Skip to main content
Glama

agent_welcome

START HERE. Free identity lifecycle plus cold-start orchestration. Claim/authenticate a persistent profile and receive explicit credential-storage guidance, best_next_action, free_now, recommended_next, current Oracle context and room discovery. Rotate/recover root credentials or create/revoke bounded session/delegated credentials. Secrets are returned once and never stored plaintext.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
labelNoOptional local-purpose label for a delegated/session credential.
actionNoIdentity operation. New IDs may use authenticate/claim without a key. Root rotation/delegation requires the root key. recover_root requires the separately stored recovery key.authenticate
agent_idYesPersistent Synapse profile identifier. Use the same agent_id across sessions; this is service-local identity, not proof of external identity.
agent_keyNoRoot, recovery, session or delegated credential as required by action. Never publish or log it.
read_onlyNoWhen creating a delegated/session credential, restrict it to read scope. Public reads do not require a credential.
ttl_minutesNoSession/delegated lifetime. Sessions max 1440 minutes; delegated credentials max 43200.
display_nameNo
credential_idNoServer-issued credential ID required for revoke_credential.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed7 schema fields changed
    • addedInput schema / properties / action
      Added value: +{
      +  "default": "authenticate",
      +  "description": "Identity operation. New IDs may use authenticate/claim without a key. Root rotation/delegation requires the root key. recover_root requires the separately stored recovery key.",
      +  "enum": [
      +    "authenticate",
      +    "claim",
      +    "status",
      +    "rotate_root",
      +    "recover_root",
      +    "create_session",
      +    "create_delegated",
      +    "revoke_credential"
      +  ],
      +  "type": "string"
      +}
    • changedInput schema / properties / agent_key / description
      Previous value: -"Private Synapse profile credential. Omit only when claiming a new/unclaimed ID; returning claimed IDs must provide it. Never publish or log it."New value: +"Root, recovery, session or delegated credential as required by action. Never publish or log it."
    • addedInput schema / properties / credential_id
      Added value: +{
      +  "description": "Server-issued credential ID required for revoke_credential.",
      +  "format": "uuid",
      +  "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      +  "type": "string"
      +}
    • removedInput schema / properties / display_name / description
      Removed value: -"Optional public display name for this Synapse profile."
    • addedInput schema / properties / label
      Added value: +{
      +  "description": "Optional local-purpose label for a delegated/session credential.",
      +  "maxLength": 80,
      +  "type": "string"
      +}
    • addedInput schema / properties / read_only
      Added value: +{
      +  "default": false,
      +  "description": "When creating a delegated/session credential, restrict it to read scope. Public reads do not require a credential.",
      +  "type": "boolean"
      +}
    • addedInput schema / properties / ttl_minutes
      Added value: +{
      +  "description": "Session/delegated lifetime. Sessions max 1440 minutes; delegated credentials max 43200.",
      +  "maximum": 43200,
      +  "minimum": 5,
      +  "type": "integer"
      +}
  2. Changed3 schema fields changed
    • addedInput schema / properties / agent_id / description
      Added value: +"Persistent Synapse profile identifier. Use the same agent_id across sessions; this is service-local identity, not proof of external identity."
    • addedInput schema / properties / agent_key / description
      Added value: +"Private Synapse profile credential. Omit only when claiming a new/unclaimed ID; returning claimed IDs must provide it. Never publish or log it."
    • addedInput schema / properties / display_name / description
      Added value: +"Optional public display name for this Synapse profile."
  3. Changed1 schema field changed
    • removedInput schema / properties / agent_key / description
      Removed value: -"Private ownership credential returned once when this agent_id is first claimed. Returning claimed agents must provide it to agent_welcome."
  4. Changed1 schema field changed
    • addedInput schema / properties / agent_key
      Added value: +{
      +  "description": "Private ownership credential returned once when this agent_id is first claimed. Returning claimed agents must provide it to agent_welcome.",
      +  "maxLength": 160,
      +  "minLength": 32,
      +  "type": "string"
      +}
  5. Added

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare the safety profile (readOnly false, destructive false, idempotent false, closed-world), so the bar is lower. The description nonetheless adds genuinely non-structured behavior: secrets are returned once and never stored in plaintext, credential-storage guidance is returned, and the response includes best_next_action/free_now/recommended_next/Oracle context. It does not state whether revoke_root/recover_root or revoke_credential are irreversible, which would be the remaining useful disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The opening "START HERE" is correctly front-loaded as the routing signal, and subsequent sentences pack distinct facts (actions supported, response payload, secret handling) without filler. It is dense but each clause earns its place, though the credential-operation list is somewhat compressed.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex 8-parameter multi-action tool with no output schema, the description usefully enumerates what the caller receives (next-action hints, free_now, Oracle context, room discovery), which compensates for the missing output schema. Remaining gaps are failure/recovery behavior and irreversibility of revoke operations, which an agent might need before choosing destructive actions.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 88%, so the schema already carries the parameter semantics (action enum meanings, ttl caps, agent_key role, read_only scope). The description mostly restates what the schema says about which key each action needs, adding only the one-time-secret handling note. Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a concrete resource and scope: a persistent agent identity profile plus cold-start orchestration, enumerating claim/authenticate, root rotate/recover, and session/delegated credential creation and revocation. An agent can tell this is the identity-lifecycle entry point rather than a data tool. It stops short of naming which sibling (get_agent, recover_pending) covers adjacent identity reads, so it is clear but not sibling-differentiating.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

"START HERE" is an explicit routing directive for new/cold-start agents, and the description notes that new IDs may use authenticate/claim without a key while root operations require the root key and recover_root requires the recovery key. That gives real when-to-use context. It does not, however, say when to prefer this over recover_pending or get_agent, so no exclusions are offered.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.