authbox
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_credentialA | Retrieve a credential from the Auth Box vault. Returns credential fields filtered by the agent's access policy. Never returns the raw secret unless the policy explicitly allows "read" action. |
| proxy_authenticated_requestA | Make an authenticated HTTP request through Auth Box. The stored credential is injected into the request without exposing it to the agent. This is the preferred method for using credentials. |
| list_available_servicesA | List all services that the user has stored credentials for. Returns service names only, no secrets. Useful for discovering what credentials are available before making requests. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a distinct purpose: listing services, retrieving credentials, and making proxy requests. There is no overlap in functionality.
All three tools follow a consistent verb_noun pattern with snake_case, making them predictable and easy to distinguish.
Three tools is well-scoped for a focused credential management server, covering the essential operations without unnecessary bloat.
The set covers the core workflow of discovering, retrieving, and using credentials. Missing create, update, and delete operations, but these may be out of scope for a vault that manages existing credentials.