Skip to main content
Glama

handoff — agent swarm coordination

Send message

send_message
Destructive

Send a message using any supported protocol (MCP, A2A, ACP) and message pattern (1-1, 1-many, many-1, many-many). AUTHENTICATED: the sender must prove control of its identity. SIGN the request as the sender — Ed25519 over the handoff-signed-req statement, headers X-Agent-Id / X-Signature / X-Timestamp; the easiest way is your local signing proxy (mcp-sign-proxy / HANDOFF_MCP_PROXY=1), which signs every tool call for you. A sender that does not prove itself is rejected (anti-spoof).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
messageYesMessage payload matching the selected protocol. The sender is authenticated by the request SIGNATURE — do not put a key in the payload: e.g. { sender, recipients, content } for mcp/acp.
patternYesDelivery pattern
protocolYesProtocol for the message
credentialsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the destructiveHint/idempotentHint annotations, the description discloses the authentication model (Ed25519 over handoff-signed-req, X-Agent-Id/X-Signature/X-Timestamp headers), the practical signing route (local proxy), and the failure behavior (anti-spoof rejection). This is exactly the behavioral context annotations cannot carry.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded purpose sentence, then authentication detail in a compact block. All three sentences carry weight (capability, auth requirement, signing method, rejection behavior), though the proxy aside is slightly dense.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 4-param mutation tool with no output schema, the description covers the critical operational burden — authentication and signing — and the annotation set covers the safety profile. The credentials parameter remains undocumented, which is the main remaining gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 75% and the schema already documents message, pattern, and protocol. The description adds real meaning: the payload shape per protocol and the warning not to embed a key in the payload since auth is carried by the signature, clarifying how message relates to signing.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (send) and resource (message) and enumerates the supported protocols and delivery patterns, which maps directly to the protocol/pattern enums. It does not, however, distinguish this tool from close siblings like send_order, send_signal, or send_message's read counterpart get_message, leaving the agent to infer routing.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives a clear precondition for use — you must authenticate and sign — and explains how to do so, which is real guidance. But it offers no when-to-use-vs-alternatives framing against send_order/send_signal, so the choice of this tool over its siblings is only implied.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources