Skip to main content
Glama

Create a polymorphic read-only embed link

embed_links_create

The capability URL is returned once; only its secret hash is stored.

POST /api/v1/embed-links

For multi-space accounts, call auth_verify, ask the user which space to use, and pass targetSpaceId. Create an embed link only when the user explicitly asks to share or preview that node. The returned URL is a bearer capability: reveal or open it only when the user requests that action.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
typeYes
typeIdYes
framePolicyNo
targetSpaceIdNoBusabase space id. Call auth_verify first and ask the user which space to use when more than one is returned.
expiresInMinutesNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations provide no behavioral details (readOnlyHint false, destructiveHint false are consistent with a creation tool), so the description carries the burden. It adds valuable security context beyond annotations: the URL is returned once and only its secret hash is stored, and the returned URL is a bearer capability that should be revealed only on user request. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is tight at four sentences and front-loads the most critical security fact (one-time URL, hash storage). The 'POST /api/v1/embed-links' line is mildly redundant with the tool name but adds concrete API context. Slightly more structure could help, but there is no waste.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description appropriately states the return semantics ('The capability URL is returned once'). It covers the multi-space auth flow, the bearer-capability handling, and when to create. The complex framePolicy parameter is well-documented in the schema itself with defaults, so the description doesn't need to repeat it. A complete definition for a create tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 20% (only targetSpaceId documented), so the description must compensate. It does clarify targetSpaceId ('pass targetSpaceId' after auth_verify) and hints at the type semantics via 'polymorphic.' However, it adds nothing about framePolicy (a complex nested anyOf) or expiresInMinutes, leaving those to the schema's structural definition. Partial compensation only.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The title and description clearly state a specific action (create) on a specific resource (embed link) with a clarifying scope qualifier (polymorphic read-only). The description reinforces purpose with 'Create an embed link only when the user explicitly asks to share or preview that node.' It naturally distinguishes from siblings embed_links_list and embed_links_revoke via the create/list/revoke lifecycle.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit when-to-use guidance: 'Create an embed link only when the user explicitly asks to share or preview that node,' and details the auth prerequisite for multi-space accounts ('call auth_verify, ask the user which space to use'). It doesn't explicitly name sibling alternatives, but the create-versus-list/revoke distinction is self-evident from the lifecycle verbs.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.