Skip to main content
Glama

Corply — Start and run your company

Upload operating evidence

upload_operating_evidence

Store exact caller-supplied evidence bytes in the active company's private canonical evidence prefix and return the server-computed SHA-256 needed by record_operating_evidence. Use only when the client has supplied the actual base64 file bytes; never invent bytes from a description. Browser/desktop clients should use POST /operating/evidence/upload for files larger than the MCP limit. Prerequisite: authenticated active company access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
fileNameYes
companyIdNocorply_companies.id. May be omitted only when this connection has exactly one company.
dataBase64YesCanonical RFC 4648 base64 for the exact file bytes, without a data-URL prefix.
contentTypeNo
_corply_contextNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • removedInput schema / properties / _corply_context / description
      Removed value: -"Echo context_engineering.context_session from the prior Corply result."
    • changedInput schema / properties / companyId / description
      Previous value: -"corply_companies.id. May be omitted only when the active organization has exactly one company."New value: +"corply_companies.id. May be omitted only when this connection has exactly one company."
  2. Changed1 schema field changed
    • addedInput schema / properties / _corply_context
      Added value: +{
      +  "additionalProperties": false,
      +  "dependentRequired": {
      +    "receipt": [
      +      "id"
      +    ]
      +  },
      +  "description": "Echo context_engineering.context_session from the prior Corply result.",
      +  "properties": {
      +    "id": {
      +      "maxLength": 200,
      +      "minLength": 16,
      +      "type": "string"
      +    },
      +    "receipt": {
      +      "maxLength": 2048,
      +      "minLength": 16,
      +      "type": "string"
      +    }
      +  },
      +  "type": "object"
      +}
  3. Added

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare non-read-only, non-destructive, closed-world, so the safety profile is partly covered; the description adds real behavioral context beyond that: the auth prerequisite, the MCP size ceiling routing to HTTP, SHA-256 return needed by a sibling, idempotency/retry guidance, and the confirmation boundary. The closing boilerplate sentence is generic template text, which keeps it from a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The critical rules are front-loaded in the first three sentences, but the trailing canonicality/idempotency/confirmation paragraphs read as generic boilerplate rather than tool-specific content, diluting density.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description usefully explains the return value (server-computed SHA-256) and covers prerequisites, canonicality, idempotency, and confirmation. The main remaining gap is undocumented fileName/contentType parameters.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 40% (fileName, contentType, and the nested _corply_context object carry no schema descriptions), and the description does not explain any of them; it only restates base64 byte semantics already given for dataBase64. It fails to compensate for the coverage gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource (store evidence bytes into the active company's canonical evidence prefix) and names the downstream consumer, record_operating_evidence, which cleanly separates it from the sibling that records the reference rather than the bytes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit when-to-use ('only when the client has supplied the actual base64 file bytes'), an explicit prohibition ('never invent bytes from a description'), and a named alternative path (POST /operating/evidence/upload for oversized files) fully route the agent.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.