Skip to main content
Glama

storage_publish

Publish a Storage object and return a presigned bucket GET URL.

Idempotent: returns the existing token if already published. Does not re-upload bytes (they already live in the bucket). Agents should use signed_url (TTL TEAMSHARED_STORAGE_SIGNED_URL_TTL_SECONDS, default 3600s) plus signed_url_expires_in / signed_url_expires_at. share_url / public_url remain the durable /d/{share_token} fallback for console/humans — not /s/{slug} (shared-file HTML). Fails closed if the object-storage bucket is unconfigured (cannot mint a signed URL).

Agent seats (org tsk_ / agent_run) are refused — call request_gated_approval(gate="publish") instead. Console humans (ts_session) still publish. After the approval child is done, a human seat calls this tool (same completion path as file_publish). drive_publish is a deprecated alias of this tool.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
file_idYesStorage object UUID to publish

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden and does so richly. It discloses idempotency, that bytes are not re-uploaded, the signed-URL TTL and expiration fields, the failure mode when the bucket is unconfigured, and the agent-seat refusal behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but every sentence adds operational value: purpose, idempotency, URL semantics, TTL details, auth gating, and deprecated alias. The core purpose is front-loaded and the supporting details are logically grouped.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a publish token tool with auth constraints, failure modes, and URL semantics, the description is exceptionally complete. It covers the output fields to use, the approval flow, the fallback behavior, and the deprecated alias, leaving no critical operational gap for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the single parameter file_id is already described as 'Storage object UUID to publish' in the schema. The description adds useful context about existing bucket bytes and idempotent behavior, but does not add significant new param-specific meaning beyond what the schema states.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Publish a Storage object and return a presigned bucket GET URL.' It distinguishes the tool from siblings like file_publish and drive_publish by clarifying that drive_publish is a deprecated alias and noting the same completion path as file_publish.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit when-to-use and when-not-to-use guidance: agent seats must call request_gated_approval(gate='publish') instead, while console humans can publish. It also directs agents to prefer signed_url fields and identifies the durable /d/{share_token} fallback versus the /s/{slug} HTML path.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.