Skip to main content
Glama

Backchannel OAuth logout

immich_logout_o_auth

Logs out an OAuth account via a logout token, invalidating the sid session or all sessions if sid is absent.

Instructions

Backchannel OAuth logout

Logout the OAuth account and invalidate the session specified by the sid claim or all sessions if the sid claim is not present.

Immich operation: POST /oauth/backchannel-logout · tag: Authentication

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
logout_tokenYeslogout_token (request body)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

B3.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=false, idempotentHint=false, and openWorldHint=true, so the safety bar is partly covered. The description adds genuinely useful behavior beyond that: the operation invalidates the session named by the sid claim, expanding to ALL sessions when sid is absent — a consequential side effect not visible in the annotations or schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is short and the key scoping rule is front-loaded in the first sentence. The repetition of the title 'Backchannel OAuth logout' as the opening line and the trailing 'Immich operation: POST ... · tag: Authentication' metadata are redundant but cheap.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a security-sensitive, unauthenticated-by-design logout endpoint with no output schema, the description covers the sid/no-sid semantics but says nothing about the logout token's provenance, signature validation requirements, or the response on an invalid token. Adequate but with a notable gap given the auth-critical nature of the endpoint.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% for the single logout_token parameter, so baseline is 3. The description adds some meaning — that the token carries an sid claim determining which session is killed — but gives no format, signature, or validation guidance for the token itself.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb+resource (logout the OAuth account / invalidate the session) and explains the mechanism via the sid claim. It does not, however, distinguish itself from the very similarly named siblings immich_logout, immich_end_session, or immich_delete_session, so an agent cannot route between them from the text alone.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no explicit statement of when to use this versus immich_logout or immich_end_session, no mention that this is the OIDC IdP-initiated backchannel endpoint, and no prerequisites. The scope rule (all sessions when sid is absent) is behavioral, not usage routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools