Skip to main content
Glama

Create Allowed Domain

create_allowed_domain
Destructive

Add an allowed domain to a Wistia account, stripping www, to control where media can be embedded or accessed. Requires confirm=true and appropriate API token permissions.

Instructions

Creates an allowed domain for the account.

Requires api token with one of the following permissions

Read, update & delete anything

Tokens with the "Act with a team member's permissions" permission (all:delegate_to_contact_permissions scope) can also be used. Requests made with such a token are authorized using the permissions of the contact assigned to the token. Requires confirm=true for the requested mutation. May share access, notify people or incur provider charges.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainNoThe domain name to add (www will be automatically stripped)
accountNoNamed private Wistia account; selects credentials, not a remote account ID.
confirmNoMust be true for the specific user-requested write.
payloadNoComplete JSON request body instead of body flags. Supports current nested customization, caption and nullable values.
payload_fileNoRegular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

A3.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare the write/destructive/non-idempotent/open-world profile, so the bar is lower, and the description adds real value on top: the exact token permission needed, the delegate_to_contact_permissions alternative, the confirm=true requirement, and side effects ('may share access, notify people or incur provider charges'). It omits what happens on duplicate domains or whether creation is reversible.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded in the first sentence, followed by a compact permission block and the confirm/side-effect notes. The fenced permission listing is boilerplate-heavy but each element is actionable for a mutation call.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive mutation with no output schema, the description supplies the missing operational context: auth requirements, the confirm gate, and potential side effects. The remaining gap is the absence of any statement about duplicate-domain behavior or error outcomes.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents domain, account, confirm, payload and payload_file, including the 'www stripped' behavior. The description only echoes the confirm requirement and adds no format or semantics beyond the schema, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Creates an allowed domain for the account'), which clearly distinguishes it from list_allowed_domains, get_allowed_domain and delete_allowed_domain by verb. It does not explicitly name those siblings, so it falls short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description covers authorization context (required token permission, delegate scope) and the confirm=true gate, which is useful pre-call guidance. However it never states when to use this tool versus the sibling list/get/delete allowed-domain tools, so usage routing is only implied.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools