A tool the flow was not granted is denied, not routed somewhere surprising. The fix is to grant it in deploy(..., tools=[...]) or in the capability manifest's tools allow-list, or remove the call. Two subtleties worth knowing: a missing grant section means unconstrained, but a present-but-empty section means deny-all, so an empty tools list blocks everything. Also, native tools are granted by tool name while MCP tools use server/tool format. If it works in dev but fails on deploy, check whether your dev deploy ran without a capability manifest while prod enforces one.

Context: My Julep deployment fails with CAP_TOOL_DENIED saying a tool is not granted. The tool works fine in dev. How do capability grants work?