Skip to main content
Glama

Manage Webhook Destinations

gnosari_manage_webhooks
Destructive

Manage outbound webhook destinations for the account.

Actions: list, get, create, update, activate, deactivate, delete, deliveries (the paginated, newest-first attempt history with outcome and failure reason per attempt -- use it to diagnose failures).

Event kinds are returned with a display name and one-line description each, so they can be reported to the user without interpreting raw topic ids.

The signing secret is NEVER returned by this tool and cannot be read through it -- view and copy it in the dashboard destination view at /settings/webhooks/{id}.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlNoDelivery endpoint address, http(s) (create/update). Unsafe addresses (internal networks, unsupported schemes) are refused by the delivery-core URL guard with the reason relayed
limitNoPage size for deliveries (default 20, max 100)
actionYesAction to perform on webhook destinations
activeNoSet the active flag directly (update only; prefer the activate/deactivate actions)
offsetNoPagination offset for deliveries
statusNoFilter delivery history by outcome (deliveries)
confirmedNoMust be true to actually delete (delete only). Ask the user to confirm first
webhook_idNoDestination ID (get/update/activate/deactivate/delete/deliveries)
event_kindsNoTopic ids to subscribe to (create/update), e.g. ['data.collected', 'data.updated']
include_provenanceNoInclude verbatim conversation quotes and message references in deliveries to this destination (create/update). Default false; omit on update to leave unchanged

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and readOnlyHint=false, so the safety profile is covered; the description adds real value beyond them by disclosing that the signing secret is never returned, that event kinds come back with display names and descriptions, and that deliveries are paginated newest-first with outcome and failure reason. It stops short of stating that delete is irreversible or that activate/deactivate are the preferred path, which the schema covers.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the purpose, then the action list, then two short clarifying notes; every sentence carries information. The event-kinds sentence is slightly tangential to selection but still useful, keeping it just under a perfect score.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 10-parameter multi-action tool with full schema coverage and an output schema, the description covers the action semantics, the secret-access limitation, and the diagnostic workflow without needing to restate return values. An agent has everything required to pick the right action and call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% (baseline 3), and the description still adds meaning: it explains what the deliveries history contains and how it should be used, and clarifies that event-kind values are human-readable topics rather than raw ids. It does not touch the confirmed/active parameters, but those are fully documented in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ("Manage outbound webhook destinations for the account") and then enumerates every action the single tool supports, so an agent knows exactly what surface it covers. It is clearly distinguishable from siblings like gnosari_manage_access, gnosari_manage_appearance, and gnosari_manage_data_collection.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives action-level guidance (deliveries is for diagnosing failures; the secret cannot be read here and must be fetched from the dashboard URL) which steers behavior. It does not, however, state when to prefer this tool over sibling management tools, but those cover unrelated resources so no exclusion is strictly needed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources