Skip to main content
Glama

Hand control to or from the user

browser_handoff

Manage control between agent and user: pause for sign-in, MFA, or payment, resume when the user returns, and claim or release a tab.

Instructions

request_user_takeover: ask the user to act (sign-in, MFA, payment, anything you must not do) and stop acting until they resume. resume: ask the user to hand control back (only the user can actually resume). claim: take the write claim on a tab without a snapshot. release: drop your claim. Check progress with browser_status.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
noteNoShort plain-language reason shown to the user with request_user_takeover. It is displayed as untrusted agent text.
actionYes
context_idNoContext id from browser_contexts, for example tab:12.
browser_instance_idNoOnly needed when several Firefox profiles are connected.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=false, idempotentHint=false), the description discloses key behaviors: the agent stops acting until the user resumes, control genuinely cannot be taken back by the agent, and claim grants a write claim without a snapshot. The note field's untrusted-display nature is covered by the schema, so remaining gaps are minor.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

One terse labeled clause per action, action names front-loaded so the agent can scan for its mode, then a closing pointer to browser_status. No filler sentences.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a stateful handoff tool with no output schema, the description covers the four modes, the pause/resume semantics, and where to check progress. It does not cover edge cases like claiming a tab that already has a snapshot, but is sufficient to call the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema documents three of four params (75% coverage), but the action enum values themselves carry no schema description – the description supplies their semantics, which is precisely the highest-value parameter information here. It adds meaning well beyond the bare enum list.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Each of the four actions is given a specific, distinct meaning: request_user_takeover asks the user to act and pauses the agent, resume asks the user to hand control back, claim takes a write claim without a snapshot, release drops the claim. An agent can tell exactly what the tool does and distinguishes it from siblings by pointing to browser_status for progress.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives concrete when-to-use triggers for request_user_takeover (sign-in, MFA, payment, 'anything you must not do') and clarifies that only the user can perform resume, plus a routing hint to browser_status. It lacks explicit exclusions or a comparison to browser_request_access, so 4 rather than 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.