Skip to main content
Glama
Pappa

mcp-oidc-proxy

by Pappa

create_persona_user

Create password-less users for persona login mode, enabling local development and testing authentication through identity selection in the interactive login UI, without password-based or OAuth grant access.

Instructions

Create a password-less user for persona login mode (local dev/testing convenience, 'login.mode: persona' in settings). The user can only authenticate by identity selection in the interactive login UI - never via password-mode login or the OAuth password grant. To keep 'create_user' unambiguous (always creates a normal, password-protected user), this is a separate tool rather than an optional password on create_user.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
emailNoEmail address (optional)
rolesNoList of roles (optional, default: ['USER'])
groupsNoList of groups (optional)
tenantNoTenant identifier (optional, default: 'default')
usernameYesUsername for the new persona-mode-only user
attributesNoCustom key-value attributes (optional)
source_aclNoSource ACL entries for document-level security
descriptionNoDisplay-only note shown in the persona login picker (optional, max 200 chars)
entitlementsNoList of entitlements
identity_classNoIdentity class (e.g., INTERNAL, EXTERNAL)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden. It discloses that the user is password-less, can only authenticate via identity selection, and never via password-mode or OAuth password grant. It also states the purpose is a dev/testing convenience. However, it does not mention permissions, reversibility, or side effects beyond creation, so it is not perfect but strong.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, front-loaded with the core purpose, then explains the auth constraint and the reason for being a separate tool. Every sentence earns its place with no fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 10 parameters and no output schema, the description covers the essential usage context (when, why, and auth behavior). It could mention the response format or any prerequisites (e.g., admin role), but the schema covers parameter details, so the description is reasonably complete for an agent to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so each parameter already has a clear description. The tool description does not add additional meaning to parameters beyond the schema, so the baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb (create), the resource (password-less user for persona login mode), and explicitly distinguishes it from the sibling create_user, which creates a normal password-protected user. The purpose is unambiguous and specific.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly explains when to use this tool (persona login mode, local dev/testing) and contrasts it with create_user, stating that create_user is for normal password-protected users. This gives clear usage direction without ambiguity.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.