Skip to main content
Glama

Bootstrap site

bootstrap_site
Idempotent

Use this to stand up a client, one website (project), and its forms in a single call. name/slug are the client; optional project_name/project_slug default to the same. Free accounts cannot create a fourth active project — call create_upgrade_link if bootstrap_site returns plan_limit. Operator tokens (all workspaces) must pass team_id from list_teams. Team-scoped tokens may omit team_id and cannot target another workspace. Idempotent on client, project, and form slugs. Site settings (domains, Turnstile, notify emails, webhook, email templates, uploads) live on the project. Email templates support {{project.name}}, {{project.slug}}, {{form.name}}, {{form.slug}}, {{count}} (1-based clean submissions on this form, including the current one), and any submission field such as {{name}} or {{email}}. Use a fallback with {{name | "New submission"}}. Missing fields render empty and never error. Do not pass HTML; Furrow renders one owned layout. Plans are capacity, not a feature ladder. Free: one workspace, 100 clean submissions/month pooled on the team, 3 active (non-archived) projects, 30-day submission retention, and email.footer_mode / branding.mode stay furrow. Yearly ($199/year): extra workspaces, 10,000 submissions/month, unlimited projects, 730-day retention, branding.mode furrow | off | agency. Expansion packs are $99/year each and add 5,000 submissions/month on a yearly account. MCP, webhooks, snippets, inheritance, Turnstile, and email templates stay available on free. Spam, honeypot, and rejected posts do not count. Use create_upgrade_link to hand a human a Stripe Checkout (or Customer Portal) URL. Pass product=expansion on a yearly team to add a pack. Checkbox groups, select multiple, and other multi-value HTML fields must use a [] suffix on the name (name="services[]") or only the last checked value is stored. Put services[] on field_contract.name too. JSON/fetch should send a real array without brackets ({ "services": ["a", "b"] }) and must not use Object.fromEntries(formData) — use formData.getAll("services"). Single checkbox, select, or combobox: no brackets. File inputs use multipart POST (name="resume[]" for multiple). Enable uploads on the project first. Downloads are the project inbox at files_url, with the form slug as a folder — never put that URL in a public snippet. Do not use when you only need to patch an existing form — call update_form.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesClient (company) display name.
slugYesLowercase hyphenated identifier, unique per team. Used for idempotent re-runs.
emailNoNotification email template for the project: subject, from_name, intro, footer_mode, include_meta.
formsNoForms to create or update on the site, matched by slug. Re-running is safe.
team_idNoTeam id from list_teams. Required for operator tokens and OAuth logins; team-scoped frw_ tokens may omit it.
from_nameNoLegacy From display name. Prefer email.from_name.
webhook_urlNoPublic https endpoint that receives a signed JSON POST per clean submission. Null disables it.
project_nameNoWebsite display name. Defaults to the client name.
project_slugNoWebsite slug. Defaults to the client slug.
notify_emailsNoAddresses that receive each clean submission (max 10). Inherited by every form.
honeypot_fieldNoName of the hidden honeypot input the snippet emits. Defaults to _gotcha.
webhook_secretNoHMAC-SHA256 secret for the X-Furrow-Signature header. Omit to have one generated and returned.
allowed_domainsNoHostnames allowed to post to this project's forms (example.com, www.example.com). Empty accepts any origin.
uploads_enabledNoAccept multipart file fields on this project's forms.
turnstile_secretNoCloudflare Turnstile secret used to verify tokens server-side. Null removes it.
upload_max_filesNoMax files per submission (up to 20).
rate_limit_per_ipNoMax submissions per IP within rate_limit_window_s.
require_turnstileNoReject submissions that lack a valid Turnstile token.
turnstile_site_keyNoCloudflare Turnstile site key for the frontend widget. Null removes it.
rate_limit_window_sNoRate-limit window in seconds (max 86400).
default_redirect_urlNoWhere classic HTML posts redirect after success. Null returns JSON/inline success instead.
upload_allowed_typesNoAllowed upload MIME types, e.g. application/pdf or image/*.
upload_max_file_bytesNoMax bytes per file (up to 25 MB).
upload_max_total_bytesNoMax total upload bytes per submission (up to 50 MB).

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only mark this as a mutating, idempotent call; the description fleshes out idempotency ('Idempotent on client, project, and form slugs'), plus auth, plan limits, token defaults, field-name bracket rules, and upload/download warnings. These are meaningful behaviors not visible in the annotations. No contradiction with readOnlyHint=false or idempotentHint=true.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose, but it is an unusually long block of prose with no structuring. Most sentences carry useful operational detail, yet some constraints (e.g., the [] suffix rule) duplicate schema descriptions, making it denser than strictly necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the large input schema and absence of an output schema, the description covers required auth, plan limits, idempotency, form-field semantics, uploads, and security warnings. It leaves the broader response shape unspecified beyond plan_limit and the webhook_secret generation noted in the schema, which is a minor gap for a resource-creating call.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is already high. The description adds value by explaining the name/slug client relationship, project_name/project_slug defaulting, team_id requirements, and crucial field-name array behavior for HTML vs JSON submissions beyond the individual schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific action and resource set: 'stand up a client, one website (project), and its forms in a single call.' It distinguishes this bundled tool from update_form by explicitly saying 'Do not use when you only need to patch an existing form.'

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit when-to-use ('Use this to stand up...'), a when-not rule ('Do not use when you only need to patch an existing form — call update_form'), and an error-path alternative ('call create_upgrade_link if bootstrap_site returns plan_limit'). It also specifies token scoping for team_id, which is a precondition for correct invocation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4/5.0
Disambiguation4/5

Most tools are clearly separated by resource and action (get_client vs list_clients vs create_client), and the descriptions explicitly warn against misuse. However, update_account and update_team both cover renaming a workspace/team, and get_account and get_project both return plan/usage/branding, creating a couple of genuinely confusing boundaries.

Naming Consistency4/5

The set overwhelmingly follows the snake_case verb_noun pattern: archive_client, create_form, get_submission, list_projects, rotate_project_inbox, test_webhook, etc. Minor deviations exist: bootstrap_site uses 'site' instead of 'project', update_team vs update_account introduces noun inconsistency, and upsert_project_webhook uses a different verb than the update_* family.

Tool Count2/5

With 27 tools, the server exceeds the 25-tool threshold that signals a too-large surface for an MCP server. While the broad scope (clients, projects, forms, submissions, teams, billing, webhooks) explains the count, there are redundant near-duplicates like update_account/update_team and bootstrap_site overlapping with multiple create tools, making the set feel bloated rather than curated.

Completeness3/5

The lifecycle coverage for clients, projects, and forms is solid with create, read, list, update, and archive operations. However, there is no unarchive (explicitly noted as unavailable), no submission management beyond read (no delete/export/update), and no webhook delivery history, leaving notable dead ends and gaps in the core workflow.