Read-only MCP server for the Apple School & Business Manager (ABM/ASM) API, built with FastMCP.
15 tools with consistent verb-noun naming (list_*, get_*) and clear, descriptive docstrings (avg ~120 chars). All tools are read-only with explicit descriptions of their purpose and when to use them. Input schemas are present with type definitions and descriptions for all parameters. However, output schemas are not documented, responses are inferred from API behavior rather than explicitly declared. Parameter descriptions lack format constraints (e.g., serial_number format, limit ranges). Error handling is generic (ABMAPIError wrapper) without recovery guidance. No tool annotations (readOnlyHint, etc.) despite all being read-only. Pagination is implemented but not uniformly documented across all list tools.
Get details for one blueprint by id.
Check the status of a device-management activity (e.g. an assignment job). Read-only status lookup; this server does not create activities.
Get AppleCare coverage details for a single device. Note: Apple exposes AppleCare one serial per call — there is no bulk endpoint — so avoid calling this in a tight loop over a large fleet.
Get the MDM server a device is currently assigned to, if any.
Get just the assigned MDM server id (linkage) for a device. Lighter than get_device_assigned_server, which returns the full server object.
Get details for one MDM-enrolled device (mdmDevices/{id}/details).
Output schemas not documented. Responses are inferred from API behavior (e.g., 'mdmServers' array, 'devices' array) but no explicit schema definitions provided. LLMs cannot reliably plan downstream tool calls or extract nested fields without documented return types.
Parameter constraints missing. 'limit' parameters accept 0 for 'all' but lack explicit min/max bounds in descriptions. 'serial_number' and 'server_id' lack format hints (e.g., 'alphanumeric, 10-20 chars'). LLMs may pass invalid values without guidance.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 69 | 2026-07-28+ | v2 |
Get details for a single MDM server by its id.
Get full details for one device by serial number. Includes attributes like os, deviceFamily, status, color, and MAC addresses (where available for the platform).
List the app ids attached to a blueprint.
List the org-device ids assigned to a blueprint.
List device blueprints (declarative device setup groupings) in the org.
List the device ids/serials currently assigned to a specific MDM server. Uses the documented relationships endpoint and returns device linkages (type + id/serial). This is the efficient way to resolve device-to-server assignments in bulk.
List devices enrolled in Apple device management services (mdmDevices). This is the MDM-enrollment view of the fleet, distinct from `list_org_devices` (which lists all Automated Device Enrollment devices in the org).
List all MDM servers defined in the organization. Returns each server's id, name, type, and timestamps. Useful for finding the server id you need for `list_devices_for_mdm_server`.
List organization devices enrolled via Automated Device Enrollment. Each item includes at least serialNumber and partNumber. For large fleets, keep `limit` modest or use `list_devices_for_mdm_server` to scope by server.
Error handling is generic. _handle() wrapper returns {'error': 'api_error', 'status_code': ..., 'message': ..., 'details': ...} but provides no recovery guidance. LLMs cannot determine if errors are retryable, user-fixable, or fatal.
No tool annotations despite all tools being read-only. FastMCP supports readOnlyHint annotation; using it would signal to agents that these tools are safe to call without confirmation and do not modify state.
Pagination documentation inconsistent. list_* tools accept 'limit' with default 0 or 100, but descriptions do not clarify whether 0 means 'all' or 'default'. No mention of cursor/offset for resuming large result sets.