---
name: looot
description: Discover, inspect, and run operations through a private looot Gateway (https://api.looot.ai/). Use when the task needs to call a real or fixture provider operation through looot instead of guessing at an API.
---

# looot

This Gateway is reachable two ways: the `looot` CLI or the MCP server mounted at `https://api.looot.ai/mcp` (Streamable HTTP
transport). Both expose the same tools (discover, inspect, run, runs, balance, search and the
rest of `looot help`) and go through the exact same tenant-scoped execution engine -- there is no
difference in what either can do.

## Setup

1. Sign in: `looot login` opens the looot dashboard (`https://looot.ai`) to approve this machine and
   saves the token. For an agent without a browser, create an agent token in the dashboard
   (Settings, "Agent tokens", "Create agent token", with `catalog.read`, `runs.read` and
   `runs.execute` at minimum) and copy the one-time `cs_ms_...` secret shown right after.
2. With a copied token, set `LOOOT_API_URL=https://api.looot.ai/` and `LOOOT_TOKEN=<that secret>` in the
   environment before running any `looot` command. Never hardcode the token into a script or
   commit it.
3. Top up before your first run: `looot balance` prints the top-up link and the minimum amount.
   A new workspace starts at $0 and every run is refused with `insufficient_balance` until you
   top up. The MCP `balance` tool shows the same, the MCP `top_up` tool returns a Stripe link,
   or pay at `https://looot.ai/usage`. Searching and inspecting are free.

## Commands

- `looot discover --mode auto --query "<task>"` -- search up to 5 eligible operations.
- `looot catalog list --text "<query>"` -- paged, filtered catalog listing.
- `looot inspect <endpoint-id>` -- exact input/output schema, price, and provider identity before running it.
- `looot run <endpoint-id> --input '{"..."}' --idempotency-key <key> [--wait]` -- validate input, reserve estimated cost, execute, return a run id. Idempotent on `idempotencyKey` -- retries never double-charge. `--wait` blocks and prints the finished run inline.
- `looot runs get|list|cancel|evidence <run-id>` -- looot lifecycle status plus result/error and cost once settled; cursor-paginated history; cancel a queued/running run; attempt-level evidence.
- `looot balance` -- available and reserved balance for this workspace, plus the minimum top-up and a payment link when credit is low.
- `looot mcp install --client claude-code` -- prints a ready-to-paste MCP client config for this Gateway's Streamable HTTP transport.

## Errors

A 201 (or a queued/running run returned by `--wait`'s own timeout) can still carry `status:"failed"` -- a pre-dispatch denial (unknown endpoint, input that fails the endpoint's own schema) never raises an HTTP error. Check the run's `status` and `error` fields, not the HTTP status code, to know whether it actually ran.

`looot verify <endpoint-id>` is for platform operators (provider-registry:write); a customer token gets 403.

Run `looot help --all` for the full command reference; every command supports `--format json|human|jsonl`.
