Skip to main content
Glama

Rotate an API key

immich_rotate_api_key

Generate a new secret for an Immich API key, immediately invalidating the previous one. Requires the current user to own the key.

Instructions

Rotate an API key

Generates a new secret for an API key, immediately invalidating the previous one. The current user must own this API key.

Immich operation: POST /api-keys/{id}/rotate · tag: API keys

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idYesformat: uuid

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With annotations present the bar is lower, and the description still adds real context: rotation returns a new secret, the old secret is invalidated immediately (non-reversible for anyone still using it), and ownership is enforced. The idempotentHint=false annotation aligns with 'immediately invalidating the previous one', so no contradiction, though the description could be more explicit that callers holding the old secret will break.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short blocks: what it does, the safety-critical consequence, and the underlying Immich route. The invalidation warning is front-loaded and nothing is redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a one-parameter mutation with no output schema, the description covers effect and authorization well. The main missing piece is what the call returns – an agent rotating a key needs to know the new secret is handed back and only shown once, which the description leaves implicit.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is a single parameter documented in the schema as a UUID, giving 100% schema coverage, so the schema already carries the semantics. The description adds only the ownership constraint on that id, not format or lookup guidance; baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific verb (rotate) and resource (API key) and spells out the effect: a new secret is generated and the previous one is invalidated. That is unambiguous in isolation, but it does not explicitly contrast with nearby siblings such as immich_update_api_key (edit key metadata) or immich_create_api_key (brand-new key), so the agent must infer the distinction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It supplies one concrete precondition – the caller must own the key – which is genuinely useful. However it never states when to prefer rotation over immich_update_api_key or immich_create_api_key, so usage is only implied by the tool name.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools