Skip to main content
Glama
oliverhruby

EduPage MCP Server

two_factor_finish

Idempotent

Complete a pending two-factor login after an EduPage sign-in requires 2FA, using a verification code or device approval polling.

Instructions

Finish a pending 2FA login. Writes: completes the pending auth flow. Only needed after a login that returned two_factor_required: True.

Args: code: Optional email/app verification code. When given it is used directly; otherwise the device-confirmation flow is polled. subdomain: School subdomain whose pending login to complete (defaults to the active subdomain). poll_seconds: How long (seconds) to wait for approval on a device when code is not given. Defaults to 60; on timeout the caller can call two_factor_finish again later.

Returns: dict: {'confirmed': True, 'logged_in': True, subdomain, user_id, role} on success, or a pending status when the confirmation wasn't approved within the poll window.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeNo
subdomainNo
poll_secondsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changedv0.6.0
    • addedInput schema / properties / code / anyOf
      Added value: +[
      +  {
      +    "type": "string"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • removedInput schema / properties / code / type
      Removed value: -"string"
    • addedInput schema / properties / poll_seconds / anyOf
      Added value: +[
      +  {
      +    "type": "integer"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • removedInput schema / properties / poll_seconds / type
      Removed value: -"integer"
    • addedInput schema / properties / subdomain / anyOf
      Added value: +[
      +  {
      +    "type": "string"
      +  },
      +  {
      +    "type": "null"
      +  }
      +]
    • removedInput schema / properties / subdomain / type
      Removed value: -"string"
  2. Changed1 schema field changedv0.5.0
    • addedInput schema / properties / poll_seconds
      Added value: +{
      +  "default": 60,
      +  "title": "Poll Seconds",
      +  "type": "integer"
      +}
  3. First observedv0.4.6

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes beyond the annotations by disclosing the pending-auth completion semantics, the code-vs-poll branching, the poll timeout fallback ('the caller can call `two_factor_finish` again later'), and the concrete success return shape. The write/idempotent profile in annotations is consistent with, and supplemented by, this detail.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the action and precondition, then organized into Args/Returns sections, so it is easy to scan. Slight redundancy between the title sentence and 'Writes: completes the pending auth flow' keeps it short of maximal conciseness.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 3-param auth tool with no output schema and sparse annotations, the description supplies the precondition, per-parameter semantics, branching logic, timeout handling, and an explicit return contract. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With 0% schema description coverage, the description carries the full burden and does: `code` is explained as a directly-used verification code that switches behavior, `subdomain` defaults to the active subdomain, and `poll_seconds` defaults to 60 and only matters when `code` is absent. Every parameter's meaning and interaction is covered.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Finish a pending 2FA login') and immediately clarifies the write nature of the operation. It is clearly distinguishable from the sibling `login` tool by its focus on the post-login confirmation step.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states the triggering condition: 'Only needed after a `login` that returned `two_factor_required: True`.' It also explains the fallback path when no code is supplied and that the tool may be re-invoked after a poll timeout, covering when and how to use it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.