Skip to main content
Glama

Mint a new API key and retire the old one

rotate_key
Destructive

Get a fresh API key for the account this connection is already acting on — the answer to a key that has been lost, leaked, pasted into a chat window, or left on a machine that is not yours.

Two calls, on purpose. rotate_key({}) mints the new key and shows it once; it revokes nothing, so whatever is running on the old key keeps running. Give the new key to the person, wait until they tell you it is saved, then call rotate_key({ confirm_saved: true, revoke_key_id: "…" }) with the id from other_live_keys to kill the old one. Revoking first would take their integration down between the two calls, and revoking without asking would do it without them knowing why.

The key is shown once and cannot be recovered. Hand it over immediately and do not repeat it in any later message, summary, log or file.

Needs a key on the connection or a linked client — it cannot help somebody holding nothing. That case starts at create_account with the account's verified address, which mails a one-time code for link_account. Free, and it renders nothing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
confirm_savedNoLeave this off for the first call: it mints the new key and shows it once, and revokes nothing. Set it to `true` — together with `revoke_key_id` — only after the human has told you they have saved the new key somewhere they can read it again. That second call is what kills the old key.
revoke_key_idNoThe id of the key to revoke, taken from `other_live_keys` in the first call's answer. Required with `confirm_saved`. Never guess one: revoking the wrong key takes down whatever was using it.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description adds substantial behavior beyond the annotations: it's destructive (destructiveHint=true) only in the second call with confirm_saved, the key is shown once and cannot be recovered, and it does not revoke on the first call to avoid downtime. This is additional context that the annotations do not provide, directly aligning with the destructive hint.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured with bold headers and paragraphs, front-loading the key facts. It is concise despite its length, with each sentence earning its place, and it uses formatting to make the two-call process easy to follow.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of a two-call destructive operation with no output schema, the description is highly complete. It covers all necessary steps, pitfalls, and edge cases, including what to do when the user has no key. No missing information is apparent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents both parameters. However, the description adds crucial meaning: it explains the two-call sequence, the need to use the id from 'other_live_keys', and warns against guessing the id. This is a moderate addition over the schema, so a 4 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states a specific verb ('mint' and 'retire') and resource ('API key'), and distinguishes this tool from the sibling 'create_account' by explaining that it cannot help someone holding nothing. The title and description work together to convey the purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly says when to use the tool ('key has been lost, leaked...') and when not to ('Needs a key on the connection or a linked client — it cannot help somebody holding nothing. That case starts at create_account'). It also provides a detailed usage protocol for the two-call process, including the need to wait for confirmation before revoking.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources