Skip to main content
Glama
shigechika

keycloak-mcp

by shigechika

detect_login_loops

Scan Keycloak LOGIN events to identify users exceeding a login threshold within a set time window, flagging possible redirect loops.

Instructions

Detect users with rapid repeated logins (possible redirect loops).

Scans all LOGIN events and finds users who logged in more than threshold times within window_seconds.

Time-bounded: this call stops after KEYCLOAK_DEADLINE seconds (default 45) and returns what it has; the counts are then a lower bound. The result then starts with a "PARTIAL RESULT" warning. Call again with a narrower window instead of retrying the same call. A wide window on a busy day is what triggers it.

Args: date_from: Start date (YYYY-MM-DD). Defaults to last 24h when omitted (KEYCLOAK_DEFAULT_DATE_FROM_HOURS). date_to: End date (YYYY-MM-DD). Empty for all. threshold: Minimum logins within the window to flag (default 10). window_seconds: Time window in seconds (default 60). top: Number of top users to show (default 20). Use 0 for all.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
topNo
date_toNo
date_fromNo
thresholdNo
window_secondsNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the KEYCLOAK_DEADLINE time bound (default 45s), that results may be partial with a 'PARTIAL RESULT' prefix, that counts become a lower bound, and the correct retry strategy. This is exactly the kind of non-obvious behavior an agent needs before calling.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose, then a well-structured args list. The deadline paragraph is slightly long but every sentence (partial results, retry advice, trigger cause) earns its place. Minor verbosity only.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 5-param detection tool with an output schema already covering return values, this description covers purpose, all parameters, time-bounding behavior, and failure handling. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must compensate, and it documents all five parameters: date formats (YYYY-MM-DD), defaults, the meaning of threshold/window_seconds, and 'Use 0 for all' for top. It fully fills the gap left by the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource+scope: 'Detect users with rapid repeated logins (possible redirect loops).' This is immediately distinguishable from siblings like spray_check and get_login_failures_by_ip, which target different attack patterns.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by the detection description, and it gives good operational guidance ('Call again with a narrower window instead of retrying'), but it never explicitly says when to choose this over a sibling like spray_check or get_login_stats. No when-not or alternative routing is provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.