Skip to main content
Glama

Delete Environment

delete_environment
Destructive

PERMANENTLY delete an environment on Cycle and EVERYTHING in it: all containers and their instances (including data on stateful instances), all virtual machines and their disks, all scoped variables, and the environment's service containers (discovery, VPN, load balancer). This is IRREVERSIBLE.

This tool is two-step by design and NOTHING is deleted on the first call:

  1. Call without confirm. The environment is resolved and the response inventories exactly what would be destroyed — the environment's name, ID, and creation date, every container with its instance count, instance totals and the servers they run on, every VM, and every scoped variable. Present ALL of those details to the user verbatim.

  2. Only after the user explicitly approves deleting that specific environment and its full contents, call again with confirm:true and environment set to the exact 24-char hex ID from step 1 (names are not accepted with confirm — the ID binds the deletion to what the user approved).

Never set confirm:true unless the user has just approved this exact deletion; a general instruction like "clean things up" is not sufficient. To delete a single container instead, use delete_container.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
confirmNoSet true ONLY after the user has explicitly approved deleting this exact environment (shown its name, ID, creation date, and the full inventory of containers, instances, VMs, and scoped variables). Requires environment to be the exact hex ID from the preview call.
contextNoWhy are you calling this tool? Briefly describe the user's goal.
environmentYesEnvironment to delete. With confirm:true: MUST be the exact 24-char hex ID returned by the preview call.
wait_secondsNoconfirm only: max seconds to wait for the delete job to complete (default 60). Environments with many workloads take longer. 0 returns immediately after the job is accepted.
conversation_idNoConversation tracking id. Omit on your first tool call; every result then includes a conversation_id line — pass that exact value on all later calls in this conversation.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and idempotentHint=false, but the description goes well beyond them: it specifies that the first call is non-destructive, that the preview returns an inventory that must be shown verbatim, that the ID (not the name) binds the deletion, and that the operation is irreversible. This is exactly the extra context annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The irreversible warning and full destruction list are front-loaded in the first two sentences, then the two-step flow is numbered so the agent can follow it sequentially. Every sentence carries an actionable constraint despite the length, which is proportionate to the risk.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description compensates by describing the preview response contents in detail (name, ID, creation date, container/instance/server counts, VMs, scoped variables). Combined with the destructive annotations, an agent has everything needed to call this safely.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% so the baseline is 3, but the description adds real semantic weight: names are rejected when confirm is set, the ID must be the exact 24-char hex value from the preview, and confirm must be tied to the specific approval. It adds little on wait_seconds/conversation_id, which the schema already documents.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ('PERMANENTLY delete an environment') and immediately enumerates the exact blast radius (containers/instances, VMs/disks, scoped variables, service containers). It also explicitly distinguishes itself from the nearest sibling: 'To delete a single container instead, use delete_container.'

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit two-step protocol with the condition that gates step 2 ('Only after the user explicitly approves...'), a negative condition ('Never set confirm:true unless...'), and a concrete example of insufficient consent ('clean things up'). Alternatives are named.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources