Skip to main content
Glama
jeonghwanko
by jeonghwanko

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
LOGIN_MCP_KEYNoIf set, exit encrypts the site profiles with scrypt and AES-256-GCM and removes the plaintext directory until the next use by this process. Without the key, profiles are only protected by filesystem permissions (chmod 0700). The key is never logged. Do not put the key on the command line.
LOGIN_MCP_DATA_DIRNoThe data directory for storing per-site Chrome profiles at $LOGIN_MCP_DATA_DIR/sites/<site>/profile../data

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
auth_statusA

One line per site: site id, confirmed login and work origins, last used time, last confirmed time, session age, and session ok or needs_login. needs_login means the last open saw a login page. Age makes a stale ok visible. Returns no cookies, tokens, or URL query secrets.

auth_loginB

Open a visible Chrome window for one site id so a human can log in. Also opens a local tab that lists the login origin and work origin, then the button 이 사이트 허용. That button confirms those origins. Returns immediately. Does not type credentials or return the confirmation code.

auth_confirmA

Record origins for one site after a human allow signal from the last 10 minutes. The 이 사이트 허용 button already confirms origins; use this after the terminal confirm command. Refuses if that signal is missing. Optional workOrigin must be part of the same human signal. Does not read cookies.

auth_openA

Open a URL in that site's Chrome profile. The origin must already be human-confirmed for the site (login origin or a work origin). Re-resolves every A/AAAA and pins Chrome to one address from that checked set, then fails closed if the connected address is outside the set. Returns human_action_required and no page text when the page looks like a login or challenge, or when the final origin is not a confirmed login or work origin. Blocks subresource requests to link-local or metadata hosts.

auth_readA

Read visible text from this site's current page, or navigate first when url is set and its origin is human-confirmed for the site. Re-resolves DNS on every call. Refuses unconfirmed origins. Truncates long text. Never returns cookies or storage.

auth_actA

Perform one click, fill, or press on this site's current page. Re-resolves DNS on every call. Refuses unconfirmed origins, password fields, and challenge widgets. fill and press require value. Does not solve CAPTCHA or 2FA.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 6 tools

Disambiguation4/5

auth_login (human-driven login window) and auth_open (agent-driven navigation in a confirmed profile) both open Chrome, which could cause confusion, but their descriptions clearly delineate human login vs. agent browsing. auth_read and auth_act are cleanly separated by read vs. interaction, and auth_status is distinct.

Naming Consistency5/5

All six tools use the consistent auth_ verb_noun pattern (auth_login, auth_confirm, auth_open, auth_read, auth_act, auth_status). Names are predictable and map cleanly to actions.

Tool Count5/5

Six tools is well-scoped for an authenticated-browsing server: setup (login, confirm), operations (open, read, act), and introspection (status). Each tool earns its place with no redundancy.

Completeness4/5

The surface covers the full login-to-automation lifecycle including origin confirmation and status reporting, with sensible safety boundaries. Session teardown/logout or multi-step action batching are minor gaps an agent can work around.

Maintenance

ActivityMaintained
ResponsivenessNo issues