Get auth code for a domain
getAuthCodeGet auth code for a domain - Get auth code for a domain by id
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| x-trace-id | No | ||
| x-request-id | Yes |
getAuthCodeGet auth code for a domain - Get auth code for a domain by id
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| x-trace-id | No | ||
| x-request-id | Yes |
Changes observed during successful MCP inspections.
Input schema / properties / x-hapi-auth-stateRemoved value: -{
- "type": "string"
-}Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations declare destructiveHint=true and readOnlyHint=false, but the description adds no context about side effects, such as whether obtaining the code invalidates existing codes or requires domain transfer eligibility. It does not contradict the annotations, but it also provides no additional behavioral information.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is short but redundant, repeating the title twice. The two phrases convey nearly identical information, and the structure is not front-loaded with distinguishing details. It could be tighter and more informative in a single sentence.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the destructive hint and absence of an output schema, the description is incomplete. It doesn't state what the auth code is used for, how to identify the domain (by name or ID), or any prerequisites. The tool is more complex than the description suggests.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain any parameters. The mention of 'by id' is insufficient; the 'domain' parameter could be an ID or name, and the required headers (x-request-id) are entirely unexplained.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool retrieves an auth code for a domain, which is a specific verb+resource. However, the phrase 'by id' is ambiguous because the parameter is named 'domain' rather than 'domain_id', and the description is repetitive, restating the title without adding clarity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. Among siblings there are other domain-related operations (e.g., retrieveDomain, cancelDomain) but no mention of when an auth code is needed, prerequisites, or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.