Skip to main content
Glama

Credentialed External Call

request_credentialed_call

Proxied external API call with server-side credential injection. VaultCrux retrieves the credential from Vault Transit, injects it per the service's auth template, makes the call, and returns the response. The credential never appears in your context window. Request and response are receipted and audit-logged.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathYesRequest path (e.g. /v1/chat/completions)
methodYesHTTP method
headersNoAdditional headers (not auth)
payloadNoRequest body for POST/PUT
service_idYesRegistered service ID
session_idNoSession ID for audit trail

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden for behavioral disclosure. It reveals key security and audit traits: credential never appears in context, server-side injection via Vault Transit, and request/response are receipted and audit-logged. This goes beyond a minimal description, though it omits error handling or potential side effects.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, front-loaded with the core purpose, and each sentence contributes non-redundant information: the proxy mechanism, the security property, and the audit logging. No filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description explains the full behavior including credential handling and audit trail, which is sufficient given the presence of an output schema and detailed parameter schema. It does not explicitly mention prerequisites like needing a registered service, but the process description implies it. Overall, complete enough for an agent to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema descriptions already cover 100% of the six parameters with meaningful details (e.g., 'Additional headers (not auth)', 'Registered service ID'). The description adds only a general process context but does not enrich individual parameter semantics beyond what the schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies the tool as a 'Proxied external API call' with 'server-side credential injection', specifying the resource (external API) and the action (make a call). It distinguishes itself from sibling tools like register_external_service and list_external_services by focusing on invoking a credentialed call.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage: call this when you need to make an external API request with injected credentials. It does not explicitly name alternatives or exclusions, but the context is clear enough that an agent would know to use this for credentialed external calls rather than registration or listing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources