Skip to main content
Glama

Update Project Metadata

update_project_metadata

Update project settings (current values appear at the top of list_files). Keys: title (2-100 chars), description, iconUrl (the app's icon/logo: favicon, home-screen icon and native app icon — a /_cdn/static/… path from upload_asset, generate_image or request_user_upload, or an absolute https URL; null resets), splashUrl (native splash screen, same value forms), mobileAppId, enableSSR (boolean), flootAiDisallowed (boolean — true opts the project out of @floot/ai), and iOS Info.plist purpose strings (NS…UsageDescription — set to a string, or null to remove) plus boolean Info.plist keys (UIViewControllerBasedStatusBarAppearance — set to a boolean, or null to restore the template default). Invalid keys/values are reported and skipped. NOTE: these take effect on the published app only after the next publish (publish_app, or the user's Publish button). The iosInfoPlist keys only affect builds made before the first iOS publish; after the iOS app is published, edit the project file static/__dev/native/ios-info.plist directly with write_file/edit_file (see get_guides('ios-info-plist')). Likewise, after the first Android publish, edit static/__dev/native/android-manifest.xml directly for manifest changes (see get_guides('android-manifest')). shareTarget makes the native app appear in the iOS and Android share sheets (other apps can share photos/videos/files/text into it): pass { enabled: true, mimeTypes?, allowMultiple? } to register, { enabled: false } to remove; receiving the shared items still needs the handler in app code — read get_guides('share-target') first and ship both together. nativeSystemBars controls how the native app treats the status bar / Android navigation bar: mode 'inset' (default) keeps the app below the bars and paints the exposed strips color (default black — set it to the app's header color for a seamless look); mode 'edge-to-edge' runs the app under the bars, which REQUIRES the app to pad by var(--safe-area-inset-top/bottom) itself — read get_guides('native-system-bars') first and ship both changes together. Not superseded by the __dev/native files. serverMemoryMb sets the memory (MB) of the project's server Lambda, which runs every endpoint, queued task, scheduled job and SSR render (default 1024 MB; 2048 for the published app when SSR is on — the dev backend never bumps). EXPERT SETTING — NEVER change it on your own initiative or as a side effect of another request, only when the user explicitly asks to change the server memory AND understands the trade-off: too low and the backend stops working entirely (killed out-of-memory); Lambda CPU scales with memory, so a lower value also makes every request slower and — because compute is billed per GB-second of billed duration — can cost MORE, not less; a higher value costs more per millisecond. Allowed range 512–4096 MB, whole MB (if a size turns out not to be available for the app's server, the deploy fails and the error names this setting). It applies to the dev backend at the next backend deploy and to the published app at the next publish. Pass null to restore the default. Read get_guides('server-memory') before changing it. analyticsMode controls the built-in visitor analytics tracker every published app includes (the project's Analytics tab): 'storage' (default) keeps a 30-minute session id in the visitor's localStorage, which is device storage that needs consent under EU ePrivacy / UK PECR — an app with EU/UK visitors pairs it with a consent banner that calls window.flootAnalytics.setMode(); 'memory' keeps the id in memory only (nothing stored on the device, no consent needed, but a reload or new tab counts as a new session); 'off' sends no analytics at all. Only change it when the user asks about analytics, cookies, consent or privacy for their published app; it takes effect at the next publish. Read get_guides('analytics') for the consent-banner API before changing it. iosDeviceFamily picks the devices the native iOS app is built for: 'iphone-and-ipad' (default, universal) or 'iphone' (iPhone only — the app still installs on iPads but runs there in iPhone compatibility mode, and App Store Connect no longer asks for iPad screenshots). This is the ONLY way to make the app iPhone-only: it is an Xcode build setting, so a UIDeviceFamily key in static/__dev/native/ios-info.plist is overwritten at build and does nothing. One-way door: App Store Connect rejects an update that drops iPad once a version supporting iPad has been released on the App Store, and the build then fails at upload. Before setting 'iphone', ask the user whether the app is already live on the App Store; if it is, tell them it cannot be made iPhone-only and do not set it. Takes effect at the next iOS publish. securityHeaders sets the published app's own page headers: embedding (who may show the app in an iframe: 'anyone' (default), 'self', 'none', or a list of https origins), csp (directive -> the COMPLETE source list for it, replacing the platform's; other directives keep the platform's), cspReportOnly (try csp without enforcing it) and referrerPolicy. Each field passed replaces the stored one and null removes it (inside csp, per directive); securityHeaders: null restores the platform defaults. Changes that would break the app are refused with the reason. Change it only when the user asks about embedding / iframes / clickjacking, a security scan finding, a stricter or looser Content-Security-Policy, or referrer privacy; it takes effect at the next publish and never in the preview. Read get_guides('security-headers') before changing it.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
updatesNoFlat metadata fields (see the tool description).
projectIdYes
shareTargetNoShare-sheet target config (iOS Share Extension + Android share sheet). Omit to leave unchanged; { enabled: false } removes it.
analyticsModeNoBuilt-in visitor analytics mode for the published app: 'storage' (default, session id in localStorage — needs a consent banner for EU/UK visitors), 'memory' (nothing stored on the device, no consent needed) or 'off' (no analytics). Omit to leave unchanged.
serverMemoryMbNoMemory (MB) of the project's server Lambda, 512–4096. EXPERT SETTING: only on an explicit user request to change the server memory (see the tool description for the risks); never touch it otherwise. Omit to leave unchanged; null restores the platform default.
iosDeviceFamilyNoDevices the native iOS app is built for: 'iphone-and-ipad' (default) or 'iphone' (iPhone only). Not possible for an app already released on the App Store with iPad support. Omit to leave unchanged.
securityHeadersNoThe published app's own page headers. Omit to leave unchanged; null restores the platform defaults. Fields: embedding ('anyone' | 'self' | 'none' | list of https origins), csp ({ directive: [complete source list] } replacing the platform's for that directive; a directive set to null goes back to the platform's), cspReportOnly (boolean), referrerPolicy. A field passed as null is removed; a field left out is kept.
nativeSystemBarsNoNative system-bars config. Omit to leave unchanged; { mode: 'inset' } with no color restores the default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / securityHeaders
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": false,
      +      "properties": {
      +        "csp": {
      +          "anyOf": [
      +            {
      +              "additionalProperties": {
      +                "anyOf": [
      +                  {
      +                    "items": {
      +                      "type": "string"
      +                    },
      +                    "type": "array"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ]
      +              },
      +              "type": "object"
      +            },
      +            {
      +              "type": "null"
      +            }
      +          ],
      +          "description": "Directive -> its COMPLETE source list, replacing the platform's for that directive, e.g. { \"form-action\": [\"'self'\"] }. A directive set to null goes back to the platform's; directives left out are kept."
      +        },
      +        "cspReportOnly": {
      +          "description": "true: send `csp` as Content-Security-Policy-Report-Only (nothing blocked) to try it on the published app first.",
      +          "type": [
      +            "boolean",
      +            "null"
      +          ]
      +        },
      +        "embedding": {
      +          "anyOf": [
      +            {
      +              "anyOf": [
      +                {
      +                  "enum": [
      +                    "anyone",
      +                    "self",
      +                    "none"
      +                  ],
      +                  "type": "string"
      +                },
      +                {
      +                  "items": {
      +                    "type": "string"
      +                  },
      +                  "type": "array"
      +                }
      +              ]
      +            },
      +            {
      +              "type": "null"
      +            }
      +          ],
      +          "description": "'anyone' (default), 'self', 'none', or a list of https origins (own origin always included)."
      +        },
      +        "referrerPolicy": {
      +          "anyOf": [
      +            {
      +              "enum": [
      +                "no-referrer",
      +                "no-referrer-when-downgrade",
      +                "origin",
      +                "origin-when-cross-origin",
      +                "same-origin",
      +                "strict-origin",
      +                "strict-origin-when-cross-origin",
      +                "unsafe-url"
      +              ],
      +              "type": "string"
      +            },
      +            {
      +              "type": "null"
      +            }
      +          ]
      +        }
      +      },
      +      "type": "object"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "description": "The published app's own page headers. Omit to leave unchanged; null restores the platform defaults. Fields: embedding ('anyone' | 'self' | 'none' | list of https origins), csp ({ directive: [complete source list] } replacing the platform's for that directive; a directive set to null goes back to the platform's), cspReportOnly (boolean), referrerPolicy. A field passed as null is removed; a field left out is kept."
      +}
  2. Changed1 schema field changed
    • addedInput schema / properties / iosDeviceFamily
      Added value: +{
      +  "description": "Devices the native iOS app is built for: 'iphone-and-ipad' (default) or 'iphone' (iPhone only). Not possible for an app already released on the App Store with iPad support. Omit to leave unchanged.",
      +  "enum": [
      +    "iphone-and-ipad",
      +    "iphone"
      +  ],
      +  "type": "string"
      +}
  3. Changed1 schema field changed
    • addedInput schema / properties / analyticsMode
      Added value: +{
      +  "description": "Built-in visitor analytics mode for the published app: 'storage' (default, session id in localStorage — needs a consent banner for EU/UK visitors), 'memory' (nothing stored on the device, no consent needed) or 'off' (no analytics). Omit to leave unchanged.",
      +  "enum": [
      +    "storage",
      +    "memory",
      +    "off"
      +  ],
      +  "type": "string"
      +}
  4. Changed1 schema field changed
    • addedInput schema / properties / serverMemoryMb
      Added value: +{
      +  "anyOf": [
      +    {
      +      "anyOf": [
      +        {
      +          "type": "integer"
      +        },
      +        {
      +          "type": "string"
      +        }
      +      ]
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "description": "Memory (MB) of the project's server Lambda, 512–4096. EXPERT SETTING: only on an explicit user request to change the server memory (see the tool description for the risks); never touch it otherwise. Omit to leave unchanged; null restores the platform default."
      +}
  5. Changed1 schema field changed
    • addedInput schema / properties / shareTarget
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "Share-sheet target config (iOS Share Extension + Android share sheet). Omit to leave unchanged; { enabled: false } removes it.",
      +  "properties": {
      +    "allowMultiple": {
      +      "description": "Also accept multi-select shares. Default true.",
      +      "type": "boolean"
      +    },
      +    "enabled": {
      +      "type": "boolean"
      +    },
      +    "mimeTypes": {
      +      "description": "MIME patterns to accept, e.g. [\"image/*\",\"video/*\"] (default). Allowed: image/*, video/*, audio/*, text/plain, application/pdf.",
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    }
      +  },
      +  "required": [
      +    "enabled"
      +  ],
      +  "type": "object"
      +}
  6. Changed1 schema field changed
    • removedInput schema / properties / shareTarget
      Removed value: -{
      -  "additionalProperties": false,
      -  "description": "Share-sheet target config (iOS Share Extension + Android share sheet). Omit to leave unchanged; { enabled: false } removes it.",
      -  "properties": {
      -    "allowMultiple": {
      -      "description": "Also accept multi-select shares. Default true.",
      -      "type": "boolean"
      -    },
      -    "enabled": {
      -      "type": "boolean"
      -    },
      -    "mimeTypes": {
      -      "description": "MIME patterns to accept, e.g. [\"image/*\",\"video/*\"] (default). Allowed: image/*, video/*, audio/*, text/plain, application/pdf.",
      -      "items": {
      -        "type": "string"
      -      },
      -      "type": "array"
      -    }
      -  },
      -  "required": [
      -    "enabled"
      -  ],
      -  "type": "object"
      -}
  7. Changed1 schema field changed
    • addedInput schema / properties / shareTarget
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "Share-sheet target config (iOS Share Extension + Android share sheet). Omit to leave unchanged; { enabled: false } removes it.",
      +  "properties": {
      +    "allowMultiple": {
      +      "description": "Also accept multi-select shares. Default true.",
      +      "type": "boolean"
      +    },
      +    "enabled": {
      +      "type": "boolean"
      +    },
      +    "mimeTypes": {
      +      "description": "MIME patterns to accept, e.g. [\"image/*\",\"video/*\"] (default). Allowed: image/*, video/*, audio/*, text/plain, application/pdf.",
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    }
      +  },
      +  "required": [
      +    "enabled"
      +  ],
      +  "type": "object"
      +}
  8. Changed3 schema fields changed
    • addedInput schema / properties / nativeSystemBars
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "Native system-bars config. Omit to leave unchanged; { mode: 'inset' } with no color restores the default.",
      +  "properties": {
      +    "color": {
      +      "description": "Inset mode only: #rrggbb paint of the strips under the bars. Default #000000.",
      +      "type": "string"
      +    },
      +    "iconStyle": {
      +      "description": "Color of the bar ICONS. Inset: defaults to contrast with `color`. Edge-to-edge: defaults to 'dark'.",
      +      "enum": [
      +        "light",
      +        "dark"
      +      ],
      +      "type": "string"
      +    },
      +    "mode": {
      +      "enum": [
      +        "inset",
      +        "edge-to-edge"
      +      ],
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "mode"
      +  ],
      +  "type": "object"
      +}
    • addedInput schema / properties / updates / description
      Added value: +"Flat metadata fields (see the tool description)."
    • changedInput schema / required
      Previous value: -[
      -  "projectId",
      -  "updates"
      -]New value: +[
      +  "projectId"
      +]
  9. First observed

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only say readOnlyHint=false/destructiveHint=false; the description discloses far more: changes apply on next publish not now, invalid keys are reported and skipped, iosDeviceFamily is a one-way door that can fail at App Store upload, securityHeaders changes that would break the app are refused, and several settings require coordinated app-code changes. This is rich behavioral context beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose is front-loaded and every topic is relevant, but the description is a single unbroken wall of text and re-explains several settings (analyticsMode, serverMemoryMb, iosDeviceFamily, securityHeaders) that the schema already documents in detail, so a meaningful share of the length is redundant. Given the genuine complexity of an 8-parameter tool, the size is defensible but the structure is not.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex, high-risk mutation tool with no output schema, the description covers deploy timing, prerequisites (get_guides), failure modes, null/reset semantics and cross-file caveats, so an agent has everything needed to invoke it safely. No return-value documentation is required since there is no output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is already 88%, but the generic `updates` flat object carries no per-key meaning on its own, and the description supplies it: title length bounds, iconUrl/splashUrl accepted value forms, null-to-reset semantics, boolean key behavior, and the full shape/meaning of shareTarget, nativeSystemBars, securityHeaders and analyticsMode beyond the schema text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Update project settings') and then enumerates the exact keys that can be changed, with a pointer to where current values live (list_files). It distinguishes itself from siblings by referencing publish_app, write_file/edit_file, upload_asset, generate_image and request_user_upload for adjacent tasks.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit when/when-not rules for the risky settings: 'EXPERT SETTING — NEVER change it on your own initiative', 'Only change it when the user asks about analytics, cookies, consent or privacy', 'Change it only when the user asks about embedding / iframes'. It also routes the agent to alternatives (edit static/__dev/native/*.plist directly after first publish, read get_guides first) so the agent knows when another tool is correct.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources