MCP server for ILM platform - exposes certificate and key management operations as AI tools
ILM MCP Server demonstrates solid tool definition quality with consistent naming patterns, comprehensive descriptions, and well-structured schemas. All 22 tools follow verb_noun naming conventions (get_, list_, search_). Descriptions are detailed (150-250 chars typical) and explain WHEN to use each tool. Input schemas are present with type definitions and parameter descriptions. However, output schemas are not explicitly documented in the source, and error handling guidance is minimal. No tool annotations (readOnlyHint, destructiveHint) are visible despite all tools being READ_ONLY. Parameter descriptions could be more prescriptive about constraints and formats.
Get detailed information about a specific certificate by its UUID. Returns full certificate details including subject DN, issuer, validity period, state, validation status, key algorithm, signature algorithm, compliance status, fingerprint, RA profile, and groups. Use this when you need complete details about a particular certificate.
Get the full certificate chain for a specific certificate by its UUID. Returns whether the chain is complete and lists all certificates in the chain from end-entity to root, with subject, issuer, and serial number for each. Use this to inspect the trust chain or diagnose chain-related issues.
Get the event history for a specific certificate by its UUID. Returns a chronological list of events including event type, status, timestamp, who performed it, and any associated messages. Use this to audit certificate lifecycle events or troubleshoot certificate issues.
Get detailed information about a specific cryptographic key by its UUID. Returns key name, description, creation time, token instance, token profile, owner, compliance status, groups, and detailed key items including type, algorithm, size, format, state, enabled status, and usage. Use this when you need complete details about a particular key.
Output schemas not documented. Tool descriptions explain what is returned (e.g., 'Returns certificate common name, UUID, serial number...') but formal output schema definitions are not visible in source code. LLMs cannot reliably plan downstream tool calls without knowing exact response structure.
No tool annotations present. All 22 tools are READ_ONLY (no state modification), but readOnlyHint is not visible in tool definitions. This prevents clients from optimizing caching, retry logic, and safety checks.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 72 | <=2025-11-25 | v2 |
Get available search filter fields for a resource type. Returns field identifiers, labels, types, and supported filter operators. Use this before search tools to discover what filters are available. Supported resource types: certificates, keys, secrets, vaults, vaultProfiles, entities, discoveries
Get detailed information about a specific secret by its UUID. Returns full secret details including name, description, type, state, version, enabled status, owner, source vault profile, groups, compliance status, creation/update timestamps, and sync vault profiles. Use this when you need complete details about a particular secret. Does not return the actual secret content for security reasons.
Get the version history of a specific secret by its UUID. Returns a list of all versions with version number, creation timestamp, and fingerprint. Use this to inspect how a secret has changed over time or verify secret rotation history.
Get overall statistics and dashboard summary of the ILM platform including total counts of certificates, groups, discoveries, connectors, RA profiles, authorities, and credentials, as well as certificate breakdowns by state, key size, expiry, validation status, and compliance status. Use this to get a high-level overview of the platform.
List all authority instances configured in the ILM platform. Returns authority name, UUID, status, connector, and kind for each instance. Use this to see which certificate authorities are available and their current status.
List all connectors configured in the ILM platform. Returns connector name, UUID, status, URL, auth type, and function groups. Use this to see which connectors are available and their connection status.
List all credentials configured in the ILM platform. Returns credential name, UUID, enabled status, kind, and connector. Use this to see which credentials are available for authentication with external systems.
List certificate discovery tasks in the ILM platform with optional filters. Use get_searchable_fields('discoveries') to discover available filter fields. Returns discovery name, UUID, status, kind, connector, start/end times, and total certificates discovered.
List entity instances configured in the ILM platform with optional filters. Use get_searchable_fields('entities') to discover available filter fields. Returns entity name, UUID, status, connector, and kind.
List all groups configured in the ILM platform. Returns group name, UUID, description, and email. Use this to see available groups for organizing certificates and keys.
List all RA (Registration Authority) profiles configured in the ILM platform. Returns profile name, UUID, enabled status, description, authority instance, and enabled protocols. Use this to see which RA profiles are available for certificate enrollment and management.
List all cryptographic token instances configured in the ILM platform. Returns token name, UUID, status, connector, kind, and number of token profiles. Use this to see which cryptographic tokens (e.g., HSMs, software tokens) are available for key management.
List vault instances configured in the ILM platform with optional filters and pagination. Use get_searchable_fields('vaults') to discover available filter fields. Returns vault name, UUID, description, and connector for each instance. Available only when connected to ILM platform 2.17 or later.
List vault profiles configured in the ILM platform with optional filters and pagination. Use get_searchable_fields('vaultProfiles') to discover available filter fields. Returns profile name, UUID, description, vault instance, and enabled status. Available only when connected to ILM platform 2.17 or later.
Search and list certificates in the ILM platform with optional filters and pagination. Use get_searchable_fields('certificates') to discover available filter fields. Returns certificate common name, UUID, serial number, status, validation status, algorithm, key size, and expiry date.
Search and list cryptographic keys in the ILM platform with optional filters and pagination. Use get_searchable_fields('keys') to discover available filter fields. Returns key name, UUID, algorithm, key size, type, state, enabled status, token instance, token profile, and owner.
Search and list secrets in the ILM platform with optional filters and pagination. Use get_searchable_fields('secrets') to discover available filter fields. Returns secret name, UUID, type, state, version, enabled status, owner, vault profile, groups, and compliance status. Available only when connected to ILM platform 2.17 or later.
Validate a specific certificate by its UUID. Returns the overall validation status and detailed validation check results including individual check statuses and messages. Use this to verify if a certificate is valid, check for issues, or audit certificate health.
Filter parameter descriptions lack prescriptive format guidance. search_certificates, search_keys, search_secrets, list_entities, list_discoveries, list_vault_instances, and list_vault_profiles accept 'filters' as JSON array strings, but descriptions do not specify exact JSON structure, required vs optional fields, or valid operator names. LLMs must infer from get_searchable_fields() calls.
No error handling guidance. Tool descriptions do not explain what happens on invalid UUID, missing resource, API timeout, or permission denial. LLMs have no recovery path when a call fails.
Pagination defaults not explicit. search_certificates, search_keys, search_secrets, list_vault_instances, and list_vault_profiles accept itemsPerPage and pageNumber with defaults (10 and 1), but descriptions do not state max allowed itemsPerPage or whether results are capped. LLMs may request excessive page sizes.