Data steps and approved tools
The approved read-only tools a workflow can use, grouped as the builder shows them, with what each reads, its chains and its call limit.
A data step runs one approved tool: a reviewed, read-only reader of Solana, EVM or public web data. This page explains how data steps work, lists every tool the builder offers in production with what it reads, and covers call limits, chain availability and the read-only guarantee. It is for creators choosing tools for a workflow.
How a data step works#
- Add it from the library: choose a tool in one of the groups, or Add a data step and pick the tool afterwards.
- In Step settings, the Tool list shows each tool as "Name · what it reads · up to N calls", with the hint "Runs only approved read-only tools. Works on (chains)."
- Set each of the tool's settings. Optional ones are marked "(optional)" and can stay empty. Each setting takes an input, another step's result or a fixed value.
- Use the tool's output fields in later steps. In value pickers they appear as "Step name → Field", for example "Token metadata → Total supply atomic".
Changing the tool of a step clears its settings and fills the new tool's required settings from your first input.
Every read a tool makes becomes an evidence item in the report: the request, the response, the block or slot it was pinned to and hashes of both. Findings cite the evidence of the steps their values came from. See Evidence.
The read-only guarantee#
- Tools have one of three capabilities: EVM reads, Solana reads or Public web pages. Each capability allows a fixed list of read methods only; signing, sending and account-management methods do not exist in any of them.
- Every request passes a runtime permit that checks the method, the tool's call ceiling, the run budget, the address scope and, for logs, the block span. A request outside them is refused and recorded as a permission failure.
- A tool may read only the addresses in its scope: by default, addresses the buyer supplied as inputs, plus fixed platform contracts the tool was reviewed to read (for example a DEX factory). See address scope.
- Tool output that does not match the tool's declared output, or that cites evidence the tool did not capture, fails the run.
The Permissions & cost tab states the result for your workflow: "Signing or sending: never".
Tool reference#
The tables below follow the library's groups and use the names the builder shows. Calls is the tool's maximum per run. Settings lists the required settings with the labels the builder shows; some settings keep a generic label, for example the address setting reads "Token contract address" on every tool.
Solana#
All Solana tools run on Solana only.
| Tool | What it reads | Calls | Settings |
|---|---|---|---|
| Address history | Recent transaction signatures of an address, newest first. | 5 | Token contract address |
| Asset metadata | A mint's token metadata from an indexed provider. | 3 | Token mint |
| Funding links | System Program transfers and account creations that funded an address, in a recent window. | 13 | Token contract address |
| Indexed funding links | Native SOL funding of an address, oldest first, from an indexed provider. | 3 | Token contract address |
| Indexed history | Transaction signatures of an address from an indexed provider, with a pagination token. | 3 | Token contract address |
| Metaplex metadata | A mint's Metaplex Token Metadata; the metadata URI is not fetched. | 3 | Token mint |
| Mint authorities | Mint and freeze authorities of an SPL mint and its parsed Token-2022 extensions. | 3 | Token mint |
| Pumpfun curve | A pump.fun token's bonding curve: progress to graduation, SOL raised, curve price, implied market cap, supply still in the curve, creator and completion. | 4 | Token mint |
| Stake pools | SPL stake pools (JitoSOL, bSOL, jupSOL and others, or one named pool): SOL staked, SOL per pool token, a yield estimate, fees and manager. | 4 | None |
| Token holders | Token accounts holding a mint, in pages; never a complete holder census. | 4 | Token mint |
| Token safety | Issuer powers over an SPL or Token-2022 mint: mint and freeze authorities, risky Token-2022 extensions and whether Metaplex metadata can still change. | 4 | Token mint |
| Validator health | One validator by vote account: current or delinquent, stake, commission, epoch credits trend, skip rate and authorised withdrawer. | 8 | Vote account |
Tokens and wallets#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Address funding | The earliest transfers into and out of an address from an indexed provider (external, internal and ERC-20), one bounded page. | Ethereum, Base | 5 | Token contract address |
| Allowance exposure | Live ERC-20 and Permit2 allowances a wallet has granted to common routers, aggregators, lending pools and vaults, plus up to four named tokens and spenders. | Ethereum, Base, Robinhood Chain | 12 | Wallet address |
| Funding links | One-hop funding links of an address from transaction hashes you supply. | Ethereum, Base | 12 | Token contract address |
| Indexed funding links | The oldest native transfers into an address, from an indexed provider. | Ethereum, Base | 3 | Token contract address |
| Indexed token metadata | A token's metadata from an indexed provider. | Ethereum, Base | 1 | Token address |
| Nft collection | An NFT collection's standard, supply, owner, royalty settings and recent mint, burn and transfer activity. | Ethereum, Base | 10 | Collection address |
| Supplied balances | ERC-20 balances of the accounts you list. | Ethereum, Base | 16 | Token address, Account list |
| Token activity | Recent ERC-20 transfer activity of one token: volume, senders and receivers, largest transfers, mints and burns, over a stated block range. | Ethereum, Base, Robinhood Chain | 12 | Token address |
| Token metadata | ERC-20 name, symbol, decimals and total supply. | Ethereum, Base, Robinhood Chain | 11 | Token address |
| Token transfers | ERC-20 Transfer events of a token over a block range you set. | Ethereum, Base, Robinhood Chain | 10 | Token address, From block, To block |
| Token vesting | One vesting schedule (a Sablier stream by id, or an OpenZeppelin VestingWallet): parties, dates, vested, withdrawable and locked amounts and next unlocks. | Ethereum, Base | 20 | Contract address |
| Wallet activity | A wallet's native balance, inbound and outbound transfers by category and token balances, from an indexed provider. | Ethereum, Base | 16 | Wallet address |
| Wallet flows | Recent inflows and outflows of one address across its chain's major tokens plus up to four named tokens, with balances and counterparties. | Ethereum, Base, Robinhood Chain | 16 | Wallet address |
| Wallet token balances | A wallet's ERC-20 balances with token metadata, from the provider's latest view (not pinned to a block). | Ethereum, Base | 7 | Owner |
Contracts and security#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Admin history | The full upgrade, admin, ownership, role and pause history of one contract from block 0, with the current proxy state. | Ethereum, Base, Robinhood Chain | 20 | Contract address |
| Contract controls | Who can change a contract: proxy admin and beacon owners, owner, pending owner, pause and access control, each classified as a key, Safe, timelock or contract. | Ethereum, Base, Robinhood Chain | 20 | Contract address |
| Contract creation | Where and by whom a contract was deployed, with the deployment block. | Ethereum, Base | 34 | Contract address |
| Contract inspect | Bytecode, EIP-1967 proxy slots and EIP-7702 designators of an address. | Ethereum, Base, Robinhood Chain | 12 | Token contract address |
| Contract origin | The creation transaction of a contract, including creations inside another contract's call. | Ethereum, Base | 16 | Contract address |
| Decode swap | Offline decoding of a swap call to Uniswap V2 Router02, V3 SwapRouter or SwapRouter02, Universal Router or Permit2; no network read. | Ethereum, Base | 1 | Sender, Recipient, Data |
| Deployer launches | Other top-level contract creations by the same sender. | Ethereum, Base | 13 | Deployer |
| Issuer controls | Issuer powers over a stablecoin or tokenised asset: pause, blacklist or freeze, minter and pauser roles, compliance registries, transfer restrictions and upgradeability. | Ethereum, Base, Robinhood Chain | 10 | Token address |
| Oracle dependency | Which price feeds an asset or contract depends on, with each feed's answer, age, bounds, pending changes, owners and observed update cadence. | Ethereum, Base | 24 | Target |
| Permissions | A contract's owner, EIP-1967 admin and declared access-control roles; role holders are not enumerated. | Ethereum, Base, Robinhood Chain | 24 | Contract address |
| Transaction flows | Where value went in one mined transaction: net native balance changes and ERC-20 and ERC-721 movements. | Ethereum, Base, Robinhood Chain | 10 | Transaction hash |
Markets and DeFi#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Dex depth | Where a token trades and how deep: pools on Uniswap V2 and V3 and Aerodrome, spot prices, dispersion and the amount that moves each pool 2%. | Ethereum, Base, Robinhood Chain | 12 | Token address |
| Indexed transfers | An address's transfers from an indexed provider (external, internal and ERC-20). | Ethereum, Base | 5 | Token contract address |
| Lending market | Risk state of one Aave V3 reserve or Compound V3 market: supply, borrows, utilisation, rates, caps, collateral factors, pause flags and oracle price. | Ethereum, Base | 10 | Protocol, Market |
| Liquid staking | Exchange rates, supply and implied ETH backing of the main Ethereum liquid staking tokens. | Ethereum | 6 | None |
| Pool liquidity | Reserves of one Uniswap V2- or V3-compatible pool you supply; no pool discovery. | Ethereum, Base | 18 | Pool address |
| Pool trades | Order flow of one Uniswap V2 or V3 or Aerodrome pool over recent blocks: swaps, volumes, VWAP, price change, fees and largest trades. | Ethereum, Base, Robinhood Chain | 12 | Pool address |
| Vault 4626 | State of one ERC-4626 vault: underlying asset, total assets, share price, deposit capacity and, for MetaMorpho vaults, fee, curator, guardian and timelock. | Ethereum, Base | 8 | Vault address |
Governance and treasuries#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Governor | An on-chain governor: voting delay and period, proposal threshold, quorum, timelock delay and the latest proposals with state and votes. | Ethereum, Base | 14 | Governor address |
| Treasury | Holdings of a treasury or multisig across major and named tokens, and its Safe configuration: threshold, owners, modules, guard and fallback handler. | Ethereum, Base, Robinhood Chain | 12 | Treasury address |
Chains and bridges#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Bridge activity | Recent ETH and ERC-20 flows through the Base canonical standard bridge, by asset, with the largest movements. | Ethereum, Base | 10 | None |
| Chain pulse | Block production now and about an hour ago: transactions per block and second, block time, gas use, base fee and blob usage. | Ethereum, Base, Robinhood Chain | 9 | None |
| Rollup controls | Who controls a rollup's Ethereum contracts (Base or Robinhood Chain): upgrade path, Safe thresholds, timelock delays, pause state and proof or challenge windows. | Ethereum | 22 | Rollup |
Public web#
| Tool | What it reads | Chains | Calls | Settings |
|---|---|---|---|---|
| Read | One HTTPS page of a site the workflow declares, as text. | Solana, Ethereum, Base, Robinhood Chain | 1 | Url |
The public web reader:
- makes one HTTPS GET on the default port, without cookies, credentials or sign-in, and never follows redirects;
- accepts text content only (plain text, Markdown, HTML, CSV and JSON), reads 64 KiB by default and at most 256 KiB, and gives up after 8 seconds;
- refuses private, local and IP-literal addresses;
- may read only hosts the workflow declares. The builder has no field for web domains: declare them in Record & replay (Declared public sites) or accept them in an assistant proposal. They then appear under Web domains in Permissions & cost.
Fetched text is untrusted third-party content: it can back a finding but cannot grant permissions or change the workflow. Workflows with web reads cannot pass the platform checks and cannot publish a saved example.
Availability on each chain#
The table above is what each tool supports. A tool must also have verified coverage on a chain before the server runs it there, and a few do not yet. At the time of writing these combinations are unavailable in production:
| Chain | Unavailable tools | Why |
|---|---|---|
| Ethereum | Supplied balances, Indexed token metadata | Fixture coverage only, until live verification |
| Base | Funding links, Indexed transfers, Indexed funding links, Wallet token balances | Fixture coverage only, until live verification |
| Solana | Token holders, Indexed history, Indexed funding links, Asset metadata | They need a provider credential that is not configured on this server |
The library still lists these tools. If you tick a chain on which a tool is unavailable, the draft validates but saving fails with a message such as "This workflow draft names tools outside the approved, covered registry: Coverage: evm.supplied-balances on ethereum has fixture coverage only and stays unavailable until live verification." Remove that chain or that step. The live coverage list is published at https://agentex.sh/v1/capabilities.
Call limits#
Three limits bound how much a data step can read:
| Limit | Where | Rule |
|---|---|---|
| Tool maximum | Fixed per tool (the Calls column above) | A workflow can never raise it. |
| Call ceiling for this workflow | Settings → Advanced limits and scope → Call ceiling for (tool) | From 1 up to the tool maximum, and never above the run budget. The builder sets it to the lower of the two. |
| Run budget | Settings → Run budget → Maximum RPC calls | The most reads one run may make across all steps, from 1 to 64 (16 by default). |
A step that reaches its ceiling fails with a message such as "Tool evm.token-metadata reached its declared ceiling of 11 calls." A run that reaches its budget stops starting new steps: "The workflow reached its read limit, so no further steps started." Provider identity checks, snapshot cross-checks and retries count against the run budget too.
Tools that read event logs (for example Token transfers, Token activity, Wallet flows, Pool trades, Governor, Bridge activity, Nft collection, Oracle dependency and Admin history) or Solana address history (Address history, Funding links) also need Maximum log block span and Maximum paged requests. Both start at 0, which turns log reads and paging off. See Run budget, limits and rights.