Skip to main content
Glama

Agentic Keychain

Unlock a purchased capability

unlock_capability
Idempotent

Exchange the license key from the checkout (a purchase requires operator approval) for a signed entitlement and a download link that lasts at most 15 minutes. How the key is handled: the privacy page at /legal/privacy/. Repeating it with the same key is safe and never charges.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
quote_idNoThe quote_id of the quote the purchase followed, if any (links the records; never changes the price).
capabilityYesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
license_keyYesLicense key from the checkout.
evaluation_idNoThe evaluation_id from evaluate_capability, if you evaluated first.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare idempotentHint=true and destructiveHint=false, but the description adds materially new traits: the download link expires in at most 15 minutes, repeating never charges, and key handling is governed by a privacy policy URL. This is real behavior beyond the structured hints, though the redundant 'repeating is safe' overlaps idempotentHint.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action, which is good, but the middle sentence 'How the key is handled: the privacy page at /legal/privacy/' is a fragment that names a topic without explaining it and could be dropped or rewritten. Two of three sentences earn their place; one does not.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description usefully describes the return ('a signed entitlement and a download link'), its time limit, and the approval prerequisite. For a mutation tool it covers the essentials, though it says nothing about failure modes (invalid/expired key) or the operator-approval workflow details.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters including the quote_id linking behavior and evaluation_id pattern. The description only restates that the license key comes from checkout, adding no syntax or format meaning beyond the schema. Baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Exchange the license key ... for a signed entitlement and a download link') and pins the scope ('from the checkout'). This is clearly distinguishable from siblings such as get_capability or evaluate_capability, which retrieve/inspect rather than unlock.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when this applies: after a purchase (which requires operator approval), and it references the evaluation path via evaluation_id in the schema. It stops short of naming explicit exclusions or a named alternative tool, so it lands at 4 rather than 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources