Skip to main content
Glama

Robot Actions — Remote Device Control

webpage_set_cookie

Set a cookie on the CURRENT page origin in the device browser (iOS Safari or Android Chrome, auto-detected), via document.cookie. Use to seed auth/session state before a flow. LIMITATION: sets a NON-HttpOnly cookie on the current document origin only (cannot set HttpOnly/Secure-only or cross-domain cookies — that needs the browser CDP Network domain, which the iOS bridge does not expose). Defaults path=/ and a 365-day expiry. Returns { set, name, cookie }.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
daysNoExpiry in days from now (default 365; 0 = session)
nameYesCookie name
pathNoCookie path (default: /)
udidYesDevice UDID / serial (iOS or Android)
valueYesCookie value
pageIdNoTarget page/tab id — auto-picked when omitted
socketNoAndroid only: abstract unix socket name (default: chrome_devtools_remote)
platformVersionNoIgnored (kept for compatibility)

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses the mechanism (document.cookie), the critical limitation (HttpOnly/Secure/cross-domain not settable), the iOS bridge constraint, and defaults (path=/ and 365-day expiry). Returns { set, name, cookie }. It does not explicitly disclose side effects like overwriting an existing cookie of the same name, but the mechanism (document.cookie) makes this inferable.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single, dense, front-loaded paragraph. Every sentence earns its place: purpose, use case, limitation, defaults, return value. Zero waste, no fluff. Effectively communicates a complex tool with meaningful constraints in ~70 words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a cookie-setting tool with no output schema and no annotations, the description comprehensively covers mechanism, platform support, limitations, defaults, and return shape. The complexity is moderate (8 params, platform differences) and the description handles it well. Minor gaps: doesn't note that setting a cookie could overwrite existing ones or whether the page must be loaded/navigable first (a live document origin is required).

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema documents all 8 parameters. The description adds value by explaining defaults (path=/, 365-day expiry, days=0 means session) beyond what the schema states. However, it doesn't clarify semantics for platformVersion ('ignored'), pageId auto-pick, or the socket default beyond what schema property descriptions already say. Baseline 3 with a slight add from days=0 clarification.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it sets a cookie on the CURRENT page origin via document.cookie, specifically for seeding auth/session state before a flow. This is specific (verb+resource+scope) and distinct from sibling tools like android_devtools_cookies and ios_safari_cookies which read cookies, while webpage_clear_cookies clears them.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description states when to use it ('to seed auth/session state before a flow') and clearly delineates what it CANNOT do (set HttpOnly/Secure-only or cross-domain cookies, which requires the CDP Network domain not exposed on iOS). It notes platform auto-detection. It doesn't explicitly name alternative tools for the cases it can't handle, but the limitation section strongly implies the boundary.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.1/5.0
Disambiguation2/5

The set contains near-identical duplicate families: web_* and playwright_* expose ~15 pairs of the same desktop-grid-browser operations (web_get_text/playwright_get_text, web_reload/playwright_reload), and screenshot/log/network/mock capabilities each have 5-8 entry points (device_screenshot vs android_mjpeg_screenshot vs ios_screenshot vs ios_fast_screenshot vs web_screenshot vs webpage_screenshot vs session_screenshot). Many individual descriptions carefully draw boundaries (devtools vs traffic, HID vs session), but an agent cannot reliably distinguish web_* from playwright_*, and ios_screenshot/ios_fast_screenshot/ios_mjpeg_screenshot blur together.

Naming Consistency2/5

The prefix scheme is broken: Android functionality is split arbitrarily between android_* and device_* (device_screenshot vs android_mjpeg_screenshot), the desktop browser gets two parallel prefixes (web_* and playwright_*), and verbs vary across equivalents (device_navigate_url vs web_navigate vs ios_safari_navigate). session_* uses bare verbs (session_url, session_back), and the same concept gets different names (ios_clipboard_get_hid vs ios_get_pasteboard; device_screen vs ios_orientation).

Tool Count1/5

333 tools is an extreme count by any measure — far beyond the 50+ threshold — and much of the bulk is duplicative (the web_*/playwright_* pairs alone double ~15 slots) or out-of-scope for a device-control server (TestRail, Jira, AzDO, agent memory, secret variables, feedback). Even granting that remote device control + test automation is a broad domain, this surface will devastate agent context budgets and is impossible to navigate coherently.

Completeness4/5

The core device-control and test-automation domain is remarkably thorough: Android and iOS each have full interaction, app-lifecycle, file, network/proxy, performance, crash, accessibility, recording, and replay coverage, with CRUD lifecycles for flows, suites, app uploads, TestRail cases, and visual-review baselines. Minor gaps exist at the margins — Jira/AzDO lack update/transition/comment operations, and iOS cannot open/close tabs — but the central workflows have no dead ends.

Resources