Skip to main content
Glama

Rotate Webhook Secret

rotate_webhook_secret

Replace a webhook signing secret. The new secret is shown only in this response; update the receiver before relying on further deliveries.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
webhook_idYes
organization_idNoPlatform admins only: select an organization for this operation. Required when changing another organization’s study or using its wallet.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYesThe webhook and its newly rotated signing secret.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / organization_id
      Added value: +{
      +  "description": "Platform admins only: select an organization for this operation. Required when changing another organization’s study or using its wallet.",
      +  "maxLength": 128,
      +  "minLength": 1,
      +  "type": "string"
      +}
  2. Changed10 schema fields changed
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • removedInput schema / additionalProperties
      Removed value: -false
    • addedInput schema / properties / webhook_id / pattern
      Added value: +"^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
    • changedOutput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • changedOutput schema / properties / result / additionalProperties
      Previous value: -trueNew value: +{}
    • removedOutput schema / properties / result / properties / signing_secret / $ref
      Removed value: -"#/properties/result/properties/study_id"
    • addedOutput schema / properties / result / properties / signing_secret / type
      Added value: +[
      +  "string",
      +  "null"
      +]
    • removedOutput schema / properties / result / properties / updated_at / $ref
      Removed value: -"#/properties/result/properties/created_at"
    • addedOutput schema / properties / result / properties / updated_at / description
      Added value: +"ISO 8601 timestamp."
    • addedOutput schema / properties / result / properties / updated_at / type
      Added value: +[
      +  "string",
      +  "null"
      +]
  3. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare non-read-only, non-idempotent, non-destructive, open-world. The description adds genuinely non-obvious behavior beyond them: the new secret is shown only once and the receiver must be updated, a one-time-reveal trait an agent must act on. It omits whether the previous secret is invalidated immediately or during a grace period, which matters for a rotation tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two tight sentences with zero waste; the core action is front-loaded and the critical one-time-reveal caveat follows immediately.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return values need not be re-explained, and the description still usefully notes the secret appears in the response. For a single-required-parameter mutation it covers purpose, reveal semantics and follow-up, missing only old-secret validity and permission scope.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 50% and the description adds no parameter detail at all. The covered parameter (organization_id) is well documented in-schema, and webhook_id is self-evident from its uuid format, so the baseline of 3 applies rather than a penalty.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Replace a webhook signing secret') that unambiguously identifies the operation. No sibling tool performs secret rotation, so it is clearly distinguishable from create_webhook/delete_webhook/update-style siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The second sentence gives operational context: the secret is revealed only in this response and the receiver must be updated before relying on further deliveries, which is effectively guidance on when this must be followed up. It stops short of stating explicit when-to-use vs when-not-to-rotate conditions or permission prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources