Skip to main content
Glama

Update Access Customizations

update_access_customizations
Destructive

Partially update a Wistia video's password-protection settings. Change only supplied fields to enable, disable, set, or remove password protection.

Instructions

Applies a partial update to a video's password-protection settings. Only the fields supplied are changed; sending a field as null deletes it.

Requires api token with one of the following permissions

Read, update & delete anything

Tokens with the "Act with a team member's permissions" permission (all:delegate_to_contact_permissions scope) can also be used. Requests made with such a token are authorized using the permissions of the contact assigned to the token. Requires confirm=true for the requested mutation. May share access, notify people or incur provider charges.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pluginNo
accountNoNamed private Wistia account; selects credentials, not a remote account ID.
confirmNoMust be true for the specific user-requested write.
payloadNoComplete JSON request body instead of body flags. Supports current nested customization, caption and nullable values.
privateNo
media_idYesThe hashed ID of the video to be customized.
encryptedNo
payload_fileNoRegular local JSON body file, at most 5 MB. Cannot be mixed with body flags or payload.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag destructiveHint=true, idempotentHint=false, and openWorldHint=true, but the description goes well beyond them: it explains the null-deletes-field partial-update semantics, spells out the authorization model including delegated tokens, requires confirm=true, and warns that the call may share access, notify people, or incur provider charges.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core behavior is front-loaded in two sentences, followed by clearly delineated permission and warning blocks. Every sentence is actionable and nothing is redundant filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an 8-parameter, nested-object mutation with no output schema, the description covers mutation semantics, auth, and side effects adequately. It is slightly thin on how the payload/payload_file alternatives interact with the individual body flags, which an agent must infer from the schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 63%, so the description must carry weight, and it does: the null-deletes semantics is a critical parameter behavior not stated in the schema. It still leaves the relationship between payload, payload_file, and the individual body flags implicit, which the schema only partially documents.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening sentence names a specific verb (partial update), the resource (a video's password-protection settings), and the scope (access customizations). This effectively disambiguates it from the many sibling customization tools such as update_sharing_customizations or update_playback_customizations.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states concrete preconditions — the required permission set, the delegate-to-contact token variant, and the confirm=true requirement for the write. It does not, however, mention when to prefer this over get_access_customizations or the sibling update_*_customizations tools, so the routing guidance is incomplete.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools