Skip to main content
Glama

integrations_capture_session

Restore an expired integration session by capturing the LIVE auth of an open browser page — works for COOKIE sessions (browser_identity) AND TOKEN/HEADER sessions (bearer / api_key / custom_headers, e.g. Devise access-token/client/uid). First call browser_open(url, identity_name) for the integration's site (the page must be logged in AND have called its API), then pass that page_id here with integration_id or base_url. For cookie sessions it captures the full storage_state (incl httpOnly cookies page JS can't read) into the bound identity; for token sessions it captures the auth headers the page sends to the API host and binds them. Re-connects the integration. The captured secret never leaves the server (returns counts only). Generic — any site, any auth scheme, no local Playwright.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
page_idYespage_id from a prior browser_open of the integration's site (logged in).
base_urlNoOr the integration's base URL, e.g. https://api.boomnow.com.
in_workspaceNoRun this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.
integration_idNoIntegration id (from integrations.list).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / in_workspace
      Added value: +{
      +  "description": "Run this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.",
      +  "type": "integer"
      +}
  2. Added
  3. Removed
  4. Added

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare it is a non-readOnly, non-destructive, non-idempotent mutation. The description adds valuable context beyond that: it re-connects the integration, captures httpOnly cookies page JS cannot read, and that the secret never leaves the server (returns counts only). It omits required permissions, which keeps it from a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded in the first clause, then setup steps and session-type detail follow. It is a dense wall of text rather than bulleted, but nearly every sentence carries actionable content with little filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a multi-step capture tool with no output schema, the description covers the prerequisite sequence, both session types, the returned value (counts only), and the secrecy guarantee. Nothing an agent needs in order to invoke it correctly appears missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds meaning: page_id must come from a prior logged-in browser_open, integration_id and base_url are alternatives that select the target, tying parameters to the workflow. This goes beyond raw schema text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource — restore an expired integration session by capturing LIVE auth from an open browser page — and distinguishes the two auth schemes (cookie storage_state vs token/header). This clearly separates it from siblings like integrations_set_auth or browser_attach_identity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit precondition flow: call browser_open(url, identity_name) first with a logged-in page that has called its API, then pass page_id with integration_id or base_url. It doesn't explicitly name a sibling as the alternative for the non-capture case, but the ordering and conditions are clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.