Skip to main content
Glama
YawLabs

@yawlabs/tailscale-mcp

by YawLabs

Create AWS external ID

tailscale_create_aws_external_id

Create or retrieve the AWS external ID to include in your IAM role trust policy for Tailscale S3 log streaming, then verify it with tailscale_validate_aws_trust_policy.

Instructions

Create or get the AWS external ID Tailscale presents when assuming your IAM role for S3 log streaming. Put it in the role trust policy's sts:ExternalId condition, then check it with tailscale_validate_aws_trust_policy.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
reusableNoDefault true: Tailscale returns the SAME external ID on repeat calls until that ID has been linked to an AWS account, so asking again does not invalidate the ID already pasted into an IAM trust policy. Set false to force a fresh ID (what Tailscale's Terraform provider does, one ID per resource).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.21.0
    • addedInput schema / properties / reusable
      Added value: +{
      +  "description": "Default true: Tailscale returns the SAME external ID on repeat calls until that ID has been linked to an AWS account, so asking again does not invalidate the ID already pasted into an IAM trust policy. Set false to force a fresh ID (what Tailscale's Terraform provider does, one ID per resource).",
      +  "type": "boolean"
      +}
  2. First observedv0.13.3

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already indicate readOnlyHint=false and idempotentHint=false, so the tool is expected to have side effects and not be idempotent. The description adds that it 'creates or gets' an ID and the intended downstream use, but it does not disclose specifics about state changes, auth requirements, or rate limits. It doesn't contradict annotations, but it also doesn't enrich them significantly.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the core purpose, and immediately directs the agent to the next action. Every word earns its place; there is no filler or redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with one well-documented parameter, clear annotations, and no output schema, the description provides sufficient context: it states what it does, why it is needed, and how to integrate it with the validation tool. It could explicitly mention that the tool returns the external ID, but that is strongly implied by 'Create or get' and the usage instructions. Overall, nothing critical is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema description coverage is 100% for the single parameter 'reusable', which is thoroughly explained (default behavior, what false means). Per the rubric, a high coverage baseline of 3 applies. The tool description itself adds no extra parameter context, so the schema carries the weight.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Create or get') and identifies the resource ('AWS external ID') with its purpose ('for S3 log streaming'). It clearly distinguishes this tool from siblings by naming the exact object and context, and it references the companion validation tool, making its role unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives a clear workflow: obtain the ID, place it in the trust policy, then validate with tailscale_validate_aws_trust_policy. It implies when to use this tool (as a prerequisite to validation) but does not explicitly state when not to use it or mention alternative approaches. The 'reusable' parameter behavior is covered in the schema, not the description.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools