Delete REST API key
delete_api_keyRevoke a REST API key by id. The last remaining key cannot be deleted.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| key_id | Yes | Key id (uuid) from the list call. |
delete_api_keyRevoke a REST API key by id. The last remaining key cannot be deleted.
| Name | Required | Description | Default |
|---|---|---|---|
| key_id | Yes | Key id (uuid) from the list call. |
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true and idempotentHint=true, so the safety profile is covered. The description adds a genuine behavioral constraint not in the annotations: the last remaining key cannot be revoked. It stops short of describing whether revocation is immediate or its effect on in-flight requests.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences with zero waste. The core action is front-loaded and the constraint follows immediately, making it easy to scan.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-param delete whose safety profile is fully carried by annotations, this is close to complete, and the last-key caveat covers the main pitfall. It could still note the return/confirmation behavior on success, but nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With a single parameter at 100% schema description coverage, the schema already documents key_id as a uuid from the list call. The description's 'by id' adds no syntax or format detail beyond the schema, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Revoke) and resource (REST API key) scoped by id, which is clear and actionable. The 'REST' qualifier implicitly separates it from the sibling delete_mcp_key, though the description never names that alternative explicitly, so it falls just short of the 5 tier.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides the precondition 'The last remaining key cannot be deleted', which is a useful when-not guardrail. However, it gives no guidance on when to revoke vs. rotate, and does not point to delete_mcp_key for MCP keys, so usage is only implied.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.