Registry · Capabilities · pinecone.io
Capability registry
What pinecone.io declares an agent can do
Measured 2026-10-04 12:18 UTC from the declarations the site publishes (record os9covf1b2). Each capability is shown as declared, under the policy class that decides whether anything may call it, beside what a call observed.
Declared versus observed
| Capability | Policy class | Declared | Observed |
|---|---|---|---|
| Pinecone OpenAPI (JSON) api · https://www.pinecone.io/openapi.json | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| Pinecone OpenAPI (YAML) api · https://www.pinecone.io/openapi.yaml | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| Pinecone marketing MCP descriptor api · https://www.pinecone.io/.well-known/mcp | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| Pinecone docs MCP server card api · https://docs.pinecone.io/.well-known/mcp/server-card.json | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted on another origin (docs.pinecone.io): only the scanned origin is called |
| A2A agent card api · https://www.pinecone.io/.well-known/agent-card.json | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| Site index for LLMs api · https://www.pinecone.io/llms.txt | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| Sitemap api · https://www.pinecone.io/sitemap.xml | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| list_indexes openapi · GET · https://api.pinecone.io/indexes | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| create_index openapi · POST · https://api.pinecone.io/indexes | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_index openapi · GET · https://api.pinecone.io/indexes/{index_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| configure_index openapi · PATCH · https://api.pinecone.io/indexes/{index_name} | Unknown never called automatically | PATCH with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| delete_index openapi · DELETE · https://api.pinecone.io/indexes/{index_name} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| list_index_backups openapi · GET · https://api.pinecone.io/indexes/{index_name}/backups | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| create_backup openapi · POST · https://api.pinecone.io/indexes/{index_name}/backups | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| list_collections openapi · GET · https://api.pinecone.io/collections | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| create_collection openapi · POST · https://api.pinecone.io/collections | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| create_index_for_model openapi · POST · https://api.pinecone.io/indexes/create-for-model | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| list_project_backups openapi · GET · https://api.pinecone.io/backups | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_backup openapi · GET · https://api.pinecone.io/backups/{backup_id} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| delete_backup openapi · DELETE · https://api.pinecone.io/backups/{backup_id} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| create_index_from_backup_operation openapi · POST · https://api.pinecone.io/backups/{backup_id}/create-index | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| list_restore_jobs openapi · GET · https://api.pinecone.io/restore-jobs | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_restore_job openapi · GET · https://api.pinecone.io/restore-jobs/{job_id} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_collection openapi · GET · https://api.pinecone.io/collections/{collection_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| delete_collection openapi · DELETE · https://api.pinecone.io/collections/{collection_name} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| listBulkImports openapi · GET · https://api.pinecone.io/bulk/imports | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| startBulkImport openapi · POST · https://api.pinecone.io/bulk/imports | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describeBulkImport openapi · GET · https://api.pinecone.io/bulk/imports/{id} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| cancelBulkImport openapi · DELETE · https://api.pinecone.io/bulk/imports/{id} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describeIndexStats openapi · POST · https://api.pinecone.io/describe_index_stats | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| queryVectors openapi · POST · https://api.pinecone.io/query | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| deleteVectors openapi · POST · https://api.pinecone.io/vectors/delete | Irreversible write never called automatically | a write whose name contains “delete” auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| fetchVectors openapi · GET · https://api.pinecone.io/vectors/fetch | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| fetch_vectors_by_metadata openapi · POST · https://api.pinecone.io/vectors/fetch_by_metadata | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| listVectors openapi · GET · https://api.pinecone.io/vectors/list | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| updateVector openapi · POST · https://api.pinecone.io/vectors/update | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| upsertVectors openapi · POST · https://api.pinecone.io/vectors/upsert | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| listNamespacesOperation openapi · GET · https://api.pinecone.io/namespaces | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| createNamespace openapi · POST · https://api.pinecone.io/namespaces | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describeNamespace openapi · GET · https://api.pinecone.io/namespaces/{namespace} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| deleteNamespace openapi · DELETE · https://api.pinecone.io/namespaces/{namespace} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| upsertRecordsNamespace openapi · POST · https://api.pinecone.io/records/namespaces/{namespace}/upsert | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| searchRecordsNamespace openapi · POST · https://api.pinecone.io/records/namespaces/{namespace}/search | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| embed openapi · POST · https://api.pinecone.io/embed | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| rerank openapi · POST · https://api.pinecone.io/rerank | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| list_models openapi · GET · https://api.pinecone.io/models | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| get_model openapi · GET · https://api.pinecone.io/models/{model_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| list_assistants openapi · GET · https://api.pinecone.io/assistants | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 1 | not attempted requires apiKey: never called without the operator's own credentials |
| create_assistant openapi · POST · https://api.pinecone.io/assistants | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| get_assistant openapi · GET · https://api.pinecone.io/assistants/{assistant_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| update_assistant openapi · PATCH · https://api.pinecone.io/assistants/{assistant_name} | Unknown never called automatically | PATCH with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| delete_assistant openapi · DELETE · https://api.pinecone.io/assistants/{assistant_name} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| list_files openapi · GET · https://api.pinecone.io/files/{assistant_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| upload_file openapi · POST · https://api.pinecone.io/files/{assistant_name} | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_file openapi · GET · https://api.pinecone.io/files/{assistant_name}/{assistant_file_id} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| upsert_file openapi · PUT · https://api.pinecone.io/files/{assistant_name}/{assistant_file_id} | Unknown never called automatically | PUT with no declared reversibility auth: apiKey · required inputs: 4 | not attempted requires apiKey: never called without the operator's own credentials |
| delete_file openapi · DELETE · https://api.pinecone.io/files/{assistant_name}/{assistant_file_id} | Irreversible write never called automatically | HTTP DELETE auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| list_operations openapi · GET · https://api.pinecone.io/operations/{assistant_name} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| describe_operation openapi · GET · https://api.pinecone.io/operations/{assistant_name}/{operation_id} | Authenticated read-only never called automatically | HTTP GET behind apiKey auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| chat_completion_assistant openapi · POST · https://api.pinecone.io/chat/{assistant_name}/chat/completions | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| chat_assistant openapi · POST · https://api.pinecone.io/chat/{assistant_name} | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| context_assistant openapi · POST · https://api.pinecone.io/chat/{assistant_name}/context | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 3 | not attempted requires apiKey: never called without the operator's own credentials |
| metrics_alignment openapi · POST · https://api.pinecone.io/evaluation/metrics/alignment | Unknown never called automatically | POST with no declared reversibility auth: apiKey · required inputs: 2 | not attempted requires apiKey: never called without the operator's own credentials |
| list_projects openapi · GET · https://api.pinecone.io/admin/projects | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| create_project openapi · POST · https://api.pinecone.io/admin/projects | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| list_organizations openapi · GET · https://api.pinecone.io/admin/organizations | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| fetch_project openapi · GET · https://api.pinecone.io/admin/projects/{project_id} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| update_project openapi · PATCH · https://api.pinecone.io/admin/projects/{project_id} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| delete_project openapi · DELETE · https://api.pinecone.io/admin/projects/{project_id} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| fetch_organization openapi · GET · https://api.pinecone.io/admin/organizations/{organization_id} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| update_organization openapi · PATCH · https://api.pinecone.io/admin/organizations/{organization_id} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| delete_organization openapi · DELETE · https://api.pinecone.io/admin/organizations/{organization_id} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| list_project_api_keys openapi · GET · https://api.pinecone.io/admin/projects/{project_id}/api-keys | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| create_api_key openapi · POST · https://api.pinecone.io/admin/projects/{project_id}/api-keys | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| fetch_api_key openapi · GET · https://api.pinecone.io/admin/api-keys/{api_key_id} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| update_api_key openapi · PATCH · https://api.pinecone.io/admin/api-keys/{api_key_id} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| delete_api_key openapi · DELETE · https://api.pinecone.io/admin/api-keys/{api_key_id} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| get_token openapi · POST · https://api.pinecone.io/oauth/token | Identity and accounts never called automatically | its name contains “token” auth: none · required inputs: 2 | not attempted on another origin (api.pinecone.io): only the scanned origin is called |
| fetch_prometheus_targets openapi · GET · https://api.pinecone.io/prometheus/projects/{project_id}/metrics/discover | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| browse-marketing a2a · https://www.pinecone.io/mcp/ | Unknown never called automatically | its effect is not stated in the declaration auth: none | not attempted classed unknown: only read-only public actions are ever called |
Where the declaration and the call disagree
None: every capability that was called answered as declared.
Signed certificate
This page’s rows, signed by the observer’s Ed25519 key: every capability’s id, endpoint, safety class, policy class and observed state, the declaration hashes and the record’s sealed manifest. The certificate is derived from the record alone, so the same record always yields the same id.
alg Ed25519 · kid hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
sig KcfyHqMxQFTYg2uVhhtrXs3b1-fVogcevdyFAhacfHvJmp3oSyu2gkbxoACWuyFBldYIVM0exdEwrIudP7BaAw
The certificate as JSON · verify it now · the key directory · machine-readability certificate
To verify it yourself: SHA-256 the certificate object as canonical JSON (keys sorted, no whitespace); the hex digest must equal certificate_sha256 and the id; then check the Ed25519 signature over "crawlcheck-capability-certificate-v1\n" followed by that hex digest, with the key in the directory whose RFC 7638 thumbprint is the kid.
Policy classes
| Policy class | Called automatically? | Rule |
|---|---|---|
| Public read-only public_read_only | yes, to verify | May be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin. |
| Authenticated read-only authenticated_read_only | never | Never called by CrawlCheck. An agent needs the user's own credentials and consent. |
| Reversible write reversible_write | never | Never invoked automatically. Needs the owner's written authorisation and a test account. |
| Irreversible write irreversible_write | never | Never invoked automatically. Deletes or changes something that cannot be undone. |
| Financial financial | never | Never invoked automatically. Moves money or creates a charge. |
| External communication external_communication | never | Never invoked automatically. Sends a message, email or notification to someone. |
| Identity and accounts identity | never | Never invoked automatically. Creates, signs in to or changes an account or credential. |
| Unknown unknown | never | Never invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case. |
| Metadata metadata | never | Nothing to invoke: a listing, a server card or a skill file, not an operation. |