Aziel Runtime
REMOTE · AZIEL-RUNTIME.VIBELOCK.WORKERS.DEV · SCANNED SEP 29
Governed MCP: agent audit, provenance, deterministic checks, and receipt-backed FragGate execution.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security51
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (mesh_leave). See how to fix → View diagnostics → Fail
- HTTPS check failed: the endpoint is reachable over plaintext HTTP. See how to fix → View diagnostics → Fail
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 19657 tokens (~546/item across 36 items; 36 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management14
- Stability check failed: schema churn in the 5 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 1 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 37 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Aziel Runtime MCP server?
Aziel Runtime is a hosted endpoint at https://aziel-runtime.vibelock.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · aziel-runtime.vibelock.workers.dev
claude mcp add --transport http azieleliab-aziel-runtime 'https://aziel-runtime.vibelock.workers.dev/mcp'
{
"mcpServers": {
"azieleliab-aziel-runtime": {
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} {
"servers": {
"azieleliab-aziel-runtime": {
"type": "http",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} [mcp_servers.azieleliab-aziel-runtime] url = "https://aziel-runtime.vibelock.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"azieleliab-aziel-runtime": {
"type": "remote",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add azieleliab-aziel-runtime --url 'https://aziel-runtime.vibelock.workers.dev/mcp' --transport streamable-http
mcp_servers:
azieleliab-aziel-runtime:
url: "https://aziel-runtime.vibelock.workers.dev/mcp" {
"McpServers": {
"azieleliab-aziel-runtime": {
"Transport": "http",
"Url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} assistant mcp add azieleliab-aziel-runtime -t streamable-http -u 'https://aziel-runtime.vibelock.workers.dev/mcp'
{
"mcpServers": {
"azieleliab-aziel-runtime": {
"type": "http",
"url": "https://aziel-runtime.vibelock.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “Softwares” rewrote its description, which is the text the model reads security
- Tool “fraggate_call” rewrote its description, which is the text the model reads security
- Tool “fraggate_describe” rewrote its description, which is the text the model reads security
- Tool “fraggate_list” rewrote its description, which is the text the model reads security
- Tool “library_lookup” rewrote its description, which is the text the model reads security
- Tool “Softwares” changed its title: Authoritative software catalog → First call — pick a Softwares slug cosmetic
- Tool “fraggate_call” changed its title: Step 3 — Call through FragGate → Step 3 — Call the picked slug through FragGate cosmetic
- Tool “fraggate_describe” changed its title: Step 2 — Describe one registry name → Step 2 — Describe the slug you picked cosmetic
- Tool “library_lookup” changed its title: Search the Aziel Digital Library → Library papers and cites cosmetic
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “runtime_run” rewrote its description, which is the text the model reads security
- Tool “runtime_session_exec” rewrote its description, which is the text the model reads security
- 26 Sept 26 +1
- Stability: 0.03 → fail ▼ security
- A breaking change shipped without a version bump: still 2.0.0-rc1 ▼ security
- Tool “runtime_software” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “fraggate_call” rewrote its description, which is the text the model reads security
- Tool “fraggate_list” rewrote its description, which is the text the model reads security
- Tool “runtime_bundle” rewrote its description, which is the text the model reads security
- Tool “runtime_skill” rewrote its description, which is the text the model reads security
- New tool “Softwares” functional
- “fraggate_call” added an optional parameter “background” cosmetic
- “fraggate_call” added an optional parameter “job_id” cosmetic
- 25 Sept 26 +11
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 48
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://aziel-runtime.vibelock.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=vibelock.workers.dev | CN=WE1,O=Google Trust Services,C=US | 28 Aug 2026 | 26 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | aaebda98eb4fe2e00ea103e87d2aeb7e |
| SANs: vibelock.workers.dev, *.vibelock.workers.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of aziel-runtime.vibelock.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'none'; base-uri 'none'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | no-referrer |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://aziel-runtime.vibelock.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://aziel-runtime.vibelock.workers.dev/mcp | Served over HTTP | 200 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
runtime_bundle List every product (bundle helper) ~101
Read a compact bootstrap of every product skill URL and invoke prefix — not Software-tab cards and not the hashed registry. Use this when a client needs skill URLs in one shot. Do not use it for Software-tab refresh, hashed registry discovery, or exec; use Softwares, fraggate_list, or fraggate_call instead. Prefer GET /v1/software for hub Software tabs. This helper is URL bootstrap only. Returns compact product list with skill URLs.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_manifest Advanced: runtime manifest ~109
[advanced/internal] Read the machine runtime manifest JSON (version, role, door=fraggate, engine slugs, registry_digest) — not the human how-to. Use this when a client needs the machine manifest rather than the human skill. Do not use it for the default agent how-to or hashed registry discovery; use runtime_skill or fraggate_list instead. Not the default agent path. Does not list hub cards or execute. Returns manifest including door=fraggate and registry_digest.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_pull Open one product ~239
Open one hub product card by slug (name, version, skill, download, ops) — not FragGate live/stub status. Use this when you already have a slug from GET /v1/software or fraggate_list and need the card, not exec. Do not use it for inspecting FragGate live/stub status or executing an op; use fraggate_describe or fraggate_call instead. Not exec — then use fraggate_call. Unknown slug throws unknown product (it does not invent a card and does not refuse FG-HALLUC-TOOL; that code is FragGate-only). Missing skill falls back to in-repo markdown. slug is required. product is an accepted alias of slug. Extra keys besides those two are ignored and are not an op payload. Returns one product card (name, version, skill, download, ops, skill_source).
| Name | Type | Req | Description |
|---|---|---|---|
| product | string | – | Alias of slug. Do not send two different values. |
| slug | string | yes | Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Alias: product. Not an exec path. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | One hub product card: name, version, skill markdown, download, ops, skill_source. Unknown slug is unknown product — not a FragGate FG-HALLUC-TOOL envelope. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_run Advanced: raw runtime_run ~548
[advanced/internal] Advanced exec façade: admit a slug+op (still DecisionGATE-admitted) and run it through a raw session. Not the default door. Use this when you were explicitly asked for the raw runtime_run path. Do not use it for the default agent exec path or an already-open session you were asked to exec on; use fraggate_call (default) or runtime_session_exec (existing session_id) instead. Side effects are operation-dependent. Not a backdoor past FragGate. Opens a session when session_id is omitted. slug and op are required for an explicit run. A question in q, question, or text with slug omitted asks the mesh router to pick one live Softwares slug and op. That pick does not exec unless confirm=true. dry_run=true returns the pick and writes nothing. session_id optional; omit to auto-open. Extra keys other than payload/session_id may be treated as payload. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns exec display envelope with session_id, result, engine_digest, ran_in, and refusal when gated.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| op | string | yes | Required allowlisted op. Stubs refuse FG-STUB. |
| payload | object | – | Optional op payload object. Engine-specific. |
| session_id | string | – | Optional existing raw session id. If omitted, a session is opened automatically. Prefer leaving session plumbing invisible unless asked. |
| slug | string | yes | Required catalog slug (or name alias). Unknown slugs refuse FG-HALLUC-TOOL. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_close Advanced: seal a session ~512
[advanced/internal] Seal a raw session so further exec or policy on that session_id is rejected. End of the raw lifecycle — not a LOCKSET seal and not a FragGate call. Use this when the user asked to close the session. Do not use it for ordinary completion, writing a ChainLock LOCKSET, or default product work; use leaving the session to TTL expire (6h), chainlock_seal for a lockset, or fraggate_call for new work instead. Destructive to further exec/policy on that session_id only (session_closed 409). Does not delete receipts. A second close does not reopen — it returns session_closed (409) while the session stays sealed. Missing session returns session_not_found. Prefer leaving sessions to expire unless asked. session_id or id (aliases) required. No force flag on the public tool — TTL expiry is the automatic close path. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns sealed session status, close receipt, and verified.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| id | string | – | Alias of session_id. The door accepts either key; do not send two different values. |
| session_id | string | yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Close body: sealed session, close receipt, verified. Errors: session_id required, session_not_found, session_closed (already sealed; does not reopen). |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_exec Advanced: raw session exec ~872
[advanced/internal] Raw session exec on an already-open session_id (FragGate-admitted). Not fraggate_call and not runtime_run auto-open. Use this when you already have a session_id and were asked for raw session exec. Do not use it for the default agent exec path or opening a session; use fraggate_call or runtime_session_open instead. Side effects are operation-dependent (read, write, or refuse). Does not mint a session_id — missing id fails before admit. Sealed sessions refuse session_closed (409); TTL 6h refuses session_expired (410); receipt cap 64 refuses receipt_cap (409). Rate-limited (exec). Binding-only ops stay per-op proxy_fallback. Prefer fraggate_call. session_id or id, plus slug and op, are required for an explicit exec. A question in q, question, or text with slug omitted asks the mesh router to pick one live Softwares slug and op. That pick does not exec unless confirm=true. dry_run=true returns the pick and writes nothing. payload is optional and engine-specific; leftover keys are not auto-payload the way fraggate_call leftover keys are. Unknown slugs refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns exec result with engine_slug, engine_op, engine_digest, ran_in, receipt, and refusal when gated.
| Name | Type | Req | Description |
|---|---|---|---|
| attempt_n | integer | – | Optional 1-based attempt number. Omitted increments from the prior session receipt with the same request_id, or 1. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| correlation_id | string | – | Optional client correlation id. Sealed on the session receipt. Null when omitted. |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| id | string | – | Alias of session_id. The door accepts either key; do not send two different values. |
| op | string | yes | Required allowlisted op. Stubs refuse FG-STUB. UI aliases still forward only after FragGate admit. |
| outcome | string | – | Optional sealed status. completed marks the attempt that finished the action. retry and failed are earlier attempts. Defaults from HTTP status when omitted. |
| parent_receipt_id | string | – | Optional prior attempt receipt hash. Null on the first attempt. Omitted links to the prior session receipt with the same request_id. Not FragGate ledger prev. |
| payload | object | – | Optional op payload object. Engine-specific. Unlike fraggate_call, leftover top-level keys are not used as payload. |
| product | string | – | Alias of slug. Do not send two different values. |
| request_id | string | – | Optional logical request id shared by retries of one action. Same value across attempts. Omitted mints a new id for this exec. |
| session_id | string | yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
| slug | string | yes | Required catalog slug to exec. Alias: product. Unknown slugs refuse FG-HALLUC-TOOL. This tool does not auto-open. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Exec body: session, receipt, engine_slug, engine_op, engine_digest, ran_in, refusal when gated. Errors: session_id required, session_closed, session_expired, receipt_cap, FG-HALLUC-TOOL, FG-STUB. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_open Advanced: open a raw session ~519
[advanced/internal] Open a raw session object (session.id). First step of open → policy → exec → receipt(s) → close. Not the default exec path. Use this when you were explicitly asked for raw session plumbing. Do not use it for the default agent exec path or attaching policy to an existing id; use fraggate_call (default) or runtime_session_policy (existing session_id) instead. Write: creates a session with a 6h TTL and receipt cap 64. Re-open on an existing id returns already=true without resetting the chain. Expired sessions refuse session_expired (410). When REQUIRE_TOKEN=1, session mutate needs RUNTIME_TOKEN; missing SESSION binding returns session_binding_missing (503). Prefer leaving sessions to TTL expire. Not chainlock_seal. Empty {} mints sess_ + 32 hex. Optional id is accepted only when it already matches that pattern; otherwise bad_session_id. source is open metadata (default worker). Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns session.id plus the first receipt in the display envelope.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| id | string | – | Optional caller-chosen session id. Must already match sess_ + 32 lowercase hex or the open refuses bad_session_id. Omit to mint one. |
| source | string | – | Optional open metadata label. Default worker. Not a permission and not a catalog slug. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Open body: session.id, receipts[0], already=true when the id already exists. Errors: bad_session_id, session_binding_missing, session_expired. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_policy Advanced: attach session policy ~643
[advanced/internal] Attach allow rules on an already-open raw session (allow_slugs / allow_ops). Policy overlay — not open and not exec. Identity remains Aziel Eliab. Use this when an already-open session needs tighter allow_slugs / allow_ops before exec. Do not use it for executing an op or opening a session; use runtime_session_exec or runtime_session_open (prefer fraggate_call, which applies defaults) instead. Write: mutates session policy only. A sealed session refuses session_closed (409). Expired sessions refuse session_expired (410). Missing both session_id and id fails before the door runs. Does not exec and does not mint a new id. session_id or id (aliases) required. allow_slugs / allow_ops replace the allow overlay when sent; omit them to leave the current lists. max_payload_bytes and kv_increment are optional overlays, not exec payload. Nested policy{} is accepted as the same overlay. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns updated session policy plus a policy receipt.
| Name | Type | Req | Description |
|---|---|---|---|
| allow_ops | array | – | Optional replacement allowlist of ops this session may exec. Omit to keep the current list. |
| allow_slugs | array | – | Optional replacement allowlist of catalog slugs this session may exec. Omit to keep the current list. |
| confirm | boolean | – | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true.… |
| dry_run | boolean | – | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call w… |
| id | string | – | Alias of session_id. The door accepts either key; do not send two different values. |
| kv_increment | boolean | – | Optional. When true, allow KV increment side effects on later exec. Not an increment itself. |
| max_payload_bytes | integer | – | Optional max payload size in bytes for later exec (integer 1..1048576). Overlay only; not the exec body. Out of range refuses bad_policy. |
| session_id | string | yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Policy body: updated session allow lists and a policy receipt. Refuses session_id required, session_not_found, session_closed, session_expired. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_receipt Advanced: last session receipt ~232
[advanced/internal] Read the last receipt only for a raw session — not the full chain. Use this when the user asked for the latest receipt on an open or sealed session. Do not use it for the full receipt chain or product output the user did not ask to audit; use runtime_session_receipts (full chain) or the product display from fraggate_call instead. Does not mutate the session. Unknown id returns session_not_found. An empty receipt list returns receipt=null rather than inventing one. Prefer product output (display) unless the user asked for the chain. session_id or id (aliases) required. No view/limit — this is always the last receipt plus a chain verified flag. Returns the last receipt object (or null) and verified.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Alias of session_id. The door accepts either key; do not send two different values. |
| session_id | string | yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Last-receipt body: receipt (or null), verified chain flag, public session. Errors: session_id required, session_not_found. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_session_receipts Advanced: session receipt chain ~219
[advanced/internal] Read the full receipt chain for a raw session — not the last receipt only. Use this when the user asked for the whole receipt chain. Do not use it for only the last receipt or ordinary product output; use runtime_session_receipt or the product display from fraggate_call instead. Does not mutate the session. Unknown id returns session_not_found. List is the stored chain (cap 64), oldest to newest, plus verified. Prefer product output unless the user asked for the chain. session_id or id (aliases) required. No pagination — the cap is the runtime receipt cap, not a cursor. Returns the receipt list (capped at 64) and verified.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Alias of session_id. The door accepts either key; do not send two different values. |
| session_id | string | yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Receipt-chain body: receipts[] (cap 64), verified, public session. Errors: session_id required, session_not_found. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
runtime_skill How to use this software ~147
Read the agent how-to (one door — discover, route, refuse; pipeline fraggate_list → fraggate_describe → fraggate_call). This is playbook markdown, not a catalog and not a machine manifest. Use this when starting a session or choosing the door before any catalog call. Do not use it for listing hashed registry names, hub Software-tab cards, or executing an engine; use fraggate_list, Softwares, or fraggate_call instead. Dual surface: agent chat has no technical UI chrome; Worker / Flutter / local install stay complete human software. Does not list slugs or run ops. Returns skill markdown plus display.title / display.summary.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
Softwares First call — pick a Softwares slug ~267
Read the Softwares catalog and pick a slug (first call). Not the hashed live/stub registry. Use this when an agent starts, or a hub refreshes the Software tab, and a slug is needed before fraggate_call. Do not use it for executing that slug, hashed live/stub discovery, or library papers; use fraggate_call after the slug is picked, fraggate_list for hashes, or library_lookup for papers instead. Empty {} only. Never enables mesh radios and never execs. tools/list name is Softwares. runtime_software is a tools/call alias and is not a second listed tool. Same JSON as GET /v1/software (also /v1/fraggate/software). Cards carry name, slug, ops, worker_home — not live/stub/digest hashes. EmbryoLock is live-with-local-destructive-boundary (worker_home embryolock-download-tracker). Plain A–Z → Gate A–Z → Lock A–Z (Clock ≠ Lock), including AZChat LIVE+bound. After this catalog, pick a slug and call fraggate_call. library_lookup is for library papers and cites. Returns sorted software cards (name, slug, ops, worker_home) matching GET /v1/software.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| display | object | – | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| door | string | – | Door name. The public door is fraggate. |
| engine_digest | string | – | 64-hex engine_digest when a true in-process engine ran (often inside result). |
| engine_op | string | – | Resolved engine op when present (often inside result). |
| engine_slug | string | – | Resolved engine slug when present (often inside result). |
| ledger_tip | – | – | Ask/refuse ledger tip when the door stamped one. |
| limitations | – | – | Capability limitations or Remain-OFF notes when present. |
| provenance | – | – | Provenance / input packet when the pipeline attached one. |
| ran_in | string | – | Execution locale (for example aziel-runtime) when present. |
| receipt | – | – | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | – | – | Explicit refuse object, code, or message when the door or engine refused. |
| result | – | – | Software-tab catalog JSON (products/cards with name, slug, ops, worker_home, sort lanes Plain→Gate→Lock). Not a hashed registry roster. |
| session_id | string | – | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| status | integer | – | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
No examples provided.
What is the Aziel Runtime MCP server?
Aziel Runtime is an MCP server listed in the public MCP registry as io.github.AzielEliab/aziel-runtime. Governed MCP: agent audit, provenance, deterministic checks, and receipt-backed FragGate execution. This page covers its hosted endpoint (https://aziel-runtime.vibelock.workers.dev/mcp).
Is the Aziel Runtime MCP server safe to use?
Aziel Runtime scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Aziel Runtime MCP server expose?
Aziel Runtime exposes 36 tools: runtime_skill, fraggate_list, fraggate_describe, fraggate_verify, fraggate_call, and 31 more. Their descriptions and schemas cost roughly 15,550 tokens of context every time the server is loaded.
Does the Aziel Runtime MCP server require authentication?
No. We connected to Aziel Runtime without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Aziel Runtime MCP server still maintained?
Aziel Runtime is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.