manage_account_security
Initiate private email, password, MFA, sessions or connected sign-in management; give the user the completion URL instead of asking for secrets.
# MCP tool reference
1 callable tools.
Use tools/call at https://mcp.schedulerzero.com/mcp with the exact tool name and arguments below. The /tools/ paths in this view are documentation identifiers, not HTTP endpoints. Request execution is disabled for this reference.
Inputs are shown for personal API keys (bound) and for OAuth/delegated agents. Output schemas describe MCP structuredContent: native objects pass through; arrays, scalars and null use a data wrapper. Text content retains the native JSON result.
[Connect a client](/mcp/connect) · [Authentication and authorization](/authentication) · [Generated auth guide](/auth.md) · [Download tool catalog](/mcp-catalog.json) · [Agent documentation](/llms.txt)
## manage_account_security
Initiate private email, password, MFA, sessions or connected sign-in management; give the user the completion URL instead of asking for secrets.
To change account security. The user completes the same API-backed UI, then reads provider state with read_account_security.
Never send passwords, OTPs, recovery codes or TOTP secrets to a tool or chat. Unsupported provider actions are reported, not emulated.
Return the authorization or checkout handoff to the person. The agent may initiate and inspect status, but must not complete the human approval.
Scopes: workspace:read
Risk: read; confirmation: human_completion; idempotency: none.
### Input schema (personal API key)
```json
{
"type": "object",
"properties": {
"intent": {
"type": "string",
"enum": [
"email",
"password",
"password-reset",
"mfa",
"sessions",
"connections"
]
}
},
"required": [
"intent"
],
"patternProperties": {
"^(?!(?:intent)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"anyOf": [
{
"type": "string",
"enum": [
"intent"
]
}
]
}
}
```
### Input schema (OAuth / delegated agent)
```json
{
"type": "object",
"properties": {
"intent": {
"type": "string",
"enum": [
"email",
"password",
"password-reset",
"mfa",
"sessions",
"connections"
]
}
},
"required": [
"intent"
],
"patternProperties": {
"^(?!(?:intent)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"anyOf": [
{
"type": "string",
"enum": [
"intent"
]
}
]
}
}
```
### Output schema (structuredContent)
```json
{
"type": "object",
"properties": {
"completionUrl": {
"$ref": "#/$defs/HttpUrl"
},
"intent": {
"type": "string",
"enum": [
"email",
"password",
"password-reset",
"mfa",
"sessions",
"connections"
]
},
"instructions": {
"$ref": "#/$defs/NonEmptyString"
}
},
"required": [
"completionUrl",
"intent",
"instructions"
],
"patternProperties": {
"^(?!(?:completionUrl|intent|instructions)$)[\\s\\S]*$": false
},
"additionalProperties": true,
"propertyNames": {
"type": "string",
"enum": [
"completionUrl",
"intent",
"instructions"
]
},
"$defs": {
"HttpUrl": {
"type": "string",
"minLength": 1,
"maxLength": 2048,
"pattern": "^https?:\\/\\/[^\\s/$.?#][^\\s]*$"
},
"NonEmptyString": {
"type": "string",
"minLength": 1,
"maxLength": 4096
}
}
}
```
### Underlying API operations
- `accountSecurity.handoff`: `POST /v1/me/security/handoff`
- `accountSecurity.read`: `GET /v1/me/security`