Skip to main content
Glama

ModelsLab Agent Control Plane

Agent API Key Management

agent-api-keys
Manage API keys for the authenticated user.
Actions: list, create, get, update, delete.
API keys are used for generation endpoints (/api/v6, /api/v7, /api/v8).
All actions require authentication.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoAPI key name (required for create, optional for update)
notesNoNotes about the API key (optional for create, update)
actionYesThe API key action: list, create, get, update, delete
key_idNoAPI key ID (required for get, update, delete)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare openWorldHint=true, so the description carries the burden. It states the auth requirement, but says nothing about the destructive/irreversible nature of delete, whether create returns a secret only once, or per-action side effects on a multi-action CRUD tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four short lines, front-loaded with the resource and action set followed by supporting context. Slightly padded by the standalone action enumeration that repeats the schema, but no wasted prose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a multi-action CRUD tool with no output schema and only openWorldHint annotation, the description covers the surface (auth, endpoint relevance) but omits per-action behavior and return expectations. Adequate but with clear gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and the required-field conditions for name/key_id are already documented per parameter. The description's action list duplicates the schema's own action enum text, adding no new parameter meaning; baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a clear verb+resource (manage API keys for the authenticated user) and enumerates the action set, so the agent knows exactly what the tool does. It does not differentiate from plausible siblings like agent-tokens, leaving ambiguity about which credential type this manages.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'All actions require authentication' is a prerequisite, but there is no guidance on when to use this tool versus agent-tokens or agent-auth, and no indication of which action to pick for a given intent. Usage is only implied by the action names inherited from the schema.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources