Skip to main content
Glama

Tommos

Make an API key

make_an_api_key

Make an API key for an agent with no person behind it, with only the scopes it needs. The secret is answered once and kept nowhere. A scope whose write only an admin grants (activities:write, settings:write, tommos:write) needs an admin or the owner.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesWhat the key is for, as the owner will read it in Settings
scopesYesThe scopes; a write scope includes its read
expires_in_daysNoDays until it stops working; leave out for a key that does not expire

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare non-readOnly, non-destructive, non-idempotent, so safety is covered. The description adds genuinely useful behaviour the annotations cannot carry: the secret is returned once and never stored, and writes on activities/settings/tommos scopes require an admin or owner. It stops short of describing what the response contains or whether the key can be re-fetched later.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, front-loaded with the purpose before the caveats. The phrasing ('answered once and kept nowhere') is slightly informal but carries meaning economically; nothing is redundant with the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with no output schema, the description covers the essential behaviour an agent needs: the one-time secret delivery and the permission gate on certain scopes. Missing only return-shape and expiry interaction detail, which is minor given the schema documents expires_in_days.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds meaning beyond it: it flags a subset of write scopes (activities:write, settings:write, tommos:write) as admin-granted, information present nowhere in the enum or the individual property descriptions. This materially helps scope selection.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Make an API key') and narrows scope to the agent-with-no-person case, which cleanly separates it from list_api_keys and revoke_an_api_key in the sibling set. An agent can identify the operation without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a clear condition for use ('for an agent with no person behind it, with only the scopes it needs') and a prerequisite for privileged write scopes (admin or owner). It does not explicitly name list_api_keys/revoke_an_api_key as the alternatives, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources