Skip to main content
Glama
oneguard-sa

oneguard-mcp

Official
by oneguard-sa

Initialize the OneGuard session

oneguard_init
Idempotent

Initializes an isolated OneGuard session for this server using an API key, verifying it against the backend when another tool reports the server is not initialized.

Instructions

Initializes this server's isolated OneGuard session with an API key and verifies it against the backend. Normally you do NOT need to call this: if ONEGUARD_API_KEY is configured on the server, the session initializes itself on the first tool call. Call this only when another tool reports that the server is not initialized, and only with a key the user gave you in this conversation — never invent one. The key is kept for this session only and does not affect the user's own oneguard login in their terminal.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
api_keyNoThe OneGuard API key. Omit to use the ONEGUARD_API_KEY configured on the server.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.3.0

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare non-destructive and idempotent, and the description adds genuinely new behavioral context beyond them: the key is session-scoped ('kept for this session only') and explicitly does not affect the user's own terminal login, plus the backend verification step. It also discloses the side effect that omitting the key falls back to server config, which is important for callers.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action, then immediately de-escalates ('Normally you do NOT need to call this') before giving the trigger condition and the safety constraint. Every sentence earns its place with no redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a one-parameter initializer with no output schema, the description supplies everything needed: purpose, auto-init behavior, trigger condition, key provenance, and session-scoping semantics. Nothing required to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% and the single parameter is documented there, including the omit-to-use-env fallback, so the baseline is 3. The description reinforces the key-provenance rule (must come from the user in this conversation) but adds little on parameter format beyond what the schema already states.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('initializes this server's isolated OneGuard session with an API key and verifies it against the backend'), and the isolation/session scoping clearly separates it from sibling tools like oneguard_status or oneguard_env_sync. An agent can tell exactly what this does without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly covers when NOT to call ('Normally you do NOT need to call this: if ONEGUARD_API_KEY is configured... the session initializes itself'), the exact trigger condition for calling ('only when another tool reports that the server is not initialized'), and the key-provenance constraint ('only with a key the user gave you in this conversation — never invent one').

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.