# Tool gateway, APIs and external integration

Protocols provide connection while business contracts define responsibility; external content and tool results are never a source of authorization. API, MCP and A2A are adapter tracks that never replace MYRILUM's tasks, permissions, budgets and commercial rules.

> Document ID: MYRILUM-DOC-ARCH-018
> Document type: concept
> Product: NOT_APPLICABLE
> Version: 0.1.0
> Region: GLOBAL
> Visibility: PUBLIC
> Publication: PUBLISHED_GLOBAL
> Content maturity: DRAFTED
> Governance: APPROVED
> Capability state: IN_DEVELOPMENT
> Availability: NOT_AVAILABLE
> Authorization: PUBLIC_INFORMATION
> Freshness: CURRENT
> Safety class: INFORMATIONAL
> Owner: Web3Capital Documentation Steward
> Approvers (assignment only; not approval evidence): Stephen
> Canonical authority: SRC-ARCHITECTURE-ATLAS-V2-2
> Source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a
> Content digest: 4b6bddfe2c9b37cc1f974b05f67cfd83933b0c7ad63384b735945842f5b55c0d
> Effective: NOT_SET
> Expires: NOT_SET
> Last verified: 2026-09-23
> Review due: 2026-10-23
> Command authority: NONE
> Canonical URL: /en/architecture/tools-and-interoperability

<a id="overview"></a>

## What this map shows

![Tool gateway, APIs and external integration diagram (A18)](/figures/atlas-v2-2/A18.png)

*MYRILUM architecture map v2.2 · A18 (public edition). Labels are in Chinese; every element is listed in English below. Select the diagram to open it at full size.*

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

Protocols provide connection and business contracts define responsibility; external content and tool results can never become a source of authorization.

API, MCP and A2A are adapter tracks; they never replace MYRILUM's task, permission, budget and commercial rules.

<a id="part-1"></a>

## Real integration levels for external capabilities

| Field | Value |
|---|---|
| Entry or embed | A link or on-screen presentation; never claimed as executable |
| Reading data | Queries, sync and references within the authorized scope |
| Taking action | Specific operations such as creating, changing or sending |
| Delegating a task | Agreed remote task status, results, cancellation and responsibility |

> **Minimum capability manifest** — Version, inputs and outputs, authentication, data destination, side effects, price, idempotency, cancellation, timeout and accountable party.

<a id="part-2"></a>

## Protocol adapters and the platform contract

| Field | Value |
|---|---|
| API (business interface) | Formal commands, queries, errors and versions |
| MCP (context protocol) | Adapter for interoperating tools, resources and context |
| A2A (agent-to-agent) | Adapter for remote task exchange across organizations |
| One internal contract | Identity, inputs and outputs, budget, permissions and evidence never depend on a single protocol |

> **Tools grant no permission** — Web pages, files, tool descriptions, error messages and returned text can never raise a user's or an agent's permissions.

<a id="part-3"></a>

## Every tool operation is checked

| Field | Value |
|---|---|
| Action request | Stable business operation identifier and a digest of the parameters |
| Parameter and authorization check | Resources, recipients, data, fees and side effects |
| Sandbox and outbound gateway | Isolation of network, files, processes, time and keys |
| External execution | Minimal credentials; external operation identifiers and receipts |

> **Recovery strategy by tool** — Reads, idempotent writes and irreversible outbound actions use different retry, query and compensation strategies.

<a id="part-4"></a>

## Returning, checking and exiting

| Field | Value |
|---|---|
| Results are data | Parsed and verified; malicious instructions in a result are never executed |
| Reconciling unknown results | Query the external state; never blindly retry an irreversible operation |
| Usage and audit events | Records the real consumption, the authorization basis and exceptions |
| Revoking or retiring a connection | Stops new calls, checks in-flight tasks and revokes credentials |

> **Integration status shown in parts** — Discoverable, connected, authorized, tested and generally available are recorded separately; never just one green “success”.

<a id="source"></a>

## Source

This page follows A18 of the MYRILUM architecture map v2.2 (public edition: restricted products and internal open items are left out). Related: “The developer and capability release lifecycle”; “Identity, authorization and access decisions”; “Commands, events and consistency”.

---

This document is read-only, grants no command authority, and does not authorize deployment, payment, provider modification, or any other real-world action.
