Featureflip
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| FEATUREFLIP_ORG | No | Org slug (needed only for multi-org personal tokens) | auto |
| FEATUREFLIP_TOKEN | Yes | ffp_ or ffs_ API token | |
| FEATUREFLIP_API_URL | No | API base URL | https://api.featureflip.io |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_projectsA | List projects in the Featureflip organization. Paginated: pass cursor from next_cursor to continue. |
| list_environmentsA | List the environments of a project (e.g. development, staging, production). |
| list_segmentsA | List reusable user segments in a project. Segments are referenced from targeting rules via userSegmentId. |
| get_segmentA | Get one user segment (its conditions, id, and metadata) by key or id. |
| list_flagsA | List feature flags in a project. Filter with search (key/name substring), tag, type, archived, owner. Each flag carries its owner ({id, email, name}, or null when unowned). Paginated via cursor. |
| get_flagA | Get one feature flag with its variations and metadata, including its owner (null when unowned). Address by flag key or id. |
| create_flagA | Create a feature flag. type is one of Boolean|String|Number|Json. Boolean flags get true/false variations automatically; for other types pass initialVariations. The flag is created in every environment of the project (disabled). |
| update_flagA | Update flag name/description/tags/clientSideVisible. Changes only the fields you pass and keeps the rest; pass description: "" to clear it. Key and type are immutable. Use toggle_flag / update_targeting for behavior changes. |
| set_flag_expiryA | Set the date a flag is expected to be removed by, or pass expiresAtUtc: null to clear it. Expiry is advisory: evaluation never changes. Once the date passes, find_stale_flags reports the flag as expired. expiresAtUtc takes a date (2026-12-31), which means the end of that day in UTC, the same as picking it in the dashboard, or a full ISO-8601 timestamp, which is stored exactly. Refused with EXPIRY_IN_PAST for a time that has already passed (today's date is allowed), and with FEATURE_NOT_ENABLED while flag expiration is not enabled for the organization. Clearing is always allowed. |
| set_flag_ownerA | Name the person responsible for a flag, or pass owner: null to leave it unowned. owner is the email of an active member of the organization, or "me" for the token's own user (needs a personal access token). The owner gets the flag's cleanup notices; evaluation never changes. Refused with OWNER_NOT_MEMBER for an email that is not an active member, and with PLAN_FEATURE_UNAVAILABLE below the Pro plan. Clearing is always allowed. |
| delete_flagA | PERMANENTLY delete a flag across all environments. Fails with FLAG_HAS_DEPENDENTS if other flags use it as a prerequisite. Prefer archive_flag unless the flag must be fully removed. |
| archive_flagA | Archive a flag (soft-hide, evaluation stops serving it). Reversible with restore_flag. Archive dependents first: refused with FLAG_HAS_DEPENDENTS while another live flag lists this one as a prerequisite, so archive those flags (blockedBy in find_stale_flags / list_removal_candidates) first. Refused with FLAG_RECENTLY_EVALUATED while live traffic is still evaluating the flag, because archiving makes every caller fall back to its own hardcoded default — normally that means the code removal has merged but not deployed yet, and the refusal clears itself once it has. |
| restore_flagB | Restore a previously archived flag. |
| toggle_flagA | Enable or disable a flag in ONE environment. Affects live evaluation immediately — double-check the environment. |
| update_flag_environment_configA | Update a flag's per-environment serving config: defaultVariationId (served on fallthrough, required), strategy (SingleVariation | PercentageRollout | TargetedRollout — only SingleVariation is currently supported at the environment level), and prerequisites. Percentage rollouts are configured on targeting rules via update_targeting. |
| flag_statusB | Compact cross-environment view of one flag: enabled state, strategy, default variation, and prerequisites per environment. |
| get_targetingA | Get a flag's current targeting configuration (enabled flag + ordered rules) in one environment. |
| update_targetingA | REPLACE all targeting rules of a flag in one environment (full PUT — rules not included are removed). Rules are evaluated in order. Get the current rules first with get_targeting. |
| manage_variationA | Manage a flag's variations. action=add requires key + value; action=update/remove require variationId (get ids via get_flag). Removing a variation fails with VARIATION_HAS_DEPENDENTS if other flags depend on it. |
| list_webhooksA | List the organization's outbound webhook subscriptions (url, event/project/environment filters, enabled state, failure count, signing secret ids — never secret values), plus availableEventTypes: the event types a subscription can filter on. Empty filter lists mean "all". Paginated via cursor. Requires an Admin token. A 404 on every webhook call means webhooks are not enabled for the organization. |
| list_webhook_deliveriesA | List one subscription's delivery attempts, most recent first. status is Pending (awaiting an attempt, backing off, or in flight), Succeeded or DeadLettered; lastResponseStatusCode and lastError explain a failure. Paginated via cursor. Requires an Admin token. A 404 on every webhook call means webhooks are not enabled for the organization. |
| manage_webhookA | action=create requires name + url and returns the signing secret. action=update/delete/rotate_secret/retire_secret require id. update changes only the fields you pass and keeps the rest; pass an empty list to widen that filter back to "all". projects take project keys or ids; environments take "/" keys (e.g. "web/production") or ids. eventTypes come from list_webhooks → availableEventTypes. create and rotate_secret return a secret that is NEVER shown again: relay it to the user verbatim so they can store it. rotate_secret adds a new active secret while the old one keeps signing; retire_secret (secretId from list_webhooks) removes one and is refused for the last active secret. A project-restricted service token must list at least one project, all in its scope. Requires an Admin token. A 404 on every webhook call means webhooks are not enabled for the organization. |
| deliver_webhookA | action=test queues one synthetic flag.toggled event to this subscription alone; action=redeliver (deliveryId from list_webhook_deliveries) re-sends a finished delivery, restarting its retry schedule. Delivery is asynchronous: read list_webhook_deliveries for the outcome. Both are refused for a disabled subscription, and redeliver for a delivery that is still Pending. Requires an Admin token. A 404 on every webhook call means webhooks are not enabled for the organization. |
| find_stale_flagsA | Find flags that look ready for code cleanup: not updated in N days AND either enabled in every environment (verify rollout is complete before removing — per-rule percentage ramps are not inspected) or disabled in every environment (dead — remove flag and code path). A flag whose expiry date (set_flag_expiry) has passed is always a candidate, however recently it was edited; if it is on in some environments and off in others its reason is past-expiry, meaning the owner has to decide which way to fold it. Every result carries expiresAtUtc, expired and owner (null when unowned). Pass owner to see one person's stale flags ("me" for your own) or "none" for the unowned ones. Every result also carries blockedBy: the live flags that still list it as a prerequisite, which have to be removed and archived before it ([] when none). blockedBy is null when the server did not classify the flag as a removal candidate, which means unknown, not unblocked. A flag that other live flags list as a prerequisite has to be removed LAST, dependents first: archiving it while a dependent still names it makes that dependent fail its prerequisite check and serve its off variation, so archive_flag refuses it with FLAG_HAS_DEPENDENTS. Checks at most 50 candidates per call, expired flags first. |
| list_removal_candidatesA | List the flags the server is confident can be removed from code, the same list the Featureflip flag cleanup GitHub Action works from. Each item has key, reason, status (Dead or Stale), treatment (true = keep the on-branch, false = keep the off-branch) and blockedBy: the live flags that still list it as a prerequisite. Only remove a flag whose blockedBy is empty. A flag that other live flags list as a prerequisite has to be removed LAST, dependents first: archiving it while a dependent still names it makes that dependent fail its prerequisite check and serve its off variation, so archive_flag refuses it with FLAG_HAS_DEPENDENTS. staleness "dead" (the default) returns only dead flags, "stale" adds stale ones. Paginated via cursor. |
| wrap_featureA | Create a Boolean feature flag and get back the SDK code snippet to guard the new code path with it. Returns the snippet only — apply the edit yourself. The flag starts DISABLED in every environment; enable it with toggle_flag when ready. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 26 tools
Most tools target distinct resources or actions, but find_stale_flags and list_removal_candidates both surface flags for cleanup with overlapping descriptions, and create_flag and wrap_feature both create flags. Descriptions help differentiate, yet an agent could still misselect between these pairs.
Tool names are consistently snake_case and nearly all follow a verb_noun pattern (list_flags, get_flag, update_targeting, etc.). The only minor deviation is flag_status, which is noun-first, but it remains readable and consistent in style.
With 26 tools, the server is on the heavy side for its purpose. Several operations could be consolidated (e.g., flag_status into get_flag, find_stale_flags and list_removal_candidates into one parameterized tool), making the surface larger than necessary despite a broad domain.
The set covers core feature flag lifecycle (create, read, update, delete, archive, restore), targeting, variations, cleanup, and webhooks well. Minor gaps exist for segments and environments (only list/get, no create/update/delete), but these are likely managed elsewhere and don't block core workflows.