MCP server exposing PocketBase through 13 intent-first tools.
Strong foundation with 13 well-named, action-verb tools (describe_*, find_*, write_*, manage_*, delete_*, connect, inspect_*, read_*). All tools have descriptions (50-250 chars, within baseline 34-392 range). Input schemas present with types and descriptions for all parameters. Tool annotations (readOnlyHint, destructiveHint, idempotentHint) correctly applied. Key gaps: output schemas not documented in source; error handling guidance minimal; some parameter descriptions lack format/constraint details (e.g., filter_template examples but no regex pattern stated); no confirmation/dry-run pattern for destructive ops despite high-risk operations.
USE WHEN you need to create or update multiple records in a single batch request. EXAMPLES: - Batch create: bulk_write(collection='posts', action='create', records=[{'title': 'A'}, {'title': 'B'}]) - Batch update: bulk_write(collection='posts', action='update', records=[{'id': 'x', 'status': 'done'}, {'id': 'y', 'status': 'done'}]) NEXT STEPS: find_records to verify; delete_records for bulk removal (if enabled).
USE WHEN you need to authenticate or check the current session identity. EXAMPLES: - Check identity: connect(as_="status") - Superuser: connect(as_="superuser", email="admin@x.com", password="...") - User: connect(as_="user", collection="users", email="u@x.com", password="...") - Impersonate: connect(as_="impersonate", user_id="abc123") NEXT STEPS: All subsequent tool calls in this session use the new identity.
USE WHEN you need to permanently delete records matching a filter. IRREVERSIBLE. Requires confirm_count. EXAMPLES: - Delete by filter: delete_records(collection='posts', filter_template='status = {:s}', filter_params={'s': 'draft'}, confirm_count=5) - Delete by id: delete_records(collection='posts', id='abc123', confirm_count=1) NEXT STEPS: Use the safe_delete prompt for a guided count-verify-then-delete flow.
USE WHEN you need to inspect a collection's schema: field names, types, constraints, and API rules. EXAMPLES: - "What fields does 'users' have?" -> describe_collection(collection='users') - "Is 'email' required?" -> describe_collection(collection='users') NEXT STEPS: find_records to query; write_record to create/update.
Output schemas not documented in source code. Tool descriptions state what they return (e.g., 'find_records returns records') but JSON Schema output structure is not visible. LLMs cannot plan downstream tool calls without knowing response field names and types.
Destructive operations (delete_records, destroy_collection) lack dry-run or explicit confirmation step. Tool requires confirm_count/confirm_name but no pre-execution preview. Agents can accidentally delete large datasets without seeing what will be removed.
Parameter descriptions lack format constraints. filter_template shows examples ('status = {:s}') but does not state the placeholder syntax formally. manage_collection fields parameter references 'PocketBase schema' without inline documentation of field shape. LLMs must infer structure from examples.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2025-06-18+ | v2 |
USE WHEN you need an overview of all collections in the PocketBase instance. EXAMPLES: - "What collections exist?" -> describe_schema() - "Refresh the schema" -> describe_schema(refresh=true) NEXT STEPS: describe_collection for field details; find_records to query.
USE WHEN you need to permanently delete a collection or all its records. IRREVERSIBLE. EXAMPLES: - delete_collection: destroy_collection(action="delete", name="temp_data", confirm_name="temp_data") - truncate: destroy_collection(action="truncate", name="events", confirm_name="events") NEXT STEPS: describe_schema to confirm removal.
USE WHEN you need to query records from a collection with optional filtering, sorting, and pagination. EXAMPLES: - All records: find_records(collection='posts') - Filter: find_records(collection='posts', filter_template='status = {:s}', filter_params={'s': 'published'}) - Sort & page: find_records(collection='posts', sort='-created', page=2, per_page=10) - Expand relations: find_records(collection='posts', expand='author') NEXT STEPS: write_record to create/update; delete_records to remove (if enabled).
USE WHEN you need an overview of server health, settings, cron jobs, and log statistics. EXAMPLES: - "Is PocketBase running?" -> inspect_server() - "What cron jobs are registered?" -> inspect_server() - "How many requests in the last 7 days?" -> inspect_server() NEXT STEPS: read_logs for detailed log entries; connect(as_='superuser') for full access.
USE WHEN you need to manage auth lifecycle: password reset, verification, email change, or token refresh. EXAMPLES: - Request reset: manage_auth(action="request_password_reset", collection="users", email="u@x.com") - Confirm reset: manage_auth(action="confirm_password_reset", collection="users", token="...", password="new", password_confirm="new") - Refresh token: manage_auth(action="refresh", collection="users") NEXT STEPS: connect(as_='status') to verify identity after refresh.
USE WHEN you need to create or modify a collection schema. EXAMPLES: - Create base: manage_collection(action="create", name="posts", fields=[{"name": "title", "type": "text", "required": True}]) - Create view: manage_collection(action="create", name="post_stats", collection_type="view", view_query="SELECT id, title FROM posts") - Update rules: manage_collection(action="update", name="posts", api_rules={"list": "@request.auth.id != ''"}) NEXT STEPS: describe_collection to verify, find_records or write_record to use.
USE WHEN you need to get a file URL, download a file, or upload a new file to a record. EXAMPLES: - URL: manage_files(action="url", collection="posts", record_id="abc", field="cover", filename="img.jpg") - Thumb: manage_files(action="url", ..., thumb="200x200") - Download: manage_files(action="download", ..., filename="doc.pdf") - Upload: manage_files(action="upload", ..., field="cover", local_path="/tmp/img.jpg", filename="img.jpg") NEXT STEPS: find_records to see the updated file field after upload.
USE WHEN you need to inspect request log entries. Superuser access required. EXAMPLES: - Latest logs: read_logs() - Single entry: read_logs(log_id="xyz") - Filter by level: read_logs(filter_template="level >= {:l}", filter_params={"l": 4}) NEXT STEPS: inspect_server for aggregate stats; connect(as_='superuser') if unauthorized.
USE WHEN you need to create or update a single record. Validates against the collection schema. EXAMPLES: - Create: write_record(collection='posts', action='create', data={'title': 'Hello', 'status': 'draft'}) - Update: write_record(collection='posts', action='update', id='abc123', data={'status': 'published'}) NEXT STEPS: find_records to verify; delete_records to remove (if enabled).
Error handling guidance minimal in tool descriptions. No recovery hints (e.g., 'If auth fails, call connect(as_="superuser") first'). Descriptions state what tools do but not what to do if they fail or what prerequisites exist.
Prompts (inspect_then_query, safe_delete, create_with_validation) are registered but not visible in source. Cannot verify their descriptions, input schemas, or guidance quality. Prompts should be as rigorously defined as tools.