Aziel Runtime
REMOTE · AZIEL-RUNTIME.VIBELOCK.WORKERS.DEV · SCANNED SEP 29
Governed MCP: agent audit, provenance, deterministic checks, and receipt-backed FragGate execution.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security51
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (mesh_leave). See how to fix → View diagnostics → Fail
- HTTPS check failed: the endpoint is reachable over plaintext HTTP. See how to fix → View diagnostics → Fail
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 19657 tokens (~546/item across 36 items; 36 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management14
- Stability check failed: schema churn in the 5 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 1 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 37 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Aziel Runtime MCP server?
Aziel Runtime is a hosted endpoint at https://aziel-runtime.vibelock.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · aziel-runtime.vibelock.workers.dev
claude mcp add --transport http azieleliab-aziel-runtime 'https://aziel-runtime.vibelock.workers.dev/mcp'
{
"mcpServers": {
"azieleliab-aziel-runtime": {
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} {
"servers": {
"azieleliab-aziel-runtime": {
"type": "http",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} [mcp_servers.azieleliab-aziel-runtime] url = "https://aziel-runtime.vibelock.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"azieleliab-aziel-runtime": {
"type": "remote",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add azieleliab-aziel-runtime --url 'https://aziel-runtime.vibelock.workers.dev/mcp' --transport streamable-http
mcp_servers:
azieleliab-aziel-runtime:
url: "https://aziel-runtime.vibelock.workers.dev/mcp" {
"McpServers": {
"azieleliab-aziel-runtime": {
"Transport": "http",
"Url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} assistant mcp add azieleliab-aziel-runtime -t streamable-http -u 'https://aziel-runtime.vibelock.workers.dev/mcp'
{
"mcpServers": {
"azieleliab-aziel-runtime": {
"type": "http",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “Softwares” rewrote its description, which is the text the model reads security
- Tool “fraggate_call” rewrote its description, which is the text the model reads security
- Tool “fraggate_describe” rewrote its description, which is the text the model reads security
- Tool “fraggate_list” rewrote its description, which is the text the model reads security
- Tool “library_lookup” rewrote its description, which is the text the model reads security
- Tool “Softwares” changed its title: Authoritative software catalog → First call — pick a Softwares slug cosmetic
- Tool “fraggate_call” changed its title: Step 3 — Call through FragGate → Step 3 — Call the picked slug through FragGate cosmetic
- Tool “fraggate_describe” changed its title: Step 2 — Describe one registry name → Step 2 — Describe the slug you picked cosmetic
- Tool “library_lookup” changed its title: Search the Aziel Digital Library → Library papers and cites cosmetic
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “runtime_run” rewrote its description, which is the text the model reads security
- Tool “runtime_session_exec” rewrote its description, which is the text the model reads security
- 26 Sept 26 +1
- Stability: 0.03 → fail ▼ security
- A breaking change shipped without a version bump: still 2.0.0-rc1 ▼ security
- Tool “runtime_software” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “fraggate_call” rewrote its description, which is the text the model reads security
- Tool “fraggate_list” rewrote its description, which is the text the model reads security
- Tool “runtime_bundle” rewrote its description, which is the text the model reads security
- Tool “runtime_skill” rewrote its description, which is the text the model reads security
- New tool “Softwares” functional
- “fraggate_call” added an optional parameter “background” cosmetic
- “fraggate_call” added an optional parameter “job_id” cosmetic
- 25 Sept 26 +11
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 48
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://aziel-runtime.vibelock.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=vibelock.workers.dev | CN=WE1,O=Google Trust Services,C=US | 28 Aug 2026 | 26 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | aaebda98eb4fe2e00ea103e87d2aeb7e |
| SANs: vibelock.workers.dev, *.vibelock.workers.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of aziel-runtime.vibelock.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'none'; base-uri 'none'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://aziel-runtime.vibelock.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://aziel-runtime.vibelock.workers.dev/mcp | Served over HTTP | 200 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
chainlock_append ChainLock append ~603
Append one fact-bearing stamp to a local ChainLock chain (CL-WP-0.4). Grounded write — not a tip read, not AKM observe, not a LOCKSET seal. Fabric, not Softwares-tab. No Node Gate. Use this when you have a concrete fact to stamp onto a named chain. Do not use it for reading the tip, adaptive memory observation, or sealing LOCKSET; use chainlock_tip, memory_observe, or chainlock_seal instead. Write: additive append (append-only vault; no chainlock_delete). Hash-only or empty fact refuses no-fact. Unknown roster name refuses unknown-chain. Oversized card refuses card-cap. Does not write godlock.uk. Omit c/chain to stamp the session chain. Door aliases: chain→c, s→subject, f→fact, kind→k. Omit k to store kind stamp. subject clips to 80; fact clips to 160 then refuses if still empty. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns the new stamp (id, h, fh, chain, seq) plus display envelope.
| Name | Type | Req | Description |
|---|---|---|---|
| c | string | – | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to stamp the session chain. |
| chain | string | – | Alias of c. Omit both to stamp the session chain. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| fact | string | yes | Required fact text clipped to 160 characters. Empty or hash-only after clip refuses no-fact. Alias: f. |
| k | string | – | Optional kind label. Omit to store kind stamp. Alias: kind. |
| subject | string | – | Optional subject clipped to 80 characters. Alias: s. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Append body: ok, stamp (id, c, k, fact, fh, stamp_sha256, prev), card, seq, vault path. Refuses: no-fact, unknown-chain, card-cap. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
chainlock_recall ChainLock recall ~357
Grounded ChainLock recall at depth 0–5 (id+h+fh facts or refuse=no-stamp). Stamped vault facts — not Bayesian rank and not tip-only. Use this when you need stamped facts from the local vault, not a Bayesian ranking. Do not use it for adaptive memory ranking or reading only the live tip; use memory_recall or chainlock_tip instead. Depth above 5 is clipped to 5. refuse=no-stamp when empty — do not invent a fact. Append-only; there is no chainlock_delete. Omit depth to use 1 (not 0). 0 = tip only; 5 = full chain / genesis budget. Omit c/chain to scan session+acts+recall+learn (not the whole roster). q/query is a case-insensitive subject/fact substring; empty q does not invent cards. Returns grounded facts (id, h, fh) or refuse=no-stamp.
| Name | Type | Req | Description |
|---|---|---|---|
| c | string | – | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to scan session, acts, recall, and learn — not the full roster. |
| chain | string | – | Alias of c. Omit both to scan session, acts, recall, and learn — not the full roster. |
| depth | number | – | Optional recall depth. Omit for 1. 0 = tip only; 5 = genesis/budget maximum. Values outside 0–5 are clipped. Alias: d. |
| q | string | – | Optional case-insensitive substring over subject/fact. Alias: query. Empty does not invent matches. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
chainlock_seal LOCKSET seal ~508
Write a new local LOCKSET over live chain tips (members {c,id,h,fh} + TemporalLock + GodLock cite, LS-WP-0.1). Not a raw-session close and not verify-only. Use this when the operator wants a new local lockset over current tips. Do not use it for verify-only, appending one fact, writing godlock.uk, or sealing a raw runtime session; use chainlock_verify, chainlock_append, or runtime_session_close instead. Write: replaces receipts/LOCKSET.json. Empty vault (no live tip on any roster chain) refuses empty-vault. Empty chains are omitted from members, not invented. Runtime cites godlock.uk and does not write the public ledger — the operator posts lockset_sha256. A later seal overwrites the previous local lockset. Empty {} still attempts the seal. Omit ts so TemporalLock stamps now. Passing ts labels that receipt only and never backdates seal authority or prior stamps. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns lockset document (members, temporal, godlock cite) and lockset_sha256.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| ts | string | – | Optional ISO-8601 timestamp copied onto the TemporalLock block. Omit to use now. Never backdates authority, prior stamps, or godlock.uk. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Seal body: ok, lockset (members, temporal, godlock, lockset_sha256), or refuse empty-vault when no live tips exist. Does not write godlock.uk. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
chainlock_tip ChainLock tip ~237
Read only the live tip card of one local ChainLock chain — not depth recall and not LOCKSET verify. Use this when you need the current tip of a named chain. Do not use it for depth-0–5 grounded recall, LOCKSET verify, or adaptive memory explain; use chainlock_recall, chainlock_verify, or memory_get instead. Does not invent a missing tip. An empty chain returns ok with tip=null and empty=true (not a refuse). Fabric module — not a Softwares-tab product. Omit c/chain to read the session chain tip (not the full vault). chain is an alias of c. This is one card, not depth recall. Returns the tip card (id, h, fh) or tip=null / empty=true when that chain has no stamp.
| Name | Type | Req | Description |
|---|---|---|---|
| c | string | – | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to read the session chain tip. |
| chain | string | – | Alias of c. Omit both to read the session chain tip. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Tip body: ok, chain, tip card or null, empty flag, seq when a stamp exists. Empty chain is ok+empty, not an invented card. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
chainlock_verify ChainLock / LOCKSET verify ~296
Confirm fail-closed integrity of ChainLock chains and LOCKSET (LS-WP-0.1): broken prev, tip drift, missing GodLock cite. Integrity check — not a new seal. Use this when you must prove local chain integrity before trusting a recall. Do not use it for appending a stamp or sealing a new lockset; use chainlock_append or chainlock_seal instead. Cites godlock.uk; does not write the public ledger. Fail-closed — do not repair silently. Break reasons include broken-prev, stamp-hash-miss, body-hash-miss, tip-drift, missing-godlock-cite. Omit c/chain to verify every roster chain plus the stored LOCKSET. require_seal=true fails closed if no lockset is stored. Returns chain_ok, LOCKSET lattice, and per-chain verify notes.
| Name | Type | Req | Description |
|---|---|---|---|
| c | string | – | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to verify every roster chain plus the stored LOCKSET. |
| chain | string | – | Alias of c. Omit both to verify every roster chain plus the stored LOCKSET. |
| require_seal | boolean | – | Optional. When true, fail-closed if receipts/LOCKSET.json is missing. When omitted, a stored lockset is still checked if present. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
decisiongate_check Run DecisionGATE on a proposal ~509
Run the named DecisionGATE five sequential gates on a proposal (Freedom without clarity is chaos) without executing a catalog product. Also runs automatically inside fraggate_call before exec. Use this when you want a gate check without executing a catalog product verb. Do not use it for executing a product op or searching the library; use fraggate_call or library_lookup instead. Write: appends an ask/refuse ledger tip (not idempotent). Empty {} still runs the five gates and stamps the ledger. Does not execute domain software. Named wrapper — same DecisionGATE kernel; not the full MASTER-33 hop list; Softwares exec stays fraggate_call. All proposal fields are optional. Missing evidence can fail a gate. accountable identity on this runtime is Aziel Eliab only. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns gate view, final_state, ledger_tip, and result (code FG-OK on the named module wrapper).
| Name | Type | Req | Description |
|---|---|---|---|
| accountable | string | – | Optional accountable party string. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| evidence | array | – | Optional evidence strings. Missing evidence can fail a gate. |
| impact_neg | array | – | Optional negative-impact list. |
| impact_pos | array | – | Optional positive-impact list. |
| statement | string | – | Optional proposal statement to evaluate. |
| values | array | – | Optional values list. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
fraggate_call Step 3 — Call the picked slug through FragGate ~1,619
Execute the slug you picked from Softwares through the FragGate single door (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return). Default exec path — not the catalog and not a raw session. Use this when Softwares already returned a slug and a live allowlisted op is known. Do not use it for picking the catalog slug, searching library papers, or raw session plumbing; use Softwares, library_lookup, or (only if asked) runtime_run / runtime_session_exec instead. Side effects are operation-dependent (read, write, or refuse). May reach an open world when the target op does (for example AZBrowser ethical_search); many ops stay isolate-local. Unknown names refuse FG-HALLUC-TOOL. Stub, local-only, and Remain-OFF verbs refuse FG-STUB / FG-LOCAL-ONLY / FG-GATE-REFUSE / FG-LAMB-REFUSE. FragGate is THE single door. Required: op, unless job_id is set (that reads a background job and does not start another). Also pass slug or name. Shorthand name foldlock/fold-preview is accepted. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id/confirm/dry_run/background/job_id become the op payload when payload is omitted. Example preview: {"name":"foldlock/fold-preview","payload":{"text":"the cat and the dog"},"dry_run":true}. Optional background=true returns Running and a job_id before the op finishes; Done only after a receipt hash exists. Poll with the same job_id and confirm=true. dry_run does not start a job. UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, doctor, pair) forward to catalog ops. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call woul…
| Name | Type | Req | Description |
|---|---|---|---|
| attempt_n | integer | – | Optional 1-based attempt number for this call. Omitted means attempt 1 of a new request_id. |
| background | boolean | – | Optional. When true, FragGate admits the call and returns Running with a job_id before the op finishes. Done is returned only after a receipt hash exists. dry_run does not start a job. A missing job… |
| claim | object | – | Optional DecisionGATE proposal attached to this call. Also runs automatically inside the door even when omitted (defaults). Freedom without clarity is chaos. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| correlation_id | string | – | Optional client correlation id. Sealed inside a ForgeReceipts hash when this call mints one. |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| job_id | string | – | Optional job id from a background call (job_ + 16 hex). When set, the call reads that job and does not start another. confirm=true is still required. It does not re-run the op. |
| name | string | – | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unkno… |
| op | string | yes | Required public allowlisted op from fraggate_describe (for example fold-preview, ethical_search, blank_key_status). UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, docto… |
| parent_receipt_id | string | – | Optional prior attempt receipt hash. Null on the first attempt. This is not FragGate ledger prev, which stays call order only. |
| payload | object | – | Optional op payload object. Shape is engine-specific (see fraggate_describe). Malformed fields are refused by the engine, not by this door schema. If omitted, leftover top-level keys are used as the… |
| request_id | string | – | Optional logical request id. The same value groups retries of one action on the ResultEnvelope and, for ForgeReceipts, inside the receipt hash. |
| slug | string | – | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
fraggate_describe Step 2 — Describe the slug you picked ~318
Inspect one FragGate card for the slug you picked from Softwares (live vs stub vs local_only, public ops, engine_digest). Not execute and not a digest-only proof. Use this when you already have a name or slug from Softwares, fraggate_list, or GET /v1/software. Do not use it for discovering the full registry, proving a digest, pulling a hub product card, or executing an op; use fraggate_list, fraggate_verify, runtime_pull, or fraggate_call instead. Missing both name and slug, or an unknown name, refuses FG-HALLUC-TOOL. Wipe/unlock on embryolock stay FG-STUB. AZChat is LIVE+bound (mesh default off; not AZMail). Pass name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted. Returns one registry card (ops, stub_ops, digest, status, aliases).
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unkno… |
| slug | string | – | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
fraggate_list Step 1 — List the FragGate registry ~613
List hashed FragGate names and digests after Softwares so you can discover names. Discovery first — not the Softwares catalog and not exec. Use this when Softwares already returned a slug and you need live, stub, local_only, or digest status. Do not use it for the first catalog read, inspecting one known card, or executing an op; use Softwares (GET /v1/software), fraggate_describe, or fraggate_call instead. Empty {} only. Never enables mesh radios. Never invents tools or ops. Compact LIVE_OPS tokens below are discovery hints required by product verify scripts — they are not exec. Call fraggate_describe for the live card; later unknown names refuse FG-HALLUC-TOOL. Returns registry entries, allowlists, digests, and the MASTER-33 pipeline cite. Not the full FragGate door. Empty fraggate_list is discovery (hashed LIVE_OPS). Catalog LIVE_OPS slugs (40): 4dmap, ark, azai, azbot, azbrowser, azchat, azclce, azcoherence, azhub, aziel-corpus, azieltether, azinterface, azmail, aznet, azos, azvpn, chronolock, codelock, decisiongate, embryolock, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, mmconsensus, peacelock, postking, shadowlock, spectrallock, staticclock, temporallock, toolbench, trajectorylock, vibelock, whistlelock, zkattest, zsolver. Compact product-verify tokens (not a second allowlist): allowlist.azhub LIVE_OPS: health, skill, region_list, place_module, remove_module, tether_declare, tether_cut, tether_list, blank_key_status, list_modules, place. allowlist.azinterface LIVE_OPS: health, skill, genesis_status, site_state_get, site_state_set, integrity_check, witness_list, page_cycle_status, genesis_boot, hold. allowlist.azbrowser LIVE_OPS: ethical_search, lamb_lens_search, navigate, airlock_ingest, airlock, home, tab_open, tab_list, receipt_list, verify, receipt_verify, sandbox_status, sandbox_render, health, skill, vpn. allowlist.azvpn LIVE_OPS: health, skill, doctor, limitation, describe, open, status, list, close, send, recv, pu…
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
fraggate_verify Verify a registry name or digest ~378
Confirm a name, slug, or 64-hex engine_digest against the hashed FragGate registry — a proof, not a card listing. Use this when you must prove a listed name or digest exists after fraggate_describe. Do not use it for listing the registry, describing ops, or executing; use fraggate_list, fraggate_describe, or fraggate_call instead. Not an exec path and not a describe card. Empty {} (no name, slug, or digest) refuses FG-HALLUC-TOOL. Digest without name/slug compares the whole registry hash (kind=registry). Name or slug with an optional digest compares that entry (kind=entry); unknown names refuse FG-HALLUC-TOOL. Mismatch returns ok=false with matched=false — it does not invent a digest. Send digest alone to proof the live registry_digest. Send name or slug (one is enough) to proof one card. Combined name+digest must equal that card's engine_digest. Returns match or mismatch (kind registry|entry, matched, registry_digest).
| Name | Type | Req | Description |
|---|---|---|---|
| digest | string | – | Optional 64-char lowercase hex engine_digest or registry digest to verify. When digest is set without name/slug, the tool compares the live registry digest. |
| name | string | – | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unkno… |
| slug | string | – | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
library_lookup Library papers and cites ~320
Search the Aziel Digital Library for papers and cites (aziel-corpus search, example, or skill) — cites, not beliefs and not vault stamps. Use this when you need a library paper, cite, example record, or library skill after Softwares and fraggate_call. Do not use it for running a Softwares slug, adaptive memory belief, ChainLock facts, or private-file search; use fraggate_call for a catalog slug, memory_recall, or chainlock_recall instead. Not a private-file search engine and not AKM/ChainLock. Empty q does not invent a cite. Unknown ops refuse FG-UNKNOWN-OP (allowed: search, example, skill, health). Named corpus wrapper — not MASTER-33; full aziel-corpus LIVE_OPS stay on fraggate_call. q is public corpus text — not memory_recall q and not ChainLock q. Omit op to search. Extra keys besides q/op/payload ride along as aziel-corpus payload (same as passing payload{}). Returns search, example, skill, or health payload inside the display envelope.
| Name | Type | Req | Description |
|---|---|---|---|
| op | string | – | Optional library verb. search (default) looks up public corpus text; example returns a sample; skill returns the library skill; health is liveness. Other values refuse FG-UNKNOWN-OP. |
| q | string | – | Optional public-corpus query for op=search. Empty q returns an empty or default hit set, not an invented cite. Not a memory or ChainLock query. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
memory_calibrate Calibrate a memory ~505
Calibrate one memory with the deterministic 3-of-4 triad plus Bayesian posterior (AKM-TRIAD-1.0). Writes a LEARN stamp — not a ranked search and not an explain view. Use this when an observed memory should receive a posterior after evidence, not a ranked search. Do not use it for observing a new fact, resolving an outcome, or explaining a stored node; use memory_observe, memory_resolve, or memory_get instead. Write: forward-only RoseClock LEARN stamp. Posterior ≠ truth. authorizes_action=false. No automatic MODEL_UPDATE. subject or memory_id recommended. use_case labels calibration; it is not a permission. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns triad_score, omitted leg, posterior, effective N, and Brier notes.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| fact | string | – | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. |
| memory_id | string | – | Optional existing memory id. Alternative to subject for resolve/calibrate/get. |
| subject | string | – | Optional subject key clipped to 80 characters. Used to find or create memory_id. |
| use_case | string | – | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
memory_get Explain a memory ~276
Read one memory's stored explanation (node, history, or calibration: posterior, triad legs, effective N, Brier) — not a ranked list. Use this when you have a memory_id (or id) and need the stored explanation. Do not use it for ranked adaptive recall or appending an observation; use memory_recall or memory_observe instead. Missing both memory_id and id, or an unknown id, refuses AKM-NOT-FOUND — do not invent a node. authorizes_action stays false. There is no memory_delete; this is the read of the append-only node. Pass memory_id or id — one is enough; they are aliases, not two different records. Omit view for the default node slice. history returns events/resolutions; calibration returns posterior/triad/Brier. subject is not a lookup key here. Returns node, history, or calibration view (belief_is_not_truth).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Alias of memory_id. Do not send two different values. |
| memory_id | string | – | Memory id to explain. Alternative to id. Missing both refuses AKM-NOT-FOUND. |
| view | string | – | Optional slice. Omit or get = stored node; history = events/resolutions; calibration = posterior, triad legs, effective N, Brier. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Explain body: ok, memory_id, status, plus node or events or calibration fields. belief_is_not_truth. Refuses AKM-NOT-FOUND when the id is missing or unknown. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
memory_observe Observe a memory ~508
Append the first memory_observation to the ChainLock learn chain (AKM-TRIAD-1.0). New fact in — not an outcome resolve and not a grounded ChainLock append. Posterior ≠ truth. Use this when you have a new fact to observe before resolve/calibrate. Do not use it for grounded ChainLock append without AKM, resolving an outcome, or ranked recall; use chainlock_append, memory_resolve, or memory_recall instead. Write: additive learn-chain stamp. authorizes_action stays false. Hash-only cards refuse AKM-NO-FACT. Append-only; there is no memory_delete. fact is required (≤160). subject/memory_id/use_case optional. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns memory_id, observation stamp, and display envelope (belief is not truth).
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| fact | string | yes | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. |
| memory_id | string | – | Optional existing memory id. Alternative to subject for resolve/calibrate/get. |
| subject | string | – | Optional subject key clipped to 80 characters. Used to find or create memory_id. |
| use_case | string | – | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
memory_recall Adaptive recall ~362
Ranked adaptive recall after ChainLock verify (AKM-TRIAD-1.0). Belief list — not raw grounded stamps, not a public corpus cite, not one-id explain. Use this when you want a ranked belief list after verify, not raw grounded stamps. Do not use it for grounded ChainLock recall, library search, or explaining one memory_id; use chainlock_recall, library_lookup, or memory_get instead. Does not authorize action (authorizes_action=false). Do not treat posterior rank as fact (belief_is_not_truth). Failed ChainLock verify refuses CHAIN_VERIFY_FAIL and does not invent cards. Empty grounded recall bubbles refuse=no-stamp. Ranking is capped at 16 cards. Omit depth to rank at 5 (full budget), unlike chainlock_recall which defaults to 1. q/query is lexical rank text, not a SQL filter. Empty q still verify-then-ranks stored cards. use_case weights triad_fit; it is not a permission. Optional limit clips the already-capped list. Returns ranked cards after verify (count, facts, belief_is_not_truth, authorizes_action=false).
| Name | Type | Req | Description |
|---|---|---|---|
| depth | number | – | Optional ChainLock recall depth after verify. Omit for 5 (full budget). 0 is tip-only ranking. |
| limit | number | – | Optional result cap. Hard ceiling is 16 (MEMORY_CONTEXT_CAP) even if a larger number is sent. |
| q | string | – | Optional lexical rank query (subject/fact). Alias: query. Empty still runs verify-then-rank; it does not invent facts. |
| use_case | string | – | Optional use-case label that weights triad_fit in ranking. Not a permission and not a truth claim. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Adaptive recall body: ok, adaptive=true, verified, count, facts (ranked cards with score/retrieval), belief_is_not_truth, authorizes_action=false. Refuses CHAIN_VERIFY_FAIL or no-stamp. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
memory_resolve Resolve a memory outcome ~554
Append a memory_resolution outcome on an already-observed memory (AKM-TRIAD-1.0). UNKNOWN is distinct from MISS. Does not rewrite history. Use this when an observed memory_id or subject now has an outcome. Do not use it for first observation, calibration, or reading history; use memory_observe, memory_calibrate, or memory_get instead. Write: additive resolution stamp. Missing memory_id/subject refuses AKM-NO-MEMORY. Does not rewrite prior observations. No memory_update — this is the forward outcome path. Requires memory_id or a previously observed subject. outcome is optional [0,1]; omit for UNKNOWN. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns resolution stamp with outcome or UNKNOWN.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| fact | string | – | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. |
| memory_id | string | – | Optional existing memory id. Alternative to subject for resolve/calibrate/get. |
| outcome | number | – | Optional graded outcome in [0, 1]. Omit (or pass UNKNOWN) for an UNKNOWN resolution — distinct from MISS. |
| outcome_label | string | – | Optional label (for example HIT, MISS, GRADED, UNKNOWN). UNKNOWN is a first-class state, not a miss. |
| subject | string | – | Optional subject key clipped to 80 characters. Used to find or create memory_id. |
| use_case | string | – | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_broadcast Register a local hash receipt ~470
Register the SHA-256 of a local file as a hash receipt — never a publish or upload path. Use this when the operator already holds a local file and wants only its hash recorded. Do not use it for uploading bytes, publishing video, sending mail, or joining a mesh node; use local qnm-node/ anon-broadcast loopback, AZMail via fraggate_call, or mesh_join instead. Write: stores a hash receipt only. Does NOT accept video bytes. Operator keeps the file. Malformed sha256 refuses MESH-BAD-INPUT; publish-shaped keys refuse MESH-NO-PUBLISH. sha256 is required (64 hex). title and product are optional labels, not file contents. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns hash receipt (sha256, optional title).
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| product | string | – | Optional catalog product slug to attribute the receipt. Not required. |
| sha256 | string | yes | Required 64-character hex SHA-256 of the local file. Hash receipt only — not a publish path. |
| title | string | – | Optional short title for the receipt. Not the file contents. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_disable Suite disable is refused ~146
Confirm that read-only QNM suite-presence stays ON (POST /v1/mesh/disable refuses MESH-DISABLE-REFUSED) — not a kill switch. Use this when a client still posts the historical disable route and needs the honest refuse. Do not use it for dropping one node or declaring an extra bearer; use mesh_leave or mesh_enable instead. Read-only refuse: suite-presence stays ON. No tethers drop. No implicit heal, no account resurrection, no wipe internals. Repeating still refuses. AZMail mesh_disable is a separate product-local mail ring. Returns MESH-DISABLE-REFUSED with enabled=true and a stay-on note.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_enable Enable QNM radios (declared bearer) ~473
Declare an extra QNM suite bearer (POST /v1/mesh/enable) — additive presence, not a first-time on-switch. Use this when an operator wants to declare an additional bearer (example: suite-presence) on top of the default-on rollup. Do not use it for reading status, joining one node, turning suite-presence off, or logging into an account; use mesh_status, mesh_join, or mesh_nodes instead. Write: stores the bearer. Rate-limited. Empty {} is refused (MESH-NEED-BEARER). Login/account/recover/gate names refuse. Does not arm, wipe, heal, or resurrect accounts. Not a login mesh. Read-only suite-presence is already ON by default. bearer is required. Example: suite-presence. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns enabled state, bearers, and suite-presence note.
| Name | Type | Req | Description |
|---|---|---|---|
| bearer | string | yes | Required declared bearer name. Example: suite-presence. Login / account / recover / recovery / gate / IP / publish / phoenix / heal names refuse MESH-ENABLE. This is not a login mesh. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_heartbeat Refresh QNM rollup presence ~593
Refresh one existing node's 5-minute QNM TTL (POST /v1/mesh/heartbeat) — not a first join. Use this when you already have a node_id from mesh_join and transmission radios are LIVE. Do not use it for first-time registration or dropping the node; use mesh_join or mesh_leave instead. Write: refreshes the strict 5-minute TTL (not idempotent). Miss the window and the node is dropped from the live roster. Radios off refuses MESH-OFF. Unknown or expired node_id refuses MESH-UNKNOWN-NODE — join again; no account resurrection. node_id is required. presence may replace the class (live|locked|isolated). Optional tip_hash and prev are 64 hex only (Split the wires + REHEAL: presence + tip hash; no body/diff/vote-to-fix). OPERATOR-OVERRIDE 2026-09-17 armed neighbor_heal. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns updated presence and TTL. Body on this plane refuses MESH-NO-BYTES. Same prev + two tips refuses MESH-EQUIVOCATION. Vote-to-fix still refuses MESH-NO-NEIGHBOR-HEAL.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| node_id | string | yes | Required node id returned by mesh_join. |
| presence | string | – | Optional replacement presence class. Other values refuse MESH-BAD-INPUT. |
| prev | string | – | Optional 64-hex prev the receiver already holds. Same prev + a different tip_hash isolates this node (MESH-EQUIVOCATION). |
| tip_hash | string | – | Optional 64-hex tip hash on the fast tick. Fixed-size. No body. Split the wires. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_join Register QNM rollup presence ~726
Register one product node into the QNM rollup (POST /v1/mesh/join) — first presence, not a TTL refresh. Use this when transmission radios are LIVE and a catalog product should appear in live/locked/isolated counts. Do not use it for refreshing an existing node, reading the roster, enabling radios, or opening an account session; use mesh_heartbeat, mesh_nodes, mesh_enable, or runtime_session_open instead. Write: additive presence with a strict 5-minute TTL. Human bearers (kind=human, bearer=human, or auto-minted mesh_*) count toward public Live Nodes when not isolated. Softwares {slug}-worker rows are software_nodes and never feed Live Nodes. Downloaded instance ids stay instance_nodes. Isolated humans do not count. No heartbeat (or fan-out refresh) inside that window drops the node from the roster. Radios off refuses MESH-OFF. Missing product / bad node_id / bad presence refuse MESH-BAD-INPUT. Downloads are not live. Read-only suite-presence is ON by default. Not an account session. AnonBroadcast is not a product. Kernel-direct fabric wrapper — same mesh kernel as FragGate mesh/join; not MASTER-33; human Join uses fraggate_call. product is required (catalog slug). node_id optional 8–80 [a-z0-9._-]. presence is live|locked|isolated (default live). kind/plane may be human|instance. bearer=human marks a human mesh user. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns node_id, presence, presence_ttl_ms (300000), and TTL note. MESH-OFF when radios are off.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| label | string | – | Optional short label for the roster. Display only; not a score. |
| node_id | string | – | Optional stable node id. When set, must be 8–80 characters matching [a-z0-9._-]. Omit to receive a generated id. |
| presence | string | – | Optional rollup class. live (default), locked, or isolated. No scores. Other values refuse MESH-BAD-INPUT. |
| product | string | yes | Required catalog product slug (a-z0-9-, for example godlock, azmail). AnonBroadcast is refused. Unknown slugs refuse MESH-BAD-INPUT. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_leave Drop QNM rollup presence ~373
Drop one node from the QNM rollup (POST /v1/mesh/leave) — not a suite-wide radio off. Use this when a previously joined node should leave the counts. Do not use it for turning suite-presence off or listing nodes; use mesh_nodes or mesh_status instead. Destructive to that node's presence only. Always allowed. No implicit heal. Repeating a missing node_id is a no-op/refuse, not resurrection. node_id is required. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns leave receipt for the node_id.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| node_id | string | yes | Required node id to drop from the rollup. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_nodes List QNM rollup nodes ~96
List the QNM node roster (node_id + presence + 5-minute TTL) — not suite totals. Use this when you need the current node list after mesh_status. Do not use it for suite counts without the roster, or mutating presence; use mesh_status, mesh_join, or mesh_leave instead. No scores. No leaderboard. Views/MCP/downloads do not enter QNM-S. Returns node roster with presence classes.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
mesh_status QNM suite rollup ~302
Read QNM suite rollup totals (enabled?, bearers, nodes = human mesh users + cited human uses, live_nodes = human mesh users + site_live_viewers, software_nodes = {slug}-worker roster) — not the node roster. Packet-transfer cite is QNS-CD-1.0 (photon QNS1 1.3 on local qnsd; GET /v1/qns cites only; Worker does not proxy via emit). Use this when you need public Nodes (users + uses), Live Nodes (users + site viewers), or software_nodes (product Worker roster). Do not use it for listing individual nodes, enabling extra radios, or executing a catalog engine; use mesh_nodes, mesh_enable, or fraggate_call instead. Read-only. Never enables radios beyond default suite-presence. Read-only suite-presence is ON by default. Not a login mesh. Views/MCP/downloads do not enter QNM-S. Full node process is local qnm-node/. Kernel-direct fabric wrapper — not MASTER-33; not a second Softwares door. Softwares exec stays fraggate_call. Returns enabled flag, bearers, nodes (human mesh users + cited uses), live_nodes (human mesh users + site_live_viewers), human_mesh_users, site_live_viewers, human_uses, active_nodes, inactive_nodes, isolated_nodes, software_nodes (product Workers), and QNS-CD-1.0 cite.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
What is the Aziel Runtime MCP server?
Aziel Runtime is an MCP server listed in the public MCP registry as io.github.AzielEliab/aziel-runtime. Governed MCP: agent audit, provenance, deterministic checks, and receipt-backed FragGate execution. This page covers its hosted endpoint (https://aziel-runtime.vibelock.workers.dev/mcp).
Is the Aziel Runtime MCP server safe to use?
Aziel Runtime scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Aziel Runtime MCP server expose?
Aziel Runtime exposes 36 tools: runtime_skill, fraggate_list, fraggate_describe, fraggate_verify, fraggate_call, and 31 more. Their descriptions and schemas cost roughly 15,550 tokens of context every time the server is loaded.
Does the Aziel Runtime MCP server require authentication?
No. We connected to Aziel Runtime without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Aziel Runtime MCP server still maintained?
Aziel Runtime is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.