Skip to main content
Glama
kitepon
by kitepon

agent_auth

Start, check, or cancel official CLI authentication for coding harnesses; display the login URL or code and send needed input in the same PTY session.

Instructions

各harnessの公式CLI認証を開始・確認・取消する。CLIごとのコマンドと認証URL/codeの抽出はAitermが所有し、資格情報は各CLIだけが保存する。waitingのURL/codeを人へ表示し、input_requiredなら同じsessionのpty_send/pty_keyで公式画面へ入力する。authenticatedは認証の結果であり、agent_launchの起動準備完了とは別。remoteは他toolと同じ標準対応。

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cwdNo公式CLIを実行する作業ディレクトリの絶対パス
actionYes
remoteNo別端末のAitermで実行する時のSSH接続情報。hostだけならssh_configの接続名として使う。Aitermは接続情報を保存・管理しない。passphraseは会話記録に残るため、ssh-agentかpassphrase_env(環境変数名)を推奨する。
harnessYes
env_varsNostartで認証PTYへ引き継ぐ環境変数名。値はreceiptへ返さない
session_idNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYes
schemaYes
statusYes
harnessYes
messageYes
user_codeYes
session_idYes
input_requiredYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.46.1

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does well: it discloses that Aiterm only extracts commands/URLs while credentials are persisted solely by each CLI, and it documents the state machine (waiting → input_required → authenticated). It omits any failure/timeout or permission behavior for start/cancel, keeping it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose statement, then proceeds through ownership, human-in-the-loop flow, state semantics, and remote support in compact sentences. Dense but each sentence carries distinct information; no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-value explanation is not required, and the description still usefully defines the waiting/input_required/authenticated statuses. For a credential-touching start/cancel tool with no annotations, the main gap is absence of error/failure guidance and permission/prerequisite notes.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 50%, so the description should compensate more than it does. It adds meaning for `remote` ('same standard support as other tools') and implies `session_id` via the pty continuation flow, but says nothing about `cwd`, `harness`, or the action enum nuances beyond restating start/status/cancel. Baseline 3 for a 50%-covered 6-param tool.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb set (開始・確認・取消 = start/status/cancel) tied to a specific resource (各harnessの公式CLI認証), and explicitly separates itself from agent_launch by noting that 'authenticated' is not launch readiness. An agent can identify the tool's scope without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete workflow routing: for 'waiting' show the URL/code to the human, and for 'input_required' feed the official screen via pty_send/pty_key in the same session. It also names the distinguishing boundary with agent_launch. It does not state when NOT to use the tool (e.g. if already authenticated), so it stops short of full when/when-not coverage.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.