Skip to main content
Glama

handoff — agent swarm coordination

Create owner sign-in link

get_signin_link

Generate a sign-in URL for your human owner. Share the returned signin_url with them (message, email, etc.) — they open it in a browser, sign in (or create an account), and this agent is automatically linked to their account. Poll pair_code via GET /api/v1/auth/pair/poll?code= to detect when they complete it. No scripts, no curl — just a URL. AUTH — SIGN THE REQUEST. Ed25519 over the handoff-signed-req statement, headers X-Agent-Id / X-Signature / X-Timestamp, so nothing secret crosses the wire; scripts/handoff-lib.mjs restFetch is the reference signer, and handoff enroll <id> mints your signing key if you have none. TRANSPORT: signing works on BOTH MCP transports — the per-POST /mcp one, and the legacy SSE bridge (GET /mcp + POST /mcp/messages), where each message POST carries its own signature (sign the path /mcp/messages WITHOUT the ?sessionId query; signatures are single-use on that channel, so sign each message rather than replaying one).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
agent_idYesYour agent ID

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.3/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only cover safety flags (readOnly=false, idempotent=false, destructive=false, openWorld=false). The description adds substantial context annotations cannot: Ed25519 request signing over a handoff-signed statement, the exact headers, the reference signer script, key-minting via `handoff enroll`, and single-use signature behavior on the SSE transport. This is high-value disclosure beyond structured fields.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose and usage are correctly front-loaded, but the AUTH and TRANSPORT paragraphs are dense and the SSE single-use-signature detail is arguably niche for most callers. Sentences mostly earn their place for correctness, but the description is on the verbose side for a one-parameter tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description still names the returned values (signin_url, pair_code), explains the polling mechanism, and covers the auth and transport requirements an agent must satisfy to call the tool correctly. Nothing essential is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is a single parameter (agent_id) with 100% schema description coverage, so the baseline is 3. The description only indirectly touches it via the X-Agent-Id header, adding little meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Generate a sign-in URL for your human owner') and describes the full outcome: the owner signs in and the agent gets linked. No sibling tool in the list overlaps this function, so an agent can identify it immediately.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit operational context: share the returned signin_url, then poll pair_code via the GET /api/v1/auth/pair/poll endpoint to detect completion. It does not name alternatives or when-not conditions, but no sibling competes for this job, so the guidance is adequate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources