spotify_get_artist
Get metadata and follower count for a Spotify artist.
This record as markdown: /tools/io-github-malamutemayhem-unclick-mcp-server/spotify-get-artist.md
What spotify_get_artist does on UnClick
AI agents call spotify_get_artist to retrieve information from UnClick without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
| Parameter | Type | Required | Description |
|---|---|---|---|
artist_id | string | Yes | |
bearer_token | string | Yes |
Parameters from the server's own tool schema.
Why spotify_get_artist is rated Low
This tool queries Spotify's API to retrieve publicly available artist information. It performs a simple data retrieval operation without creating, modifying, deleting, or executing any actions. The information retrieved (metadata and follower counts) are static, informational attributes. No reversible or irreversible changes are made to any system state.
From the tool's definition Tool description states 'Get metadata and follower count for a Spotify artist' - uses verb 'Get' and retrieves read-only data (metadata, follower count) with no modification or side effects.
Attacks that exploit this kind of access
The rule that runs spotify_get_artist safely
PolicyLayer is an MCP gateway: it sits between your AI agents and UnClick, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For spotify_get_artist, this is the rule to start with:
spotify_get_artist is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect UnClick, apply this rule, and every spotify_get_artist call is checked against it from then on.
Questions about spotify_get_artist
Get metadata and follower count for a Spotify artist. It is categorised as a Read tool in the UnClick MCP Server, which means it retrieves data without modifying state.
spotify_get_artist accepts 2 parameters: artist_id, bearer_token. Required: artist_id, bearer_token. The full parameter table on this page comes from the server's own tool schema.
Register the UnClick MCP server in PolicyLayer and add a rule for spotify_get_artist: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches UnClick. Nothing to install.
spotify_get_artist is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the spotify_get_artist rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for spotify_get_artist. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
spotify_get_artist is provided by the UnClick MCP server (@unclick/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on UnClick, and thousands of servers like it.
This server
Across the catalogue