Skip to main content
Glama

Criar dono

criar_dono

Cria o convidado (token edm_…, emitido pela biblioteca de conta) que abre alertas e vigias, e o segredo whsec_… que assina os webhooks. Sem cadastro; o token é mostrado uma única vez — guarde e mande em Authorization: Bearer nas tools de alerta e vigia. O token é emitido e assinado pela biblioteca de conta, com teto por rede e por hora, para a franquia grátis não virar infinita. Ele é mostrado uma única vez e não tem recuperação — entre na conta e traga as listas para ela (POST /api/auth/claim, que a página da conta faz sozinha ao entrar) para não depender dele. O webhook_segredo pode ser relido em GET /api/dono. Todo POST do webhook leva webhook-id, webhook-timestamp (segundos Unix) e webhook-signature: v1,<base64>: HMAC-SHA256 de id.timestamp.corpo com a chave do seu whsec_… (o base64 depois do prefixo). É o padrão Standard Webhooks — qualquer biblioteca dele confere; rejeite timestamp fora de 5 minutos. Depois de POST /api/dono/segredo, o anterior ainda assina por 24 h (duas partes v1, no cabeçalho).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations, it discloses substantial behavior: the token is shown only once with no recovery, it is rate-limited per network and per hour, the webhook secret can be re-read and rotated with a 24h dual-signature grace period, and it even specifies the webhook signature scheme and timestamp window. This is rich operational context well past what readOnlyHint/idempotentHint convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded, but the text is bloated: the HMAC-SHA256 construction of 'id.timestamp.corpo', the 5-minute timestamp rejection rule, and the Standard Webhooks library reference are receiver-side verification instructions, not guidance for invoking this tool. Much of the length does not earn its place for tool selection.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must explain the return artifacts, and it does: the 'edm_…' bearer token and the 'whsec_…' secret, including where the token goes (Authorization: Bearer) and how the secret is later retrieved. Nothing needed to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so there is nothing for the description to disambiguate. The baseline for a no-parameter tool is 4, and the description correctly explains the artifact returned rather than inventing parameter details.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening states a concrete verb and resource: it creates the guest owner credential — the 'edm_…' token that unlocks alerts and watches plus the 'whsec_…' webhook signing secret. This clearly maps to the criar_/dono family, though it never explicitly names which sibling to pick instead (e.g. dono, rotacionar_segredo_webhook).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It signals the context ('Sem cadastro') and advises storing the one-time token and later claiming lists via the account page so you don't depend on it. However, it never states explicitly when to choose this over siblings like dono (read) or rotacionar_segredo_webhook (rotate); usage is implied rather than routed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources