self::ID, 'label' => __( 'Start Templately Google Sign-In', 'templately' ), 'description' => __( 'Get the URL to connect this site to a Templately account via Google sign-in. Completing sign-in requires opening the URL in a real browser.', 'templately' ), 'input_schema' => [ 'type' => 'object', 'properties' => (object) [], 'additionalProperties' => false, ], 'output_schema' => [ 'type' => 'object', ], 'execute_callback' => [ self::class, 'execute' ], 'permission_callback' => [ Permissions::class, 'can_use_abilities' ], 'access_level' => ToolDescriptor::ACCESS_FULL, 'annotations' => [ 'readonly' => true, 'destructive' => false, 'idempotent' => false ], ]; } /** * @param array $input * @return array */ public static function execute( array $input ): array { // Self-generated — guaranteed to already match MCP::is_valid_oauth_state()'s // format, so no extraction/validation round-trip is needed here. $token = wp_generate_password( 32, false ); $url = Http::get_instance()->google_auth_url( $token ); // Marker only — no user id needed. Attribution happens later, when // the user pastes the api_key back for an auth-login-with-api-key // call in this agent's own authenticated session. set_transient( MCP::OAUTH_TOKEN_TRANSIENT_PREFIX . $token, true, 5 * MINUTE_IN_SECONDS ); return [ 'url' => $url, 'instructions' => __( 'Open this URL in a browser and complete Google sign-in. Instead of connecting automatically, the page will show you an API key — copy it and give it to the agent, which will call templately-auth-login-with-api-key to finish connecting this site.', 'templately' ), ]; } }