Skip to main content
Glama

Attenuate a Macaroon

proof.attenuate
Read-onlyIdempotent

Attenuate an authentic, unexpired L402 parent macaroon by appending restrictive caveats and optionally ttlSeconds. At least one restriction is required. Requires its own L402 authorization; the parent's payment proof remains required for child redemption. Delegation cannot widen authority or reset an inherited quota.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
caveatsYesList of restriction caveats to append (e.g. ['time_before = 2026-12-31', 'max_target = 870000', 'allowed_tools = stratigraphy.get,stratigraphy.get_digest']). Existing allowed_path and max_requests restrictions are also supported. Constraints: maxItems: 16. Example: ["time_before = 2026-12-31","max_target = 870000","allowed_tools = stratigraphy.get,stratigraphy.get_digest"].
macaroonYesRequired authentic, unexpired parent L402 macaroon (1-8192 characters); caveats and ttlSeconds can only narrow its scope. Constraints: minLength: 1; maxLength: 8192. Example: "base64url-parent-macaroon".
ttlSecondsNoOptional positive integer TTL of 1-2592000 seconds (e.g. 3600); appends an expiration caveat without extending the parent's expiry. Constraints: minimum: 1; maximum: 2592000. Example: 3600.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYesSuccessful attenuation status. Example: "attenuated".
issuedAtYesUTC issuance timestamp. Constraints: format: date-time. Example: "2026-09-27T21:00:00.000Z".
appliedCaveatsYesNew canonical caveats appended to the parent; inherited caveats are preserved inside the token. Example: ["max_target=870000"].
attenuatedMacaroonYesEncoded child subscription macaroon. Treat as a bearer credential. Example: "base64url-child-macaroon".

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed4 schema fields changed
    • changedInput schema / examples
      Previous value: -[
      -  {
      -    "caveats": [
      -      "allowed_tools = stratigraphy.get,stratigraphy.digest",
      -      "max_target = 870000"
      -    ],
      -    "macaroon": "base64url-parent-macaroon",
      -    "ttlSeconds": 3600
      -  }
      -]New value: +[
      +  {
      +    "caveats": [
      +      "allowed_tools = stratigraphy.get,stratigraphy.get_digest",
      +      "max_target = 870000"
      +    ],
      +    "macaroon": "base64url-parent-macaroon",
      +    "ttlSeconds": 3600
      +  }
      +]
    • changedInput schema / properties / caveats / description
      Previous value: -"List of restriction caveats to append (e.g. ['time_before = 2026-12-31', 'max_target = 870000', 'allowed_tools = stratigraphy.get,stratigraphy.digest']). Existing allowed_path and max_requests restrictions are also supported. Constraints: maxItems: 16. Example: [\"time_before = 2026-12-31\",\"max_target = 870000\",\"allowed_tools = stratigraphy.get,stratigraphy.digest\"]."New value: +"List of restriction caveats to append (e.g. ['time_before = 2026-12-31', 'max_target = 870000', 'allowed_tools = stratigraphy.get,stratigraphy.get_digest']). Existing allowed_path and max_requests restrictions are also supported. Constraints: maxItems: 16. Example: [\"time_before = 2026-12-31\",\"max_target = 870000\",\"allowed_tools = stratigraphy.get,stratigraphy.get_digest\"]."
    • changedInput schema / properties / caveats / example
      Previous value: -[
      -  "time_before = 2026-12-31",
      -  "max_target = 870000",
      -  "allowed_tools = stratigraphy.get,stratigraphy.digest"
      -]New value: +[
      +  "time_before = 2026-12-31",
      +  "max_target = 870000",
      +  "allowed_tools = stratigraphy.get,stratigraphy.get_digest"
      +]
    • changedInput schema / properties / caveats / examples
      Previous value: -[
      -  [
      -    "time_before = 2026-12-31",
      -    "max_target = 870000",
      -    "allowed_tools = stratigraphy.get,stratigraphy.digest"
      -  ]
      -]New value: +[
      +  [
      +    "time_before = 2026-12-31",
      +    "max_target = 870000",
      +    "allowed_tools = stratigraphy.get,stratigraphy.get_digest"
      +  ]
      +]
  2. Changed3 schema fields changed
    • changedInput schema / description
      Previous value: -"Derive a narrower child of an authentic, unexpired subscription macaroon; this delegation call does not issue a payment invoice."New value: +"Provide an authentic parent macaroon, an array of restrictions, and optional TTL; child caveats intersect with inherited constraints and no payment invoice is issued."
    • changedInput schema / properties / macaroon / description
      Previous value: -"Base L402 Macaroon string to attenuate. Constraints: minLength: 1; maxLength: 8192. Example: \"base64url-parent-macaroon\"."New value: +"Required authentic, unexpired parent L402 macaroon (1-8192 characters); caveats and ttlSeconds can only narrow its scope. Constraints: minLength: 1; maxLength: 8192. Example: \"base64url-parent-macaroon\"."
    • changedInput schema / properties / ttlSeconds / description
      Previous value: -"Optional time-to-live in seconds to automatically append an expiration caveat. Must be a positive integer of at most 30 days. Constraints: minimum: 1; maximum: 2592000. Example: 3600."New value: +"Optional positive integer TTL of 1-2592000 seconds (e.g. 3600); appends an expiration caveat without extending the parent's expiry. Constraints: minimum: 1; maximum: 2592000. Example: 3600."
  3. Added

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations cover safety (readOnlyHint, idempotentHint, destructiveHint=false), but the description adds context annotations cannot express: the operation requires its own L402 authorization, the parent's payment proof is still needed for child redemption, and delegation cannot widen authority or reset an inherited quota. That narrowing/authority semantics is genuinely useful behavioral disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four short sentences, front-loaded with the core action and followed by requirements and constraints. Only minor redundancy, since 'At least one restriction is required' restates the required caveats array from the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return values need no explanation, and the description covers the auth requirement, restriction minimum, and non-widening rule. It is essentially complete for a 3-param credential-derivation tool, with only the missing sibling routing as a gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already documents caveat format, array limits, macaroon constraints, and TTL bounds. The description reinforces the narrowing semantics ('cannot widen authority or reset an inherited quota') but adds no format or syntax detail beyond the schema, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('attenuate') and resource ('L402 parent macaroon'), then defines the operation precisely as appending restrictive caveats plus optional TTL. This is clearly distinct from proof.verify, proof.ground, or proof.submit; an agent can place it without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives real preconditions ('At least one restriction is required', 'Requires its own L402 authorization') which function as when-to-use guidance. However, it never contrasts with sibling tools (proof.verify, proof.ground) or says when attenuation is the wrong choice, so usage remains implied rather than routed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources