Skip to main content
Glama

clerk.create_m2m_token

Create an M2M token in a connected Clerk instance.

Sensitive — the returned token is a high-privilege secret; do not log or expose it.

Call clerk.get_connected_accounts first. Pass clerk_instance_id to target a specific connection, or omit it to use the default account.

Returns the created M2M token.

Cost = 15 tokens.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
claimsNoOptional custom claims embedded in the token.
token_formatNoToken format: "opaque" (default) or "jwt".
clerk_instance_idNoClerk instance id (ins_...) from clerk.get_connected_accounts. Omit to use the default connected account.
machine_secret_keyYesMachine secret key (msk_...) used to authenticate the create request.
seconds_until_expirationNoToken lifetime in seconds.
min_remaining_ttl_secondsNoFor opaque tokens, reuse an existing token with at least this TTL remaining.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
m2m_tokenNoCreated M2M token from the Backend API.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Added

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations present, the description adds important behavioral context by flagging the token as 'high-privilege secret' and instructing not to log or expose it. It also discloses the 'Cost = 15 tokens' operational cost. However, it doesn't describe token lifecycle details like revocation, but the schema and sibling tools partially cover that.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded: the purpose is stated in the first sentence, followed by a crucial security warning, usage steps, return value, and cost. Each sentence earns its place with no redundant filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the essential aspects: what it creates, sensitivity handling, prerequisite steps, instance selection, and cost. The output schema exists and all parameters are documented, so the description doesn't need to explain return values in detail. It could expand on post-creation lifecycle (e.g., revocation), but overall it's adequate for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

All six parameters have descriptions in the schema (100% coverage), so the schema carries the semantic burden. The description largely restates clerk_instance_id guidance already in the schema, adding only the prerequisite call to get_connected_accounts. No new parameter-specific meaning is provided beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action: 'Create an M2M token in a connected Clerk instance.' It names the specific resource type (M2M token) and context, but doesn't explicitly compare against sibling token-creation tools like create_actor_token or create_session_token, so it doesn't fully achieve sibling differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It provides a clear precondition: 'Call clerk.get_connected_accounts first.' It explains how to choose a connection with clerk_instance_id or omit it for the default, giving concrete usage context. It doesn't state when not to use it or list alternative tools, but the guidance is sufficient.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation5/5

Each tool has a distinct purpose, further clarified by group prefixes and clear descriptions. Within each group, tools perform different operations (e.g., domains.lookup vs. domains.whois vs. domains.rdap) with no ambiguity.

Naming Consistency5/5

All tools follow a consistent group.tool_name pattern using snake_case. The naming is predictable and uniformly applied across all groups.

Tool Count4/5

78 tools is high, but the server aggregates multiple distinct API domains (11 groups). Each group has a reasonable number of tools, typically under 10, with TikTok having 17. The count reflects breadth, not bloat.

Completeness5/5

Each domain's tool set covers the primary expected operations (e.g., search, details, reviews, metrics, user info). There are no obvious gaps for read-only analytical use; features like posting are likely out of scope.