Automate test dependencies
Everything on the Dependencies tab is available without the console. This page lists the REST routes, the MCP tools and the skill behavior, and explains how a builder field refers to a dependency.
REST API
Section titled “REST API”Every request needs an Authorization: Bearer <your-key> header (a console session token or an mpak_
API key) and an X-Account-Id: <account-id> header. The base URL is https://app.maxoperf.com/v1. The
test, secret and entity ids come from the console URLs or from the list routes.
# List a test's dependenciesGET /v1/tests/{testId}/dependencies
# Replace a test's manual secret bindingsPUT /v1/tests/{testId}/secret-bindings
# Bind, update or remove a virtual servicePUT /v1/virtual-services/bindingsDELETE /v1/virtual-services/bindings/{bindingId}
# Bind, update or remove a tunnelPUT /v1/tests/{testId}/dependencies/tunnels/{tunnelId}DELETE /v1/tests/{testId}/dependencies/tunnels/{tunnelId}
# Bind, update or remove a browser fleetPUT /v1/tests/{testId}/dependencies/browser-fleets/{fleetId}DELETE /v1/tests/{testId}/dependencies/browser-fleets/{fleetId}
# See what uses an entityGET /v1/dependencies/usage?kind=<kind>&entityId=<id>
# See a run's leasesGET /v1/runs/{runId}/dependenciesPUT on a binding is an upsert: calling it again with the same test and entity changes the variable
name. A stem that is not upper-snake, or is longer than 40 characters, is rejected with
invalid_env_var_name.
Bind a secret
Section titled “Bind a secret”PUT /v1/tests/{testId}/secret-bindings replaces the test’s manually bound secrets with the list you
send, so include the ones you want to keep. Bindings that the test’s model creates inline are not
touched. envName must match ^SECRET_[A-Za-z0-9_]{1,120}$. Leave it out to inject the secret under
its own name.
curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/secret-bindings \ -H "Authorization: Bearer <your-key>" \ -H "X-Account-Id: <account-id>" \ -H "Content-Type: application/json" \ -d '{ "bindings": [ { "secretId": "sec-0123456789", "envName": "SECRET_PAYMENTS_API_KEY" } ] }'Bind a virtual service
Section titled “Bind a virtual service”autoStart defaults to true.
curl -X PUT https://app.maxoperf.com/v1/virtual-services/bindings \ -H "Authorization: Bearer <your-key>" \ -H "X-Account-Id: <account-id>" \ -H "Content-Type: application/json" \ -d '{ "testId": "tst-0123456789", "virtualServiceId": "vs-0123456789", "envVarName": "PAYMENTS", "autoStart": true }'The response includes injectedEnvName, here MAXOPERF_VS_PAYMENTS_URL.
Bind a tunnel
Section titled “Bind a tunnel”curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/dependencies/tunnels/tun-0000000001 \ -H "Authorization: Bearer <your-key>" \ -H "X-Account-Id: <account-id>" \ -H "Content-Type: application/json" \ -d '{ "envVarName": "SHOP" }'Bind a browser fleet
Section titled “Bind a browser fleet”curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/dependencies/browser-fleets/flt-0000000001 \ -H "Authorization: Bearer <your-key>" \ -H "X-Account-Id: <account-id>" \ -H "Content-Type: application/json" \ -d '{ "envVarName": "EU" }'The response lists the four injectedEnvNames. A fleet binding has no autoStart field.
Check what uses an entity
Section titled “Check what uses an entity”curl "https://app.maxoperf.com/v1/dependencies/usage?kind=secret&entityId=sec-0123456789" \ -H "Authorization: Bearer <your-key>" \ -H "X-Account-Id: <account-id>"kind is secret, virtual_service, tunnel or browser_fleet. The response lists the tests that
bind the entity with their variable names and origin, a hiddenCount for tests you cannot view, and
the liveRuns that hold it.
MCP tools
Section titled “MCP tools”| Tool | Use |
|---|---|
list_test_dependencies | Every binding a test has, plus a read-only data summary and shadowing warnings. |
bind_test_dependency | Bind a secret, virtual service, tunnel or browser fleet. env_var_name is required except for secrets. auto_start applies to virtual services only. |
unbind_test_dependency | Remove the test’s own manual binding. |
get_run_dependencies | A run’s leases, with state and timestamps. Secrets are not listed. |
get_dependency_usage | The tests and live runs that use an entity. Call it before you delete or stop one. |
set_eux_probe | Set or clear the browser test that runs next to a performance test. |
The full argument tables are on MCP tools.
The MaxoPerf skill
Section titled “The MaxoPerf skill”The MaxoPerf skill uses the same tools. When a test needs a credential, it creates the
workspace secret, binds it with bind_test_dependency and tells the script to read the resulting
variable instead of a literal. It checks get_dependency_usage before it deletes or stops a
dependency. It never repeats a secret’s value in the chat.
Inline chips and runtime placeholders
Section titled “Inline chips and runtime placeholders”In the HTTP request builder, click Use dependency beside the URL field and pick a virtual service or tunnel. The field then holds a chip instead of typed text, and a small Env var name field under it sets the stem. The binding appears on the Dependencies tab marked Used in the test model and is removed by editing the model, not from the tab. A browser step’s value field offers the same picker for virtual services and tunnels.
The builder writes a placeholder such as ${MAXOPERF_RUNTIME__MAXOPERF_VS_PAYMENTS_URL}.
Every runner exports each injected variable twice: under its own name, and under the same name with a
MAXOPERF_RUNTIME__ prefix. A script reads the plain name. The builder’s rendered requests use the
prefixed one. Prefer the chip to typing the placeholder yourself: it creates the binding, and a run
refuses to start with a 400 when a chip’s binding has been removed, instead of sending an unresolved
placeholder.
Next steps
Section titled “Next steps”- Worked example: a checkout test bound to every kind.
- Run-time behavior: what the leases show.