Skip to main content
Glama

Roastify Forget Credentials

roastify_forget_credentials

Delete vaulted credentials for a specific service and npub.

For operator credentials, pass the operator's own npub. For patron credentials, pass the patron's npub. Always requires proof of npub ownership — a deletion is as destructive as a write.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
npubYesThe Nostr public key (npub1...) whose credentials to forget.
serviceYesThe credential service to forget.
dpop_tokenYesRaw JSON of a kind-27235 Nostr event signed by npub — not base64, not NIP-98 'Authorization: Nostr <b64>' framing. Its `u` tag must hold THIS tool's exact name (from tools/list), not the endpoint URL; content:"", created_at within 60s of now, and a random `nonce` tag recommended. Or a cached dpop_token phrase.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A3.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations at all, the description carries the full burden and it does add valuable behavioral context: 'Always requires proof of npub ownership — a deletion is as destructive as a write.' This signals authentication requirements and destructive potential, which is not inferable from the schema alone. It stops short of detailing reversibility or return behavior, but it is a strong disclosure for a delete operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is only three sentences and front-loads the core action. Every sentence earns its place: action, parameter disambiguation, and the destructive/auth warning. It does not repeat the verbose dpop_token schema text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For the credential-deletion operation itself, the description covers the action, the key parameters, and a warning. However, it does not situate the tool among the overlapping sibling delete_operator_credential/delete_patron_credential, leaving a material contextual gap for a destructive operation. The existence of an output schema mitigates the need to describe return values, but not the routing ambiguity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds meaning beyond the schema by clarifying that npub should be the operator's own for operator credentials and the patron's for patron credentials, and by emphasizing that dpop_token must prove ownership of that npub. This extra guidance justifies a 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific action and object: 'Delete vaulted credentials for a specific service and npub.' It clearly states what the tool does. However, it does not distinguish itself from sibling tools like roastify_delete_operator_credential and roastify_delete_patron_credential, which appear to cover the same operation, so it misses the top score.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides context about which npub to pass for operator vs patron credentials, but it never explains when to choose this tool over the sibling 'delete_*' tools. There is no explicit when/when-not or alternative guidance, so an agent cannot route correctly among the overlapping credential-deletion tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.