Skip to main content
Glama
shigechika

keycloak-mcp

by shigechika

get_login_stats

Retrieve Keycloak login success and failure statistics for a specified date range to monitor authentication outcomes and investigate access issues.

Instructions

Get login success/failure statistics with full pagination.

Time-bounded: this call stops after KEYCLOAK_DEADLINE seconds (default 45) and returns what it has; the counts are then a lower bound. The result then starts with a "PARTIAL RESULT" warning. Call again with a narrower window instead of retrying the same call. A wide window on a busy day is what triggers it.

Args: date_from: Start date (YYYY-MM-DD). Defaults to last 24h when omitted (KEYCLOAK_DEFAULT_DATE_FROM_HOURS). date_to: End date (YYYY-MM-DD). Empty for all.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
date_toNo
date_fromNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden, and it delivers real behavioral context: a 45s deadline, partial results returned as a lower bound, and an explicit 'PARTIAL RESULT' warning marker. It omits auth/permission requirements, but the timeout semantics are the key non-obvious trait and are well disclosed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the purpose, then the timeout behavior, then args — a logical order with no filler sentences. Slightly verbose with env-var names, and the Args block restates parameter names already in the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-value documentation is not needed. The description covers purpose, defaults, and the failure mode adequately; the main omission is routing guidance relative to the many sibling stats tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does: date_from defaults to the last 24h (KEYCLOAK_DEFAULT_DATE_FROM_HOURS) and empty date_to means 'all'. Format (YYYY-MM-DD) is also stated. Minor gap is that the interaction between the two dates is not explained.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (login success/failure statistics) plus a scope note about pagination. However, it never distinguishes itself from close siblings like get_login_stats_by_client, get_login_stats_by_hour, or get_login_failures_by_ip, which an agent must choose between.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives solid operational guidance for the timeout case (call again with a narrower window rather than retrying), but offers no guidance on when to pick this aggregate tool over the by-client, by-hour, or by-IP siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.