Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

activate_vm_eval_license

Activate the free permanent evaluation license on an unlicensed FortiGate-VM by logging in to FortiCloud, so the VM stops refusing API calls. Requires confirm=true because the firewall reboots.

Instructions

Activate the free permanent evaluation license on an unlicensed FortiGate-VM by logging in to FortiCloud from the FortiGate (the same call the GUI makes). The FortiCloud account comes from the FORTICLOUD_ACCOUNT and FORTICLOUD_PASSWORD environment variables, never from tool arguments. The FortiGate reboots to apply it. Unlicensed VMs refuse most API calls, so use session auth (FORTIGATE_USERNAME/PASSWORD) on a fresh VM. FortiCare error 10 means wrong credentials, an IAM sub-user, or 2FA on the account.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)
confirmYesMust be true: the FortiGate reboots
is_governmentNoGovernment account (default false)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the reboot side effect, that credentials come from environment variables rather than arguments, the auth mode required, and the meaning of FortiCare error 10. These are exactly the operational facts an agent needs before invoking a mutation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the action and mechanism, then prerequisites and error semantics. Every sentence earns its place, though the error-10 sentence is somewhat tangential to selecting and invoking the tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a no-annotation, no-output-schema mutation tool, the description covers the critical behaviors: side effect, auth requirements, credential sourcing, and a common failure mode. It stops short of describing the response or idempotency, which are minor gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds value beyond the schema by clarifying that FortiCloud credentials are sourced from env vars and never from arguments, and it reinforces that confirm triggers a reboot, which the schema already notes.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Activate the free permanent evaluation license on an unlicensed FortiGate-VM') and explains the mechanism (FortiCloud login, same call the GUI makes). It is clearly distinguishable from siblings like get_license_status or get_license_limits.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear conditions: use on an unlicensed/fresh VM, and use session auth because unlicensed VMs refuse most API calls. It does not explicitly name sibling alternatives or state when NOT to use it, but the preconditions are concrete enough to route the agent correctly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.