> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firedrill.run/llms.txt
> Use this file to discover all available pages before exploring further.

# Open one Tool app in a ready environment

> Issues short-lived access to one package's isolated browser app using the same environment data. Requires drill.run and the observed ready runtime version and generation. No control or ordinary world bearer is returned. The credential is in the URL fragment; do not log or persist this response. Opening an app does not run your agent or wake compute. After reset or expiry, obtain a fresh link explicitly; never resend an uncertain Tool action. Responses are private and non-cacheable.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/projects/{projectId}/environments/{environmentId}/tool-apps
openapi: 3.1.0
info:
  title: Firedrill Control API
  version: 1.0.0
  description: >-
    The control plane for drills, drill runs, and the worlds they run in. Errors
    always carry the canonical envelope; unsafe operations require an
    Idempotency-Key; long work returns an operation resource.
servers:
  - url: https://api.firedrill.run
security:
  - controlCredential: []
paths:
  /v1/projects/{projectId}/environments/{environmentId}/tool-apps:
    post:
      summary: Open one Tool app in a ready environment
      description: >-
        Issues short-lived access to one package's isolated browser app using
        the same environment data. Requires drill.run and the observed ready
        runtime version and generation. No control or ordinary world bearer is
        returned. The credential is in the URL fragment; do not log or persist
        this response. Opening an app does not run your agent or wake compute.
        After reset or expiry, obtain a fresh link explicitly; never resend an
        uncertain Tool action. Responses are private and non-cacheable.
      operationId: environments.openToolApp
      parameters:
        - name: projectId
          in: path
          required: true
          schema:
            type: string
            pattern: ^prj_[0-9a-z]{12,32}$
        - name: environmentId
          in: path
          required: true
          schema:
            type: string
            pattern: ^env_[0-9a-z]{12,32}$
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 8
            maxLength: 128
            pattern: ^[A-Za-z0-9._:-]+$
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IssueEnvironmentToolAppRequest'
      responses:
        '200':
          description: Scoped isolated Tool app link
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HostedToolAppAccess'
        '400':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        default:
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    IssueEnvironmentToolAppRequest:
      type: object
      properties:
        actorId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        actorInstanceId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        packageId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        instanceId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        ttlMs:
          type: integer
          minimum: 0
          exclusiveMinimum: true
          maximum: 300000
        expectedRuntimeVersion:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        expectedLeaseGeneration:
          type: integer
          minimum: 0
          exclusiveMinimum: true
          maximum: 9007199254740991
      required:
        - actorId
        - packageId
        - expectedRuntimeVersion
        - expectedLeaseGeneration
      additionalProperties: false
    HostedToolAppAccess:
      type: object
      properties:
        schemaVersion:
          type: number
          enum:
            - 1
        packageId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        instanceId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        actorId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        actorInstanceId:
          type: string
          minLength: 1
          maxLength: 96
          pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
        sessionId:
          type: string
          pattern: ^ses_[0-9a-z]{12,32}$
        buildHash:
          type: string
          pattern: ^sha256:[0-9a-f]{64}$
        url:
          type: string
          format: uri
        expiresAtMs:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        replayed:
          type: boolean
      required:
        - schemaVersion
        - packageId
        - actorId
        - sessionId
        - buildHash
        - url
        - expiresAtMs
        - replayed
      additionalProperties: false
    ErrorEnvelope:
      type: object
      properties:
        code:
          type: string
          pattern: ^(control|world)\.[A-Z][A-Z0-9]*(_[A-Z0-9]+)*$
        message:
          type: string
          minLength: 1
        correlationId:
          type: string
          minLength: 1
        retryable:
          type: boolean
        retryAfterMs:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
        operationId:
          type: string
        source:
          type: string
          enum:
            - platform
            - simulated_provider
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              code:
                type: string
              message:
                type: string
            required:
              - path
              - code
              - message
            additionalProperties: false
        details:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        evidence:
          type: object
          properties:
            sessionId:
              type: string
            runId:
              type: string
            journalSeq:
              type: integer
              minimum: 0
              maximum: 9007199254740991
            buildHash:
              type: string
          additionalProperties: false
      required:
        - code
        - message
        - correlationId
        - retryable
        - source
      additionalProperties: true
  securitySchemes:
    controlCredential:
      type: http
      scheme: bearer
      description: Opaque control credential

````