Get auth code for a domain
getAuthCodeGet auth code for a domain - Get auth code for a domain by id
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| x-trace-id | No | ||
| x-request-id | Yes |
getAuthCodeGet auth code for a domain - Get auth code for a domain by id
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| x-trace-id | No | ||
| x-request-id | Yes |
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Input schema / properties / x-hapi-auth-stateRemoved value: -{
- "type": "string"
-}Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations declare destructiveHint=true and readOnlyHint=false, but the description adds no context about side effects, such as whether obtaining the code invalidates existing codes or requires domain transfer eligibility. It does not contradict the annotations, but it also provides no additional behavioral information.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is short but redundant, repeating the title twice. The two phrases convey nearly identical information, and the structure is not front-loaded with distinguishing details. It could be tighter and more informative in a single sentence.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the destructive hint and absence of an output schema, the description is incomplete. It doesn't state what the auth code is used for, how to identify the domain (by name or ID), or any prerequisites. The tool is more complex than the description suggests.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain any parameters. The mention of 'by id' is insufficient; the 'domain' parameter could be an ID or name, and the required headers (x-request-id) are entirely unexplained.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool retrieves an auth code for a domain, which is a specific verb+resource. However, the phrase 'by id' is ambiguous because the parameter is named 'domain' rather than 'domain_id', and the description is repetitive, restating the title without adding clarity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. Among siblings there are other domain-related operations (e.g., retrieveDomain, cancelDomain) but no mention of when an auth code is needed, prerequisites, or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
Many tools have clearly distinct CRUD roles per resource, but there are several confusing overlaps: start/stop/restart/shutdown/rescue are similar lifecycle actions, and there are duplicate audit tools like retrieveImageAuditsList and retrieveImageAuditsList1 (one even mislabeled as DNS Zones audit). Additionally, retrieveTagAuditsList appears to duplicate retrieveAssignmentsAuditsList, and updateDnsZoneRecord incorrectly says 'Create resource record'. These overlaps and mislabeled descriptions make it hard to pick the right tool.
The naming is a mix of camelCase verb_noun patterns, but inconsistent. Some tools use 'retrieveXList' while others use 'listX', some use 'Cancel' with a capital letter, and 'tool_search' uses snake_case. Numeric suffixes like 'retrieveImageAuditsList1' and verbs like 'patchInstance' instead of 'updateInstance' further break consistency.
With 124 tools, this is an extremely large tool surface for an MCP server. Even for a broad cloud provider API, this overwhelms an agent's context and selection capabilities. The number far exceeds reasonable scoping and creates unnecessary selection overhead.
The tool set covers a wide range of resources thoroughly: instances, snapshots, images, private networks, object storage, DNS, domains, tags, roles, users, secrets, and audits. Most resources have create/retrieve/update/delete lifecycle operations, and there are extensive audit history tools. Minor gaps exist (e.g., no explicit instance deletion besides cancel, no separate firewall management beyond upgradeInstance), but overall the surface is quite complete for its domain.