Skip to main content
Glama

get_free_key

Get a free developer key for the metered tools on this server, without leaving this session. No payment, no account, no card. The key holds a small daily allowance that refills every day, and one credit is consumed per verdict, nothing on an error. Present it as the X-API-Key header on this MCP connection, or hand it to whoever configures your client. Throttled exactly as the equivalent HTTP endpoint is: one key per source per window, so calling this again shortly after will be refused rather than minting a second key. Store the key when you get it: it is shown once and cannot be recovered.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
tierNo
errorNoPresent instead of a key when one could not be minted right now.
api_keyNoShown once. Store it before doing anything else.
creditsNo
daily_limitNoScans per day, refilled daily.
retry_after_hoursNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations are minimal (readOnlyHint false, etc.), so the description carries the burden. It discloses critical behaviors: one credit consumed per verdict (and none on error), throttling to one key per source per window, and that the key is shown once and cannot be recovered. This goes well beyond what annotations provide and is fully transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose, then covers usage, throttling, and storage in a logical sequence. Every sentence provides essential information without redundancy. It is appropriately sized for the complexity of the tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema is present and parameters are none, the description fully covers what an agent needs: the key's behavior, how to use it, its limitations, and the one-time display. Nothing essential is missing for correct invocation and handling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and schema coverage is 100% (trivially). Per the baseline for 0 params, a 4 is appropriate. The description does not need to explain parameters and adds no parameter-specific information, which is expected.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Get') and the resource ('free developer key'), with the specific scope 'for the metered tools on this server'. It also distinguishes itself from the sibling scanning/checking tools by its purpose, so there is no ambiguity about what it does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It provides clear context on when to use it (when a key is needed without leaving the session) and how to present it (X-API-Key header). It mentions throttling and the one-time nature, which informs usage frequency. It doesn't explicitly name alternatives, but the sibling tools are obviously different in function, making the usage context clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.