Skip to main content
Glama
Vortitron

home-assistant-mcp

by Vortitron

Remove a user's login without deleting the user

ha_remove_user_credentials
Destructive

Remove local username/password login from a Home Assistant user while keeping the account and other login methods. Use for revoking sign-in access without deleting the user.

Instructions

Remove the local username/password login from a user, without deleting the user record itself. The user still exists (and keeps any other login method) but can no longer sign in with this username. Use ha_delete_user to remove the account entirely. Requires ha:config.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
usernameYesThe username to remove (not the user id).
instance_idNoOptional: the instance you mean (as listed by vomehome_list_instances). When given, the call is refused if this session is targeting a different home, instead of answering from it.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.10.0

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and readOnlyHint=false, so the safety profile is known; the description adds genuinely useful scope detail beyond that — the user record survives, other login methods survive, and only this username stops working. It also discloses the required permission (ha:config), which annotations cannot express. No statement about reversibility of the removal itself.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, front-loaded with the core action and its scope, then the alternative, then the permission requirement. No filler or restatement of the title.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter destructive tool with no output schema and full annotation coverage, the description covers what an agent needs: what is removed, what survives, the sibling to use instead, and the permission gate. Only the effect on the deleted credential (recoverability, error behavior) is left unstated.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and both parameters are well documented there (including that 'username' is not the user id and what instance_id does). The description adds nothing about parameter format or semantics, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a precise verb and scope: removing the *local username/password login* while explicitly preserving the user record. It draws a clear line against ha_delete_user, so an agent can distinguish this from account deletion without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit when-not and alternative: 'Use ha_delete_user to remove the account entirely.' That is strong routing. It does not, however, distinguish this from the nearer credential siblings ha_set_user_credentials and ha_change_user_password, which an agent could plausibly confuse with a credential-removal operation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools