Kiteworks policy and, for `acl=otp`, whether recipients have a phone number on file. Returns a `validationId` to reuse on later calls and on `send_email`. Calling this and stopping is how a message is saved without sending; each call without a `validationId` leaves another draft behind. |
| `send_email` | Send a message `compose_email` has already drafted. Takes only that `validationId` (plus an optional `id` cross-check) — no message content, so it sends the draft exactly as validated. Requires confirmation. |

## Forms

Generating Kiteworks Forms.

| Tool | What it does |
|---|---|
| `create_form` | Generate Kiteworks Forms from templates with preview links. |
| `get_create_form_schema` | Retrieve the JSON schema for form creation. |

## User Operations

Identity lookups available to any signed-in user — no administrator role required.

| Tool | What it does |
|---|---|
| `get_user_info_whoami` | Get current Kiteworks user information. |
| `find_user_by_email` | Find a Kiteworks user by their exact email address, returning display name and UUID. |
| `search_users_ldap` | Search the configured LDAP/Active Directory by email or display name. |

## Risk Policies

Read-only visibility into the policies that govern data movement. Useful as a pre-flight check before an agent moves anything.

| Tool | What it does |
|---|---|
| `get_risk_policies` | Retrieve all Kiteworks risk policies. Read-only. |

## Administration

Administrator-only tools, reached through the Kiteworks admin API. These require an administrative role on the signed-in account — a standard user calling them gets a permission error.

### User Management

| Tool | What it does |
|---|---|
| `search_users` | Search Kiteworks users via the admin API with optional filters and pagination. |
| `get_user_metadata` | Retrieve detailed information about a single user by UUID — profile, quota, features, device installs, sessions, and status. |
| `create_user` | Create a new user. `email` and `sendNotification` are required; name, profile, verified flag, and admin-set password are optional. |
| `update_user` | Update mutable fields on a user — name, password, suspended, verified, deactivated, and active. |
| `reset_user_totp` | Delete TOTP/authenticator secrets for one or more users, forcing re-enrollment. |

### Shared Mailboxes

| Tool | What it does |
|---|---|
| `list_mailboxes` | List shared mailboxes with optional filters and pagination. |
| `create_mailbox` | Convert an existing user into a shared mailbox and assign initial members. |
| `delete_mailbox` | Permanently delete one or more shared mailboxes. Irreversible. |
| `update_mailbox_members` | Replace the full member list of a shared mailbox. |

### Activity Logs

| Tool | What it does |
|---|---|
| `get_user_activity` | Retrieve user activity log entries with date range, text search, activity type filter, and pagination. |
| `get_admin_activity` | Retrieve admin activity log entries via the admin API, with date range, free-text search, event/object filtering, and pagination. |

### User Profiles

| Tool | What it does |
|---|---|
| `list_user_profiles` | List all user profiles — numeric ID and name. |
| `get_profile` | Retrieve a single user profile by numeric ID. |
| `get_profile_eligibility` | Test profile mapping rules against a username or email and see which rules would match. |
| `list_profile_users` | List users assigned to a specific profile with optional filters and pagination. |
| `create_user_profile` | Create a new user profile. |
| `assign_user_profile` | Assign a single user to a profile — promotion or demotion. |
| `bulk_assign_profile` | Assign one or more users to a profile in bulk, with data-retention controls for demotions. |

### Security Tags

| Tool | What it does |
|---|---|
| `create_tag` | Create a new security tag used as a DLP policy condition. |

## Frequently Asked Questions

### How many tools does the Kiteworks MCP Server expose?

The Kiteworks MCP Server exposes 51 tools across 9 families: file operations, folder operations, folder and file members, search, mail, forms, user operations, risk policies, and administration.

### Which Kiteworks MCP tools only work in STDIO mode?

`download_file_to_path` and `upload_file_from_path` are the only path-based tools, and they require Local STDIO mode because they read and write the local filesystem. `read_file_contents` and `create_file_from_content` do equivalent work through conversation context and are available in every deployment mode.

### Which Kiteworks MCP tools require confirmation before they run?

`delete_file`, `delete_folder`, `delete_mailbox`, `send_email`, and every `manage_members` action require explicit confirmation before they execute. `delete_mailbox` is irreversible.

### Can I control which tools an AI agent is allowed to call?

Yes. Every tool runs under the signed-in user’s own Kiteworks permissions, so an agent can never exceed what that user can do. In Claude Desktop you can additionally set each tool to Always allow, Needs approval, or Blocked in the connector settings.

### Can an agent read PDF or Office files directly?

No. `read_file_contents` returns UTF-8 text only. PDF, Word, Excel, and PowerPoint files must be downloaded with `download_file_to_path` first and then parsed locally, which means those formats require STDIO mode.

## Next Steps

Ready to put these tools to work?

- [Installation & Setup →](mcp-installation-setup.html) Connect the MCP Server in the deployment mode you need
- [Configure Tool Permissions →](configure-mcp-connector-claude.html#permissions) Set each tool to Always allow, Needs approval, or Blocked in Claude Desktop
- [MCP Tool Taxonomy →](mcp-overview.html#tool-taxonomy) How these tools map onto data, control, and audit planes for policy decisions
- [Agent Marketplace →](mcp-agent-marketplace.html) Ready-to-use governed agents built on these tools
