Skip to main content
Glama

exchange_code

Exchanges an OAuth authorization code for an access token, keeps it server-side, and saves it to the environment file for authenticated API calls.

Instructions

Step 2 of OAuth: exchange the code for an access token. The token is kept in this server (and saved to the env file); it is not shown to you.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeYes
redirect_uriNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden. It usefully discloses that the token is kept server-side, saved to an env file, and not shown to the caller, but it does not cover permissions, error cases, code expiration/single-use behavior, or redirect_uri requirements.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences, front-loaded with the core purpose and followed by the key behavioral caveat. Nothing is wasted and the structure is easy to scan.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an OAuth exchange tool with no annotations, no output schema, and 0% parameter description coverage, the description is incomplete. It explains token handling but leaves out how the required code and optional redirect_uri should be supplied, error behavior, and prerequisites.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters1/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% for both parameters, and the description provides no semantics for code or redirect_uri. The word 'code' appears only as part of the OAuth flow description, not as parameter guidance, so the agent gets no additional meaning beyond the bare schema names.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb and resource: 'exchange the code for an access token.' Calling it 'Step 2 of OAuth' clearly distinguishes this tool from auth_url and the token-management siblings without needing to name them.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'Step 2 of OAuth' framing tells the agent this tool belongs in a specific sequence after obtaining a code. It provides clear context but does not explicitly name auth_url as the preceding step or mention any conditions where this tool should not be used.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.