Skip to main content
Glama
ry-ops

fortigate-mcp-server

by ry-ops

fortigate_api

Call any FortiOS REST endpoint directly when no dedicated tool covers it. Use /api/v2/ paths for configuration or live state, with read-only guardrails enforced.

Instructions

Call any FortiOS REST endpoint directly. path must start with /api/v2/ (cmdb/... for configuration, monitor/... for live state). FORTIGATE_READ_ONLY still applies. Prefer the dedicated tools when one exists.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bodyNoJSON body for POST/PUT
pathYese.g. /api/v2/cmdb/system/global or /api/v2/monitor/system/ha-peer
vdomNoVDOM (default: FORTIGATE_VDOM, usually root)
methodYesGET, POST, PUT or DELETE
paramsNoQuery parameters

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.4.1

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it does disclose the FORTIGATE_READ_ONLY gate plus the /api/v2/ path requirement. However, for a tool that can issue POST/PUT/DELETE against arbitrary endpoints, it says nothing about destructive-operation warnings, permissions, or error behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four short sentences, each carrying a distinct fact, with the core purpose and the sibling-routing rule front-loaded. Zero filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a generic REST passthrough, the description covers the essentials an agent needs to invoke it correctly: path format, config-vs-monitor intent, read-only enforcement, and fallback routing. No output schema exists, so return values need not be explained, though it could say more about write safety.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all five parameters, setting the baseline at 3. The description adds path-prefix and cmdb/monitor semantics beyond the schema, but gives no extra meaning for method, body, vdom, or params.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource: 'Call any FortiOS REST endpoint directly,' and explicitly positions itself against siblings with 'Prefer the dedicated tools when one exists.' An agent can immediately tell this is the generic escape hatch versus the many dedicated CRUD tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a clear routing rule (prefer dedicated tools) and distinguishes cmdb/... for configuration from monitor/... for live state, which directs endpoint choice. It stops short of stating explicit exclusions or edge cases, but the primary when-to-use condition is present.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.