> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure team toolkit sharing

> The owner can share a toolkit with one team or update its credential settings. The caller’s active team is resolved server-side. Omitted fields retain their current values. Initial sharing requires credential_mode. A supplied secret_bindings map replaces all bindings; switching to personal mode clears them. Shared mode requires an explicit saved secret for every required environment variable. Teammates can execute with those credentials in their workspaces. Deleting a bound secret requires the owner to reconnect it.



## OpenAPI

````yaml /openapi/neo.public.openapi.json patch /api/v1/dynamic-toolkits/{toolkit_id}/sharing
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/dynamic-toolkits/{toolkit_id}/sharing:
    parameters:
      - description: Toolkit UUID or visible toolkit identifier.
        in: path
        name: toolkit_id
        required: true
        schema:
          type: string
    patch:
      tags:
        - Dynamic Tools
      summary: Configure team toolkit sharing
      description: >-
        The owner can share a toolkit with one team or update its credential
        settings. The caller’s active team is resolved server-side. Omitted
        fields retain their current values. Initial sharing requires
        credential_mode. A supplied secret_bindings map replaces all bindings;
        switching to personal mode clears them. Shared mode requires an explicit
        saved secret for every required environment variable. Teammates can
        execute with those credentials in their workspaces. Deleting a bound
        secret requires the owner to reconnect it.
      operationId: patch-v1-dynamic-toolkits-id-sharing
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ToolkitSharingPatch'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ToolkitDetails'
          description: Updated toolkit and credential readiness.
        '400':
          description: No active team, or invalid or incomplete credential bindings.
        '403':
          description: Only the toolkit owner can configure sharing with an active team.
        '404':
          description: Toolkit is unavailable.
components:
  schemas:
    ToolkitSharingPatch:
      additionalProperties: false
      minProperties: 1
      properties:
        credential_mode:
          enum:
            - personal
            - shared
          type: string
        secret_bindings:
          additionalProperties:
            format: uuid
            type: string
          description: >-
            Required environment-variable names mapped to saved secret IDs owned
            by the toolkit owner. Values are never accepted here.
          type: object
      type: object
    ToolkitDetails:
      properties:
        config_hash:
          type: string
        created_at:
          format: date-time
          type: string
        dependencies:
          additionalProperties:
            type: string
          type: object
        description:
          type: string
        env_vars:
          items:
            type: string
          type: array
        id:
          format: uuid
          type: string
        init_code:
          type: string
        installation_error:
          type: string
        installation_status:
          enum:
            - not_started
            - installing
            - installed
            - failed
          type: string
        is_system_global:
          type: boolean
        language:
          enum:
            - ts
            - python
            - go
          type: string
        name:
          type: string
        pinned:
          type: boolean
        sharing:
          $ref: '#/components/schemas/ToolkitSharing'
        tags:
          items:
            type: string
          type: array
        toolkit_id:
          type: string
        updated_at:
          format: date-time
          type: string
      required:
        - id
        - toolkit_id
        - name
        - language
        - is_system_global
        - pinned
        - installation_status
        - created_at
      type: object
    ToolkitSharing:
      properties:
        can_edit:
          type: boolean
        can_unshare:
          type: boolean
        credential_mode:
          enum:
            - personal
            - shared
          type: string
        credential_status:
          description: >-
            Configuration readiness only; configured does not verify that an
            external service still accepts the credential. Personal mode
            requires credentials selected for the execution context.
          enum:
            - configured
            - requires_caller_secrets
            - missing_owner_secret
          type: string
        missing_env_vars:
          items:
            type: string
          type: array
        owner_email:
          type: string
        secret_bindings:
          additionalProperties:
            format: uuid
            type: string
          description: >-
            Current bindings, visible only to the owner; empty for teammates.
            Never contains secret values.
          type: object
        team_id:
          format: uuid
          nullable: true
          type: string
      required:
        - owner_email
        - credential_mode
        - credential_status
        - can_edit
        - can_unshare
        - missing_env_vars
        - secret_bindings
      type: object

````