List, read and manage Grain meeting recordings, transcripts, tags, shares and webhooks, plus a workspace's users, teams and meeting types, via the Grain Public API (v2).
Grain ships in the w6w first-party pack. It declares 19 actions, 2 health checks, and the host runs its code in a sandbox that never sees the credential.
io.w6w.grainGrain brings AI meeting recordings, transcripts and highlights into a workflow — listing and reading recordings, pulling structured or plain-text transcripts, and managing who a recording is shared with. Actions cover the full recording lifecycle: list and filter recordings by team, meeting type or date, read a recording’s metadata and AI-generated summary content, fetch its transcript in JSON or as plain text/WebVTT/SubRip, and share or unshare it with individual users or whole teams.
Tagging actions add and remove labels on a recording for organization, and a dedicated upload flow mints a single-use URL a workflow can hand off to whatever has the actual video bytes — Grain then processes the file and reports the result through a webhook rather than synchronously. Webhook management actions let a workflow register, list and remove delivery targets for Grain’s own event notifications.
Read-only actions round out the picture: listing a workspace’s users, teams and configured meeting types, so a workflow can resolve names and IDs before acting on a specific recording.
Three routes to the same 19 actions. The Workflow tab is generated from Grain's own manifest and carries its real ids, so it is copy-pasteable; the Code and CLI examples are the same call for any action on any app, so every app-specific value in them is a blank you fill in.
hook-create Register a URL to receive Grain's recording/highlight/story/upload-status events. Grain verifies the URL answers 2xx before the hook is created.
recording-list List recordings visible to this credential, with optional filtering and includes.
recording-transcript-download Fetch a recording's transcript as plain text, WebVTT (.vtt) or SubRip (.srt).
recording-transcript-get Fetch a recording's transcript as structured entries (speaker, start, end, text).
recording-unshare-team Remove a workspace team's access to a shared recording.
recording-unshare-user Remove a workspace user's access to a shared recording.
recording-upload-create Mint a single-use URL to PUT a .mov/.mp4/.mp3/.m4a file to — the bytes never pass through this workflow. Grain notifies upload_status hooks once processing finishes.
A workflow step names the app and the action, and the editor fills in the
connection when you pick one. This is the Step shape from the
workflow spec, carrying Grain's real ids.
{
"manifestVersion": "2",
"name": "grain-example",
"steps": [
{
"id": "hook-create",
"uses": {
"app": "io.w6w.grain",
"action": "hook-create",
"connection": "conn_YOUR_CONNECTION_ID"
},
"with": {
"hookUrl": "<hookUrl>",
"hookType": "<hookType>"
}
}
]
}hook-create hook-list meeting-type-list recording-download recording-get +14 more actions available
Every app-specific value here is a blank you have to fill in. An
app action is reached through the connection that authenticates it, so the
address is a connection id, not the app id — and connections belong to your account,
so a public page cannot know yours. Create one for Grain, then fill in
the three blanks: conn_YOUR_CONNECTION_ID, the action key, and the
parameters that action declares. The call itself is real — the shape is transcribed
from the studio's own snippet builder, which prints the same kind of blanks — but
nothing in it is specific to Grain. The Workflow tab is where this app's
real ids are.
npm install @w6w/sdkyarn add @w6w/sdkpnpm add @w6w/sdkdeno add npm:@w6w/sdkimport { W6wClient, isActionRun } from "@w6w/sdk";
// Reads W6W_BASE_URL and W6W_TOKEN from the environment when omitted.
const client = new W6wClient();
const envelope = await client.run({
urn: "conn_YOUR_CONNECTION_ID",
action: "hook-create",
payload: {
hookUrl: "<value>",
hookType: "<value>",
// includeHighlights: "<value>",
// includeParticipants: "<value>",
// includeAiActionItems: "<value>",
// includeAiSummary: "<value>",
// includePrivateNotes: "<value>",
// includeCalendarEvent: "<value>",
// includeHubspot: "<value>",
// includeScreenshares: "<value>",
// includeAiTemplateSections: "<value>",
// aiTemplateSectionsFormat: "<value>",
// aiTemplateSectionsAllowedSections: "<value>",
// includeHighlightTranscript: "<value>",
// includeHighlightSpeakers: "<value>",
},
});
if (isActionRun(envelope)) console.log(envelope.value); npm install -g @w6w/cli w6w run conn_YOUR_CONNECTION_ID --action hook-create --payload '{"hookUrl":"<value>","hookType":"<value>"}' Give an AI agent Grain — without giving it Grain's credentials. One MCP endpoint exposes every app, function and workflow the caller is entitled to, as tools it can discover and run. Access is granted per team while we onboard.
One tool call{
"name": "w6w_invoke",
"arguments": {
"ref": "app:io.w6w.grain#hook-create",
"input": {
"hookUrl": "<hookUrl>",
"hookType": "<hookType>"
}
}
}
Every tool names its target with a single ref. The
app: form above doesn't name a connection at all — the
host resolves which of the caller's Grain connections to sign
with, and refuses rather than guesses when the answer is ambiguous.
The token is attached host-side, at the moment of the call. It is never a tool argument, never in the model's context, and never in a transcript — so a prompt injection has nothing to exfiltrate.
Tools are derived per end user from what that person has actually connected and is entitled to — not one shared bot identity carrying the union of everyone's access.
Multi-step work runs on the workflow engine and returns a run handle the agent can poll — retries, branching and state survive the conversation that started them.
Grain's declared health checks are on the surface too, so an agent can tell "the vendor is down" from "your credential expired" before it burns a retry on either.
The MCP surface is part of the hosted platform. Grain itself is MIT, and the runtime that executes it is source-available (FSL).
Grain declares its own checks, so its health is a property of the app rather than something the host guesses at.
Atlassian Statuspage rollup for www.grainstatus.com (status.grain.com redirects here), with per-component detail. Unauthenticated and unsigned.
Requests left in the current account-wide rate-limit window, read from the x-ratelimit-* headers on a POST /v2/teams call.