Skip to content
v0.3

read.internal.customer

One customer by id, with their addresses + orders. Internal face only (PII).

  • Surface: GET /v1/read/internal/customer · MCP tool read.internal.customer
  • Auth:Internal read (operator) — a tenant credential is REQUIRED; requires the customer.admin.write scope. The tenant is resolved from the CALLER’s identity, never from store. Personal fields come back MASKED for an actor without pii.read (the shape is unchanged).
{
"properties": {
"customer_id": {
"minLength": 1,
"type": "string"
}
},
"required": [
"customer_id"
],
"type": "object"
}

Open (unknown) — this capability does not declare an output schema.

validation_failed (400) · not_found (404) · unauthorized (401) · forbidden (403)