One action, every caller
Write an operation once, as an Action class, and the same class answers a route, Artisan, the queue, TypeScript, an agent and MCP clients.
- Web routePOST /actions/create-post
- TypeScriptcreatePost()
- Artisanactions:run create-post
- The queueCreatePost::dispatch()
- exposure
- token abilities
- tenant membership
- authorize()
- validation
- handle()
- output allowlist
- A laravel/ai agenta tool it can call
- MCP clientsthe create-post tool
The action
An action is one class that extends AgenticActions\Action. Its properties declare facts: what it does, its effect, what a success makes stale. Its methods declare behaviour: the input, the output, who may run it, and the work.
#[Expose]opens the route, agents and MCPfinal class CreatePost extends Action- facts
$descriptionwhat a model reads before it calls$effect = Effect::WriteRead, Write, Destructive or External$touches = ['posts']what a success makes stale- behaviour
schema()the input: rules, tool schema, TypeScript typesoutputSchema()the only keys that leave the serverauthorize()who may run it; without it, nobodyhandle()does the work
Without authorize() the action is denied everywhere, and a key outputSchema() does not declare never leaves the server. See The action in Concepts for every member.
What each caller gets
Each caller comes in its own way, then takes the same steps, so a rule written once in authorize() or schema() holds for a form, a worker and a model alike. What each step answers when it says no is on the pipeline, and the full list in What that one class gets.
- Web routePOST /actions/create-postJSON gets the output; a form gets a redirect.Actions::routes()
- TypeScriptcreatePost()The route, typed from schema() and outputSchema().actions:typescript
- Artisanactions:run create-postRuns as the user --as names.no #[Expose] needed
- The queueCreatePost::dispatch()The worker runs the whole pipeline, as the caller.no #[Expose] needed
- laravel/ai agentcreate-postThe model reads $description and the schema.composer require laravel/ai
- MCP clientscreate-postListed for a token that names actions:write.a token guard
What #[Expose] opens
#[Expose] is the only way onto the route, agents and MCP. Artisan, the queue and your own run() reach an action without it. See Effects and surfaces.