Skip to main content
Glama

Create Expiring Access Token

create_expiring_access_token
Destructive

Generate time-limited Wistia access tokens for iframe embeds or REST API requests, scoped by permissions and authorizations.

Instructions

🚫 Alert
This API is still under development and can change at any time.

This endpoint is for creating expiring access tokens which can be used for some iframe embeds and, when granted the all:delegate_to_contact_permissions scope, for REST API requests authorized by the token's authorizations.

Requires api token with one of the following permissions

Read, update & delete anything

Tokens with the "Act with a team member's permissions" permission (all:delegate_to_contact_permissions scope) can also be used. Requests made with such a token are authorized using the permissions of the contact assigned to the token. Requires confirm=true for the requested mutation. May share access, notify people or incur provider charges.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
accountNoNamed private Wistia account; selects credentials, not a remote account ID.
confirmNoMust be true for the specific user-requested write.
payloadNoComplete JSON request body instead of body flags. Supports current nested customization, caption and nullable values.
payload_fileNoRegular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload.
secret_result_fileYesNew private local result file, saved with exclusive creation and mode 0600. Parent must be owner-only on POSIX. No credentials are returned to the AI client.
expiring_access_tokenNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true, idempotentHint=false and openWorldHint=true, but the description adds meaningful context beyond them: the under-development warning, the exact permission requirement ("Read, update & delete anything"), the delegation semantics of scoped tokens, and the note that the call may share access, notify people or incur provider charges. This is strong disclosure; only return-format behavior is left unaddressed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The development alert is front-loaded, which is good, but the description is verbose and repeats scope/permission details that already live in the schema, so not every sentence earns its place. Structure is navigable via headings but the payload is heavier than necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a mutation tool with nested objects and no output schema, the description covers the permission model, the confirm requirement, the delegated-authorization behavior and the maturity caveat. The remaining gap — what the call returns and how the secret result file relates to it — is partly addressed by the schema, leaving it largely complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 83%, so the schema documents the critical fields (scopes, expires_at, authorizations, confirm, secret_result_file). The description restates the `confirm=true` requirement and the scope concept but adds little parameter meaning beyond what the schema already provides, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ("creating expiring access tokens") and names the concrete use cases: iframe embeds and REST API requests authorized by the token's authorizations. An agent can distinguish this token-minting operation from the sibling read tool `get_current_token` without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when the token is applicable (iframe embeds, REST API with the `all:delegate_to_contact_permissions` scope) and states the required permissions and the `confirm=true` prerequisite. It stops short of explicit when-not-to-use guidance or naming a sibling alternative, but for a niche token-creation endpoint the positive conditions are well covered.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools