AgeKey MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_organizationsA | List all AgeKey organizations you have access to. Returns organization details including your role and the number of applications. |
| list_applicationsA | List all applications in an AgeKey organization. Returns app names, IDs, and credential status. |
| get_applicationA | Get detailed information about a specific AgeKey application including credentials and redirect URIs. |
| create_applicationA | Create a new AgeKey application. Returns test credentials (secret shown only once!). Requires Admin role or higher in the organization. |
| get_credentialsB | Get credentials (App ID, Secret, Authority URL) for an AgeKey application. Specify 'test' or 'live' environment. Requires orgId (the organization that owns the app). |
| rotate_credentialsA | Rotate credentials for an AgeKey application. For TEST mode: Requires Member role or higher. For LIVE mode: Requires Admin role or higher AND explicit confirmation phrase. ⚠️ WARNING: Old credentials are invalidated immediately! |
| add_redirect_uriA | Add a redirect URI to an AgeKey application. For TEST mode: Any valid URL (localhost allowed). Requires Member role. For LIVE mode: Must be HTTPS (no localhost). Requires Admin role AND confirmation. |
| remove_redirect_uriA | Remove a redirect URI from an AgeKey application. For TEST mode: Requires Member role. For LIVE mode: Requires Admin role AND confirmation. ⚠️ WARNING: Removing a live URI will immediately break any production integration using it! |
| decode_jwtA | Decode and explain an AgeKey JWT token. Shows header, payload, expiration status, and human-readable explanation of age verification results. |
| explain_errorA | Get a detailed explanation of an AgeKey/OIDC error code including common causes, solutions, and documentation links. |
| get_code_sampleB | Get integration code samples for AgeKey in various languages. Optionally pre-fill with your app credentials. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 11 tools
Most tools map cleanly to distinct resources and actions. get_application and get_credentials both surface credential information, which could cause an agent to pick the wrong one, though get_credentials is environment-specific.
All tools use a consistent snake_case verb_noun pattern (list_*, get_*, create_*, rotate_*, add_*, remove_*), making the set predictable. No mixed conventions or vague verbs.
With 11 tools, the set is appropriately scoped for an AgeKey administration and integration server. Each tool addresses a meaningful operation without redundancy or bloat.
The surface covers org listing, app creation/inspection, credential rotation, redirect URI management, and helpful utilities. However, there is no update or delete application tool, so full application lifecycle management is incomplete.