Skip to main content
Glama

Set embed origins

set_embed_origins
Destructive

Replace the project's embed allowlist — the hostnames permitted to load this project through the public embed. Pass the full desired list; it overwrites the previous one. An empty array turns embedding OFF (the public embed endpoint 404s the project). Each entry is normalized to a bare lowercased hostname (scheme, port, and path stripped, e.g. "https://example.com/x" → "example.com"); duplicates are dropped. Morpha sends the listed websites no request: the list decides which of them may load the project, so any page on an allowed host can show it. The embed serves only saved bookmarks (save_version), never unsaved edits, and leaves out who the project is shared with. Reference: https://morphareels.ai/docs/tools#setembedoriginsorigins

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
originsYesFull desired allowlist. Each entry may be a bare hostname or a URL; it is normalized to a bare lowercased hostname. Empty array disables embedding.
projectIdYesOpaque project id (a v4 UUID, from list_projects/create_project). Selects which existing project this call mutates.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYesWhether the call succeeded.
dataNoThe payload, shaped by the tool.
noteNoWhat to do next when not ready.
errorNoWhy it failed.
statusNoFor cache-backed readers: whether the answer was ready.
editorUrlNoOpens this project in the editor.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • removedInput schema / properties / anonymousToken
      Removed value: -{
      -  "description": "The token create_anonymous_account returned. This connection has no Morpha key, so every call carries it.",
      -  "type": "string"
      -}
    • changedInput schema / required
      Previous value: -[
      -  "origins",
      -  "projectId",
      -  "anonymousToken"
      -]New value: +[
      +  "origins",
      +  "projectId"
      +]
  2. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "description": "The result envelope every Morpha tool returns.",
      +  "properties": {
      +    "data": {
      +      "description": "The payload, shaped by the tool.",
      +      "type": [
      +        "object",
      +        "array",
      +        "string",
      +        "number",
      +        "boolean",
      +        "null"
      +      ]
      +    },
      +    "editorUrl": {
      +      "description": "Opens this project in the editor.",
      +      "type": "string"
      +    },
      +    "error": {
      +      "description": "Why it failed.",
      +      "type": "string"
      +    },
      +    "note": {
      +      "description": "What to do next when not ready.",
      +      "type": "string"
      +    },
      +    "ok": {
      +      "description": "Whether the call succeeded.",
      +      "type": "boolean"
      +    },
      +    "status": {
      +      "description": "For cache-backed readers: whether the answer was ready.",
      +      "enum": [
      +        "ready",
      +        "not-ready"
      +      ],
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "ok"
      +  ],
      +  "type": "object"
      +}
  3. Changed2 schema fields changed
    • addedInput schema / properties / anonymousToken
      Added value: +{
      +  "description": "The token create_anonymous_account returned. This connection has no Morpha key, so every call carries it.",
      +  "type": "string"
      +}
    • changedInput schema / required
      Previous value: -[
      -  "origins",
      -  "projectId"
      -]New value: +[
      +  "origins",
      +  "projectId",
      +  "anonymousToken"
      +]
  4. First observed

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already signal a destructive mutating call (destructiveHint=true, readOnlyHint=false), and the description adds substantial behavior beyond them: entry normalization (scheme/port/path stripped, lowercased, with concrete example), duplicate dropping, empty-array-disables-embedding (404), 'Morpha sends the listed websites no request,' and the embed serving only saved bookmarks (save_version) never unsaved edits. No contradiction with annotations — the destructive hint aligns with the overwrite semantics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but information-dense; every sentence adds a distinct fact (overwrite semantics, normalization rule, duplicate handling, off-behavior, security context, saved-versus-unsaved scoping). It is front-loaded with the core purpose before edge cases, and closes with a reference link. Slightly verbose but fully justified — no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given an output schema exists (so return values need not be explained) and annotations carry the destructive/safety profile, the description covers everything an agent needs: overwrite semantics, normalization behavior, the empty-array-off edge case, duplicate handling, security implications, and the saved-bookmark scoping. For a tool of this complexity it is essentially complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents both parameters in detail (normalization, empty-array meaning, opaque UUID projectId). The description adds modest incremental value over the schema — the concrete normalization example 'https://example.com/x' → 'example.com' and the duplicate-dropping note — but most parameter meaning is already carried by the schema, matching the baseline of 3.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a precise verb-resource pair: 'Replace the project's embed allowlist.' It distinguishes itself from the incremental siblings (add_embed_origin, remove_embed_origin) by emphasizing 'Pass the full desired list; it overwrites the previous one,' making the whole-list semantics unmistakable. An agent can select this tool over its add/remove counterparts without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'Pass the full desired list; it overwrites the previous one' clearly conveys that this is the replace-style variant, implicitly contrasting with incremental add/remove siblings. However, it never explicitly names add_embed_origin or remove_embed_origin nor states 'use this when you want to set the entire list at once,' so the routing is implied rather than spelled out — clear context, but no explicit exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources