Skip to main content
Glama
Vortitron

home-assistant-mcp

by Vortitron

Create a guest link

vomehome_create_guest_link
Destructive

Create a revocable guest login link for a Vome-hosted Home Assistant instance, generating a non-admin user and one-click URL that expires automatically.

Instructions

Create a non-admin (unless admin=true) Home Assistant user for this instance, plus a one-click login URL for it — self-serve, revocable sharing without handing out the owner's own login. Only works for Vome-hosted instances (not self-hosted/relay ones): minting a token for someone other than the owner needs direct network access to the VM.

Home Assistant's permission model is coarse. A non-admin guest is locked out of Settings and Developer Tools, but can still call services on any entity the dashboard shows them — there is no per-entity guest scoping in Home Assistant itself. This is safe on a dedicated demo/sandbox instance built to be poked at. It is not a substitute for real access control on somebody's actual house — do not point a guest link at one.

The link expires automatically (default 24h, max 30 days) and can be revoked early with vomehome_revoke_guest_link. Treat the returned URL as a secret; do not log it.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
adminNoGrant full admin access instead of a restricted account. Default false — choose true deliberately.
dashboardNoLovelace url_path to land the guest on after sign-in, instead of the default dashboard.
expires_inNoSeconds until this link is auto-revoked. Default 24h (86400), capped at 30 days.
instance_idYesVomeHome instance id (UUID) to create the guest user on.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.10.0

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=false, destructiveHint=true, openWorldHint=true, so the mutation/side-effect profile is covered. The description goes beyond that with genuinely useful context: the permission model of the created user, default/max expiry, revocability, and secret-handling of the returned URL. Return format beyond 'the URL' is not described, and no output schema exists, but the safety-relevant behavior is well disclosed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action, then caveats in a clearly separated emphasis block. Every sentence carries information, though the permission-model paragraph is dense enough that it borders on over-length for a create tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with no output schema, the description covers the missing pieces: what is created, instance-type restriction, expiry/revocation lifecycle, and the need to treat the returned URL as a secret. Nothing an agent needs to call it safely is absent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents all four parameters. The description restates the admin flag and the 24h default / 30-day cap, but adds no syntax or format detail beyond what the schema provides. Baseline 3 applies when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific compound verb+resource: creates a non-admin Home Assistant user plus a one-click login URL, and clarifies admin=true is the exception. An agent can distinguish this from ha_create_user (no guest link) and vomehome_get_login_url (owner login URL) without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names the precondition (only works for Vome-hosted instances; minting a token for a non-owner needs direct VM network access), names the alternative for early termination (vomehome_revoke_guest_link), and gives an explicit when-not-to-use (do not point at somebody's actual house).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools