Skip to main content
Glama

List secrets

list_secrets
Read-only

List the secrets belonging to the authenticated tenant (metadata only — never the secret value). A secret is a stored credential (API key, token) that an api template references by slug in its auth block to inject on outbound calls. Use this to discover which secrets exist so you can wire an api template's auth.secret to the right slug. If the secret you need does not exist yet, send the user to https://tessryx.io/dashboard/secrets to create it — secrets cannot be created or set through this assistant.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
page_sizeNomaximum number of secrets to return in this page
page_tokenNotoken from a previous response's next_page_token to fetch the next page
slug_prefixNoonly return secrets whose slug starts with this prefix

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
secretsYes
next_page_tokenYes

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, destructiveHint=false, and openWorldHint=false, so the safety profile is covered. The description adds valuable behavioral context beyond that: it discloses that only metadata is returned and never the secret value, and it states the important limitation that secrets cannot be created or set through this assistant — both of which materially shape how an agent should act.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The primary purpose and scope are front-loaded in the first sentence, with use-case guidance and limitation disclosure following in the second. The brief definition of what a secret is earns its place because it grounds the agent in domain semantics, and every sentence carries distinct information. Slightly dense but not wasteful.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple list tool with an output schema present, zero required parameters, and safety annotations already covering the mutation profile, the description covers purpose, scope, usage context, domain meaning, and a key limitation. The pagination mechanics are implicitly referenced via page_token's schema description, so nothing critical is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all three parameters (page_size, page_token, slug_prefix) are already documented in the schema. The description reinforces the slug concept by explaining that api templates reference secrets by slug, which adds minor semantic context for slug_prefix, but it does not need to compensate for any schema gap. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource+scope: 'List the secrets belonging to the authenticated tenant.' It further distinguishes itself from sibling get_secret by clarifying it returns metadata only, and from secret creation by stating secrets cannot be created or set through the assistant. An agent can unambiguously determine what this tool does and what it does not do.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives a concrete use case — discovering which secrets exist so an api template's auth.secret can be wired to the correct slug — and provides an explicit fallback path (send the user to the dashboard) when the needed secret doesn't exist. It does not explicitly name the sibling get_secret as an alternative for retrieving a specific secret's details, which would have made the routing complete.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4/5.0
Disambiguation5/5

Every resource family follows the same verb+noun pattern and each tool name uniquely identifies a resource-action pair (create_app vs create_app_version vs update_app vs publish_app). Closest overlaps like analyze_resource vs get_resource_graph and patch_datafile vs update_datafile are explicitly differentiated by their descriptions, so misselection risk is low despite the scale.

Naming Consistency5/5

Names are almost uniformly verb_noun snake_case with a consistent lifecycle vocabulary: create/get/update/delete/list/publish/unpublish/version. Minor outliers like whoami and run_schedule_now are idiomatic and do not break the predictability of the set.

Tool Count1/5

At 93 tools this far exceeds the calibration's 50+ extreme-mismatch case. The count is inflated by repeating create/get/update/delete/version/publish/unpublish across ten resource families; even though each family is systematic, the combined surface is very hard for an agent to navigate and keep in context.

Completeness4/5

Core CRUD/publish/version lifecycles are present for apps, workflows, endpoints, schedules, schemas, datafiles, and api templates, and dependency analysis is well covered. However, secret creation/updating, asset upload, custom-domain deletion, and version-range enumeration for several resource types are absent or left to the external dashboard, so agents hit a few manual dead ends.

Resources