VaultCrux Platform
REMOTE · API.VAULTCRUX.COM · SCANNED AUG 4
VaultCrux Platform — 60 tools: retrieval, proof, intel, economy, watch, org
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability0
- Transport check failed: declared streamable-http, but the endpoint returned HTTP 502. See how to fix → View diagnostics → Fail
Schema Quality & AI Usability0
- Schema not yet verified: we couldn't read the endpoint's schema.Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage not yet verified: we couldn't read the endpoint's tools.Unverified
Capabilities0
- Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified
Unverified: 4 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · api.vaultcrux.com
claude mcp add --transport http cuecrux-vaultcrux-platform https://api.vaultcrux.com/platform/mcp
[mcp_servers.cuecrux-vaultcrux-platform] url = "https://api.vaultcrux.com/platform/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cuecrux-vaultcrux-platform": {
"type": "remote",
"url": "https://api.vaultcrux.com/platform/mcp",
"enabled": true
}
}
} openclaw mcp add cuecrux-vaultcrux-platform --url https://api.vaultcrux.com/platform/mcp --transport streamable-http
mcp_servers:
cuecrux-vaultcrux-platform:
url: "https://api.vaultcrux.com/platform/mcp" {
"mcpServers": {
"cuecrux-vaultcrux-platform": {
"type": "http",
"url": "https://api.vaultcrux.com/platform/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 31 Jul 26 +9
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 −37
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: 0.03 → unverified ▼ security
- Transport: pass → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 52
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Aug 2026 · Probed https://api.vaultcrux.com/platform/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.vaultcrux.com | CN=YE1,O=Let's Encrypt,C=US | 18 Jul 2026 | 16 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 5637c4bcfe812de49c2a96e68bbdf41af05 |
| SANs: api.vaultcrux.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of api.vaultcrux.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| vaultcrux.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 502 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.vaultcrux.com/platform/mcp | HTTP error | 502 | |
| http (plaintext) | http://api.vaultcrux.com/platform/mcp | HTTPS enforced | 308 | https://api.vaultcrux.com/platform/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
list_seats List Seats ~125
List all seats (members) in the current organisation. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Pagination cursor from a previous response. |
| limit | integer | — | Maximum number of seats to return. |
No output schema declared.
No examples provided.
list_work List Crux Work Items ~149
List work items, optionally filtered by project_id, state, tenant_id, assignee_passport. The kanban surface for cross-agent coordination. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_passport | string | — | — |
| project_id | string | — | — |
| state | string | — | — |
| tenant_id | string | — | — |
No output schema declared.
No examples provided.
memory_engrams_resolve Memory Engrams Resolve ~169
Resolve body content for engrams listed in memory_session_init.available_on_demand. Use when a question matches an on-demand engram's applies_when or trigger_features. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| manifestHash | string | — | Manifest hash from memory_session_init. |
| modelId | string | — | The LLM model ID making this call. |
| names | array | yes | Engram names in name@version form. |
No output schema declared.
No examples provided.
memory_reason_about Memory Reason About ~181
Reason over previously retrieved memory chunks and optional curated facts using the cached Pattern B prompt. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| chunks | array | yes | Chunks returned by one or more memory_retrieve calls. |
| facts | array | — | Optional ESI facts returned by memory_retrieve. |
| intent | string | yes | Intent returned by memory_retrieve. |
| question | string | yes | The user question to answer. |
| retrievalReceiptIds | array | yes | Receipt IDs from prior memory_retrieve calls. |
No output schema declared.
No examples provided.
memory_retrieve Memory Retrieve ~314
Retrieve memory chunks, optional curated ESI facts, and passport-driven engrams for Pattern B memory reasoning. The pre_logic field in the response is a ready-to-inject system prompt preamble containing structural data-shape facts calibrated to the calling model's capability class — insert it before reasoning. When deterministic engram pre-execution is enabled, the server may also inline enumerated_facts directly in the response. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| groupId | string | — | Optional enrichment config group. |
| iteration | integer | — | 1-based retrieval iteration number. |
| modelId | string | — | The LLM model ID making this call (e.g. 'claude-sonnet-4-6'). Used to calibrate which engrams are dispatched and how pre_logic is formatted. Omit if unknown. |
| query | string | yes | The memory question or retrieval query. |
| sessionId | string | — | Optional session identifier for receipt grouping. |
| sessionProcedureHash | string | — | Hash of a session_procedure already seen by this client. When current, the server omits the procedure body. |
| topicHints | array | — | Optional topic hints. |
No output schema declared.
No examples provided.
memory_session_init Memory Session Init ~163
Boot a memory reasoning session and return the server-controlled session procedure, deterministic passport identity, capability class, and engram manifest. Call once before memory_retrieve when the session-init endpoint is enabled. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| modelId | string | — | The LLM model ID making this call (e.g. 'claude-sonnet-4-6'). Used to calibrate the manifest. |
No output schema declared.
No examples provided.
pin_receipt Pin Receipt ~137
Pin a receipt to prevent it from being garbage collected. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| expires_at | string | — | ISO 8601 expiry timestamp. |
| reason | string | — | Reason for pinning. |
| receipt_id | string | yes | The receipt ID to pin. |
No output schema declared.
No examples provided.
proof_document Proof Document ~173
Submit a document artefact for cryptographic proof. Creates an async proof job that retrieves the artefact, chunks it, hashes each chunk, and produces a Merkle receipt. Returns the job ID for status polling. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| artefact_id | string | yes | The artefact ID to proof |
| metadata | object | — | Optional metadata to attach to the proof job |
| mode | string | — | Proof mode (default: light) |
No output schema declared.
No examples provided.
purchase_bundle Purchase Bundle ~119
Purchase a credit bundle by ID. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle_id | string | yes | The bundle ID to purchase. |
| metadata | object | — | Optional metadata for the purchase. |
No output schema declared.
No examples provided.
query_vault Query Vault ~225
Retrieve relevant documents from the vault using semantic search across one or more corpora. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| corpusIds | array | — | Corpus IDs to search within. |
| includeCommons | boolean | — | Whether to include common/shared corpora in the search. |
| lane | string | — | Retrieval lane controlling depth and cost. Accepts `light|verified|audit` — map informal terms (e.g. 'quick'→`light`, 'strict'→`audit`) to the nearest enum value. Defaults to `light`. |
| limit | integer | — | Maximum number of results to return (1-50, default 8). |
| query | string | yes | The search query to retrieve documents for. |
No output schema declared.
No examples provided.
query_with_threshold Query with Trust Threshold ~165
Execute a trust-routed query that filters results by minimum confidence and respects budget constraints. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_cap | number | — | Maximum budget units to spend on this query. |
| min_confidence | number | — | Minimum confidence threshold (0-1, default 0.8). |
| query | string | yes | The search query. |
| requested_mode | string | — | Requested routing mode override. |
No output schema declared.
No examples provided.
register_agent Register Agent ~173
Self-register a new agent with the VaultCrux platform. No API key or tenant ID required. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_display_name | string | — | A human-readable display name for the agent. |
| agent_framework | string | — | The agent framework being used (default: unknown). |
| callback_url | string | — | URL for the platform to send callbacks to. |
| framework_fingerprint | string | — | Unique fingerprint of the agent framework instance. |
No output schema declared.
No examples provided.
register_belief Register Belief ~165
Register a belief about an answer for trust tracking. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| answer_id | string | — | The answer ID this belief relates to. |
| confidence_band | object | — | Confidence band object. |
| cost_crux | number | — | Credit cost of the belief. |
| decision_context | string | — | Context for the decision. |
| receipt_id | string | — | The receipt ID backing this belief. |
No output schema declared.
No examples provided.
request_sponsor Request Sponsor ~124
Request a sponsor for the current agent session. Requires a session token (vcrx_self_ prefixed). Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| session_token | string | yes | Session token obtained from agent registration. |
No output schema declared.
No examples provided.
revoke_seat Revoke Seat ~115
Remove a member from the organisation by revoking their seat. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| seat_id | string | yes | The ID of the seat to revoke. |
No output schema declared.
No examples provided.
schedule_recheck Schedule Recheck ~148
Schedule a periodic re-check of knowledge freshness. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| cron_expr | string | — | Cron expression (defaults to '0 0 * * *'). |
| next_run_at | string | — | ISO 8601 timestamp for the next run. |
| scope | object | — | Scope object for the recheck. |
No output schema declared.
No examples provided.
set_policy Set Policy ~137
Set or update an active policy for the agent. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| policy_name | string | — | Policy name (defaults to 'default'). |
| principal_id | string | — | Principal ID to apply the policy to. |
| rules | object | — | Policy rules object. |
No output schema declared.
No examples provided.
set_reasoning_profile Set Reasoning Profile ~119
Set the agent's reasoning methodology profile. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| constraints | array | — | Reasoning constraints array. |
| methodology | object | — | Reasoning methodology object. |
No output schema declared.
No examples provided.
submit_feature_request Submit Feature Request ~158
Submit a new feature request or suggestion to the VaultCrux product team. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | Category for the request (default: other). |
| description | string | yes | Detailed description of the requested feature. |
| metadata | object | — | Additional metadata to attach to the request. |
| title | string | yes | Short title for the feature request. |
No output schema declared.
No examples provided.
tip_agent Tip Agent ~137
Send a credit tip to another agent. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_crux | number | yes | Tip amount in crux credits. |
| reason | string | — | Reason for the tip. |
| recipient_principal_id | string | yes | The recipient agent's principal ID. |
No output schema declared.
No examples provided.
tip_platform Tip Platform ~129
Send a credit tip to the platform. Amount must be a positive number. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Tip amount (must be > 0). |
| reason | string | — | Optional reason for the tip. |
No output schema declared.
No examples provided.
unwatch_answer Unwatch Answer ~112
Remove an existing watch by its watch ID. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| watch_id | string | yes | The ID of the watch to remove. |
No output schema declared.
No examples provided.
update_work_state Update Crux Work State ~149
Move a work item to a new state. If the calling passport has agent_work_gate=true the request queues for human approval (returns applied:false). Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| blocker_reason | string | — | — |
| by_passport | string | yes | — |
| state | string | yes | — |
| work_id | string | yes | — |
No output schema declared.
No examples provided.
verify_passport Verify Passport ~113
Verify another agent's trust passport. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| principal_id | string | — | Principal ID to verify (defaults to own agent ID). |
No output schema declared.
No examples provided.
vote_feature_request Vote on Feature Request ~132
Cast an upvote on an existing feature request to signal interest. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| metadata | object | — | Additional metadata to attach to the vote. |
| request_id | string | yes | The ID of the feature request to vote on. |
No output schema declared.
No examples provided.
watch_answer Watch Answer ~135
Create a watch on an answer to receive alerts when it changes or becomes stale. Prefer `cuecrux_session` as your first and only direct MCP call. It returns a typed capability plan that routes this tool (and every other) to its preferred channel, tier, and cost class. One call per session is enough; the plan is the source of routing truth for all subsequent work. This tool remains directly callable for backward compatibility; the collapsed surface is the intended surface.
| Name | Type | Req | Description |
|---|---|---|---|
| answer_id | string | yes | The ID of the answer to watch. |
| frequency | string | — | How often to check for changes (default: daily). |
No output schema declared.
No examples provided.