DevelopersRead only

list_customers

API reference — one of six tools an AI assistant can call on an Avrosh account.

What it does

The people this business has on record: name, email, phone, the operator's private note, booking count, last seen. query substring-matches name, email and phone. At most 500 rows, most recently seen first. Erased people never appear - absence here does not mean the business never knew them.

This is the exact text the model reads before deciding to call.

Parameters

business_idstringrequired

The id returned by list_businesses.

querystringoptional

Substring of name, email or phone.

Request

curl -X POST https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_customers","arguments":{"business_id":"926135ac-487d-4367-8bad-25397d0d4b87","query":"wijaya"}}}'

Response

The result arrives as an MCP content block; the JSON below is what the text field parses to.

{
  "customers": [
    {
      "id": "ct12…",
      "name": "Budi Wijaya",
      "phone": "+62812…",
      "email": null,
      "bookingCount": 3,
      "lastSeenAt": "2026-08-10T04:00:00.000Z"
    }
  ],
  "count": 1
}

Authentication

Every request carries Authorization: Bearer avk_…. Create a key in the Avrosh dashboard under Docs; it is shown once, because only its hash is stored.

One key reaches every business on the account that made it, and no others. There are no scopes to configure and nothing to switch on — a connected assistant receives the whole toolset. What bounds it is whose account the key belongs to, which is enforced in the database rather than by a permission anybody sets.

curl https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY"