Skip to main content
Glama

authenticate

Idempotent

MCP.AI for IDE agents (Cursor, etc.): log in in the browser, copy the access token. Best: add it to this server's config as a header Authorization: Bearer <token> for a permanent, non-expiring connection. Or paste it here for a session-only login: call with { token: "" } after the user pastes, or with no args to get the link.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
tokenNo

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond annotations (idempotentHint, destructiveHint, readOnlyHint), the description reveals that the tool can either persist the token (if config is set) or use it only for the session, and that calling without args returns a login link. It does not contradict annotations: idempotentHint is consistent as calling with the same token multiple times results in same state. It does not disclose error handling or security implications, but overall adds useful behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single paragraph that is information-dense but logically organized: it starts with the target audience and primary use case (permanent token), then the session variant, then explicit function call syntax. Every sentence adds value. Could be slightly more concise, but it's well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given that the tool has only one optional parameter and no output schema, the description covers the essential usage scenarios: permanent config, session login, and obtaining the login link. It explains the authentication flow effectively. However, it omits details like what the response looks like (e.g., success message) or how to handle errors, but for the tool's simplicity, it is reasonably complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema only defines 'token' as an optional string with no description. The description compensates fully by explaining that the token is a JWT, and specifies the two call patterns: with token for session login, without token to get link. This adds essential meaning that the schema lacks.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states that the tool is for authentication: it allows the user to either configure a permanent token via server config or pass a token for session login, or get a link to log in. It uses specific verbs like 'log in', 'copy', 'add', 'paste', which precisely describe the action. It distinguishes itself from sibling tools by focusing on token-based authentication for the MCP server.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit instructions on when to use each variant: for permanent connection, add to config; for session, call with token; to get login link, call with no args. It does not directly compare with siblings like 'connect', but within the tool's purpose, it gives clear guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation4/5

Most tools have clearly distinct purposes, especially within the openfinance_* family where each targets a different resource or action. A few minor overlaps exist—connect vs toolkit_info both report connection state, and marketplace internally includes report_bug while a top-level report_bug also exists—but these are unlikely to cause serious misselection.

Naming Consistency4/5

The openfinance_* tools follow a consistent snake_case prefix with mostly verb_noun patterns like list_accounts, get_item_status, and force_sync. The general tools are also snake_case but mix verbs (connect, authenticate) with nouns (marketplace, toolkit_info), and openfinance_provider_status breaks the verb_noun pattern slightly.

Tool Count3/5

25 tools is at the upper boundary of a heavy surface, but the Open Finance domain genuinely spans connections, accounts, transactions, bills, loans, investments, categories, and provider health. It feels dense rather than bloated, though a few general utilities like show_version and report_bug could arguably be consolidated.

Completeness4/5

The Open Finance surface is well covered: connection management, account/balance/transaction retrieval, credit card bills, loans, investments, category correction, force sync, and provider status are all present. Minor gaps exist—such as no direct investment position detail endpoint beyond the portfolio list, and payments/initiation are out of scope—but agents can accomplish the core read-only financial workflows without dead ends.