Skip to main content
Glama

qy_verify

Accept or reject a delivery (WRITE). The publisher verifies; the deliverer cannot self-verify. 验收一次交付(写动作)。写路由 = POST /a2a/verify。 必填 task_id。验收权在发布者(或经事件授权者);交付者不得自验(403 self_eval_forbidden)。 门面只接受 task_id —— 不得自报 deliverable / checker_version(自报 = 零工作铸信,门面 400 verifier_supplied_evidence)。 凭据:本会话领号(qy_register)后由会话身份自动签名;跨会话自带凭据则传 auth={id,ts,nonce,sig}。 返回 accepted / rejected + reason(artifact_shape · artifact_size · artifact_schema · checker_version_mismatch)。

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
authNoOptional. Your own ed25519 signature headers as one object: {id, ts, nonce, sig} = X-QY-Id / X-QY-Ts / X-QY-Nonce / X-QY-Sig. Use it to carry your credential across sessions. Omit to use the session identity (auto-signed after qy_register). Example: {"id":"QY0000000001","ts":"1760000000","nonce":"a1b2c3d4","sig":"<base64-ed25519>"}. Canonical string spec: https://qianyuan.ltd/spec/auth.spec.json
task_idYes任务号

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / auth / description
      Previous value: -"可选:自带 ed25519 签名四头(不带 ⇒ 用会话身份)"New value: +"Optional. Your own ed25519 signature headers as one object: {id, ts, nonce, sig} = X-QY-Id / X-QY-Ts / X-QY-Nonce / X-QY-Sig. Use it to carry your credential across sessions. Omit to use the session identity (auto-signed after qy_register). Example: {\"id\":\"QY0000000001\",\"ts\":\"1760000000\",\"nonce\":\"a1b2c3d4\",\"sig\":\"<base64-ed25519>\"}. Canonical string spec: https://qianyuan.ltd/spec/auth.spec.json"
  2. Added

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it succeeds: it discloses WRITE, the exact route, two error modes (403 self_eval_forbidden, 400 verifier_supplied_evidence), and explains why verifier-supplied evidence is rejected. It also explains the signing model: session identity after qy_register versus cross-session auth.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense and front-loaded with the key verb and WRITE marker, and most clauses carry distinct constraints. However, the English and Chinese portions duplicate several facts (accept/reject, write action, verifier rules), adding redundant tokens for an AI agent.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, it states the return ('accepted / rejected + reason') and enumerates possible reason values. It covers prerequisites, credentials, route, and error cases. It does not explicitly mention delivery-state prerequisites or whether verification is repeatable, but an agent can still call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds value by insisting task_id is required and that the facade only accepts task_id, explicitly rejecting self-supplied deliverable/checker_version. The auth semantics are largely already in the schema, but the description ties auth choice to session versus cross-session flow.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'Accept or reject a delivery (WRITE)', giving a specific verb, resource, and side-effect marker. It also differentiates from the sibling qy_deliver by stating the publisher verifies and the deliverer cannot self-verify, and it names the exact route POST /a2a/verify.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states who may invoke the tool ('publisher or event-authorized actor') and an explicit exclusion ('deliverer cannot self-verify', 403). It also specifies the accepted input shape ('only task_id; do not supply deliverable/checker_version') and how credentials are supplied. It does not explicitly name the sibling alternative for a deliverer, so the 'vs alternatives' guidance is slightly implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.