Skip to main content
Glama

create_delegation

Create a delegation (Proof of Delegation): a control-proven domain authorizes a typed url/purl artifact for a set of capability scopes and receives a publishable signed token. The attestation is that the domain's controller authorized this artifact — nothing more; it says nothing about the artifact or the business behind it. Each mint is a billable proof. A requested lifetime longer than the control proof's remainder is rejected, never truncated. The result carries the publishable token AND the DERIVED effective_status/is_valid — the same pair the list and get tools return, so the shape does not depend on which verb produced it.

ACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
scopeYes1-32 capability scopes: lowercase kebab-case tokens, at most 64 characters each (e.g. send-email). NOT API scopes — an API-style resource:action such as payments:read is rejected with invalid_scope.
delegateYesThe typed artifact being authorized
expires_inNoLifetime in seconds (must not exceed the control proof's remainder)
control_proofYesPublic handle (ph_ctl_<32 hex>) of YOUR active domain control proof

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description fully carries the behavioral disclosure burden. It reveals that the attestation says nothing about the artifact or business behind it, that each mint is billable, that over-long lifetimes are rejected and never truncated, and that the result consistently includes the effective_status/is_valid pair across create/get/list. These are significant behavioral commitments beyond a simple 'creates X' statement.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but every sentence carries information: core semantics, attestation limits, billing, lifetime behavior, response shape consistency, and authentication requirements. It is front-loaded with the main definition and uses an ACCESS section for operational prerequisites. No filler or repeated schema content is present.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, so the description appropriately explains the return result (publishable token plus DERIVED effective_status/is_valid). It also covers authentication, proof account requirements, the key lifetime constraint, billing, and the exact scope of the attestation. Given the complexity of a billable, security-sensitive minting operation, this is remarkably complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters, including format constraints, examples, and rejection rules. The description adds useful high-level context like the control proof remainder relationship and the publishable signed token, but it does not materially add per-parameter meaning beyond the schema. This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action ('Create a delegation'), the precise resource ('a typed url/purl artifact'), and the exact scope of the operation ('for a set of capability scopes'). It also clarifies what the attestation does and does not mean, which distinguishes it from a generic create tool. This is far beyond a tautology or vague restatement.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear prerequisites and a when-not condition: it requires a Proof account and explicit authentication, and states that start_login does NOT open this tool. It also frames the operation around control-proven domains, which implies when it is appropriate. It does not explicitly compare against related tools like create_authorization or verify_delegation, but the access guidance is concrete and actionable.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.