Skip to main content
Glama
shigechika

keycloak-mcp

by shigechika

get_login_stats_by_client

Retrieve login statistics grouped by client for a given date range. Use to analyze authentication activity per service provider in Keycloak.

Instructions

Get login statistics broken down by client (SP).

Time-bounded: this call stops after KEYCLOAK_DEADLINE seconds (default 45) and returns what it has; the counts are then a lower bound. The result then starts with a "PARTIAL RESULT" warning. Call again with a narrower window instead of retrying the same call. A wide window on a busy day is what triggers it.

Args: date_from: Start date (YYYY-MM-DD). Defaults to last 24h when omitted (KEYCLOAK_DEFAULT_DATE_FROM_HOURS). date_to: End date (YYYY-MM-DD). Empty for all.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
date_toNo
date_fromNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does well: it discloses the KEYCLOAK_DEADLINE time bound, that counts become a lower bound on truncation, and that output is prefixed with a "PARTIAL RESULT" warning. It omits auth/permission requirements, but for a read-only stats tool that gap is minor.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded in one line, the time-bound caveat follows, and the Args block is compact. Nothing is filler, though the deadline paragraph could be trimmed by a sentence without losing meaning.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return structure needn't be restated, and the description covers the non-obvious failure mode (partial results under deadline). Missing only permission/scope framing and explicit sibling routing; otherwise complete for a 2-param stats tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does: date_from gets a format (YYYY-MM-DD) and a default (last 24h via KEYCLOAK_DEFAULT_DATE_FROM_HOURS), and date_to gets a format plus the "empty for all" semantics. The "empty for all" wording is slightly ambiguous but the essential semantics are covered.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ("Get login statistics") plus the aggregation dimension ("broken down by client (SP)"), which is exactly what separates it from siblings get_login_stats and get_login_stats_by_hour. An agent can route to it without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives useful operational guidance for the timeout case ("call again with a narrower window instead of retrying") and explains what triggers a partial result. It never says when to prefer this tool over get_login_stats or get_login_stats_by_hour, so the alternative-selection guidance is only implied by the breakdown dimension.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.