> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create mass-action

> Commit a previewed plan into a running bulk dispatch. Requires the commit_token from preview_mass_action over EXACTLY these inputs: the server re-derives the HMAC, so an edited plan, a changed scope or a different caller is 422 invalid_commit_token, and a token older than 15 minutes is 422 commit_token_expired. Re-preview in either case.

Re-runs the full preview validation, then inserts the run plus its items and starts dispatching in one transaction. Always asynchronous, even for one item: the returned sid IS the monitoring handle. Poll get_mass_action with include=metrics or get_mass_actions_metrics, or subscribe to the mass-actions.settled / .paused webhooks.

With canary_mode=first_item only item 1 runs until it succeeds; a canary failure pauses the run with paused_reason=canary_failed. A none-scope run is created empty (total_count 0) and dispatches nothing until an auto-scrape appends leads into it. Replaying a still-valid token creates a SECOND identical run, so discard the token after use.

Contract:
- MCP tool `create_mass_action`, registry package `mcp.orchestration/mass_actions`, mount `orchestration.mass_actions`.
- Operation `create`, response envelope `create`.
- Flags: none.



## OpenAPI

````yaml /api-reference/orchestration/openapi.yaml post /api/mass-actions
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.orchestration'
  description: >-
    The cross-service execution plane: the platform-wide webhook registry and
    delivery log, plus mass actions (preview, commit, pace, pause, resume,
    canary) and their per-item child rows.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.orchestration`, 21
    operations. Internal (`/internal`) and health endpoints are deliberately
    absent; the code-faithful spec that documents those lives in
    `product/openapi/gtm.openapi.tech`.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/orchestration/v4
    description: Production, through the app.gtm-api.com gateway
  - url: http://localhost:8025
    description: Local Docker (gtm_orchestration_nginx_dev)
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: mass_action_items
    description: >-
      Registry package `mcp.orchestration/mass_action_items`, served on MCP
      mount `orchestration.mass_actions`.
  - name: mass_actions
    description: >-
      Registry package `mcp.orchestration/mass_actions`, served on MCP mount
      `orchestration.mass_actions`.
  - name: webhook_logs
    description: >-
      Registry package `mcp.orchestration/webhook_logs`, served on MCP mount
      `orchestration.webhooks`.
  - name: webhooks
    description: >-
      Registry package `mcp.orchestration/webhooks`, served on MCP mount
      `orchestration.webhooks`.
paths:
  /api/mass-actions:
    post:
      tags:
        - mass_actions
      summary: Create mass-action
      description: >-
        Commit a previewed plan into a running bulk dispatch. Requires the
        commit_token from preview_mass_action over EXACTLY these inputs: the
        server re-derives the HMAC, so an edited plan, a changed scope or a
        different caller is 422 invalid_commit_token, and a token older than 15
        minutes is 422 commit_token_expired. Re-preview in either case.


        Re-runs the full preview validation, then inserts the run plus its items
        and starts dispatching in one transaction. Always asynchronous, even for
        one item: the returned sid IS the monitoring handle. Poll
        get_mass_action with include=metrics or get_mass_actions_metrics, or
        subscribe to the mass-actions.settled / .paused webhooks.


        With canary_mode=first_item only item 1 runs until it succeeds; a canary
        failure pauses the run with paused_reason=canary_failed. A none-scope
        run is created empty (total_count 0) and dispatches nothing until an
        auto-scrape appends leads into it. Replaying a still-valid token creates
        a SECOND identical run, so discard the token after use.


        Contract:

        - MCP tool `create_mass_action`, registry package
        `mcp.orchestration/mass_actions`, mount `orchestration.mass_actions`.

        - Operation `create`, response envelope `create`.

        - Flags: none.
      operationId: create_mass_action
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateMassActionRequest'
      responses:
        '200':
          description: '`create` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateMassActionResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    CreateMassActionRequest:
      type: object
      description: Request body of `create_mass_action`.
      properties:
        title:
          type: string
          nullable: true
          maxLength: 255
        target_entity:
          type: string
          maxLength: 128
        scope:
          anyOf:
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - objects
                object_sids:
                  type: array
                  items:
                    type: string
                    minLength: 18
                    maxLength: 18
                  minItems: 1
                  maxItems: 100
                  description: Existing rows of the target_entity family, 1..100.
              required:
                - kind
                - object_sids
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - targets
                targets:
                  type: array
                  items:
                    type: object
                    additionalProperties: {}
                  minItems: 1
                  maxItems: 100
                  description: >-
                    1..100 payload-kind identities (send-class); per-item
                    params, shape owned by the target entity.
              required:
                - kind
                - targets
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - generate
                count:
                  type: integer
                  minimum: 1
                  maximum: 100
                  description: >-
                    N slot items with no pre-existing object; step 1 must be a
                    creates: verb.
              required:
                - kind
                - count
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - none
              required:
                - kind
              description: >-
                Empty: a STANDING run at 0 items that an auto-scrape appends
                into over time.
        plan:
          type: object
          properties:
            steps:
              type: array
              items:
                type: object
                properties:
                  tool:
                    anyOf:
                      - type: string
                        enum:
                          - >-
                            linkedin-connection-requests.send-linkedin-connection-request
                          - linkedin-posting.react
                          - email-messages.send
                      - type: string
                        enum:
                          - linkedin-connection-requests.send
                    description: >-
                      Dotted verb '{entity-kebab-plural}.{verb}'. Only these are
                      step-eligible today; anything else fails preview with 422
                      not_step_eligible on field plan.steps.{i}.tool.
                      'linkedin-connection-requests.send' is a legacy alias of
                      the send-linkedin-connection-request case, accepted but
                      not the spelling to author.
                  args:
                    type: object
                    additionalProperties: {}
                    description: >-
                      The verb's own arguments, EXCLUDING the target: the target
                      is injected per item from the object cursor or the item
                      payload. Shared across every item of the run.
                required:
                  - tool
              minItems: 1
              maxItems: 3
              description: >-
                1..3 steps, run in order per item. Step ids are server-assigned
                1-based ordinals; do not send them. Longer intents split into
                sequential mass-actions.
          required:
            - steps
        schedule:
          type: object
          nullable: true
          properties:
            interval_seconds_min:
              type: integer
              minimum: 30
              maximum: 86400
            interval_seconds_max:
              type: integer
              minimum: 30
              maximum: 86400
              description: '>= interval_seconds_min.'
          required:
            - interval_seconds_min
            - interval_seconds_max
          description: >-
            Paces ITEM STARTS with per-gap jitter (item k starts at item k-1
            plus a uniform draw from this window). Steps inside one item run
            contiguously. Mandatory when the plan carries a send-class step.
        canary_mode:
          type: string
          enum:
            - none
            - first_item
        commit_token:
          type: string
          maxLength: 512
          description: >-
            The token preview_mass_action returned for these exact inputs. Not
            the confirmation token of the protected-tool preview flow: it comes
            from preview_mass_action and nowhere else.
      required:
        - target_entity
        - scope
        - plan
        - commit_token
    CreateMassActionResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - create
        item:
          type: object
          properties:
            sid:
              type: string
            team_sid:
              type: string
            target_entity:
              type: string
            plan:
              type: object
              additionalProperties: {}
            canary_mode:
              type: string
              enum:
                - none
                - first_item
            status:
              type: string
              enum:
                - active
                - paused
            total_count:
              type: number
            credits_spent:
              type: number
            title:
              type: string
              nullable: true
            schedule:
              type: object
              nullable: true
              additionalProperties: {}
            paused_reason:
              type: string
              nullable: true
              enum:
                - manual
                - limit_reached
                - account_unavailable
                - canary_failed
                - other
            hold_till:
              type: string
              nullable: true
            canary_satisfied_at:
              type: string
              nullable: true
            started_at:
              type: string
              nullable: true
            settled_at:
              type: string
              nullable: true
            created_by:
              type: object
              nullable: true
              properties:
                actor_type:
                  type: string
                  enum:
                    - user
                    - support
                    - api_key
                    - system
                actor_sid:
                  type: string
                  nullable: true
                team_sid:
                  type: string
                permissions:
                  type: object
                  additionalProperties: {}
                request_sid:
                  type: string
                  nullable: true
                reason:
                  type: string
                  nullable: true
              required:
                - actor_type
                - actor_sid
                - team_sid
                - permissions
            deleted_by:
              type: object
              nullable: true
              properties:
                actor_type:
                  type: string
                  enum:
                    - user
                    - support
                    - api_key
                    - system
                actor_sid:
                  type: string
                  nullable: true
                team_sid:
                  type: string
                permissions:
                  type: object
                  additionalProperties: {}
                request_sid:
                  type: string
                  nullable: true
                reason:
                  type: string
                  nullable: true
              required:
                - actor_type
                - actor_sid
                - team_sid
                - permissions
            created_at:
              type: string
            updated_at:
              type: string
            deleted_at:
              type: string
              nullable: true
          required:
            - sid
            - team_sid
            - target_entity
            - plan
            - canary_mode
            - status
            - total_count
            - credits_spent
            - title
            - schedule
            - paused_reason
            - hold_till
            - canary_satisfied_at
            - started_at
            - settled_at
            - created_by
            - deleted_by
            - created_at
            - updated_at
            - deleted_at
        already_exists:
          type: boolean
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
      required:
        - success
        - operation
        - item
        - already_exists
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: object
                      properties:
                        rule:
                          type: string
                        message:
                          type: string
                      required:
                        - rule
                        - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````