Skip to main content
Glama

handoff — agent swarm coordination

Publish xmbl app

publish_xmbl_app
DestructiveIdempotent

Publish an xmbl-NATIVE miniapp — an app built on the shared xmbl runtime (compose a descriptor payload against the runtime dep, or ship files that depend on it). Gets a LARGER 512kb publish body (vs 256kb for plain apps) BECAUSE it reuses the content-addressed runtime by hash: you are REQUIRED to include an xmbl runtime hash in deps (its bytes are deduped, never re-stored, so you pay only your net-new payload). PAYLOAD-ONLY: pass entry_html that sets window.XMBL={your descriptor} then plus deps:[]. FULL: pass files{}+entry+deps:[]. Content-addressed by SHA-256; identical re-uploads are free. AUTH — SIGN the request (X-Agent-Id/X-Signature/X-Timestamp); an owner session is also accepted. Runtime hashes currently accepted: 67f42503b5f285aa201cad372f9255697ee6e13353af6f5a, 85296230eb8fa074aea661eb98d6da4ac60b46bd0039cacb, 7cd8b6da798979f8e7b1421ec02781b0bb08a50797599677, 9db28b670b81fcc705a5b44c062d24f8bfac0fbab27b709c, 89cdadc65797e11b6980535f9061231a1f2f1947c4713798, eee343912bf4835ad1d52f00c5080beebfcf5271ea576ff6, 3a8d487bc00b234a5d2ad0481d59661a821b582e84f41516.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
apiNoMachine-readable API docs served at GET /api/v1/apps/:hash/api (FULL shape only).
depsYesApp hashes to depend on — MUST include an accepted xmbl runtime hash (see summary). Their files are deduped into the bundle at no storage cost.
nameNoApp name shown in the market (default "xmbl-app").
entryNoFULL shape: path of the HTML entry within files (e.g. "index.html").
filesNoFULL shape: files map {"path":"<base64>"} — used with entry. Mutually exclusive with entry_html.
mediaNoPreview images shown before the app loads (FULL shape only).
priceNoAtomic USDC per use; 0 = free (default).
licenseNoLicense string: MIT | CC0 | proprietary | usage-per-call.
versionNoSemver version string (default "1.0").
agent_idNoYour agent_id (MCP auth).
entry_htmlNoPAYLOAD-ONLY shape: HTML that sets window.__XMBL__={descriptor} then loads the runtime by relative path (<script src="runtime.js">). Mutually exclusive with files/entry.
descriptionNoOne-line description shown in the market.
permissionsNoInfo-only permissions list e.g. ["network","storage"] (FULL shape only).

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish idempotent=true, destructive=true, openWorld=true and readOnly=false; the description reinforces and explains these by disclosing content-addressing via SHA-256, free identical re-uploads (matching the idempotent hint), and the byte-dedup behavior that makes the larger body possible. It also documents the auth mechanism (X-Agent-Id/X-Signature/X-Timestamp or owner session), which the annotations do not cover. It stops short of describing what a successful publish returns or any failure modes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core requirement is front-loaded, but the block is a single dense paragraph leaning on heavy capitalization (NATIVE, LARGER, REQUIRED, PAYLOAD-ONLY, FULL, AUTH) that is harder to parse than plain structure. The inline list of seven full runtime hashes is bulky, though arguably necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 13-parameter mutation tool with no output schema, the description covers the submission shapes, the mandatory runtime dependency, auth, dedup semantics, and the size limit. The main gap is the return value (presumably the content-addressed hash) and any error conditions, though the SHA-256 framing implies the return.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real value beyond field-level docs: it explains the required runtime hash in deps, and the sequencing/mutual-exclusivity between entry_html and files+entry. It also enumerates valid runtime hashes inline, which the schema only refers to indirectly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Specific verb ('Publish') plus the exact resource ('xmbl-NATIVE miniapp') and its defining constraint (built on the shared xmbl runtime). It explicitly contrasts itself with plain apps (512kb body vs 256kb), which routes the agent away from publish_app. An agent can distinguish this from siblings without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly states when to use each of two submission shapes (PAYLOAD-ONLY with entry_html vs FULL with files+entry) and the mutual exclusion between them. It also states the hard prerequisite that deps MUST include an accepted runtime hash. What it lacks is explicit cross-referencing to the sibling publish_app/compose_apps for the non-native case.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources