Skip to main content
Glama
matt-coppinger

Horizon MCP Server

horizon_logout

Log out of an active Horizon session by invalidating its access and refresh tokens; omit the refresh token to revoke the credential stored at login.

Instructions

Invalidate the current Horizon session (access + refresh tokens).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
base_urlNoHorizon server URL. Defaults to HORIZON_BASE_URL env var.
refresh_tokenNoRefresh token to invalidate. Omit to use the one the server stored at login.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed7 schema fields changedv0.2.0
    • addedInput schema / properties / refresh_token / anyOf
      Added value: +[
      +  {
      +    "format": "password",
      +    "type": "string",
      +    "writeOnly": true
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • addedInput schema / properties / refresh_token / default
      Added value: +null
    • changedInput schema / properties / refresh_token / description
      Previous value: -"Refresh token to invalidate"New value: +"Refresh token to invalidate. Omit to use the one the server stored at login."
    • removedInput schema / properties / refresh_token / format
      Removed value: -"password"
    • removedInput schema / properties / refresh_token / type
      Removed value: -"string"
    • removedInput schema / properties / refresh_token / writeOnly
      Removed value: -true
    • removedInput schema / required
      Removed value: -[
      -  "refresh_token"
      -]
  2. First observedv0.1.0

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=false and destructiveHint=false, so the state-changing nature is covered. The description adds genuinely useful detail that both access AND refresh tokens are invalidated, but says nothing about auth requirements, whether an already-invalid session errors, or idempotency behavior (annotations claim idempotentHint=false, which is questionable for a logout but not contradicted).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single, front-loaded sentence with zero filler that conveys the exact effect of the call. Nothing is wasted and nothing essential is buried.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need no explanation, and both parameters are documented in the schema. For a simple token-invalidation tool with full annotation coverage, the description is nearly sufficient; only the routing versus sibling session tools is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%: base_url and the optional refresh_token override are fully documented in the schema, including the 'omit to use the stored token' fallback. The description adds no parameter-level meaning beyond that, so baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (invalidate) and resource (current Horizon session, access + refresh tokens), which is more precise than 'logout' alone. It implicitly differs from logoff_sessions (which terminates user sessions on machines) but never names that sibling or horizon_refresh_token, so differentiation is left to inference.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance, no prerequisites, and no mention of alternatives such as horizon_login (to start a session) or logoff_sessions (to end a user's remote session). The agent must guess the routing from the description's scope alone.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.