Skip to main content
Glama

Replace my bearer token

rotate_token
Destructive

Replace your passport bearer token (for example after it leaked). The old token stops working at once; the new token is returned ONCE, so update your Authorization header right away. Needs a request signed with a passport key: a token (header or passport_token) is refused with signature_required, so a leaked token can never do this. A passport your MCP app signed in for has no bearer token and never gets one (app_sign_in_only): the app keeps the sign-in, out of your context.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
passport_tokenNoYour amp_ token, only if your client cannot send it as an Authorization header; leave it out when your MCP app signed in.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • addedInput schema / additionalProperties
      Added value: +false
    • changedInput schema / properties / passport_token / description
      Previous value: -"Leave it out when your MCP app signed in to AgentMart (it is refused then). Otherwise your passport bearer token (amp_...) or session token (amp_s_...), only if your client cannot send it as an Authorization header. A token here sits in your context, so it never authorizes sensitive actions."New value: +"Your amp_ token, only if your client cannot send it as an Authorization header; leave it out when your MCP app signed in."
  2. First observed

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag destructive/non-idempotent, but the description adds substantial behavior the annotations cannot convey: the old token dies immediately, the new token is returned only ONCE, the call requires a signed request with a passport key, and a leaked token is refused with signature_required. These are exactly the consequences an agent must know before invoking.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the action and its consequence, then the authentication constraint, then the app_sign_in_only edge case. Dense but every sentence carries distinct information; no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description compensates by explaining what is returned (the new token, exactly once) and the immediate invalidation of the old one. Combined with the auth/error conditions, an agent has everything needed to call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and the single passport_token parameter is already fully documented in the schema, including the header-vs-token fallback. The description largely restates that guidance, so the schema does the heavy lifting and baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Replace your passport bearer token') and adds the motivating scenario ('for example after it leaked'). It is clearly distinguishable from sibling passport tools like create_passport, revoke_passport, and remove_passport.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear usage context (after a leak) and an explicit when-not case: passports signed in via an MCP app have no bearer token and 'never get one (app_sign_in_only)'. It stops short of naming an alternative tool, so it is clear context rather than full routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources