Skip to main content
Glama
Pappa

mcp-oidc-proxy

by Pappa

create_user

Provision new NanoIDP user accounts with username, password, roles, groups, and optional custom attributes to enable OIDC authentication.

Instructions

Create a new user in NanoIDP

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
emailNoEmail address (optional)
rolesNoList of roles (optional, default: ['USER'])
groupsNoList of groups (optional)
tenantNoTenant identifier (optional, default: 'default')
passwordYesPassword for the new user
usernameYesUsername for the new user
attributesNoCustom key-value attributes (optional)
source_aclNoSource ACL entries for document-level security
descriptionNoDisplay-only note shown in the persona login picker (optional, max 200 chars)
entitlementsNoList of entitlements
identity_classNoIdentity class (e.g., INTERNAL, EXTERNAL)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It only restates the operation ('Create a new user') and adds nothing about side effects, validation, default role assignment, idempotency, or error behavior. For a mutation tool, this is a significant gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence with no filler or redundant phrasing. It is appropriately brief, though minimal; it could arguably use a second sentence about behavior or sibling distinction, but structurally it is clean.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With 11 parameters, nested objects, no output schema, and no annotations, this tool is complex, yet the description offers only the bare operation statement. It omits behavioral defaults (e.g., default roles/tenant from the schema), possible auth requirements, and the critical distinction from create_persona_user, so the agent lacks enough context to call it correctly in all cases.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema documents all 11 parameters with descriptions, so schema coverage is 100% and the baseline is 3. The description itself contributes no parameter-level semantics, but it doesn't need to because the schema already carries that load. No penalty beyond baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a clear verb ('Create') and resource ('a new user in NanoIDP'), so an agent can tell it creates a user. However, it does not distinguish this from the sibling tool 'create_persona_user' – both appear to create users, so the agent cannot tell which one fits a persona-user scenario.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to use this tool versus alternatives like create_persona_user, nor any prerequisites or preconditions for creating a user. The description simply announces the operation without context, so the agent is left to guess based on parameter names.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.