Skip to main content
Glama

Create Webhook

create_webhook

Register a new webhook to deliver LightCMS events to a URL and get a one-time HMAC-SHA256 secret for verification.

Instructions

Create a new webhook. Returns the generated HMAC-SHA256 secret ONCE — save it immediately.

Valid event types: content.create, content.update, content.publish, content.unpublish, content.delete, comment.created, content.pending_approval, asset.pending_review

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesEndpoint URL to deliver events to,required
nameYesName for the webhook,required
activeNoWhether the webhook is active (default true)
eventsYesEvent types to subscribe to (e.g. content.publish),required

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv7.3.4

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only cover openWorldHint and destructiveHint; the description adds the genuinely important trait that the HMAC-SHA256 secret is returned ONCE and must be saved immediately — critical operational context the agent could not infer. It stops short of stating permission/auth requirements or whether delivery is verified by the caller.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The one-time-secret warning is front-loaded right after the purpose statement, and the event list is compact. Slightly deductive that the event enumeration arguably belongs in the schema rather than prose, but every sentence carries weight.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description covers the key return value (the secret) and the full event vocabulary, and the schema handles defaults for `active`. Gaps are modest: no auth/permission prerequisites and no note on whether an inactive webhook can be created.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline would be 3, but the description supplies the closed list of valid event types for the `events` array while the schema has no enum and only an 'e.g.' example. That materially improves correctness of the most error-prone parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Create a new webhook') that cleanly separates it from the create/update/delete/list webhook siblings in the tool set. It goes further by enumerating the valid event types, so an agent understands the resource's domain without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied: the agent can infer this is the tool for registering a new endpoint, and the valid-event list implicitly tells it what can be subscribed to. There is no explicit when-to-use guidance and no routing to alternatives such as update_webhook or regenerate_webhook_secret.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools