Thmenu
Server Details
Restaurant menus, carts, reservations and owner drafts for AI agents (Thmenu MCP).
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-03-26
- URL
TDQS
Scored across 27 tools
Most tools have clearly distinct purposes (order lifecycle, reservations, loyalty, content drafting). A few pairs could be confused: draft_product_description, draft_site_text, and draft_translation all create DRAFT change sets, and get_cart/create_cart vs place_order flow requires reading descriptions to understand the guest-confirms pattern. Descriptions are detailed enough to resolve ambiguity in practice.
Mixed conventions: verb_noun (place_order, get_cart, cancel_reservation), noun_noun without verb (menu_audit, sales_summary, reservation_summary), and bare verb_noun phrases (waiter_call, apply_promo). Readable but not a single predictable pattern.
27 tools is on the heavy side for a restaurant platform, especially with several overlapping draft/read tools. Each tool earns some place, but the surface is crowded enough that it borders on excessive.
Strong lifecycle coverage: search/list restaurants and menus, cart flow, order placement/status/cancel, reservations, loyalty, billing, and content drafting. Minor gaps exist (e.g., no explicit update/delete for reservations beyond cancel, no user account management), but core workflows are well covered.
Available Tools
27 toolsapply_promoPreview a promo codeARead-onlyIdempotentInspect
Validate a promo code (eligibility preview only — does NOT reserve a slot). Returns valid=true with discount info when the code is currently redeemable; pass the same code as place_order.promo_code to actually apply + redeem it (the slot is consumed only when the order lands).
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | ||
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true and destructiveHint=false, so the safety profile is covered. The description adds real value beyond them: it discloses that no slot is reserved, that the slot is consumed only when the order lands, and the return shape ('valid=true with discount info'). It stops short of auth or rate-limit context, so a 4 rather than a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single dense sentence, front-loaded with the core action and scope caveat, followed by the downstream usage pointer — only one sentence and no filler. Slightly long/parenthetical-heavy but every clause carries information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description supplies the return semantics (valid=true plus discount info) and the side-effect contract (no slot consumed). Given only 2 params and one being a session identifier conventional across the sibling set, this is nearly complete, with only agent_session_id unaddressed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must carry the parameter burden. It does clarify 'code' semantics by tying it to place_order.promo_code, but says nothing about agent_session_id, leaving one of two required parameters undocumented anywhere. Partial compensation merits a mid score.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('Validate a promo code') and explicitly delimits the scope ('eligibility preview only — does NOT reserve a slot'), which resolves the tension between the imperative name apply_promo and the preview title. An agent can distinguish this from place_order without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Names the alternative path explicitly ('pass the same code as place_order.promo_code to actually apply + redeem it') and gives the condition that selects each path (preview vs. actual consumption on order landing). This is exactly the when/when-not/alternative guidance the dimension asks for.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
cancel_orderCancel an orderADestructiveIdempotentInspect
Cancel an order placed via the same agent_session_id. Atomic — only succeeds while the order is still in "pending" or "confirmed" (the early KDS-accept state). Once the kitchen starts preparing, you must escalate to waiter_call. Idempotent: replays return the original outcome. Idempotency-Key header REQUIRED.
| Name | Required | Description | Default |
|---|---|---|---|
| order_id | Yes | ||
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover destructive/idempotent/readOnly, but the description adds substantial new context: atomicity, the exact precondition states that gate success, escalation behavior on failure, replay semantics returning the original outcome, and a mandatory Idempotency-Key header not captured anywhere in structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the action, then layered with preconditions, escalation path, and idempotency in tight sentences. No filler; each clause adds actionable constraint information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive, precondition-gated tool with no output schema, the description covers success window, failure escalation, idempotent replay behavior, and the required header. Nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description carries full burden. It clarifies agent_session_id semantics (the order must have been placed via the same session) but says nothing about order_id's format or origin. Partial compensation for the coverage gap warrants a mid-range score.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ("Cancel an order") and scopes it to orders placed via the same agent_session_id, distinguishing it from unrelated siblings like cancel_reservation. An agent can identify the target operation without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states the success window ("only succeeds while the order is still in 'pending' or 'confirmed'"), the failure condition ("once the kitchen starts preparing"), and names the alternative ("escalate to waiter_call"). This is textbook when/when-not/alternative guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
cancel_reservationCancel a reservation requestADestructiveIdempotentInspect
Cancel a reservation using the 6-character confirmation code the GUEST received by email/SMS (the code is the authorisation; ask the guest for it — this tool never issues or reveals codes). Thin wrapper over the venue's own cancellation endpoint, which answers uniformly: status is "cancelled" or "noop" (unknown code · already cancelled · seated/completed · less than 30 minutes away — it does not say which). Only report a cancellation to the guest when cancelled is true. PUBLIC tool, no auth.
| Name | Required | Description | Default |
|---|---|---|---|
| confirmation_code | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations. It discloses that the endpoint answers uniformly with `status` = cancelled or noop, that noop conflates four distinct causes (unknown code, already cancelled, seated/completed, <30 min away) without saying which, and that cancellation should only be reported on `cancelled`. It also states this is a PUBLIC tool with no auth.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Information-dense and front-loaded: the core action and required input lead, then the response-semantics and reporting caveats follow. No sentence is filler despite the parenthetical density.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description fully covers what the agent needs: the required input, the exact response shape and its ambiguity, the auth profile, and the reporting rule. Nothing material is missing for correct invocation or interpretation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must carry the parameter meaning, and it does: it explains the code is 6 characters and comes to the guest by email/SMS, and that the tool cannot reveal or issue codes. The '6-character' claim sits slightly awkwardly against the schema's maxLength of 12, a minor imprecision.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (cancel) and resource (reservation) and pins down the exact input needed: the confirmation code the guest received. It is clearly distinguishable from sibling reservation tools such as request_reservation or get_reservation_slots.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear operational context — the code is the authorisation, the agent must ask the guest for it, and the tool never issues codes. It also states the report-to-guest rule. It stops short of naming explicit alternatives for cases where no code exists, so a 4 rather than a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
check_loyaltyLoyalty balanceARead-onlyIdempotentInspect
Look up a loyalty member by member_id. Returns balance, tier, lifetime_points, and the most recent 10 transactions so the agent can ground its recommendation ("you have 320 points, enough for a free coffee").
| Name | Required | Description | Default |
|---|---|---|---|
| member_id | Yes | ||
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover readOnly/idempotent/non-destructive, so the safety profile is settled. The description adds value beyond that by disclosing the return payload (balance, tier, lifetime_points, last 10 transactions), which matters because there is no output schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Back-loaded with the key return-field list and one illustrative example; the quoted sample message adds a little flavor but the core content is front-loaded and tight.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description usefully enumerates what comes back, which is the main completeness concern. The only real hole is the undocumented agent_session_id and the absence of any not-found/error behavior.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% and the description only glosses member_id, leaving agent_session_id completely unexplained in both schema and prose. For a 2-param tool with no structured documentation, the description does not compensate for the gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Specific verb+resource ('Look up a loyalty member by member_id') and it enumerates the returned fields, which cleanly separates it from write-side siblings like join_loyalty and apply_promo.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a rationale ('so the agent can ground its recommendation'), which implies the context of use, but never states when to prefer this over join_loyalty or apply_promo, nor any prerequisites such as an existing membership.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
create_cartCreate a cartAInspect
Build an anonymous takeaway or delivery cart for a listed restaurant and get a one-time confirmation link for the guest. PUBLIC tool, no auth. Table orders are not supported here (they stay on the QR menu). Send the guest to confirm_url. Prices are re-read there from the live menu; name, phone, delivery address and payment are entered by the guest on that page — never through this tool. Nothing is ordered until the guest confirms. The link expires 30 minutes after creation and can be used once.
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | Order-level note for the kitchen. Do not put the guest's name, phone or address here. | |
| items | Yes | ||
| order_type | Yes | ||
| restaurant | Yes | Restaurant slug (from search_restaurants / list_public_menus) or id. | |
| scheduled_for | No | ISO date-time for a scheduled pickup/delivery (optional; the venue may refuse on the confirmation page). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations (readOnlyHint=false, idempotentHint=false, destructiveHint=false) by disclosing that nothing is ordered until guest confirmation, prices are re-read live on the confirmation page, the link expires in 30 minutes and is single-use, and PII/payment are never passed through this tool. These are exactly the operational traits an agent needs to avoid misuse.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the action and the returned artifact, then proceeds through constraints in priority order (public/no-auth, exclusions, handoff, pricing, expiry). Dense but every sentence carries distinct information with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description names the key return (confirm_url) and explains its lifecycle (30-minute expiry, single use), and it covers auth, ordering semantics, and PII boundaries. An agent has everything needed to call this correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
At 60% schema coverage, the description compensates with meaningful negative guidance: name, phone, delivery address and payment are entered by the guest, never through this tool, and prices are re-read rather than supplied. This clarifies that items carry ids/quantities but not prices, though it does not describe order_type/items semantics that the schema already covers reasonably.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (build a cart) and resource (anonymous takeaway/delivery cart) with the exact output (one-time confirmation link). It also draws the boundary against table orders and against immediate ordering, so an agent can distinguish it from siblings like place_order or get_cart without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear when-to-use context (anonymous takeaway/delivery for a listed restaurant) and explicit exclusions (table orders stay on the QR menu), plus the handoff action 'Send the guest to confirm_url.' It stops short of naming the sibling tool (place_order) that finalizes the order, leaving that routing implicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
draft_product_descriptionDraft a product descriptionAInspect
Propose a new description for one of your products. Nothing goes live: the text is saved as a DRAFT change set the owner reviews, previews and publishes (or discards) in the admin panel.
| Name | Required | Description | Default |
|---|---|---|---|
| product_id | Yes | Product id from menu_audit or get_restaurant_menu. | |
| description | Yes | Proposed description in the menu language. Plain text, no links, no claims you cannot verify. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=false, destructiveHint=false, and idempotentHint=false; the description adds real context beyond that by explaining the draft change-set workflow: nothing goes live, the owner reviews, previews, publishes, or discards it. This clarifies what the non-destructive write actually produces, though it doesn't cover auth needs or what the call returns.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, zero waste, and the draft-only safety semantics are front-loaded right after the core action. Nothing repeats the schema or the name.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter write tool with no output schema, the description covers the essential outcome (a draft change set awaiting owner review) and pairs well with the annotations. It stops short of describing what the caller gets back or any limits on repeat calls, but the idempotency hint is already supplied structurally.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters are already documented in the schema (including the product_id source tools and the plain-text/no-links constraint). The description adds no parameter detail beyond that, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: "Propose a new description for one of your products." The product scope distinguishes it from other drafting siblings like draft_site_text or draft_translation, though it never names those alternatives explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use it (you want a new product description) but gives no explicit when-to-use guidance, prerequisites, or routing versus the drafting siblings such as draft_site_text and draft_translation. Usage is inferable rather than stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
draft_site_textDraft the website text packAInspect
Propose the public website text of your restaurant — tagline, about paragraph, SEO title and SEO description — as a DRAFT change set. Only declared facts are allowed: no numbers, awards, links or markup; validation rejects anything else. The owner publishes from the admin panel.
| Name | Required | Description | Default |
|---|---|---|---|
| about | Yes | ||
| tagline | Yes | ||
| seo_title | Yes | ||
| seo_description | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare a non-read-only, non-destructive, non-idempotent write. The description adds meaning beyond that: the output is an unpublished draft change set with a separate owner-publish step, and it enumerates hard validation rules (no numbers, awards, links or markup).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three tight sentences, front-loaded with what is produced, followed by the constraint and the workflow. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description still conveys what is returned (a draft change set) and how it is consumed. It could more explicitly describe the return payload, but it is adequate for a four-field drafting tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must carry the semantics. It names and semantically explains all four required fields (tagline, about paragraph, SEO title, SEO description), though it does not restate the length limits that the schema already enforces.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (propose/draft) and resource (public website text pack) and enumerates the four fields. It is clearly distinguishable from siblings like draft_product_description and draft_translation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description makes the draft-vs-publish boundary explicit: this only proposes a change set and 'the owner publishes from the admin panel.' It does not explicitly contrast itself with the other draft_* siblings, but the context is clear enough.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
draft_translationDraft a menu translationAInspect
Propose a translation (name and/or description) of one product or category into one menu language. Nothing goes live: it is saved as a DRAFT change set the owner reviews and publishes in the admin panel; manual translations override machine translation once published.
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Translated name (optional). Keep brand names as they are. | |
| entity | Yes | ||
| locale | Yes | Target menu language (two letters), different from the menu source language. | |
| entity_id | Yes | Product or category id from get_restaurant_menu / menu_audit. | |
| description | No | Translated description (optional). Plain text, no links, same meaning as the source — never add ingredients or claims. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With annotations marking this as a non-read-only write, the description adds genuinely useful context beyond them: nothing goes live, output is a draft change set requiring owner review/publication, and manual translations override machine output. It does not address idempotency (repeated calls with idempotentHint=false may create duplicate drafts) or auth requirements, keeping it short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single dense sentence, front-loaded with the core action before the draft/review behavior. Every clause earns its place, though it packs a lot into one sentence rather than segmenting purpose from consequences.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 5-parameter write tool with no output schema, the description covers the key lifecycle behavior (draft, review, publish) and the manual-override rule, and the schema handles the rest. Only the idempotency/duplicate-draft question is left unaddressed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 80%, so parameters are already well documented in the schema itself (including the 'keep brand names' and 'never add ingredients or claims' guidance). The description only loosely maps to the entity/locale/name/description fields without adding syntax or format meaning, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Propose a translation') and resource ('name and/or description of one product or category') with clear scope ('into one menu language'). It is distinguishably a translation-drafting tool, but it never names or contrasts with the closely related siblings draft_product_description and draft_site_text, so differentiation is left to inference.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage via 'saved as a DRAFT change set the owner reviews and publishes' and the manual-overrides-machine note, but it gives no explicit when-to-use versus alternatives (e.g., draft_product_description, draft_site_text). Usage is inferable but not spelled out.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_cartCart contentsARead-onlyIdempotentInspect
Read an anonymous cart by cart_id: state (open · consumed · expired), the one-time confirmation link while open, lines re-priced from the live menu, and the order id once the guest has confirmed. PUBLIC tool, no auth.
| Name | Required | Description | Default |
|---|---|---|---|
| cart_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive, and closed-world; the description adds real context beyond that — no auth required, the one-time confirmation link only exists while the cart is open, lines are re-priced from the live menu, and the order id appears only after guest confirmation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
One dense sentence with the key and the returned state set front-loaded; every clause carries information. Slightly long and run-on, which keeps it from a 5.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the return-value burden and does so well: it enumerates the state values and the conditional fields (confirmation link, order id). Nothing an agent needs to call or interpret this read correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Only one parameter and the schema carries no description (0% coverage), though it does encode the format via a 32-hex pattern. The description confirms cart_id is the key but adds no format or lookup semantics beyond the schema, so the baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Read an anonymous cart by cart_id') and enumerates the fields returned, so an agent can distinguish it from create_cart or get_order_status without opening a schema. The 'anonymous cart' scoping is precise.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Clearly signals the operating context ('PUBLIC tool, no auth') and the keyed lookup (by cart_id), which implies when it applies. It stops short of naming an alternative or an explicit when-not condition, so it falls short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_faqFrequently asked questionsARead-onlyIdempotentInspect
Return the FAQ entries from the public /faq page in the requested locale (31 locales; unknown locale falls back to en and the response says which locale was served). Useful for grounding answers to common product questions.
| Name | Required | Description | Default |
|---|---|---|---|
| locale | No | en |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive, closed-world. The description adds genuine behavior not in the annotations: 31 locales, fallback to 'en' on unknown locale, and that the response reports which locale was served. It does not mention caching or pagination, but nothing suggests those apply.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, zero filler, with the resource and locale scoping front-loaded and the fallback caveat immediately after. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a no-required-param read tool with no output schema, the description covers what the tool returns, the locale contract, the fallback behavior, and a usage rationale. Nothing an agent needs to invoke it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must carry the locale semantics — and it does, specifying 31 supported locales, the default/fallback to 'en', and that the served locale is echoed back. This meaningfully exceeds what the bare 'locale: string, default en' schema conveys.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Return) and resource (FAQ entries from the public /faq page), plus the scoping dimension (requested locale). No sibling tool overlaps with FAQ retrieval, so the agent can identify it immediately.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides a clear use context: 'grounding answers to common product questions.' It stops short of explicit when-not-to-use guidance or naming alternatives, but for a single-purpose lookup tool the intended usage is unambiguous.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_order_statusOrder statusARead-onlyIdempotentInspect
Poll the current status of an order. Returns status, prepared_items_count, total_items_count, eta_minutes (if available), and an optional customer-facing message. Safe to call every 30 seconds; do NOT poll faster.
| Name | Required | Description | Default |
|---|---|---|---|
| order_id | Yes | ||
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent and non-destructive, so the safety profile is covered. The description adds value beyond them with a rate-limit/cadence constraint and the notion of an optional customer-facing message, which annotations cannot express. It does not explain behavior for unknown or expired order_id values.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences with zero filler; the core action leads and the polling cadence follows as an actionable constraint. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description usefully enumerates the return fields and discloses the polling constraint, which is the main risk for this tool. Minor gaps remain around error/expired-session behavior, but nothing essential for a correct call is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% for both required parameters, so the description carries the full burden — yet it never mentions order_id or agent_session_id. order_id is self-evident, but agent_session_id's origin and expected format are left entirely undocumented.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Poll the current status of an order') and enumerates the returned fields, so the agent knows exactly what this yields. No sibling tool covers order status polling, but the description never explicitly contrasts itself with siblings such as reservation_summary or get_cart.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives concrete operational guidance — 'Safe to call every 30 seconds; do NOT poll faster' — which is exactly the when/when-not information an agent needs for a polling tool. It stops short of naming alternatives or prerequisite steps (e.g., that it follows place_order or requires an active session).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_pricingPlans and pricesARead-onlyIdempotentInspect
Return the canonical two-track subscription matrix: the restaurant track (Starter, Lite, Pro, Platinum, Diamond) plus the dedicated Hotels track (Hotels, Hotels+). Billing is YEARLY ONLY — each tier carries its USD yearly list price and the founding-cohort yearly price, plus the feature list. Generated from the same source as the public pricing page; stable identifiers — safe to cache.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive and closed-world, so the safety profile is covered. The description adds value beyond them: provenance ('generated from the same source as the public pricing page'), identifier stability, and explicit cache-safety guidance, which is real behavioral context for an agent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two dense sentences, front-loaded with what is returned, followed by the billing constraint and cache note. Every clause carries information, though the tier enumeration and price-type listing make it heavier than strictly minimal.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, so the description must convey the return shape — and it does: both tracks, tier names, yearly list price plus founding-cohort price, and feature list, along with the yearly-only billing constraint. An agent can use this without further documentation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters, so the baseline is 4. The description correctly implies a no-argument call and instead spends its words on the returned structure, which is the right trade-off for a parameterless lookup.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Names a specific verb+resource ('Return the canonical two-track subscription matrix') and enumerates exactly what that resource contains (restaurant vs Hotels tracks, their tier names, yearly prices, feature lists). No sibling touches pricing, so it is trivially distinguishable from all 25 other tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear context for use — it is the canonical pricing source — and adds an actionable qualifier ('stable identifiers — safe to cache'). It does not state when NOT to use it, but no sibling offers pricing data, so no routing alternative exists to name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_reservation_slotsReservation slotsARead-onlyIdempotentInspect
List bookable 30-minute reservation slots for the next 1–7 days (venue timezone) for a listed restaurant with a reservation module. busy_count is the number of existing requests at that slot and is informational. A reservation is a REQUEST that the restaurant confirms; no per-slot capacity cap is configured, so busy_count is informational only. Never tell the guest a table is guaranteed or "available" — say the request will be sent and the restaurant will confirm. PUBLIC tool, no auth.
| Name | Required | Description | Default |
|---|---|---|---|
| days | No | ||
| restaurant | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish it is a safe, idempotent read; the description adds substantial context beyond them: busy_count is informational because no per-slot cap exists, a reservation is a request the restaurant confirms, and the tool is public with no auth.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core capability before the caveats, and the guest-messaging rule is well placed. Slight redundancy: 'busy_count ... is informational' is stated twice, and the mid-sentence 'A reservation is a REQUEST' interrupts the slot/return-value flow.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the burden and explains the one non-obvious returned field (busy_count) and the request-not-confirmation model. It omits any mention of other slot fields or result size, which is a minor gap for a 2-param read tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must compensate and it largely does: 'days' is bounded to 1-7 and 'restaurant' is constrained to a listed venue with a reservation module, plus slot duration and timezone semantics. It stops short of describing accepted restaurant identifier formats.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a precise verb+resource (list bookable reservation slots), with granularity (30-minute), horizon (next 1-7 days) and timezone. The scoping phrase 'for a listed restaurant with a reservation module' distinguishes it from siblings like request_reservation and reservation_summary.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear context for use (a listed restaurant that has a reservation module) and adds an important behavioral rule about how to communicate results to guests, distinguishing slot lookup from an actual booking. It does not explicitly name request_reservation as the follow-up action, so routing is implied rather than stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_restaurantRestaurant profileARead-onlyIdempotentInspect
Fetch a public restaurant profile by slug: name, description, address/city/country, currency, timezone, phone, menu URL, opening hours (7 days, minutes from midnight) with isOpenNow evaluated in the venue's own timezone (null when hours are unknown), owner-declared attributes (cuisine, dietary, …; null = not declared, never "no"), derived channels (order · reservation · pickup · delivery), policies derived from the venue's settings (ordering accepted / holiday mode / staff approval / payment timing / scheduled orders, takeaway & delivery ETA and fees, reservation party cap, table calls, tip cap), per-field owner verification timestamps, categories and product count. Only restaurants opted into the public directory are visible.
| Name | Required | Description | Default |
|---|---|---|---|
| slug | Yes | Restaurant slug, e.g. lily-rose-bistro |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnly, idempotent, non-destructive). The description goes further with genuine behavioral context: visibility gating via public-directory opt-in, timezone-relative isOpenNow with null semantics for unknown hours, and sentinel conventions (null = not declared, never 'no'). Those conventions matter and aren't in the schema or annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the verb and resource, which is good, but sentence one is a sprawling comma-separated field dump that runs dozens of items long, and the eligibility caveat is buried at the end. The information is useful but the density makes it hard to scan.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-param read with no output schema, the description covers what gets returned, the null conventions, and the visibility gate. What's missing is pagination/size or any note on failure modes when a slug isn't public, but the important shape is conveyed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the single slug parameter is fully documented in the schema including an example. The description adds no format or syntax detail beyond what the schema already provides, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Clear verb ('Fetch') and resource ('public restaurant profile by slug'), with a rich enumeration of the returned fields. It doesn't explicitly distinguish itself from sibling search_restaurants or get_restaurant_menu, but the field list makes the scope obvious to a reader.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The closing sentence establishes eligibility ('Only restaurants opted into the public directory are visible'), implying when the tool will succeed. However, it never says when to use this versus search_restaurants or get_restaurant_menu, and gives no exclusion criteria.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
join_loyaltyJoin the loyalty programmeAInspect
Enrol the authenticated customer in the restaurant loyalty programme. Returns the member id, current points balance, and tier. Safe to call even if the customer is already enrolled — returns existing data in that case. Requires an active agent_session_id and the customer email or phone.
| Name | Required | Description | Default |
|---|---|---|---|
| No | Customer email (either email or phone required). | ||
| phone | No | Customer phone in E.164 format (either email or phone required). | |
| display_name | No | Optional display name shown in the loyalty dashboard. | |
| agent_session_id | Yes | Active session id from start_order_session. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, destructive=false, openWorld=false, idempotent=false, so the safety profile is partly covered; the description adds real value by disclosing the return fields (member id, points balance, tier) and the repeat-enrolment behavior. There is a mild tension with idempotentHint=false, since "returns existing data in that case" reads as repeat-safe, but it is not a flat contradiction of the read/write nature of the tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three tight sentences, front-loaded with purpose, then return values, then safety and prerequisites. The final sentence largely duplicates what the schema already states, which is the only wasted content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description correctly compensates by naming the returned fields. It covers required inputs, repeat-call behavior, and the return shape; only error cases and permission details are absent, which is minor for this operation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all four parameters, including the email-or-phone requirement and E.164 formatting. The description only restates the session and email/phone requirement without adding format or validation detail, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The opening sentence gives a precise verb and resource: "Enrol the authenticated customer in the restaurant loyalty programme." This clearly separates it from the read-side sibling check_loyalty, though that sibling is never named explicitly, so the differentiation is inferred rather than stated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It states prerequisites ("Requires an active agent_session_id and the customer email or phone") and gives a useful when-to-call condition ("Safe to call even if the customer is already enrolled"), which tells the agent not to gate on a prior check_loyalty call. No explicit alternative or when-not-to-use guidance is given, so it falls short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
place_orderPlace an orderAIdempotentInspect
Place an order against the agent_session_id from start_order_session. Atomically inserts the order + items, applies server-side canonical pricing + tax (do NOT trust the unit_price you compute — we re-read it from D1), decrements inventory, optionally redeems a promo code, and creates a Stripe hosted Checkout Session so the customer can pay + authenticate on their own device. Returns order_id, total_cents (tax-inclusive), currency, promo_discount, and a hosted_confirm_url (a Stripe checkout link) to share with the human. Idempotency-Key header REQUIRED.
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | Optional order-level note (max 500 chars). | |
| items | Yes | ||
| room_id | No | Diamond tier only — hotel room id. | |
| table_id | No | Optional table id when ordering at a table. | |
| guest_name | No | Required when room_id is set. | |
| order_type | No | Channel: 'dine_in' (default — table or room) or 'takeaway' (pickup; requires customer_name + customer_phone, ignores table_id/room_id, only when the restaurant has takeaway enabled — else channel_not_available). Delivery is not offered to agents. | |
| promo_code | No | Optional promo code to redeem at order time (validate first with apply_promo). The redemption slot is consumed only when this order lands. | |
| customer_name | No | Required for takeaway — who picks the order up. | |
| customer_phone | No | Required for takeaway — reachable phone (digits, +, spaces/dashes tolerated). | |
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: reveals canonical server-side pricing (do NOT trust computed unit_price), atomic transaction semantics, inventory decrement, optional promo redemption, Stripe hosted Checkout flow, the returned fields, and that an Idempotency-Key header is REQUIRED. This adds substantial behavioral context not present in the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the core action and builds outward through effects, returns, and the idempotency requirement with little waste. It is dense with compound clauses but nearly every clause conveys necessary behavior.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 10-param mutation with no output schema, the description supplies the missing return shape (order_id, total_cents, currency, promo_discount, hosted_confirm_url), prerequisites, side effects, and the idempotency requirement. Nothing an agent needs to invoke it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is already 80%, so the schema carries most parameter meaning (order_type channel rules, guest_name, promo_code). The description still adds value on promo_code redemption timing (slot consumed only when the order lands) and the pricing semantics, exceeding the baseline 3.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (place) and resource (order) and enumerates the concrete effects: atomic insert of order+items, server-side pricing/tax, inventory decrement, promo redemption, and Stripe Checkout creation. It is clearly distinguished from siblings like start_order_session (the prerequisite) and apply_promo (validation).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Names the prerequisite source of agent_session_id (start_order_session) and instructs to validate promo codes with apply_promo first, plus notes delivery is unavailable to agents. It stops short of explicitly contrasting place_order with create_cart/get_cart, so the routing to alternatives is implied rather than complete.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
request_billRequest the billAInspect
Ask the venue to bring the bill for a table. INSERTs a bill_requests row + fires the admin push notification. The split_type defaults to "full"; pass "personal" for German-style per-device splits.
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | ||
| table_id | Yes | ||
| split_type | No | full | |
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the tool is not read-only, not idempotent, and not destructive. The description adds valuable context beyond that by stating it INSERTs a bill_requests row and fires an admin push notification, which clarifies the side effects and internal state change. It does not cover permissions, rate limits, or error behavior, but the added side-effect disclosure is substantial.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the core purpose and followed by side-effect and split_type details. Every sentence adds useful information with no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the absence of an output schema and annotation coverage for safety, the description adequately explains the tool's action and one parameter. However, with 0% schema description coverage, it should do more to describe the remaining three parameters and provide usage context relative to siblings. The result is acceptable but incomplete for an agent that needs to call it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must explain all four parameters. It only clarifies split_type (defaults to 'full', pass 'personal' for German-style per-device splits), while note, table_id, and agent_session_id receive no explanation. This leaves three of four parameters undocumented and forces the agent to guess their meaning and format.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Ask the venue to bring the bill') and resource ('the bill for a table'), making it immediately distinguishable from siblings like waiter_call or place_order. It is not a tautology of the name and tells the agent exactly what action is performed.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description does not say when to use this tool versus alternatives such as waiter_call or get_order_status, nor does it mention any prerequisites or when-not-to-use conditions. The only usage hint is implied by the action itself, which is insufficient for an agent choosing among 26 sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
request_reservationRequest a reservationAInspect
Create an anonymous reservation REQUEST (date-time, party size, note) for a listed restaurant and get a one-time confirmation link. PUBLIC tool, no auth. Send the guest to confirm_url: they enter their name and email or phone there and submit the request themselves — never through this tool. The restaurant then confirms or declines; the guest receives the confirmation code by email/SMS. A reservation is a REQUEST that the restaurant confirms; no per-slot capacity cap is configured, so busy_count is informational only. Never tell the guest a table is guaranteed or "available" — say the request will be sent and the restaurant will confirm.
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | Occasion, seating preference, accessibility needs. Do not put the guest's name, phone or email here. | |
| party_size | Yes | ||
| restaurant | Yes | ||
| reserved_at | Yes | ISO date-time; at least 30 minutes ahead, at most 90 days. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare the write/non-idempotent/non-destructive profile, and the description adds substantial context: no-auth public access, one-time confirmation link, restaurant confirms or declines, guest notified by email/SMS, and that busy_count is informational with no capacity cap. The only gap is any notion of error/expiry behavior for the link itself.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads what is created and what is returned, then layers the crucial guest-flow safety rules. It is dense and slightly repetitive in restating twice that a reservation is a request the restaurant confirms, but nearly every sentence carries operational value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 4-param mutation tool with no output schema, the description covers the return artifact (confirm_url), the downstream lifecycle (restaurant decision, SMS/email code) and the guest-handoff contract. An agent has everything needed to call it and to instruct the guest correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 50%: note and reserved_at carry descriptions, while restaurant and party_size rely on constraints only. The description restates the three inputs in parentheses but adds no format or semantic detail beyond the schema, so it neither compensates for nor worsens the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource (create an anonymous reservation REQUEST) plus scope (for a listed restaurant) and the return (one-time confirmation link). It is clearly separable from siblings like get_reservation_slots, reservation_summary and cancel_reservation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says the tool is public/no-auth, that the guest must be sent to confirm_url to submit their own name and contact details, and that those details must never be passed through this tool. It also names the exclusion to avoid ('never tell the guest a table is guaranteed'), leaving nothing to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
reservation_summaryUpcoming reservationsARead-onlyIdempotentInspect
Reservation requests of your restaurant for the next 14 days grouped by day and status, with pending requests that still need an answer. Read-only; no guest contact details.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, closed-world behavior, so the safety profile is covered. The description adds genuinely new context: the 14-day window, day/status grouping, and that guest contact details are excluded from the payload.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that front-loads the resource, scope, and grouping, then appends the two facts an agent most needs (pending-request handling, read-only/contact-data exclusion). No waste.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the return-shape burden and does so reasonably: grouping dimensions, time window, and excluded data are stated. It could say more about ordering or volume, but nothing essential is missing for a parameterless read tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters, so per the rubric the baseline is 4. There is nothing for the description to disambiguate beyond what the (empty) schema already communicates.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Specific verb+resource: it returns reservation requests for the restaurant grouped by day and status over a fixed 14-day window. This clearly separates it from siblings like get_reservation_slots (availability lookup) and request_reservation (creation), though it never names an alternative explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied rather than stated: the mention of 'pending requests that still need an answer' signals this is the view for triaging incoming bookings, but there is no explicit when-to-use/when-not guidance or named alternative among the 20+ siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
sales_summaryOrders summary (7 and 30 days)BRead-onlyIdempotentInspect
Order counts by status, order total sums, top products by quantity and busiest hours for the last 7 and 30 days of your restaurant. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false, and openWorldHint=false, so the safety profile is covered by structured data. The description's 'Read-only' merely restates an annotation and it adds no auth, rate-limit, caching, or freshness context. It does describe the shape of the aggregated content returned, which is modest added value.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence that leads with the metric list and closes with the time scope and a one-word safety note. It is dense rather than wasteful, though the appended 'Read-only' is redundant with the annotations and slightly lengthens an otherwise tight statement.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no parameters and no output schema, the description should describe the returned data, and it does enumerate the aggregates (status counts, totals, top products, peak hours) over fixed windows. An agent has enough to know what calling it yields, though the exact response format and any empty-state behavior are left implied.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes no parameters and schema coverage is 100%, so there is nothing for the description to compensate for. The description correctly avoids inventing parameters and just characterizes the fixed 7- and 30-day windows.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific analytical resource and enumerates the exact metrics produced: order counts by status, total sums, top products by quantity, and busiest hours, scoped to 7- and 30-day windows. This clearly distinguishes it as the sales-analytics tool among siblings, though it never names an alternative it is not (e.g., get_order_status for a single order).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no explicit when-to-use or when-not-to-use guidance and no routing to a sibling such as reservation_summary or get_order_status. The 7/30-day window is the only usage context offered, so an agent must infer that this is a reporting/overview tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_productsSearch productsARead-onlyIdempotentInspect
Search products inside a single restaurant by keyword. Returns up to 20 matching products with name, description, price, allergen tags, and the deep-link URL. Restaurant must be in the public directory.
| Name | Required | Description | Default |
|---|---|---|---|
| slug | Yes | Restaurant slug. | |
| limit | No | ||
| query | Yes | Free-text search across name + description. | |
| locale | No | en |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, closed-world behavior, so the safety profile is covered. The description adds value beyond that by disclosing the result cap ('up to 20'), return field set (name, description, price, allergen tags, deep-link URL), and the public-directory requirement.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the core action, then return shape, then prerequisite. No filler and nothing to trim.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description usefully enumerates return fields and the result cap, and it states the access prerequisite. It leaves locale and the limit default unexplained, which is a minor but real gap for a 4-parameter tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 50%: only slug and query are documented in the schema, while limit and locale are not. The description's 'up to 20 matching products' loosely maps to limit's maximum of 20 but does not explain the default of 10 or the locale parameter, so it only partially compensates.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Search) plus resource (products) and scope (inside a single restaurant by keyword). This clearly separates it from search_restaurants (cross-restaurant) and get_restaurant_menu (full menu retrieval).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides a concrete prerequisite: the restaurant must be in the public directory, which is a real gating condition an agent needs. It doesn't explicitly name sibling alternatives such as get_restaurant_menu, so it stops short of the top score.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_restaurantsSearch restaurantsARead-onlyIdempotentInspect
Search the public directory (opt-in venues only) by location, opening status, cuisine, dietary options, declared attributes and ordering channel. Neutral ranking (AI-K6): distance in 0.5 km bands when near is given → availability (open now first; unknown hours before closed) → profile freshness (owner-verified within 90 days first) → name. Subscription tier never affects order. Cuisine, dietary and other attributes are owner declarations, not verified facts; venues without a declaration are excluded only when an attribute filter is used, and venues without coordinates only when near is used. Returns slug, name, city, country, distance_km, is_open_now (serve-time, in the venue's own timezone; null when hours are unknown), channels (order · reservation · pickup · delivery), declared attributes, freshness and the menu URL. Paginated.
| Name | Required | Description | Default |
|---|---|---|---|
| q | No | Free text over name and description (min 2 chars). | |
| city | No | ||
| near | No | Search centre. Venues without coordinates are excluded when set. | |
| page | No | ||
| limit | No | ||
| channel | No | order = digital ordering at the table; reservation; pickup = takeaway; delivery = venue's own delivery. | |
| country | No | ISO 3166-1 alpha-2 | |
| cuisine | No | All listed cuisines must be declared by the venue. | |
| dietary | No | Owner declaration, not a certification. | |
| open_now | No | Only venues open right now in their own timezone; venues with unknown hours are excluded when true. | |
| radius_km | No | ||
| attributes | No | Any declared attribute token (meals, family, outdoor, accessibility, cuisine, dietary). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly/idempotent/non-destructive), the description discloses the exact ranking algorithm and tie-breakers, the 0.5 km distance banding, the guarantee that subscription tier never affects order, and that attributes are owner declarations rather than verified facts. This is behavioral context an agent could not get from the structured fields, and it does not contradict the readOnly annotation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose and ranking are front-loaded in the first sentence, followed by important caveats and then the return shape — a logical order. The prose is dense and information-rich, though the 'owner declarations, not verified facts' point marginally duplicates the `dietary` schema text and the sentences run long.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, but the description explicitly lists the returned fields (slug, name, city, distance_km, is_open_now, channels, declared attributes, freshness, menu URL) and states that results are paginated. Combined with the ranking and exclusion rules, an agent has everything needed to call and interpret this tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 67%, and the description compensates for the gaps: it explains the effect of `near` and `radius_km` banding, the exclusion behavior tied to filters, the interaction between `open_now` and unknown hours, and the timezone basis of is_open_now. It adds meaning beyond the schema for the ambiguous parameters even though a few fields (q, city, page/limit) get no extra prose.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource+scope ('Search the public directory (opt-in venues only)') and enumerates every filterable dimension, which cleanly separates it from siblings like get_restaurant and list_public_menus without needing to open any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives rich conditional guidance — venues without a declaration are excluded only when an attribute filter is used, venues without coordinates only when `near` is set — so the agent understands the consequences of each filter. However it never names an alternative tool or states when to prefer get_restaurant over this search, so it stops short of full sibling routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
start_order_sessionStart an order sessionAInspect
Open a 30-minute transactional window for an AI agent against a specific restaurant. Returns an agent_session_id you MUST pass to every downstream order tool (place_order, cancel_order, request_bill, waiter_call, apply_promo). Also returns the customer-facing confirmation URL — share it with the human so they can review the cart before checkout.
| Name | Required | Description | Default |
|---|---|---|---|
| restaurant_id | Yes | Canonical restaurant id from get_restaurant or search_products. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare this is a state-changing, non-idempotent operation. The description adds valuable behavioral detail beyond annotations: the 30-minute lifetime, the required agent_session_id propagation, and the customer-facing URL. It does not cover failure modes or expiry handling, keeping it from a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tightly written sentences with no filler. The session lifetime and required session-id propagation are front-loaded before the secondary confirmation URL detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description correctly explains the two key return values (agent_session_id and confirmation URL). Annotations cover the safety profile. It stops short of describing expiry behavior or authentication prerequisites, but is otherwise complete for a session-starter tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% for the single restaurant_id parameter, so the schema already provides full parameter meaning. The description adds only the phrase 'against a specific restaurant,' which does not deepen understanding beyond the schema's canonical-id guidance.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: opening a 30-minute transactional session against a restaurant. It distinguishes itself from siblings by naming the downstream order tools that depend on the returned agent_session_id.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Clearly implies this must be called before place_order, cancel_order, request_bill, waiter_call, and apply_promo, and explains sharing the confirmation URL with the human. It lacks explicit when-not guidance or alternative session-starting tools, but the workflow context is strong.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
waiter_callCall a waiterAInspect
Flag a waiter to the table. INSERTs a waiter_calls row + fires the admin push notification. Pass an optional human-readable message (max 500 chars) the staff sees in the dashboard.
| Name | Required | Description | Default |
|---|---|---|---|
| message | No | ||
| table_id | Yes | ||
| agent_session_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations establish this as a non-read-only, non-destructive, non-idempotent, closed-world operation, and the description adds real value beyond them by disclosing concrete side effects: an INSERT into waiter_calls plus an admin push notification. It does not describe auth requirements or whether duplicate calls are collapsed, which the idempotentHint=false makes relevant.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the purpose, then side effects, then the one parameter detail that matters. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema and no parameter descriptions in the schema, the description is complete on the 'what happens' axis but incomplete on the 'what do I pass' axis for the two required identifiers. Adequate for the side-effect disclosure, insufficient for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description carries the full burden, yet it only explains the optional 'message' parameter (max 500 chars, visible to staff). The two required parameters, table_id and agent_session_id, get no explanation at all, leaving their format and source undocumented.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a specific verb and resource ('Flag a waiter to the table') that is clearly distinct from siblings such as request_bill or cancel_order. It stops short of explicitly naming or contrasting with those adjacent tools, so differentiation is left to inference.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the name and by the note that staff see the message in the dashboard, but there is no explicit 'use this when...' or 'use request_bill instead for...' guidance. For a tool sitting next to request_bill and cancel_reservation, that routing help matters.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
27 tool updates
- First observed
apply_promo - First observed
cancel_order - First observed
cancel_reservation - First observed
check_loyalty - First observed
create_cart - First observed
draft_product_description - First observed
draft_site_text - First observed
draft_translation - First observed
get_cart - First observed
get_faq - First observed
get_order_status - First observed
get_pricing - First observed
get_reservation_slots - First observed
get_restaurant - First observed
get_restaurant_menu - First observed
join_loyalty - First observed
list_public_menus - First observed
menu_audit - First observed
place_order - First observed
request_bill - First observed
request_reservation - First observed
reservation_summary - First observed
sales_summary - First observed
search_products - First observed
search_restaurants - First observed
start_order_session - First observed
waiter_call
Related MCP Connectors
Per-restaurant MCP servers: menu, hours, delivery terms; live example below
Hosted MCP server to manage a restaurant menu from AI agents - 39 tools over the DuckHub API.
Hosted MCP for e-commerce: live product catalog, stock, and pricing for AI agents.
Run your restaurant from an AI client: orders, menu, reports, refunds, payouts and staff.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to manage restaurant reservations through typed MCP tools, including checking table availability, creating and canceling reservations, and listing the day's confirmed bookings.-
- AlicenseNot gradedqualityCmaintenanceHosted MCP server to manage a restaurant menu from AI agents - 39 tools over the DuckHub API (menu, categories, modifiers, prices, images, translations, promotions, and orders).MIT
- AlicenseNot gradedqualityBmaintenanceMCP server for AI-native restaurant discovery with three-tier search (verified, menu_indexed, discovered), Menu Protocol menus, and structured menu validation.2 npmMIT
- AlicenseNot gradedqualityCmaintenanceAn MCP server that lets restaurants operate their point-of-sale through an LLM agent — edit menus, 86 items, check sales, restock inventory, monitor voids, and more via twenty tools over both stdio and Streamable HTTP transports with per-request tenancy from API keys.Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.