Skip to main content
Glama

get_card_details

Read-onlyIdempotent

Get decrypted PAN, CVV, expiry, and current balance for a specific card. Use this only when you need to fill in a payment form — prefer get_card_balance if you only need the balance. May require human approval before returning credentials. If approval is required, prompt the user and then call approve_request. Card details are encrypted at rest with AES-256-GCM.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
card_idYesThe card ID
approval_idNoApproval id from a prior approval_required response, once the user has approved. Only for cards created through ANOTHER app: first call without it (the user is emailed an approve link), then retry with it.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
last4NoLast four digits of the card number. Present only when status is "details".
cardIdNoThe card ID.
expiryNoCard expiry (MM/YY). Present only when status is "details".
statusNoOutcome discriminator: "details" when credentials were returned, "approval_required" when human approval is needed first, "not_accessible" when the card exists outside this connection's scope, "managed_by_organization" for org-issued read-only cards.
messageYesHuman-readable card details (or an approval-required prompt).
approvalIdNoThe approval request ID to pass to approve_request. Present only when status is "approval_required".
cardStatusNoCard status, e.g. "active" or "closed". Present only when status is "details".
balanceCentsNoCard balance in cents. Present only when status is "details".
balanceDollarsNoCard balance formatted as USD dollars, e.g. "12.50". Present only when status is "details".

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Discloses that the tool requires human approval before returning credentials and that card details are encrypted at rest with AES-256-GCM. Annotations already declare read-only and non-destructive, so this adds valuable behavioral context without contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four sentences with no filler: front-loaded purpose, alternatives, approval, and encryption. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (sensitive data, approval flow, two params, output schema exists), the description covers all necessary aspects: what data is returned, when to use, approval process, and encryption. No gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with basic descriptions, but the description explains the approval_id parameter workflow (first call without, then retry with it), adding meaning beyond schema. This warrants a score above baseline 3.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool returns decrypted PAN, CVV, expiry, and balance, and distinguishes from get_card_balance, citing specific use cases. This is a specific verb+resource with sibling differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use (for filling payment forms) and when not (prefer get_card_balance for just balance). Also describes the approval workflow, including when to call approve_request, providing complete guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation4/5

Most tools have clearly distinct purposes, especially in areas like card management and shopping. However, the KYC flow has multiple overlapping tools (start_kyc, get_kyc_status, check_kyc_document, submit_kyc_document, submit_kyc_fields) that could confuse an agent despite detailed descriptions.

Naming Consistency4/5

Tool names consistently use snake_case with a verb_noun pattern (e.g., add_funds, create_card, list_cards). A few exceptions like surprise_me and whoami break the pattern but are still intuitive overall.

Tool Count3/5

50 tools is on the high side for a single server, but the broad domain (cards, shopping, KYC, support, settings) partially justifies it. Some tools could be merged (e.g., KYC flow tools) without losing clarity.

Completeness4/5

The tool surface covers core workflows: CRUD for cards, transactions, KYC, support, shopping, and account management. Minor gaps exist (e.g., no update_card general, no cancel order in shopping), but overall the set is comprehensive for the stated purpose.

Resources