fetch and your own key (see Call your API).
Verified against lua-cli 3.33.0.
Before you begin
- A connection of that type on the agent (see Connect a Unified.to integration).
- The provider’s own API documentation:
pathis relative to the provider’s API base URL and is relayed untouched.
1
Write the tool
Integrations.passthrough(type, { method, path, query?, data?, headers? }) returns { status, headers, data }, where data is parsed JSON when the provider answered JSON and the raw string otherwise. A provider error such as a 403 for a missing scope comes back in status, not as an exception.src/skills/tools/SearchLinearIssuesTool.ts
method is one of GET, POST, PUT, PATCH, DELETE, HEAD; an object data is sent as JSON, a string verbatim; query is appended to the URL; headers are forwarded except Authorization, Cookie, and hop-by-hop headers, which the relay owns.2
Handle relay errors
The call throws only when the relay itself refuses: no bound connection, passthrough disabled for the type, the per-agent rate limit, an invalid request, or the vendor not answering. The error’s Codes:
name is IntegrationPassthroughError and code says why; the class isn’t exported from 'lua-cli', so narrow on those two fields in the same tool.src/skills/tools/SearchLinearIssuesTool.ts
passthrough_no_connection (404), passthrough_disabled (403), passthrough_rate_limited (429), passthrough_invalid_request (400), and VENDOR_UNAVAILABLE (503, when Unified.to didn’t answer; retryAfterSeconds is set only for a GET or HEAD, and vendor, vendorStatus, and requestId identify the fault). statusCode carries the relay’s HTTP status. A provider that answered 5xx or 429 isn’t a relay error: read status on the envelope.3
Register and test locally
Add the tool to a skill on the agent (
integrations-samples in this guide), then run it. lua test sends the call through the platform with your CLI credential, so the agent’s real connection is used.Output
4
Release
Push the skill, snapshot the agent, and promote the version (see Releasing).
Options you may need
Which connection answers
Underlua test the call carries your credential: it resolves the agent’s own connections, and a personal connection only when you own it. Deployed code resolves any connection bound to the agent, a mounted personal connection included, on behalf of whichever end user is in the conversation. The per-end-user filter on About Spaces applies to the tools a consulted member carries, the model’s <type>_passthrough tool among them, which is pinned to the connection mounted for that turn; Integrations.passthrough from your code isn’t filtered that way.
Limits
- 120 calls per minute per agent, in a sliding window, counting calls from your code and from the model’s
<type>_passthroughtool alike; above that the call throws with codepassthrough_rate_limited(HTTP 429) and no retry-after value. A provider’s own 429 comes back instatusinstead. Integrations.passthroughtakes an integration type, not a connection ID; with several connections of one type, the active, most recently updated one answers.- Deployed, the relay abandons a call after 60 seconds end to end, so a provider that takes longer fails the call with a thrown error.
pathis at most 2,048 characters. A?inside it is merged withquery, and..segments are rejected.- Scopes are enforced by the provider: a call outside the connection’s grant returns the provider’s 401 or 403 in
status. Change the grant withlua integrations update --scopes. - The platform can switch passthrough off per integration type, which yields
passthrough_disabled. - Every call is logged by the platform for support and abuse review, with the integration, connection, method, path, status, and latency and never bodies or headers; the log isn’t readable through the CLI or API.
If it isn’t working
Agent has no bound 'linear' connection
Agent has no bound 'linear' connection
The agent has no connection of that type, or the type is spelled differently from
lua integrations available. Connect it, and use the type in parentheses from that list.Passthrough rate limit exceeded (120 calls/min per agent) — retry shortly
Passthrough rate limit exceeded (120 calls/min per agent) — retry shortly
The tool loops or a job fans out too fast. Batch the calls or wait for the window to pass; the limit is per agent, not per tool, and the error carries no retry-after value.
status is 401 or 403 in the envelope
status is 401 or 403 in the envelope
The provider refused the credential or the scope. Re-authorize with
lua integrations update --connection-id <id> --scopes all, or add the scope the endpoint needs.Next steps
Integrations reference
Request and response fields, and the error shape.
Manage integration MCP tools
The provisioned tools, before you write your own.
Add a tool
Tool anatomy, input schemas, and registration.
About integrations
What a connection provides and who owns it.

